GDPR self-serve
Norma operates under UK GDPR. You have eight rights over your data; this article covers what each one means in practice and how to action it self-serve from the account.
The eight rights
- Right to be informed. What we collect and why; covered by the privacy policy at <a href="/legal/privacy">/legal/privacy</a>.
- Right of access. A copy of the data we hold on you. Self-serve below.
- Right to rectification. Correct anything wrong. Self-serve from "Account settings".
- Right to erasure. Delete personal data. Self-serve plus retention notes below.
- Right to restrict processing. Pause processing while a dispute is resolved.
- Right to data portability. Get the data in a machine-readable format.
- Right to object. Opt out of profiling, marketing, or other specific processing.
- Right not to be subject to automated decision-making. Be able to challenge automated decisions.
How to export your data
- Sign in to your account.
- Go to "Account settings > Data and privacy".
- Click "Export my data".
We package everything into a single zip:
- Profile data: name, email, addresses, phone (if provided), marketing preferences.
- Orders: all orders, line items, designs uploaded, recipients (where you placed multi-recipient orders).
- Workspaces: workspaces you belong to and your role in each.
- Audit log: sign-ins, password changes, address changes.
Export is ready within 1 working day. We email a download link valid for 7 days. The zip is password-protected with the password sent in a separate email.
How to correct data
From "Account settings", you can change:
- Name, email, phone. Self-serve.
- Addresses. Edit or delete saved addresses.
- Marketing preferences. Toggle each marketing channel on or off.
- Notification preferences. Toggle each transactional notification on or off (some, like order confirmations, are not toggleable for legal and operational reasons).
For corrections to historical orders (e.g. a misspelled recipient name on a past order), reply to the order email or contact support@normamade.com.
How to restrict processing
Restriction pauses processing while a dispute is being resolved. To request:
- Go to "Account settings > Data and privacy".
- Click "Restrict processing".
- Pick which processing to restrict: marketing, analytics, third-party sharing.
Marketing and analytics restrictions take effect immediately. Order-related processing (we need your address to ship) cannot be restricted while orders are in flight.
How to object
Use the "Restrict processing" flow above; mark the specific processing you object to. Marketing opt-outs take effect within 1 working day across our systems and downstream tools.
Subject Access Request via email
If the self-serve export does not cover what you need, send a Subject Access Request to privacy@normamade.com with:
- The email on the account.
- What specifically you are asking for (e.g. logs of every sign-in for the last 12 months).
- Proof of identity (we will ask for a copy of photo ID for non-trivial requests).
We respond within 1 month per UK GDPR. For most requests we respond within 5 working days.
See also
- <a href="/help/articles/account-deletion">Account deletion</a>: the right to erasure in practice.
- <a href="/legal/privacy">Privacy policy</a>: the full detail.
- <a href="/legal/cookies">Cookies policy</a>: cookie-level consent.