Privacy Policy
Version 2026-07-14 · Effective 7/14/2026
DATA PRIVACY POLICY
NOAL AI, Inc.
Version 2026-07-14 · Effective July 14, 2026
Last Updated: July 14, 2026
NOAL AI, Inc., a Delaware corporation with its principal place of business at 175 S. 3rd Street, Suite 200, Columbus, Ohio 43215 (“NOAL AI,” “we,” “us,” or “our”), is committed to protecting the privacy and security of the data provided by our subscribers and users. This Data Privacy Policy (this “Policy”) explains how we collect, use, disclose, retain, and safeguard your information when you access or use the websites operated by NOAL AI at noal.ai and its subdomains (the “Site”) and the NOAL AI software-as-a-service product suite, application programming interfaces, applications, integrations, and related products and services (collectively with the Site, the “Services”).
PLEASE READ THIS POLICY CAREFULLY. THIS POLICY IS INCORPORATED INTO AND FORMS PART OF THE NOAL AI TERMS OF SERVICE. BY ACCESSING, REGISTERING FOR, OR USING THE SERVICES, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTAND THIS POLICY. THIS POLICY INCLUDES A LIMITATION ON LIABILITY FOR UNCONTROLLABLE EVENTS (SECTION 9) THAT AFFECTS YOUR LEGAL RIGHTS.
Scope. This Policy applies only to personal information collected by NOAL AI in connection with the Services from individuals who (a) execute an Order Form or register for an account (“Subscribers”); (b) are Authorized Users of a Subscriber; (c) visit the Site as a prospective customer; or (d) otherwise interact directly with NOAL AI in a business context (collectively, “Users” or “you”). This Policy does not apply to, and NOAL AI disclaims responsibility for, the privacy practices of any third party, including any third-party site, integration, advertiser, or service that may be linked to or accessible through the Services, or the privacy practices of any of our Subscribers or their clients.
Users Only; No Third-Party Rights. This Policy creates rights, expectations, and obligations only between NOAL AI and the individual User to whom it applies. It does not create any rights or obligations in favor of, and is not enforceable by, any third party, including any client, investor, borrower, lender, counterparty, prospect, or beneficiary of any User or of any Subscriber. Where the Services are used to process information about non-Users (for example, individuals whose information appears in Subscriber Data uploaded by a Subscriber, such as borrowers or counterparties identified in T12 statements, rent rolls, or loan documents), NOAL AI processes that information solely as a service provider or processor on behalf of the applicable Subscriber, and the Subscriber—not NOAL AI—is responsible for providing privacy notices to, and obtaining any necessary consents from, such individuals.
Services Designed for Institutional Use. The Services are designed for, and offered only to, institutional investors, financial professionals, and their authorized personnel for business purposes. The Services are not directed to, and are not intended for use by, individual consumers or children, and NOAL AI does not knowingly collect personal information directly from children under the age of sixteen (16). If we learn that we have collected personal information from a child without appropriate authorization, we will delete it.
- Data Collection
1.1 Subscriber-Provided Data
We collect data you explicitly provide, including:
Account Information: name, business email, business phone, job title, company name, credentials, and similar information for account registration and Team Management.
Financial Assets and Deal Materials: T12 statements, rent rolls, loan documents, leases, appraisals, operating statements, offering memoranda, Waterfall Configurations, and other financial documents uploaded for Portfolio Analysis, underwriting, loan analysis, or return analysis.
Payment Data: billing address, credit card and other billing information, processed securely via our payment-processing subprocessor, Stripe, Inc. We do not store full payment-card numbers on our systems.
Communications: the contents of messages, emails, support tickets, survey responses, and other communications you send to us, including to support@noal.ai.
Recruiting Information: where you apply for a job with NOAL AI, your resume, work history, references, and similar information.
1.2 Automated Data Collection
We collect technical data automatically when you access or use the Services, including:
Device and technical information: IP addresses, device identifiers, browser type and version, operating system, language preferences, time-zone setting, referring/exit URLs, and similar information.
Usage data: pages and features viewed or used, tokens consumed (Token Usage), session duration, navigation paths, error logs, and performance metrics, to monitor performance and prevent unauthorized access.
Cookies and similar technologies: information collected through cookies, web beacons, pixels, software development kits, local storage, and similar technologies, as further described in our Cookie Policy.
AI-interaction telemetry: prompts, instructions, and inputs you submit to AI-enabled features, the resulting Generated Output, and quality signals such as edits, thumbs-up/down, regenerations, and ratings.
1.3 Information from Third Parties
Authentication providers (e.g., single sign-on identity providers) when you choose to sign in using a third-party identity.
Payment processors and billing providers, including Stripe.
Marketing, sales-intelligence, analytics, and lead-enrichment vendors.
Your employer or organization (in connection with a Subscriber subscription) and its administrators.
Publicly available sources, such as professional networking sites and business directories.
- Use of Data
2.1 Service Provision. We use Subscriber Data to provide and operate the Services, including to generate underwritings, proformas, valuations, loan analyses, return analyses, submarket benchmarks, and “Buy, Hold, or Sell” recommendations and other Generated Output, to authenticate Users, process transactions, provide customer support, and communicate about the Services.
2.2 AI Model Optimization. Your Data is Yours. We do not sell your raw financial data to third parties. We do not use identifiable Subscriber Data to train our generative AI models, and we contractually require our AI subprocessors not to use Subscriber Data to train their generative AI models, unless expressly authorized in writing by the applicable Subscriber. We may use de-identified, aggregated, or anonymized data to improve our machine-learning models and provide submarket benchmarks and analytics. We may use prompts, inputs, Generated Output, and quality signals from AI-enabled features to operate the feature, perform abuse and safety monitoring, and debug; provided that we will not use such data to train generative AI models except in de-identified, aggregated, or anonymized form.
2.3 Service Improvement. We use information to improve, develop, and personalize the Services, analyze usage patterns, debug, test new features, and conduct research.
2.4 Communication. We use contact information to send onboarding materials, critical system alerts, security notifications, and administrative communications relating to your account or the Services, and (in accordance with applicable law and your communication preferences) marketing communications about NOAL AI products and services.
2.5 Compliance; Enforcement; Safety. We use information to monitor and enforce compliance with our Terms of Service, Acceptable Use restrictions, and applicable law; to detect, investigate, and prevent fraud, abuse, security incidents, and other unlawful or harmful activity; to comply with applicable laws, legal process, governmental requests, and our legal, regulatory, contractual, and accounting obligations; and to establish, exercise, or defend legal claims, and to protect the rights, property, and safety of NOAL AI, our Users, and others.
Where required by applicable law, we rely on the following legal bases for processing: (a) the performance of a contract with you or your organization; (b) our legitimate interests, which include operating, securing, and improving the Services; (c) compliance with legal obligations; and (d) your consent, where applicable. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
- Data Sharing and Disclosure
3.1 Authorized Users. Your data is shared within your designated team based on the roles you assign within the Services. We are not responsible for your organization’s internal access decisions or its privacy practices.
3.2 Third-Party Sub-Processors. We share data with trusted sub-processors necessary for the Services, including cloud infrastructure (e.g., Amazon Web Services), payment processing (e.g., Stripe), authentication, dedicated LLM API providers (e.g., OpenAI, Anthropic, Google), transactional email, analytics, and similar service providers. A current list is available at noal.ai/sub-processors (our "Sub-Processor List"). Each sub-processor is bound by a written data-processing agreement that imposes confidentiality and security obligations consistent with this Policy.
3.3 Affiliates. We may share personal information with our parent, subsidiaries, and other Affiliates for the purposes described in this Policy.
3.4 Professional Advisors. We may share personal information with our auditors, attorneys, accountants, insurers, and similar professional advisors under duties of confidentiality.
3.5 Business Transfers. We may share or transfer personal information in connection with, or during negotiations of, any merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider.
3.6 Legal Requirements. We may disclose information if required by law, regulation, court order, subpoena, or other legal process, or to respond to lawful requests by governmental or regulatory authorities, to enforce our Terms of Service or other agreements, to protect the rights, property, safety, or security of NOAL AI, our Users, or others, or to detect, prevent, or address fraud, security, or technical issues.
3.7 With Your Consent; Aggregated Data. We may share personal information with your consent or at your direction. We may also share aggregated, de-identified, or anonymized information that does not identify you with any third party for any lawful purpose, including marketing, research, and benchmarking.
WE DO NOT SELL YOUR RAW FINANCIAL DATA OR YOUR PERSONAL INFORMATION FOR MONEY, AND WE DO NOT SHARE PERSONAL INFORMATION FOR CROSS-CONTEXT BEHAVIORAL ADVERTISING, AS THOSE TERMS ARE DEFINED UNDER APPLICABLE U.S. STATE PRIVACY LAWS.
- Data Security
4.1 Encryption. All Subscriber Data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher.
4.2 Access Control. We implement strict internal access controls to ensure that NOAL AI employees only access Subscriber Data when necessary for technical support or as requested by the Subscriber. Access is logged and reviewed.
4.3 Organizational Safeguards. We maintain administrative, technical, and physical safeguards designed to protect Subscriber Data, including network segmentation, vulnerability management, security monitoring, secrets management, and personnel training.
4.4 No Guarantee. Notwithstanding the foregoing, no system or method of transmission over the Internet is completely secure, and we cannot guarantee the security of your personal information. You are responsible for safeguarding your credentials and for promptly notifying us of any unauthorized use of your account.
- Data Retention and Deletion
5.1 Active Subscription. We retain Subscriber Data as long as your account is active and as needed to provide the Services.
5.2 Termination; Data Export. Upon termination of your Terms of Service or applicable Order Form, you may export your Subscriber Data from the platform using the Services’ standard export functionality. Subscriber Data is retained unless and until you request its deletion as described in Section 5.3.
5.3 Right to Deletion. Users may request the deletion of their personal account data at any time by contacting support@noal.ai. We will respond within thirty (30) days, or such shorter time as required by applicable law. We may retain certain information as permitted or required by law (for example, to comply with legal obligations, resolve disputes, or enforce our agreements).
5.4 General Retention Schedule. Retention periods are determined based on (a) the duration of our relationship with you or your organization; (b) the existence of any legal, regulatory, accounting, tax, or contractual obligation; (c) the need to defend or pursue legal claims; and (d) our legitimate business interests.
- Privacy Rights
6.1 Ohio Stewardship. Consistent with Ohio consumer protection standards, we provide transparency regarding our data practices. While Ohio does not currently have a comprehensive “CCPA-style” state law, we adhere to high standards of data stewardship to protect your corporate and personal information.
6.2 U.S. State Privacy Rights. Subject to and to the extent provided by applicable U.S. state privacy laws (including the California Consumer Privacy Act, as amended (“CCPA”), and analogous laws in other U.S. states), residents of certain states may have rights to (a) request access to or a copy of personal information; (b) request correction of inaccurate personal information; (c) request deletion of personal information; (d) opt out of “sales” or “sharing” of personal information for cross-context behavioral advertising or out of certain profiling; and (e) appeal a denial of a request. We do not engage in “sales” or “sharing” of personal information as those terms are defined under such laws. To exercise these rights, please submit a verifiable request to support@noal.ai or privacy@noal.ai. You may use an authorized agent to submit a request on your behalf with appropriate documentation of authority. We will not discriminate against you for exercising your rights.
6.3 EEA, UK, and Switzerland. Subject to and to the extent provided by applicable European data-protection laws (including the EU General Data Protection Regulation and the U.K. GDPR), residents of the European Economic Area, the United Kingdom, and Switzerland may have rights to (a) access; (b) rectification; (c) erasure; (d) restriction of processing; (e) data portability; (f) objection (including to processing based on legitimate interests and to direct marketing); and (g) withdraw consent. You may exercise these rights by contacting privacy@noal.ai. You also have the right to lodge a complaint with the data-protection authority in your country.
6.4 Subscriber Data. If you wish to exercise privacy rights with respect to personal information contained in Subscriber Data, please direct your request to the applicable Subscriber. We will reasonably assist the Subscriber to respond, as required by our data-processing agreement with the Subscriber.
6.5 Do Not Track. We do not currently respond to “Do Not Track” browser signals, as no consistent industry standard has been adopted. Where required by applicable law, we honor recognized opt-out signals (such as the Global Privacy Control) for the categories of processing subject to opt-out under the applicable law.
6.6 Marketing Opt-Out. You may opt out of receiving marketing emails from us by following the unsubscribe instructions in the email or by contacting privacy@noal.ai. We may continue to send you administrative communications relating to your account or the Services.
-
International Data Transfers
NOAL AI is headquartered in the United States, and we process personal information in the United States and in other jurisdictions where we and our sub-processors operate. The data-protection laws of these jurisdictions may differ from those of your country. Where required by applicable law, we use lawful transfer mechanisms, such as the European Commission’s Standard Contractual Clauses, the U.K. International Data Transfer Addendum, and the EU-U.S. Data Privacy Framework (and the U.K. and Swiss extensions thereof), to govern transfers of personal information from the European Economic Area, the United Kingdom, and Switzerland to the United States and other countries. -
Third-Party Sites, Integrations, and Services
The Services may contain links to, or integrations with, third-party websites, applications, or services that are not owned, operated, or controlled by NOAL AI. We are not responsible for the privacy practices, content, or availability of any such third-party sites, integrations, or services. We encourage you to review the privacy notices of any third-party site or service you visit or use. Your use of any third-party site or service is at your own risk and subject to that third party’s terms and privacy notice. -
Limitation of Liability for Uncontrollable Events (Force Majeure)
9.1 LIMITATION OF LIABILITY. NOTWITHSTANDING ANY OTHER PROVISION IN THIS POLICY OR THE TERMS OF SERVICE, NOAL AI, INC. SHALL NOT BE HELD LIABLE FOR ANY DATA BREACH, UNAUTHORIZED ACCESS, LOSS, OR CORRUPTION OF SUBSCRIBER DATA OR PERSONAL INFORMATION RESULTING FROM EVENTS BEYOND OUR REASONABLE CONTROL.
9.2 SCOPE OF EXEMPT EVENTS. THESE EVENTS INCLUDE, WITHOUT LIMITATION: TERRORISM; CYBER-WARFARE (INCLUDING STATE-SPONSORED ATTACKS); RANSOMWARE; ZERO-DAY EXPLOITS; ADVANCED PERSISTENT THREATS; DENIAL-OF-SERVICE ATTACKS; GOVERNMENTAL ACCESS OR DISCLOSURE MANDATES; NATURAL DISASTERS; PANDEMICS; AND LARGE-SCALE UTILITY, INTERNET, OR CLOUD-INFRASTRUCTURE OUTAGES, INCLUDING ANY BREACH OCCURRING AT THE SUB-PROCESSOR LEVEL PROVIDED THAT NOAL AI HAS MAINTAINED COMMERCIALLY REASONABLE SECURITY STANDARDS IN ITS SELECTION AND OVERSIGHT OF SUCH SUB-PROCESSORS.
9.3 ASSUMPTION OF RISK. BY USING THE NOAL AI PRODUCT SUITE, THE SUBSCRIBER AND EACH USER ACKNOWLEDGE THAT NO DIGITAL ENVIRONMENT IS 100% SECURE AND ASSUME THE RISK OF DAMAGES ARISING FROM THE UNCONTROLLABLE EVENTS LISTED ABOVE, TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW. THIS SECTION SUPPLEMENTS, AND DOES NOT LIMIT, THE LIMITATIONS OF LIABILITY SET FORTH IN THE TERMS OF SERVICE.
-
Children’s Privacy
The Services are not directed to children under the age of sixteen (16), and we do not knowingly collect personal information from children. If you believe that we have collected personal information from a child without appropriate authorization, please contact privacy@noal.ai, and we will take appropriate steps to delete the information. -
Notice to California Residents
Without limiting Section 6, this Section provides additional disclosures required by the CCPA. The categories of personal information we have collected, the sources, the purposes for collection, and the categories of recipients with which we have disclosed personal information in the prior twelve (12) months are summarized below. We do not “sell” or “share” personal information as those terms are defined in the CCPA.
Retention. We retain each category of personal information for the period described in Section 5.
Shine-the-Light. California residents may request information about our disclosure of personal information to third parties for direct-marketing purposes by writing to privacy@noal.ai.
-
Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will post the revised Policy on the Site, update the “Last Updated” date, and, where reasonably feasible, notify you by email or through the Services. Your continued use of the Services after the effective date of any update constitutes your acknowledgment of the updated Policy. -
Contact Us
If you have questions or concerns about this Policy or our privacy practices, or to exercise privacy rights or request deletion of your personal account data, please contact us at:
NOAL AI, Inc.
Attn: Privacy Office175 S. 3rd Street, Suite 200 Columbus, Ohio 43215
Email: privacy@noal.ai | support@noal.ai
© 2026 NOAL AI, Inc. All rights reserved.