These terms are also available in Norwegian.
Who you are agreeing with
These terms are an agreement between Nrth AI AS and the company or organization that uses Nrth OS. Nrth AI AS makes Nrth OS.
Nrth AI AS · [business address], Bergen, Norway · Org. no. [org.nr]. More about us on the company page.
- General: hello@trynrth.com
- Pilot program: pilot@trynrth.com
- Privacy: privacy@trynrth.com
- Security: security@trynrth.com
In these terms, “we” and “us” mean Nrth AI AS. “You” means the company or organization that uses Nrth OS. “Your users” are the people you give access to. Together, you and we are “the parties”.
The terms cover Nrth OS, including the pilot program. How we handle personal data is described in the privacy policy.
Nrth OS is made for businesses and other organizations. It is not offered to consumers. If you accept these terms on behalf of a company, you confirm that you are allowed to do so.
The agreement is made up of these terms, including the pilot terms below, and the data processing agreement (DPA). If the parties have entered into a separate written agreement, such as a pilot agreement, it applies ahead of these terms where the two differ. For personal data in your content, the DPA applies ahead of these terms.
Nrth OS and the pilot program
Nrth OS is under development. Before open launch, it is offered to a small group of companies in the Nordics and the US in a pilot program. Pilots help decide what gets built.
The features described on this website are still being built, and some may not be ready when your pilot starts. Pilots get access to features as they become ready. Where these terms describe how Nrth OS works or handles data, they describe how it is built to work.
What Nrth OS is
Nrth OS is a workspace where businesses set up AI assistants for parts of their work, such as accounting, marketing, quotes or customer service. It is a hosted service that we run with cloud providers, not software you install.
The first version is being built so that your company can:
- set up assistants, each with its own instructions, sources, skills, memory and data policy
- run tasks now or on a schedule, and get the results in the app and by email
- give feedback on a result and run the task again
- turn a task that works into a skill your assistants can reuse
- connect knowledge: uploaded files, Google Drive files and folders you pick, and SharePoint libraries or OneDrive folders you connect
- let tasks search the web and show their sources
- see what each assistant did, what it cost and where the data was processed
- see what your assistants have learned: their sources, when each source was last synced, and everything in memory
What your assistants learn comes from knowledge, memory and skills. None of it is training a model.
The first version has no chat. It does not read your email, and it does not connect to other business systems, such as accounting or CRM software. You can connect your own model endpoint, but Nrth OS itself does not run on your own machines. Running fully on your own hardware comes in a later version, Nrth Node.
The connection to Microsoft 365 and the connection to your own model endpoint may come somewhat later than the rest of the first version.
Illustrations and examples on this website are labelled as such. They show how Nrth OS is built to work. They are not screenshots of a finished product or live results.
Pilot terms
[pilot terms]
What we ask of pilots is on the pilot page. It costs nothing to apply for the pilot, and applying does not by itself create an agreement to use Nrth OS. How we handle the information in your application is described in the privacy policy.
What to expect during the pilot
- Features can change, be added or be removed while we build.
- We do not promise a set level of availability or response time. Errors can happen, tasks can fail or be delayed, and Nrth OS can be unavailable for periods, for example when we pause it for updates.
- The model catalog can change as we test models. The table under “Every model, labelled” is an example. The final catalog will be published there before launch.
- Your content is stored in your home region, and your tasks are processed as each assistant's data policy allows. Changes to subprocessors are handled as set out in the DPA.
- Nrth OS is not a backup service. Keep your own copies of files that matter. Files in Google Drive and Microsoft 365 stay where they are.
Prices and credits
What pilots pay is set out under Pilot terms above. Prices for open launch will be set before launch and published on the pricing page. Tasks use credits. Nrth OS is built to show an estimate before each task and to stop tasks when your company reaches its limit. Nothing runs up a bill your company has not agreed to.
Acceptable use
Use Nrth OS for lawful work in your business. Your company is responsible for how Nrth OS is used, and for the content it puts in or connects.
You must not use Nrth OS to:
- break the law, or violate other people's rights, such as privacy, copyright or trade secrets
- process content you do not have the right to use
- create or spread content that is illegal, deceptive, harassing or discriminatory, or commit fraud
- send spam or other messages to people who have not asked for them
- make or spread malware, or attack other systems
- carry out practices that are prohibited under the EU AI Act
- make decisions about people based only on results, when those decisions have legal or similarly significant effects, such as hiring, credit, insurance or access to services
Decisions like these must be made or reviewed by a person.
You must also not:
- use Nrth OS in areas the EU AI Act treats as high-risk, unless we have agreed to it in writing first
- try to get around the security of Nrth OS, the separation between companies, credit limits, the limits on each task or other technical limits
- try to reach other companies' data, or parts of Nrth OS you have not been given access to
- hide instructions in documents or web pages to make an assistant act against the people using it
- test, scan or probe the security of Nrth OS without our written permission
- overload Nrth OS in a way that affects other customers, for example with automated requests outside normal use
- copy, decompile or reverse engineer the software, beyond what the law allows
- sell or rent out access to Nrth OS, or let people outside your company use it, unless we have agreed to it in writing
Your company decides who gets access, and is responsible for its users and what they do in Nrth OS. Each user must have their own sign-in and keep it safe. If you think someone has access who should not, tell us right away at security@trynrth.com.
If you find a security weakness, tell us at security@trynrth.com. Model providers have their own rules for what their models can be used for. Tasks that break them can be refused.
If use breaks these rules, or puts other customers or Nrth OS at risk, we can stop tasks or pause access for the users or assistants involved. When we can, we tell you first. We tell you why, unless the law prevents it, and restore access when the problem is fixed. If the breach is serious, we can also end the agreement, as described under Termination.
Your data and results
Your content is yours
As between your company and us, your company's content belongs to your company: the files you upload or connect, the instructions you give, the tasks you run, the results they produce, the feedback you give, and the memory built from your instructions and feedback. We get no ownership of it.
Results are made by AI models. Results made by AI are not always protected by copyright, and other customers may get similar results for similar tasks.
Skills your company builds with the skill builder are kept in your company's library and shared only within your company. [Ownership of skills that customers build with the skill builder.]
What stays ours
Nrth AI AS and its licensors own Nrth OS, including its software, its design, the name Nrth OS, the skills in the Nrth library and this website. Some parts of Nrth OS are open-source software used under their own licenses. While the agreement lasts, your company may use Nrth OS in its business under these terms.
If you send us suggestions about Nrth OS itself, for example in calls with us or by email, we may use them freely to improve the product, with no obligation to you. This does not include your content. The feedback you give on results inside Nrth OS is part of your content. It is used only for your company's own assistants, for example in memory and when you run a task again.
How we use your content
Your company gives us the right to use its content for one purpose only: to provide Nrth OS to your company. For that purpose we can:
- store it
- index it as knowledge
- write memory from your instructions and feedback
- send it to the models your assistant's data policy allows
- use it in the web searches your assistants make
- keep logs of each run for operations, security, fixing faults and cost
- show and deliver results in the app and by email
We do not use it for anything else, unless the law requires it.
- No model is trained on your content. Nrth OS learns through the knowledge you connect, the memory you can read and edit, and the skills you approve.
- We do not sell your content or use it for advertising.
- We share it only with the subprocessors needed to run the service, such as the model providers your assistant's data policy allows. If an assistant uses Our own model, its tasks also go to the model endpoint your company has connected. The list of subprocessors will be published in the privacy policy before launch.
- People at Nrth AI AS do not look at your content, except when you ask us to (for example when you need help), when it is needed to keep Nrth OS secure, or when the law requires it.
Nrth OS is being built to the rules listed under How Nrth OS is built. A full security page and the DPA will be published before launch.
Personal data
Nrth AI AS is the controller for account data, such as users, sign-in and billing. For the content your company puts into or connects to Nrth OS, your company is the controller and Nrth AI AS is the processor. We process that content only on your company's instructions.
We enter into a data processing agreement (DPA) with each customer. Companies in the pilot program enter into the DPA before they add any content to Nrth OS. The DPA lists the subprocessors that will process their content.
Your company is responsible for having a lawful basis for personal data in its content, and for informing the people it concerns where the law requires it.
The privacy policy describes how we process account data, which subprocessors we use (the list will be published before launch), and how people can use their rights, including the right to complain to a data protection authority, such as Datatilsynet in Norway.
Where your content is processed
Your company chooses a home region when it signs up: the EU (Frankfurt) or the US. It cannot be changed afterwards. Your files, knowledge index and memory are stored in that region. Account data, such as company and user details, is stored in the EU for all customers.
Each assistant has a data policy that decides where its tasks can be processed. For a company with the EU as home region, the choices are:
- In the EU (the default): processed in the EU. Some of these providers are US-owned and subject to US law, whatever the region. We label them, so you can choose.
- European providers only: processed in the EU by EU-owned providers only.
- Our own model: tasks go to your company's own model endpoint, not to a model we provide. Your company chooses the model, and is responsible for that endpoint and for the provider it chooses to run it. What happens to data there is between your company and that provider.
Our own model may not be available when your pilot starts.
Companies with the US as home region get the same kind of choice, with processing in the US as the default. When a task searches the web, the search query goes to a web search provider for your home region.
When personal data is transferred out of the EU/EEA, we use the EU standard contractual clauses (SCCs) or the EU–US Data Privacy Framework where it applies. More about how your data is handled is on the Your data page.
Memory
Memory is what Nrth OS keeps from your instructions and feedback, in two layers: about the company, and about each assistant. You can read, change or delete every line, or delete all of it at once.
Some things are never written to memory, whatever you tell it: ID numbers, payment card and account numbers, health information, information about children, and special categories of personal data under GDPR article 9. See What it never keeps.
These rules apply to memory. Files you upload or connect as knowledge are indexed with the content they contain. Add only the files and folders an assistant needs.
Google Drive and Microsoft 365
You decide what Nrth OS can read. When you connect Google Drive or Microsoft 365, the person who connects gives Nrth OS access on their behalf.
- Google Drive. Nrth OS uses the drive.file permission. It gives access only to the files and folders that person picks with the Google Picker, not to the rest of their Drive. With openid, email and profile, Nrth OS gets the name, email address and profile picture of the person who connects the account, so it can identify that person and the connected account.
- Microsoft 365. Nrth OS uses Microsoft Graph with the delegated permissions Files.Read, Sites.Read.All, User.Read and offline_access. Delegated means Nrth OS acts for the person who connects a source, and can only reach what that person already has access to. Files.Read gives read access to that person's own files in OneDrive, and Sites.Read.All to the SharePoint sites that person can access. Nrth OS still reads and indexes only the SharePoint libraries and OneDrive folders you connect as sources. User.Read gives Nrth OS the sign-in profile, such as name and email address, of the person who connects the source. offline_access lets scheduled sync run when that person is not signed in. Depending on your organization's settings, your IT administrator may need to approve Nrth OS first.
Nrth OS fetches the files from these sources, splits the text into excerpts and stores the excerpts in a searchable index in your company's home region. The assistant uses them as knowledge in its tasks. In the first version, sources are synced daily and when you ask for it. The files themselves stay in Google Drive or Microsoft 365.
Content from these sources:
- is sent to the models the assistant's data policy allows, in excerpts when it is indexed, and in excerpts or as whole files when a task uses it
- is never sold and never used for advertising
- is not used to train AI models
- is not shared except with the subprocessors needed to run the service and, if the assistant uses Our own model, the model endpoint your company has connected
- is deleted from the index when you remove the source
Results and workspace files made with this content stay in your company's workspace after the source is removed.
Nrth OS is built to keep the keys that give access to your connected accounts in an encrypted vault, never in the task itself. The person who connected a source can also remove Nrth OS's access in their Google or Microsoft account settings, or your IT administrator can do it for your organization. Sync then stops, but what is already indexed stays until you remove the source in Nrth OS.
Nrth OS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The privacy policy describes in more detail how Nrth OS accesses, uses, stores and shares data from Google and Microsoft.
Your company must have the right to connect the accounts, files and libraries it chooses, and must follow its own rules for them. Your use of Google and Microsoft services is also governed by their terms.
Nrth OS is an AI system
The EU AI Act asks for openness about AI systems. This is what that means for Nrth OS.
- Nrth OS is an AI system. Its results are made by AI models, not written by a person.
- Results can be wrong, incomplete or out of date, even when they read well. Check them before you use them, share them or base decisions on them, especially numbers, accounts, contracts and text that will be sent out.
- Which models are used, and where, is shown in the model catalog. Each model is labelled with where it processes data, where the provider is based and what it keeps. In Nrth OS, this is shown under “Details”. The table under “Every model, labelled” is an example. The final catalog is set after testing and will be published there before launch.
- The data policy you choose for an assistant decides which models it can use. How thorough you ask a task to be, Quick, Standard or Thorough, decides which class of model is used.
- Nrth OS learns through the knowledge you connect, the memory it builds from your feedback and the skills you approve. None of this is training. No model is trained on your content.
- Nrth OS is built so that actions with effects outside Nrth OS, such as sending something on your behalf, need your approval first. What you approve is your company's responsibility. Delivering results to you in the app and by email, searching the web during a task and syncing the sources you have connected do not need separate approval.
- Documents and web pages can contain hidden instructions. Nrth OS is being built so that every skill is tested against attempts to slip instructions in this way. We cannot guarantee that every attempt is stopped.
Your company is responsible for how it uses results, including telling others that content was made with AI where the law requires it. It is up to your company to assess when that applies.
Limitation of liability
Nrth OS helps with work. It does not replace professional judgement. Your company is responsible for how results are used, for example in accounts, quotes, contracts or messages to customers. We are not liable for loss caused by a result being used without being checked.
During the pilot, Nrth OS is provided “as is”. It is still being built. We work to keep it running and your content safe, but we do not promise that it is free of errors, that it is always available or that results are correct.
We are not liable for indirect losses, such as lost profit, lost revenue, lost savings, lost contracts, business interruption, lost data or claims from third parties.
Our total liability under the agreement is limited to [liability cap].
These limits do not apply to loss caused intentionally or by gross negligence, or where the law does not allow liability to be limited. Liability for personal data is also regulated in the DPA.
Neither party is liable for delays or failures caused by events outside its control that it could not reasonably have foreseen or avoided.
Your company is liable to us for loss caused by breaking the rules on acceptable use, for example if someone claims compensation from us because content your company put into Nrth OS violates their rights.
Termination
The pilot lasts [pilot length].
Your company can end the agreement with [notice period for customers] notice, by email to hello@trynrth.com, or to pilot@trynrth.com if you are in the pilot program.
We can end the agreement with [notice period for Nrth AI AS] notice. If we close the pilot program or change our plans for the product, we tell you as early as we can.
We can end the agreement with immediate effect if your company seriously breaks these terms and does not put it right within a reasonable time after we have told you, or if the law requires us to.
When the agreement ends
- Your users lose access to Nrth OS.
- Before that, you can download your results and export your memory. Skills your company built cannot be exported in the first version.
- Nrth OS's access to your connected Google and Microsoft accounts ends, and the stored keys are deleted.
- We delete your content from your home region within [deletion period after termination], unless the law requires us to keep it or the DPA says otherwise. This covers files, knowledge indexes, memory, results and the skills your company built.
- Account and billing records we must keep by law, such as accounting records, are kept for as long as the law requires. The privacy policy has the details.
The parts of these terms on ownership, liability, governing law and venue still apply after the agreement ends.
Governing law
These terms and the agreement are governed by Norwegian law.
We are working on separate terms for customers based in the US. [Governing law and venue for customers based in the US, set before the US launch.]
Venue for disputes
If the parties disagree, they first try to solve it through negotiation. If that does not work, disputes are settled by the Norwegian courts, with [agreed venue court] as the agreed venue.
Changes to these terms
These terms are written for the pilot phase. We may change them, for example when the product changes or when the law changes.
When we change the terms, we update the date on this page. If a change affects your company's rights or obligations, we tell your company's contact person by email at least [notice period for changes] before it takes effect. If your company does not accept the change, it can end the agreement before the change takes effect. If it keeps using Nrth OS after the change takes effect, it accepts the new terms.
Questions about these terms: hello@trynrth.com.