Legal
Privacy Policy
This policy explains what personal data Nordic Cloud ApS processes, why we process it and what rights you have under the General Data Protection Regulation and the Danish Data Protection Act.
1. Data controller
Nordic Cloud ApS, Lundeborgvej 71, 6000 Kolding, Denmark, is the data controller for personal data collected through this website and in the course of our client engagements. Where we process data on behalf of a client, for example inside their advertising or analytics accounts, that client is the controller and we act as processor under a separate data processing agreement.
2. What we collect
We limit collection to what the purpose requires. In practice this means:
- Enquiry data. Name, company, website address and the description you submit through the forms on this site.
- Subscription data. The work email address you provide for our monthly field notes.
- Technical data. IP address, browser and device type, referring page and pages viewed, collected in aggregate for security and performance monitoring.
- Analytics data. Anonymised usage statistics, collected only after you accept analytics cookies.
We do not ask for special category data and request that you do not include it in free-text fields.
3. Purpose and legal basis
- Responding to enquiries — processing is necessary to take steps at your request prior to entering a contract, Article 6(1)(b) GDPR.
- Delivering engagements — performance of a contract, Article 6(1)(b) GDPR.
- Field notes subscription — your consent, Article 6(1)(a) GDPR, withdrawable at any time through the unsubscribe link in every message.
- Site security and performance — our legitimate interest in operating a secure and functional website, Article 6(1)(f) GDPR.
- Analytics cookies — your consent, given through the cookie banner and withdrawable at any time.
4. Cookies
Essential cookies keep the site functional and record your consent choice. Nothing else is set until you accept. Analytics cookies help us understand which pages answer visitor questions and which do not. We do not place advertising or cross-site tracking cookies on this website.
You can change your choice at any time by clearing this site’s storage in your browser settings, which restores the consent banner on your next visit.
5. Processors and recipients
We use a small number of service providers to host this website, deliver email and operate analytics. Each is bound by a data processing agreement that restricts them to processing on our documented instructions. We do not sell personal data and we do not share it with advertising networks.
Where a provider processes data outside the European Economic Area, transfers are covered by the European Commission’s Standard Contractual Clauses together with supplementary technical measures such as encryption in transit and at rest.
6. Retention
- Enquiries that do not lead to an engagement are deleted after 12 months.
- Client records are retained for the duration of the engagement and for five years afterwards, in line with Danish bookkeeping requirements.
- Subscription data is retained until you unsubscribe.
- Server logs are retained for 90 days.
7. Your rights
Under the GDPR you have the right to:
- Request access to the personal data we hold about you.
- Have inaccurate data corrected or incomplete data completed.
- Request erasure where the data is no longer necessary for the purpose.
- Request restriction of processing, or object to processing based on legitimate interest.
- Receive your data in a portable, machine-readable format.
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, submit a request through the form on our homepage stating clearly which right you are invoking. We respond within one month. If you believe we have handled your data incorrectly, you may lodge a complaint with the Danish Data Protection Agency, Datatilsynet.
8. Security
Access to personal data is restricted to the team members who need it for their work. Data in transit is protected with TLS, infrastructure is hosted within the European Union, and access to client systems is granted on a least-privilege basis and revoked when an engagement ends.
9. Changes to this policy
We update this policy when our processing activities or the underlying legal requirements change. The revision date at the top of the page always reflects the current version. Material changes affecting active clients are communicated directly.
Have a question about how we handle data in an engagement?
Send us the question