Legal

Privacy Policy

This policy explains how Nördia may process personal information through this website and in connection with website enquiries.

01

Who we are

Nördia AB is a Swedish company providing software engineering, product development and managed technology services. Current company details are available in the legal information published on this website.

02

Information we may receive

Depending on how the website is used, we may receive a name, email address, telephone number, company details, information submitted in a project enquiry, technical request data and information generated by analytics or cookie technologies where the required consent has been given.

03

Why information is processed

We may process information to respond to enquiries, assess or deliver an engagement, administer a commercial relationship, protect the website and systems, maintain records or meet applicable legal obligations.

04

Legal basis

Depending on the activity, processing may rely on steps taken before entering into a contract, performance of a contract, legitimate interests, consent or a legal obligation. The applicable basis depends on the purpose of the processing and the information involved.

05

Service providers and international processing

Nördia may use service providers for hosting, email, security, monitoring and other operational functions. The relevant provider and international-transfer considerations depend on the services in use.

06

Retention and individual rights

Information should not be retained longer than necessary for its purpose or applicable legal obligations. Depending on the circumstances and governing law, rights may include access, correction, erasure, restriction, objection, portability and withdrawal of consent.

07

Security

Nördia applies technical and organisational measures intended to protect information in a manner appropriate to the service and risk. No internet-connected system or method of transmission can be guaranteed to be completely risk-free.

08

Data minimisation is part of the website design

We aim to collect information that is relevant to the service or enquiry rather than asking for data simply because a field can be added. Collecting less unnecessary information reduces what later has to be secured, retained and deleted.

Where a project requires more sensitive information, the appropriate handling should be defined for that engagement rather than inferred from this public website.

09

Access to personal information should follow operational need

Information submitted through the website may need to be available to people handling enquiries, administration or technical support, but access should remain proportionate to the task. Internal convenience alone is not a reason for broad access.

Where systems supporting the website provide access controls, those controls should be used to limit exposure and keep sensitive administration separate from ordinary public functionality.

10

Security measures cannot eliminate all risk

Reasonable technical and organisational controls can reduce risk, but no internet service can guarantee that unauthorised access, loss or disruption will never occur. Security therefore needs more than one layer, including prevention, detection, recovery and incident handling.

Project-specific systems may require materially stronger measures than this public website depending on data sensitivity, regulatory context and operational consequence.

11

Changes to providers should be reflected in the policy

Providers used for hosting, email, analytics, security or other operational functions may change over time. The policy is intended to reflect the services in use rather than list hypothetical tools for completeness.

Where a provider processes personal data on Nördia's behalf, relevant contractual and transfer requirements should be considered according to the applicable role and jurisdiction.