Ga naar inhoud

Privacy policy

Privacy policy

Last updated: 5 October 2026

This policy explains which personal data NORD processes, why, on what legal basis, for how long, with whom we share it and what your rights are. It covers all our services: the website nordsolutions.nl, the NORD app at app.nordsolutions.nl (formerly agent.nordsolutions.nl), NORD Desktop, our emails and the AI colleague itself. The Dutch version is leading; this is a faithful translation. Missing something? Email privacy@nordsolutions.nl.

1. Who we are

The controller is V.O.F. NORD SOLUTIONS (trading as NORD), Musschenbroekstraat 50, 5621 ED Eindhoven, the Netherlands (KvK 42120558 · VAT NL869821039B01). In this policy: "NORD", "we" or "us".

For anything about privacy and your rights: privacy@nordsolutions.nl, or by post to the address above, marked "Privacy". We have not appointed a data protection officer because the GDPR does not require one for our organisation (Art. 37 GDPR); this address is our point of contact.

2. Our role: controller and processor

For data we process about you (as a visitor, prospect or customer), we are the controller.

If you use NORD for your business, the content you provide may contain personal data of others: your clients' emails, supplier invoices, documents in your knowledge base. For that data you (your organisation) are the controller and we are the processor, under our data processing agreement (Art. 28 GDPR), which is part of our terms. We process that data only on your instructions and to provide the service.

3. What data we process

By situation, as concretely as we can:

SituationData
You visit nordsolutions.nlTechnical data every web server receives (IP address, browser and device, requested page, time) for security and troubleshooting. Only if you accept analytics cookies: a session identifier, pages visited, referring page and campaign codes (utm), IP address and browser data, and form interactions (which field, not what you type).
You request access via nordsolutions.nl/startWhat you fill in: type of work, team size, desired start, name, email address, phone number, company name. Plus the landing page, referrer and campaign codes, and from your first answer your IP address and browser data (to detect spam and abuse). A completed request becomes an access request that we review.
You use the contact formName, email address, company, website, your question or challenge, revenue band (optional), IP address, browser data and campaign codes.
You have a NORD accountEmail address, a hashed version of your password, sign-in and session data, your invitation, preferences (language, theme, notifications) and which features are enabled for your account.
You work with NORDYour messages and the replies, files you upload, what NORD does for you (tools used and their results), goals and scheduled tasks, your knowledge base with the search index derived from it, skills, and the memory NORD builds about you and your work (see §5).
You connect servicesAccess tokens for services you connect yourself (Google Gmail and Drive, Microsoft Outlook, Notion, GitHub, Slack, MCP servers, your own API keys). Stored encrypted; content of those services (such as emails or files) is only fetched when NORD performs a task at your request.
You use NORD DesktopA link key for your computer, which folders you share, and the files NORD reads or writes at your request. A log of that stays on your own computer.
You use Finance (invoice check)Invoice data (supplier, invoice number, date, amounts, VAT, ledger account, description, the document if provided), the check's verdict, and the reviewer's decisions and notes.
You payYour Stripe customer ID, payment status, invoices, your credit balance and its ledger, and your usage per model and per message. We never see your full card or account number; Stripe processes it.
We communicate with youEmails we send (welcome, low balance, task results, invoices, payment reminders) and whether they were sent; push notifications if you enable them (an address at your browser's push service); feedback you give and, if you ask for a call back, your phone number.
Security and operationsIP addresses on sign-in and other sensitive actions (against abuse), technical logs, error reports (without personal data, see §9), and an audit trail of administrative actions by NORD staff.

We do not ask for special categories of personal data (such as health, religion or political views) and do not need them. If you include them in a message or document anyway, we process them only to carry out your request. We do not use national identification numbers.

4. Purposes and legal bases

PurposeLegal basis (Art. 6(1) GDPR)
Providing the NORD service: account, chat, tasks, connections, Desktop, FinancePerformance of a contract (b)
Answering and following up your access request or contact questionPre-contractual steps at your request (b)
Payments, invoicing and statutory record keepingContract (b) and legal obligation (c)
Security, abuse and fraud prevention, fixing faultsLegitimate interest (f): a safe, working service
Website statistics via cookiesConsent (a), given and withdrawn via the cookie notice
Improving the service using aggregated usage figures that cannot identify youLegitimate interest (f)
Service messages about your account (e.g. balance, changes to this policy)Contract (b)
Newsletters or marketing emailOnly with your consent (a); we do not send these at present
Complying with a lawful demand by a competent authorityLegal obligation (c)

Where we rely on legitimate interest, we have weighed that your interests do not override it: it concerns security and figures that cannot identify you. You can always object (§11).

Data needed to perform the contract (such as your email address) is mandatory: without it we cannot give you an account. Form fields marked optional may be left empty.

5. How the AI handles your data

NORD works with large language models from specialised providers. To produce an answer we send your message, the relevant context (earlier messages, passages from your knowledge base, tool results) and NORD's instructions to the model.

  • Model requests go through OpenRouter, Inc. (United States), which passes the request to the provider of the chosen model and returns the answer.
  • The default model is a Claude model by Anthropic. You can choose another model in the model picker, which shows each model's provider.
  • Some models are run by providers in the People's Republic of China. They carry a visible CN label, are never our default and are only used if you choose them yourself. There is no adequacy decision for China; see §8. Email us if you want them disabled for your account.
  • After each finished conversation, NORD has a small model propose short memory notes (e.g. your preferences or facts about your business) so NORD can help you better. We also use such a small model for titles and for drafting skills. Those requests go only to providers in the US or EU that do not retain the request for their own purposes, never to a provider in China. You can view, edit and delete your memory in the app.
  • To make your knowledge base searchable, NORD sends chunks of text from the documents you add to OpenAI (model text-embedding-3-small, US), which turns them into a series of numbers. We store those numbers and your documents in the EU; under its terms OpenAI does not use API data to train models.
  • NORD itself does not use your content to train AI models. How long a model provider temporarily keeps a request (for example for abuse detection) is governed by its own terms, linked in §9.
  • There is no automated decision-making with legal effects (Art. 22 GDPR). An AI verdict, such as a flagged invoice in Finance, is advice: a human decides.
  • Actions towards the outside world (sending an email, publishing something): in a conversation NORD is set up to ask for your confirmation first; for goals and scheduled tasks NORD waits for your approval before such an action runs.

6. Cookies and similar technologies

We use no third-party advertising or tracking cookies and no marketing pixels. We only place analytics cookies after your consent; change your choice via "Cookie settings" at the bottom of every page.

NameWherePurposeDurationType
nord_cookie_consentnordsolutions.nlRemember your cookie choice12 monthsFunctional
nord_session_idnordsolutions.nlCount visits within one session (statistics)30 minutes after your last clickAnalytics, consent only
sb-…-auth-tokenapp.nordsolutions.nl, adminKeep you signed inSession, refreshed up to 7 daysFunctional
__Host-csrf, nord_oauth_nonceapp.nordsolutions.nlSecurity of forms and of connecting servicesSession / 10 minutesFunctional
nord_legal_ackapp.nordsolutions.nlRemember that you saw a notice180 daysFunctional
Local storageBoth sitesPreferences on your device, such as theme, language and open panelsUntil you clear itFunctional

Functional cookies are necessary for the service to work and fall under the exemption in Article 11.7a of the Dutch Telecommunications Act; we do not ask consent for them.

7. Who we share data with

We never sell your data and do not share it with advertisers. We only share it with:

  • Processors that help us provide the service (hosting, database, payments, email, AI models, error reporting). We have a data processing agreement with each; the full list is in §9.
  • Services that you connect (such as Google, Microsoft, Notion, Zapier or Exact Online). Data only goes there or comes from there on your instruction; you have your own agreement with those services.
  • Our accountant and the Dutch Tax Administration, for tax records.
  • Competent authorities when the law requires it. We check such a demand first and inform you unless we are not allowed to.
  • A possible successor of our business in a merger or acquisition, under the same protection; we will tell you in advance.

8. Data outside the European Economic Area

Your account, conversations, knowledge base, memory and encrypted keys are stored in the EU: the database at Supabase in Frankfurt and the AI server at DigitalOcean in Amsterdam. The websites run on Vercel in EU regions.

Some processors are (also) established in the United States, notably for AI models (OpenRouter and the model providers) and error reporting. Transfers to the US rely on the EU-US Data Privacy Framework where the recipient is certified, and otherwise on the European Commission's standard contractual clauses (2021/914), with supplementary measures where needed (such as encryption in transit).

If you choose a model with the CN label yourself, the content of that request goes to a provider in the People's Republic of China. No adequacy decision exists for China, and Chinese law can require providers to hand data to authorities. If you process other people's personal data, we advise against these models.

9. Our processors

ProcessorPurposeLocationTerms
SupabaseDatabase, sign-in, file storageEU (Frankfurt)DPA
VercelHosting of the websites and the appEU regions; Vercel Inc. (US)DPA
DigitalOceanServer running the AI colleague, backupsAmsterdam; DigitalOcean LLC (US)DPA
Stripe Payments EuropePayments and invoicesIrelandDPA
ResendSending emailEU region; Resend Inc. (US)DPA
OpenRouterPassing AI requests to the chosen modelUSTerms
AnthropicAI model (default, Claude)USDPA
OpenAISearch index of your knowledge base: chunks of text from your documents (embeddings); and the AI model if you choose an OpenAI modelUSDPA
Google and other model providersAI model, only if you choose that modelPer provider, shown in the model pickerTerms via OpenRouter
Providers for small platform tasks (e.g. BaseTen, DeepInfra, Together)Memory notes, titles, skills (see §5)US / EU; never ChinaTerms via OpenRouter
Sentry (Functional Software)Error reports, without personal dataUS or EUDPA
Meta (WhatsApp)Internal incident and deployment alerts to the NORD team; no conversation contentUS / EUTerms
CloudflareDNS only (domain names); no traffic passes through CloudflareUS / worldwideDPA
Your browser's push service (Google, Mozilla, Apple)Only if you enable push notificationsPer browserYour browser's terms

When this list changes we update it here; business customers with a data processing agreement are told about a new subprocessor at least 30 days in advance and may object.

10. How long we keep data

DataRetention
Website statistics (page views, form interactions)90 days, then deleted automatically
Requests via /start, contact form, feedbackUp to 24 months after last contact, then deleted automatically
Access requestsUntil handled, then 24 more months
Account, conversations, memory, knowledge base, skills, tasks, connectionsAs long as your account exists. After deletion a 30-day grace period, then erased
Access tokens of connected servicesUntil you disconnect or delete your account
Finance data (invoice checks)As long as your account exists; you keep your own books
Invoices, payments and your credit ledger7 years (statutory tax retention, Art. 52 AWR)
Technical logs and error reportsAt most 90 days
Per-message usage log (model, tokens, cost, speed; pseudonymised)12 months
Audit trail of administrative actions24 months
BackupsConversation snapshots: continuously replaced; daily encrypted database backup: 14 days
Push subscriptionsUntil you turn notifications off or your browser revokes the subscription

11. Your rights

You have the following rights (Art. 15-22 GDPR):

  • Access: know what data we hold about you and get a copy. In the app: Settings → Account → export data.
  • Rectification: have incorrect data corrected. You change your email address and preferences yourself in the app.
  • Erasure: have your account and data deleted. In the app via Settings → Account; data with a statutory retention duty (invoicing) is kept as long as the law requires.
  • Restriction: have processing paused temporarily, for example while we assess a correction request.
  • Portability: receive your data in a common, machine-readable format (the export in the app).
  • Objection: to processing based on legitimate interest, and always to direct marketing.
  • Withdrawing consent: for cookies via "Cookie settings", for anything else by email. Withdrawal applies to the future.

Send a request to privacy@nordsolutions.nl. We respond within one month; for complex requests this can be extended by two months, and we will tell you so within the first month. It is free. To prevent someone else from requesting your data, we may ask you to confirm from your account's email address; we never ask for a copy of your ID.

If you are a client of a business that uses NORD and your request concerns data that business processes in NORD (§2), please contact that business; we help it handle your request.

12. Security

  • All connections are encrypted (TLS). Access tokens and API keys of connected services are stored encrypted with AES-256-GCM; the app only shows them truncated.
  • Each customer has its own isolated working environment on the AI server; the database denies outside access by default, and every database query is limited to the signed-in user.
  • Sign-in uses a password stored only as a hash; sensitive actions are protected against CSRF and rate-limited.
  • Administrative access is limited to designated NORD staff, is logged, and the admin environment lives on a separate domain with its own sign-in.
  • We test security periodically (including penetration tests), keep software up to date with security patches and make daily encrypted backups.

If something does go wrong with personal data (a data breach), we notify the Dutch Data Protection Authority within 72 hours where required, and inform you without undue delay if the breach poses a high risk to you (Art. 33-34 GDPR).

13. Children

NORD is meant for businesses and not for people under 16. We do not knowingly process children's data. If you believe we do, contact us and we will delete it.

14. A complaint

If you are unhappy with how we handle your data, please tell us first; we are happy to resolve it. You always have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or with the supervisory authority in the EU country where you live or work.

15. Changes

We update this policy when our service or the law changes. The date at the top shows when that last happened. For important changes we email customers at least 30 days in advance.