Privacy policy
Privacy policy
Last updated: 5 October 2026
This policy explains which personal data NORD processes, why, on what legal basis, for how long, with whom we share it and what your rights are. It covers all our services: the website nordsolutions.nl, the NORD app at app.nordsolutions.nl (formerly agent.nordsolutions.nl), NORD Desktop, our emails and the AI colleague itself. The Dutch version is leading; this is a faithful translation. Missing something? Email privacy@nordsolutions.nl.
1. Who we are
The controller is V.O.F. NORD SOLUTIONS (trading as NORD), Musschenbroekstraat 50, 5621 ED Eindhoven, the Netherlands (KvK 42120558 · VAT NL869821039B01). In this policy: "NORD", "we" or "us".
For anything about privacy and your rights: privacy@nordsolutions.nl, or by post to the address above, marked "Privacy". We have not appointed a data protection officer because the GDPR does not require one for our organisation (Art. 37 GDPR); this address is our point of contact.
2. Our role: controller and processor
For data we process about you (as a visitor, prospect or customer), we are the controller.
If you use NORD for your business, the content you provide may contain personal data of others: your clients' emails, supplier invoices, documents in your knowledge base. For that data you (your organisation) are the controller and we are the processor, under our data processing agreement (Art. 28 GDPR), which is part of our terms. We process that data only on your instructions and to provide the service.
3. What data we process
By situation, as concretely as we can:
| Situation | Data |
|---|---|
| You visit nordsolutions.nl | Technical data every web server receives (IP address, browser and device, requested page, time) for security and troubleshooting. Only if you accept analytics cookies: a session identifier, pages visited, referring page and campaign codes (utm), IP address and browser data, and form interactions (which field, not what you type). |
| You request access via nordsolutions.nl/start | What you fill in: type of work, team size, desired start, name, email address, phone number, company name. Plus the landing page, referrer and campaign codes, and from your first answer your IP address and browser data (to detect spam and abuse). A completed request becomes an access request that we review. |
| You use the contact form | Name, email address, company, website, your question or challenge, revenue band (optional), IP address, browser data and campaign codes. |
| You have a NORD account | Email address, a hashed version of your password, sign-in and session data, your invitation, preferences (language, theme, notifications) and which features are enabled for your account. |
| You work with NORD | Your messages and the replies, files you upload, what NORD does for you (tools used and their results), goals and scheduled tasks, your knowledge base with the search index derived from it, skills, and the memory NORD builds about you and your work (see §5). |
| You connect services | Access tokens for services you connect yourself (Google Gmail and Drive, Microsoft Outlook, Notion, GitHub, Slack, MCP servers, your own API keys). Stored encrypted; content of those services (such as emails or files) is only fetched when NORD performs a task at your request. |
| You use NORD Desktop | A link key for your computer, which folders you share, and the files NORD reads or writes at your request. A log of that stays on your own computer. |
| You use Finance (invoice check) | Invoice data (supplier, invoice number, date, amounts, VAT, ledger account, description, the document if provided), the check's verdict, and the reviewer's decisions and notes. |
| You pay | Your Stripe customer ID, payment status, invoices, your credit balance and its ledger, and your usage per model and per message. We never see your full card or account number; Stripe processes it. |
| We communicate with you | Emails we send (welcome, low balance, task results, invoices, payment reminders) and whether they were sent; push notifications if you enable them (an address at your browser's push service); feedback you give and, if you ask for a call back, your phone number. |
| Security and operations | IP addresses on sign-in and other sensitive actions (against abuse), technical logs, error reports (without personal data, see §9), and an audit trail of administrative actions by NORD staff. |
We do not ask for special categories of personal data (such as health, religion or political views) and do not need them. If you include them in a message or document anyway, we process them only to carry out your request. We do not use national identification numbers.
4. Purposes and legal bases
| Purpose | Legal basis (Art. 6(1) GDPR) |
|---|---|
| Providing the NORD service: account, chat, tasks, connections, Desktop, Finance | Performance of a contract (b) |
| Answering and following up your access request or contact question | Pre-contractual steps at your request (b) |
| Payments, invoicing and statutory record keeping | Contract (b) and legal obligation (c) |
| Security, abuse and fraud prevention, fixing faults | Legitimate interest (f): a safe, working service |
| Website statistics via cookies | Consent (a), given and withdrawn via the cookie notice |
| Improving the service using aggregated usage figures that cannot identify you | Legitimate interest (f) |
| Service messages about your account (e.g. balance, changes to this policy) | Contract (b) |
| Newsletters or marketing email | Only with your consent (a); we do not send these at present |
| Complying with a lawful demand by a competent authority | Legal obligation (c) |
Where we rely on legitimate interest, we have weighed that your interests do not override it: it concerns security and figures that cannot identify you. You can always object (§11).
Data needed to perform the contract (such as your email address) is mandatory: without it we cannot give you an account. Form fields marked optional may be left empty.
5. How the AI handles your data
NORD works with large language models from specialised providers. To produce an answer we send your message, the relevant context (earlier messages, passages from your knowledge base, tool results) and NORD's instructions to the model.
- Model requests go through OpenRouter, Inc. (United States), which passes the request to the provider of the chosen model and returns the answer.
- The default model is a Claude model by Anthropic. You can choose another model in the model picker, which shows each model's provider.
- Some models are run by providers in the People's Republic of China. They carry a visible CN label, are never our default and are only used if you choose them yourself. There is no adequacy decision for China; see §8. Email us if you want them disabled for your account.
- After each finished conversation, NORD has a small model propose short memory notes (e.g. your preferences or facts about your business) so NORD can help you better. We also use such a small model for titles and for drafting skills. Those requests go only to providers in the US or EU that do not retain the request for their own purposes, never to a provider in China. You can view, edit and delete your memory in the app.
- To make your knowledge base searchable, NORD sends chunks of text from the documents you add to OpenAI (model text-embedding-3-small, US), which turns them into a series of numbers. We store those numbers and your documents in the EU; under its terms OpenAI does not use API data to train models.
- NORD itself does not use your content to train AI models. How long a model provider temporarily keeps a request (for example for abuse detection) is governed by its own terms, linked in §9.
- There is no automated decision-making with legal effects (Art. 22 GDPR). An AI verdict, such as a flagged invoice in Finance, is advice: a human decides.
- Actions towards the outside world (sending an email, publishing something): in a conversation NORD is set up to ask for your confirmation first; for goals and scheduled tasks NORD waits for your approval before such an action runs.
7. Who we share data with
We never sell your data and do not share it with advertisers. We only share it with:
- Processors that help us provide the service (hosting, database, payments, email, AI models, error reporting). We have a data processing agreement with each; the full list is in §9.
- Services that you connect (such as Google, Microsoft, Notion, Zapier or Exact Online). Data only goes there or comes from there on your instruction; you have your own agreement with those services.
- Our accountant and the Dutch Tax Administration, for tax records.
- Competent authorities when the law requires it. We check such a demand first and inform you unless we are not allowed to.
- A possible successor of our business in a merger or acquisition, under the same protection; we will tell you in advance.
8. Data outside the European Economic Area
Your account, conversations, knowledge base, memory and encrypted keys are stored in the EU: the database at Supabase in Frankfurt and the AI server at DigitalOcean in Amsterdam. The websites run on Vercel in EU regions.
Some processors are (also) established in the United States, notably for AI models (OpenRouter and the model providers) and error reporting. Transfers to the US rely on the EU-US Data Privacy Framework where the recipient is certified, and otherwise on the European Commission's standard contractual clauses (2021/914), with supplementary measures where needed (such as encryption in transit).
If you choose a model with the CN label yourself, the content of that request goes to a provider in the People's Republic of China. No adequacy decision exists for China, and Chinese law can require providers to hand data to authorities. If you process other people's personal data, we advise against these models.
9. Our processors
| Processor | Purpose | Location | Terms |
|---|---|---|---|
| Supabase | Database, sign-in, file storage | EU (Frankfurt) | DPA |
| Vercel | Hosting of the websites and the app | EU regions; Vercel Inc. (US) | DPA |
| DigitalOcean | Server running the AI colleague, backups | Amsterdam; DigitalOcean LLC (US) | DPA |
| Stripe Payments Europe | Payments and invoices | Ireland | DPA |
| Resend | Sending email | EU region; Resend Inc. (US) | DPA |
| OpenRouter | Passing AI requests to the chosen model | US | Terms |
| Anthropic | AI model (default, Claude) | US | DPA |
| OpenAI | Search index of your knowledge base: chunks of text from your documents (embeddings); and the AI model if you choose an OpenAI model | US | DPA |
| Google and other model providers | AI model, only if you choose that model | Per provider, shown in the model picker | Terms via OpenRouter |
| Providers for small platform tasks (e.g. BaseTen, DeepInfra, Together) | Memory notes, titles, skills (see §5) | US / EU; never China | Terms via OpenRouter |
| Sentry (Functional Software) | Error reports, without personal data | US or EU | DPA |
| Meta (WhatsApp) | Internal incident and deployment alerts to the NORD team; no conversation content | US / EU | Terms |
| Cloudflare | DNS only (domain names); no traffic passes through Cloudflare | US / worldwide | DPA |
| Your browser's push service (Google, Mozilla, Apple) | Only if you enable push notifications | Per browser | Your browser's terms |
When this list changes we update it here; business customers with a data processing agreement are told about a new subprocessor at least 30 days in advance and may object.
10. How long we keep data
| Data | Retention |
|---|---|
| Website statistics (page views, form interactions) | 90 days, then deleted automatically |
| Requests via /start, contact form, feedback | Up to 24 months after last contact, then deleted automatically |
| Access requests | Until handled, then 24 more months |
| Account, conversations, memory, knowledge base, skills, tasks, connections | As long as your account exists. After deletion a 30-day grace period, then erased |
| Access tokens of connected services | Until you disconnect or delete your account |
| Finance data (invoice checks) | As long as your account exists; you keep your own books |
| Invoices, payments and your credit ledger | 7 years (statutory tax retention, Art. 52 AWR) |
| Technical logs and error reports | At most 90 days |
| Per-message usage log (model, tokens, cost, speed; pseudonymised) | 12 months |
| Audit trail of administrative actions | 24 months |
| Backups | Conversation snapshots: continuously replaced; daily encrypted database backup: 14 days |
| Push subscriptions | Until you turn notifications off or your browser revokes the subscription |
11. Your rights
You have the following rights (Art. 15-22 GDPR):
- Access: know what data we hold about you and get a copy. In the app: Settings → Account → export data.
- Rectification: have incorrect data corrected. You change your email address and preferences yourself in the app.
- Erasure: have your account and data deleted. In the app via Settings → Account; data with a statutory retention duty (invoicing) is kept as long as the law requires.
- Restriction: have processing paused temporarily, for example while we assess a correction request.
- Portability: receive your data in a common, machine-readable format (the export in the app).
- Objection: to processing based on legitimate interest, and always to direct marketing.
- Withdrawing consent: for cookies via "Cookie settings", for anything else by email. Withdrawal applies to the future.
Send a request to privacy@nordsolutions.nl. We respond within one month; for complex requests this can be extended by two months, and we will tell you so within the first month. It is free. To prevent someone else from requesting your data, we may ask you to confirm from your account's email address; we never ask for a copy of your ID.
If you are a client of a business that uses NORD and your request concerns data that business processes in NORD (§2), please contact that business; we help it handle your request.
12. Security
- All connections are encrypted (TLS). Access tokens and API keys of connected services are stored encrypted with AES-256-GCM; the app only shows them truncated.
- Each customer has its own isolated working environment on the AI server; the database denies outside access by default, and every database query is limited to the signed-in user.
- Sign-in uses a password stored only as a hash; sensitive actions are protected against CSRF and rate-limited.
- Administrative access is limited to designated NORD staff, is logged, and the admin environment lives on a separate domain with its own sign-in.
- We test security periodically (including penetration tests), keep software up to date with security patches and make daily encrypted backups.
If something does go wrong with personal data (a data breach), we notify the Dutch Data Protection Authority within 72 hours where required, and inform you without undue delay if the breach poses a high risk to you (Art. 33-34 GDPR).
13. Children
NORD is meant for businesses and not for people under 16. We do not knowingly process children's data. If you believe we do, contact us and we will delete it.
14. A complaint
If you are unhappy with how we handle your data, please tell us first; we are happy to resolve it. You always have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or with the supervisory authority in the EU country where you live or work.
15. Changes
We update this policy when our service or the law changes. The date at the top shows when that last happened. For important changes we email customers at least 30 days in advance.