Skip to main content

Privacy Policy

How Nordvec collects, processes, and protects your data, in full compliance with GDPR.

Last updated: 2026-05-16

Overview

At Nordvec, we prioritise data security and confidentiality. This privacy policy describes how we collect, use, disclose, and store personal data when you visit our website, create an account, or use our AI platform. When you use our Service on behalf of your employer (who is our B2B customer), we act primarily as a Data Processor, and your employer acts as the Data Controller. This policy applies to data we process as Data Controller (e.g., your login credentials, payment data, and website analytics). For data we process on behalf of your employer, please refer to our Data Processing Agreement (DPA).

1. What data do we collect?

We collect: identification and contact information (name, email, company name), account and authentication data (passwords hashed via bcrypt, profile pictures via OAuth, integration tokens encrypted with AES-256), payment information (processed via our EU payment provider Mollie once billing is enabled; we store only a token reference, never full card details), technical data (IP address masked in Sentry, browser type, login timestamps, page views), desktop file synchronisation data (file names, content, and metadata from locally synced folders, with file paths stored in hashed form), and AI interaction history (queries, AI responses, cited sources, and timestamps).

2. Purpose and legal basis

We process your personal data for: Service delivery (Art. 6(1)(b): creating and managing your user account, providing support), Payment and bookkeeping (Art. 6(1)(c): invoicing and 5-year record retention per the Danish Bookkeeping Act), Improvement and security (Art. 6(1)(f): preventing misuse, debugging, and analysing anonymised usage data; we do NOT train AI models on your data), and Marketing (Art. 6(1)(a): newsletters and updates, only with active opt-in via cookie banner or sign-up form; withdrawable at any time).

3. Use of AI and third parties

Nordvec is built around Large Language Models (LLMs). Nordvec does not use your queries or documents to train AI models. Only 5-15 relevant document chunks are sent per query, never entire documents. Your data is isolated per tenant via Row Level Security (RLS) on all database tables. Generation runs in France and embeddings and reranking run in Berlin. Documents are stored in Ireland and Nuremberg. Some providers are incorporated outside the European Economic Area, so their remote access counts as a transfer under GDPR Chapter V; our sub-processor register names each one with the transfer basis that applies.

4. International transfers

Documents are stored in Ireland (via Supabase) and Nuremberg (via Hetzner). All AI inference takes place in the EU: generation in France, embeddings in Berlin. We are migrating to our own servers in Germany, and until that migration completes some providers are EU-hosted with a parent company outside the EEA. Our sub-processor register records each provider, its transfer basis, and the status of that migration.

5. Data retention

We retain your profile information as long as you have an active account. When you delete your account: all personal data is atomically deleted (documents, conversations, memories, embeddings, integration tokens, storage files), accounting records are retained for 5 years per the Danish Bookkeeping Act, audit logs are anonymised but retained per EU AI Act Art. 12, and Supabase backups rotate automatically after 7 days. Data from connected systems is deleted at the next sync cycle or within 30 days of contract termination.

6. Your rights

Under GDPR you have the following self-service rights: Right of access (Art. 15) via Settings > Account > Export Data, Right to rectification (Art. 16) by editing your profile and conversation history directly, Right to erasure (Art. 17) via Settings > Account > Delete Account (atomic, irreversible), Right to restriction (Art. 18) via source toggles and upload exclusion settings, Right to data portability (Art. 20) via structured JSON export, Right to object (Art. 21) by contacting privacy@nordvec.com, and regarding Automated decisions (Art. 22): our AI is exclusively advisory and never makes binding decisions about individuals.

7. Cookies

We use necessary cookies (session tokens, authentication; cannot be deactivated), analytics cookies (only with active consent via cookie banner), and marketing cookies (only with active consent). See our separate Cookie Policy for details. You can change preferences at any time via Cookie Settings in the footer.

8. Changes to this policy

We reserve the right to update this privacy policy to reflect changes in legislation or our Service. We will notify you via email or through the platform of significant changes.

9. Contact

If you have questions or wish to exercise your rights, contact: Nordvec ApS, Email: privacy@nordvec.com, Data Protection Officer: dpo@nordvec.com, Web: nordvec.com. You also have the right to file a complaint with the Danish Data Protection Agency (www.datatilsynet.dk).