Privacy Policy Background

Privacy Policy

Effective Date: June 23, 2026

Nordic Cyber Group AB respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect personal data when you visit our website, contact us, or subscribe to our newsletter.

1. Who we are

The data controller responsible for the processing of your personal data is:

Nordic Cyber Group AB

Company registration number: 559457-8139

Registered address: Östervägen 14 A 1205, 169 52 Solna, Sweden

Email: info@ncgrp.se

For privacy and data protection questions, please contact us at info@ncgrp.se.

Nordic Cyber Group AB has not appointed a Data Protection Officer. Please use the general privacy contact above for any privacy-related requests.

2. Personal data we collect

We only collect personal data that is necessary for the purposes described in this Privacy Policy.

Contact form

When you contact us through our website contact form, we may collect:

• Full name

• Email address

• Company name

• Phone number, if provided

• Message content

• Technical metadata connected to the form submission, such as timestamp, IP address, browser information, and security logs

Newsletter

When you subscribe to our newsletter, we may collect:

• Email address

• Subscription status

• Consent record

• Any other information you voluntarily provide when signing up

Website and technical data

When you visit our website, our website infrastructure and security services may process technical data, including:

• IP address

• Browser and device information

• Pages visited

• Date and time of access

• Server logs

• Security and performance logs

We do not use advertising cookies or advertising tracking on the website.

3. How we use your personal data

We process personal data for the following purposes:

To respond to inquiries

We use contact form data to respond to your message, answer questions, discuss potential projects, and communicate with you about our services.

Legal basis: legitimate interest and, where applicable, steps taken before entering into a contract.

To send newsletters

We use newsletter subscription data to send newsletters, updates, and relevant communications to people who have signed up.

Legal basis: consent.

You can unsubscribe at any time using the unsubscribe link in our emails or by contacting us at info@ncgrp.se.

To operate and protect the website

We use technical data to keep the website available, secure, and functioning correctly, including protection against spam, abuse, attacks, and technical errors.

Legal basis: legitimate interest.

To comply with legal obligations

If an inquiry leads to a customer or supplier relationship, we may need to process certain personal data for contracts, accounting, invoicing, compliance, or legal claims.

Legal basis: legal obligation, contract, and legitimate interest.

4. We do not collect sensitive personal data

Please do not submit sensitive personal data through the contact form or newsletter form.

Sensitive personal data includes information about health, political opinions, religious beliefs, trade union membership, genetic data, biometric data, sexual orientation, or similar protected categories.

5. Newsletter and email communication

We only send newsletters or marketing-style email updates to people who have subscribed or otherwise provided permission where required.

You can withdraw your consent at any time. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

6. Cookies and similar technologies

Our website may use strictly necessary cookies or similar technologies required for:

• Website functionality

• Security

• Form submission

• Spam protection

• Load balancing

• Performance and error handling

We do not use advertising cookies or third-party advertising trackers.

If we introduce analytics, advertising cookies, or other non-essential tracking in the future, we will update this Privacy Policy and, where required, ask for consent before placing such technologies on your device.

7. Service providers and recipients

We may share personal data with trusted service providers that help us operate, host, secure, maintain, and develop our website and systems.

These may include:

• Cloudflare

• GitHub

• Vercel

• Amazon Web Services, AWS

• Email, newsletter, or form handling providers, if used

These providers may only process personal data according to our instructions and for the purposes described in this Privacy Policy, unless they are independently required to process data under applicable law.

We do not sell personal data.

8. International transfers

Some of our service providers may process personal data outside the EU/EEA.

When personal data is transferred outside the EU/EEA, we take steps to ensure that the transfer is protected by appropriate safeguards, such as:

• An adequacy decision by the European Commission

• Standard Contractual Clauses

• Other lawful transfer mechanisms under GDPR

9. How long we keep personal data

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy.

Contact inquiries

Contact form submissions and related correspondence are normally kept for up to 24 months after the last contact, unless we need to keep the information longer because of an ongoing business relationship, legal obligation, dispute, or legitimate business need.

Newsletter data

Newsletter subscription data is kept until you unsubscribe or withdraw consent. We may keep limited information necessary to document your unsubscribe request and ensure that we do not send further newsletters to you.

Technical and security logs

Technical logs are normally kept for up to 12 months, unless a longer retention period is needed to investigate security incidents, abuse, technical errors, or legal claims.

Business records

If you become a customer, supplier, or business contact, we may retain certain information for as long as required by accounting, tax, contract, or other legal obligations.

10. How we protect your personal data

We use technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure.

These measures may include:

• Access controls

• Secure hosting providers

• Encryption where appropriate

• Security monitoring

• Limited internal access

• Regular review of systems and providers

11. Your rights

Under GDPR, you have rights in relation to your personal data. Depending on the situation, you may have the right to:

• Request access to your personal data

• Request correction of inaccurate personal data

• Request deletion of your personal data

• Request restriction of processing

• Object to processing based on legitimate interests

• Request data portability

• Withdraw consent at any time, where processing is based on consent

• Lodge a complaint with the Swedish Authority for Privacy Protection, IMY

To exercise your rights, contact us at info@ncgrp.se.

We may need to verify your identity before responding to your request.

12. Complaints

If you believe that we process your personal data in breach of GDPR, you can contact us at info@ncgrp.se.

You also have the right to lodge a complaint with Integritetsskyddsmyndigheten, IMY, the Swedish Authority for Privacy Protection.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The latest version will always be available on our website.