

Privacy Policy
Effective Date: June 23, 2026
Nordic Cyber Group AB respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect personal data when you visit our website, contact us, or subscribe to our newsletter.
1. Who we are
The data controller responsible for the processing of your personal data is:
Nordic Cyber Group AB
Company registration number: 559457-8139
Registered address: Östervägen 14 A 1205, 169 52 Solna, Sweden
Email: info@ncgrp.se
For privacy and data protection questions, please contact us at info@ncgrp.se.
Nordic Cyber Group AB has not appointed a Data Protection Officer. Please use the general privacy contact above for any privacy-related requests.
2. Personal data we collect
We only collect personal data that is necessary for the purposes described in this Privacy Policy.
Contact form
When you contact us through our website contact form, we may collect:
• Full name
• Email address
• Company name
• Phone number, if provided
• Message content
• Technical metadata connected to the form submission, such as timestamp, IP address, browser information, and security logs
Newsletter
When you subscribe to our newsletter, we may collect:
• Email address
• Subscription status
• Consent record
• Any other information you voluntarily provide when signing up
Website and technical data
When you visit our website, our website infrastructure and security services may process technical data, including:
• IP address
• Browser and device information
• Pages visited
• Date and time of access
• Server logs
• Security and performance logs
We do not use advertising cookies or advertising tracking on the website.
3. How we use your personal data
We process personal data for the following purposes:
To respond to inquiries
We use contact form data to respond to your message, answer questions, discuss potential projects, and communicate with you about our services.
Legal basis: legitimate interest and, where applicable, steps taken before entering into a contract.
To send newsletters
We use newsletter subscription data to send newsletters, updates, and relevant communications to people who have signed up.
Legal basis: consent.
You can unsubscribe at any time using the unsubscribe link in our emails or by contacting us at info@ncgrp.se.
To operate and protect the website
We use technical data to keep the website available, secure, and functioning correctly, including protection against spam, abuse, attacks, and technical errors.
Legal basis: legitimate interest.
To comply with legal obligations
If an inquiry leads to a customer or supplier relationship, we may need to process certain personal data for contracts, accounting, invoicing, compliance, or legal claims.
Legal basis: legal obligation, contract, and legitimate interest.
4. We do not collect sensitive personal data
Please do not submit sensitive personal data through the contact form or newsletter form.
Sensitive personal data includes information about health, political opinions, religious beliefs, trade union membership, genetic data, biometric data, sexual orientation, or similar protected categories.
5. Newsletter and email communication
We only send newsletters or marketing-style email updates to people who have subscribed or otherwise provided permission where required.
You can withdraw your consent at any time. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
6. Cookies and similar technologies
Our website may use strictly necessary cookies or similar technologies required for:
• Website functionality
• Security
• Form submission
• Spam protection
• Load balancing
• Performance and error handling
We do not use advertising cookies or third-party advertising trackers.
If we introduce analytics, advertising cookies, or other non-essential tracking in the future, we will update this Privacy Policy and, where required, ask for consent before placing such technologies on your device.
7. Service providers and recipients
We may share personal data with trusted service providers that help us operate, host, secure, maintain, and develop our website and systems.
These may include:
• Cloudflare
• GitHub
• Vercel
• Amazon Web Services, AWS
• Email, newsletter, or form handling providers, if used
These providers may only process personal data according to our instructions and for the purposes described in this Privacy Policy, unless they are independently required to process data under applicable law.
We do not sell personal data.
8. International transfers
Some of our service providers may process personal data outside the EU/EEA.
When personal data is transferred outside the EU/EEA, we take steps to ensure that the transfer is protected by appropriate safeguards, such as:
• An adequacy decision by the European Commission
• Standard Contractual Clauses
• Other lawful transfer mechanisms under GDPR
9. How long we keep personal data
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy.
Contact inquiries
Contact form submissions and related correspondence are normally kept for up to 24 months after the last contact, unless we need to keep the information longer because of an ongoing business relationship, legal obligation, dispute, or legitimate business need.
Newsletter data
Newsletter subscription data is kept until you unsubscribe or withdraw consent. We may keep limited information necessary to document your unsubscribe request and ensure that we do not send further newsletters to you.
Technical and security logs
Technical logs are normally kept for up to 12 months, unless a longer retention period is needed to investigate security incidents, abuse, technical errors, or legal claims.
Business records
If you become a customer, supplier, or business contact, we may retain certain information for as long as required by accounting, tax, contract, or other legal obligations.
10. How we protect your personal data
We use technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure.
These measures may include:
• Access controls
• Secure hosting providers
• Encryption where appropriate
• Security monitoring
• Limited internal access
• Regular review of systems and providers
11. Your rights
Under GDPR, you have rights in relation to your personal data. Depending on the situation, you may have the right to:
• Request access to your personal data
• Request correction of inaccurate personal data
• Request deletion of your personal data
• Request restriction of processing
• Object to processing based on legitimate interests
• Request data portability
• Withdraw consent at any time, where processing is based on consent
• Lodge a complaint with the Swedish Authority for Privacy Protection, IMY
To exercise your rights, contact us at info@ncgrp.se.
We may need to verify your identity before responding to your request.
12. Complaints
If you believe that we process your personal data in breach of GDPR, you can contact us at info@ncgrp.se.
You also have the right to lodge a complaint with Integritetsskyddsmyndigheten, IMY, the Swedish Authority for Privacy Protection.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The latest version will always be available on our website.