How Nordic Riser AB collects, uses, and protects your personal information in accordance with the EU General Data Protection Regulation (GDPR).
What changed in this update: this policy previously covered our consulting business only. It now also covers the Member Portal, NR-BOS, and Global Reach. We added a Controller vs. Processor section, a full named Sub-processor list, an explicit disclosure of the AI provider used in NR-BOS, and split the Cookies section between the marketing site and our authenticated products. A Terms of Service and a Data Processing Agreement are published alongside this policy for the first time — see the Legal index.
Nordic Riser AB (“we”, “our”, or “us”) is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information across everything we operate: this website, our strategic consulting services, the Nordic Riser Member Portal, and the software products we build and license — including NR-BOS and Global Reach.
This policy is designed to comply with the EU General Data Protection Regulation (GDPR) and applicable data protection legislation. By using our website, our Member Portal, or any of our software products, or by submitting an inquiry, you acknowledge that you have read and understood this policy.
Nordic Riser AB is the data controller responsible for your personal information collected through this website, the Member Portal, and our consulting engagements. Section 3 explains the separate case — building and hosting software for a client — in which Nordic Riser AB instead acts as a data processor.
For all data protection matters, please contact us using the details above with the subject line “Data Protection Inquiry”.
Nordic Riser AB relates to personal data in two different capacities, and which one applies depends on what you're using.
As a controller, we decide why and how personal data is processed for our own consulting business, this marketing website, and the Member Portal we operate under our own brand. This Privacy Policy governs that processing.
As a processor, when we build, host, or operate a system on a client's behalf — for example, an NR-BOS deployment run for a construction company's own workforce and clients — the client is the data controller for the personal data in that system, and Nordic Riser AB processes it only on the client's documented instructions, under a Data Processing Agreement. If you are an employee, subcontractor, or client of one of our software customers, this Privacy Policy is not the governing document for how your data is handled there — your relationship is with that customer, and our obligations run to them under the DPA, not directly to you.
We offer a Data Processing Agreement to any client on request — see our Legal index for the DPA.
We collect information that you voluntarily provide to us, including:
When you visit our website, we may automatically collect:
As a registered member, we collect:
NR-BOS is typically operated by one of our clients for their own workforce, in which case Nordic Riser AB processes this data as a processor, not a controller (see Section 3). We describe it here so that anyone who is a data subject within an NR-BOS deployment understands what is collected:
As a Global Reach user:
We process your personal data only for the purposes outlined below, each supported by a lawful basis under GDPR:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Responding to consultation requests and inquiries | Contract performance / Legitimate interest |
| Providing strategic advisory, technology, and global collaboration services | Contract performance |
| Operating and securing the Member Portal, including authentication and document/message storage | Contract performance |
| Delivering NR-BOS to our licensing customers, including field reporting, project tracking, and AI-assisted analysis | Contract performance (as processor, per our client's instructions) |
| Providing real-time translation within Global Reach | Contract performance |
| Communicating about our services and engagement progress | Contract performance / Consent |
| Improving our website and service quality | Legitimate interest |
| Coordinating with third-party professionals (legal, accounting) | Contract performance / Legitimate interest |
| Compliance with legal and regulatory obligations | Legal obligation |
We will not sell, rent, or trade your personal information to third parties. We will not use your data for purposes incompatible with those stated above.
Where required to deliver our services, we may share relevant information with qualified third-party professionals, including:
All third parties are required to maintain appropriate security measures and are permitted to process your data only as directed by us and within the scope of their professional obligations.
We may disclose your personal information when required to do so by law, regulation, legal process, or a legitimate governmental request.
Where personal data is transferred outside the EU/EEA, we ensure an appropriate transfer mechanism — typically the European Commission's Standard Contractual Clauses — is in place before any such transfer takes place. Section 7 lists every sub-processor we use, including where each one is located and which transfer mechanism applies. One of those transfers, described in full below, is to a company based in China, a jurisdiction without an EU adequacy decision.
NR-BOS includes an optional AI Assistant that generates risk, cost, and productivity insights from a project's data. We are describing this plainly, including the parts that are not yet as protective as we'd like, rather than describing a safeguard that isn't actually in place:
To help meet our own transparency obligations and give you full visibility into who processes personal data on our behalf, we maintain a complete, current sub-processor list — what each one does, what data category it touches, where it's located, and what transfer safeguard applies — as its own page, linked from our Legal index.
If we add a new sub-processor, we will update that list and, for clients with a Data Processing Agreement in place, give notice before the change takes effect, consistent with the objection right described in that agreement.
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These measures include:
For the Member Portal, this includes Firebase Authentication together with Firestore and Storage security rules that restrict each user to their own data. For NR-BOS worksite photographs, this includes keeping files in a private object store reachable only through short-lived signed links rather than any public path. While we take all reasonable precautions, no method of electronic transmission or storage is entirely secure. We cannot guarantee absolute security, but we are committed to protecting your data to the highest practicable standard.
We retain your personal information only for as long as is necessary to fulfil the purposes outlined in this policy and to comply with our legal obligations:
Upon expiry of the applicable retention period, personal data is securely deleted or anonymised.
As a data subject under the GDPR, you have the following rights in relation to your personal data:
Request a copy of the personal data we hold about you.
Request correction of inaccurate or incomplete data.
Request deletion of your data in certain circumstances (“right to be forgotten”).
Request that we limit how we use your data in specified circumstances.
Receive your data in a structured, machine-readable format where applicable.
Object to processing based on legitimate interests or for direct marketing purposes.
Withdraw any consent given at any time, without affecting prior processing.
Lodge a complaint with the relevant supervisory authority (see Section 14).
To exercise any of the above rights, please contact us at info@nordicriser.com with the subject line “Data Subject Request”. We will respond within one calendar month as required by GDPR. If you are a data subject within a client's NR-BOS deployment, please direct your request to that client first, since they are the controller for that data — see Section 3.
This marketing website is a static informational site with minimal tracking. We may use essential cookies required for the basic operation of the site, including remembering your selected language. We do not currently use third-party advertising or behavioural tracking cookies. If we implement analytics or additional tracking technologies here in the future, we will obtain your prior consent before setting any non-essential cookie, disclose its purpose and duration, and offer a straightforward way to withdraw that consent.
The Member Portal and NR-BOS are authenticated applications, unlike the marketing website, and use cookies and equivalent local storage that are strictly necessary for them to function: maintaining your logged-in session, authentication tokens, and security measures such as CSRF protection. These are essential to the service and cannot be disabled without losing the ability to log in. We do not currently use analytics or advertising cookies in the Member Portal or NR-BOS; if that changes, the same consent-first commitment above applies there exactly as it does on the marketing website.
You may control and delete cookies through your browser settings at any time. Please note that disabling essential cookies will prevent you from logging in to the Portal or NR-BOS, and may affect the marketing website's functionality.
Our website, consulting services, and software products are directed exclusively at adults conducting professional and business activities. We do not knowingly collect personal data from individuals under the age of 18. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will take appropriate steps to delete that information.
We may update this Privacy Policy periodically to reflect changes in our practices, applicable legislation, or operational procedures. Material changes will be communicated by:
We encourage you to review this policy periodically. Your continued use of our website, Member Portal, or software products following any update constitutes acceptance of the revised policy.
If you have concerns about how we handle your personal data and you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority:
Integritetsskyddsmyndigheten (IMY) — Swedish Authority for Privacy Protection
Box 8114, 104 20 Stockholm — Phone: +46 8 657 61 00 — Website: www.imy.se
If you have any questions, concerns, or requests relating to this Privacy Policy or our data practices, please contact us directly:
Email us with the subject line “Privacy Policy Inquiry” and we will respond promptly.