Legal

Privacy Policy

How Nordic Riser AB collects, uses, and protects your personal information in accordance with the EU General Data Protection Regulation (GDPR).

This document is not yet available in Deutsch. The English text below is authoritative while a professional legal translation is prepared. Contact us with questions.
Last Updated: 19 August 2026

What changed in this update: this policy previously covered our consulting business only. It now also covers the Member Portal, NR-BOS, and Global Reach. We added a Controller vs. Processor section, a full named Sub-processor list, an explicit disclosure of the AI provider used in NR-BOS, and split the Cookies section between the marketing site and our authenticated products. A Terms of Service and a Data Processing Agreement are published alongside this policy for the first time — see the Legal index.

1 Introduction

Nordic Riser AB (“we”, “our”, or “us”) is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information across everything we operate: this website, our strategic consulting services, the Nordic Riser Member Portal, and the software products we build and license — including NR-BOS and Global Reach.

This policy is designed to comply with the EU General Data Protection Regulation (GDPR) and applicable data protection legislation. By using our website, our Member Portal, or any of our software products, or by submitting an inquiry, you acknowledge that you have read and understood this policy.

2 Data Controller

Nordic Riser AB is the data controller responsible for your personal information collected through this website, the Member Portal, and our consulting engagements. Section 3 explains the separate case — building and hosting software for a client — in which Nordic Riser AB instead acts as a data processor.

Nordic Riser AB
Email: info@nordicriser.com

For all data protection matters, please contact us using the details above with the subject line “Data Protection Inquiry”.

3 Controller vs. Processor — Which Applies to You

Nordic Riser AB relates to personal data in two different capacities, and which one applies depends on what you're using.

As a controller, we decide why and how personal data is processed for our own consulting business, this marketing website, and the Member Portal we operate under our own brand. This Privacy Policy governs that processing.

As a processor, when we build, host, or operate a system on a client's behalf — for example, an NR-BOS deployment run for a construction company's own workforce and clients — the client is the data controller for the personal data in that system, and Nordic Riser AB processes it only on the client's documented instructions, under a Data Processing Agreement. If you are an employee, subcontractor, or client of one of our software customers, this Privacy Policy is not the governing document for how your data is handled there — your relationship is with that customer, and our obligations run to them under the DPA, not directly to you.

We offer a Data Processing Agreement to any client on request — see our Legal index for the DPA.

4 Information We Collect

4.1 Information You Provide Directly

We collect information that you voluntarily provide to us, including:

  • Contact Information: Name, email address, phone number
  • Professional Information: Business type, professional background, business objectives
  • Consultation Request Data: Purpose of consultation and description of your situation as submitted via our contact form
  • Communication Data: Information contained in emails and other correspondence with our team

4.2 Information Collected Automatically

When you visit our website, we may automatically collect:

  • Technical Data: IP address, browser type, operating system, device information
  • Usage Data: Pages visited, time spent on pages, navigation paths
  • Cookies: Small data files stored on your device (see Section 11)

4.3 Member Portal (portal.nordicriser.com)

As a registered member, we collect:

  • Account Data: name, email address, authentication credentials, and role, managed through Firebase Authentication
  • Documents: files you upload for case processing
  • Messages: the content of secure messages you exchange through the portal
  • Case & Timeline Data: status and progress information related to your case
  • Payment Records: invoices, payment claims, and top-up requests you submit — we do not collect or store card numbers; payments are reviewed manually rather than through an automated payment processor

4.4 NR-BOS

NR-BOS is typically operated by one of our clients for their own workforce, in which case Nordic Riser AB processes this data as a processor, not a controller (see Section 3). We describe it here so that anyone who is a data subject within an NR-BOS deployment understands what is collected:

  • Account & Company Data: the names, roles, and employment relationship of individuals a client organisation adds as NR-BOS users
  • Worksite Photographs: photographs uploaded through field reports. The photo file is stored exactly as uploaded, including any location or timestamp metadata (EXIF) already embedded by the device that took it. Separately, the field report itself records GPS coordinates and a timestamp reported by the submitting device at the moment of filing, for site-verification purposes. Worksite photographs are never made public — every photo is kept in a private file store and is only ever reachable through short-lived, authenticated links available to authorised members of the relevant project
  • Project & Task Records: project names, task titles, status, due dates, and assignee
  • Working Hours: hours logged against tasks by named employees
  • Cost Data: cost entries associated with projects and tasks

4.5 Global Reach

As a Global Reach user:

  • Chat Messages: the content of messages sent through Global Reach's live collaboration rooms, including message text submitted for real-time translation — see Section 6.4 for how that translation is provided and Section 7 for the sub-processor involved

5 How We Use Your Information

We process your personal data only for the purposes outlined below, each supported by a lawful basis under GDPR:

PurposeLegal Basis (GDPR)
Responding to consultation requests and inquiriesContract performance / Legitimate interest
Providing strategic advisory, technology, and global collaboration servicesContract performance
Operating and securing the Member Portal, including authentication and document/message storageContract performance
Delivering NR-BOS to our licensing customers, including field reporting, project tracking, and AI-assisted analysisContract performance (as processor, per our client's instructions)
Providing real-time translation within Global ReachContract performance
Communicating about our services and engagement progressContract performance / Consent
Improving our website and service qualityLegitimate interest
Coordinating with third-party professionals (legal, accounting)Contract performance / Legitimate interest
Compliance with legal and regulatory obligationsLegal obligation

We will not sell, rent, or trade your personal information to third parties. We will not use your data for purposes incompatible with those stated above.

6 Data Sharing and Disclosure

6.1 Professional Service Partners

Where required to deliver our services, we may share relevant information with qualified third-party professionals, including:

  • Legal counsel and specialist advisors engaged in connection with your matter
  • Accounting and tax professionals involved in business formation or compliance
  • Technology providers supporting our website, Member Portal, and software product hosting — see our full Sub-processor list, Section 7

All third parties are required to maintain appropriate security measures and are permitted to process your data only as directed by us and within the scope of their professional obligations.

6.2 Legal Requirements

We may disclose your personal information when required to do so by law, regulation, legal process, or a legitimate governmental request.

6.3 International Data Transfers

Where personal data is transferred outside the EU/EEA, we ensure an appropriate transfer mechanism — typically the European Commission's Standard Contractual Clauses — is in place before any such transfer takes place. Section 7 lists every sub-processor we use, including where each one is located and which transfer mechanism applies. One of those transfers, described in full below, is to a company based in China, a jurisdiction without an EU adequacy decision.

6.4 AI Processing in NR-BOS

NR-BOS includes an optional AI Assistant that generates risk, cost, and productivity insights from a project's data. We are describing this plainly, including the parts that are not yet as protective as we'd like, rather than describing a safeguard that isn't actually in place:

  • When this feature is used, the relevant project data — including project and company names, budget figures, task details, cost entries, and the full names and roles of assigned team members — is sent to our AI provider, DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.), to generate the analysis.
  • We do not currently redact or anonymise personal identifiers before this data is transmitted. If this matters to how you use NR-BOS, contact us or your NR-BOS administrator — a client operating NR-BOS as controller can restrict use of the AI Assistant for their own deployment.
  • DeepSeek's own API data policy states that data submitted through its API is not used to train its models. This is DeepSeek's representation, not a guarantee we independently audit.
  • The output is advisory only. Nothing in NR-BOS acts on an AI-generated insight automatically — a person always reviews it and decides what, if anything, to do.
  • Because DeepSeek is based in China, this transfer relies on Standard Contractual Clauses as the GDPR Chapter V safeguard. China has no European Commission adequacy decision, and transfers of this kind are subject to heightened regulatory attention across the EU. We are disclosing this specifically, by name, so that you can decide with full information whether it matters to you — see Section 7 for the full sub-processor entry.

7 Sub-processors

To help meet our own transparency obligations and give you full visibility into who processes personal data on our behalf, we maintain a complete, current sub-processor list — what each one does, what data category it touches, where it's located, and what transfer safeguard applies — as its own page, linked from our Legal index.

If we add a new sub-processor, we will update that list and, for clients with a Data Processing Agreement in place, give notice before the change takes effect, consistent with the objection right described in that agreement.

8 Data Security

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encrypted communication channels for the transmission of sensitive information
  • Secure server infrastructure and data storage systems
  • Access controls and authentication procedures for internal systems
  • Regular review and updating of security practices
  • Staff awareness of data protection obligations

For the Member Portal, this includes Firebase Authentication together with Firestore and Storage security rules that restrict each user to their own data. For NR-BOS worksite photographs, this includes keeping files in a private object store reachable only through short-lived signed links rather than any public path. While we take all reasonable precautions, no method of electronic transmission or storage is entirely secure. We cannot guarantee absolute security, but we are committed to protecting your data to the highest practicable standard.

9 Data Retention

We retain your personal information only for as long as is necessary to fulfil the purposes outlined in this policy and to comply with our legal obligations:

  • Active Client Data: Duration of the engagement plus 7 years (in accordance with applicable accounting and record-keeping legislation)
  • Inquiry Data (non-converted): 2 years from the date of last contact
  • Website Analytics Data: Maximum 26 months
  • Software Product Data (Member Portal, NR-BOS): retained for the duration of the account or licensing relationship, plus a reasonable period after termination for legal, accounting, and dispute-resolution purposes, unless a shorter period is agreed in a client's Data Processing Agreement
  • Consent Records: Until consent is withdrawn, plus a reasonable period thereafter for record-keeping purposes

Upon expiry of the applicable retention period, personal data is securely deleted or anonymised.

10 Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights in relation to your personal data:

Right of Access

Request a copy of the personal data we hold about you.

Right to Rectification

Request correction of inaccurate or incomplete data.

Right to Erasure

Request deletion of your data in certain circumstances (“right to be forgotten”).

Right to Restrict Processing

Request that we limit how we use your data in specified circumstances.

Right to Data Portability

Receive your data in a structured, machine-readable format where applicable.

Right to Object

Object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Withdraw any consent given at any time, without affecting prior processing.

Right to Complain

Lodge a complaint with the relevant supervisory authority (see Section 14).

To exercise any of the above rights, please contact us at info@nordicriser.com with the subject line “Data Subject Request”. We will respond within one calendar month as required by GDPR. If you are a data subject within a client's NR-BOS deployment, please direct your request to that client first, since they are the controller for that data — see Section 3.

11 Cookies and Tracking Technologies

11.1 Marketing Website (nordicriser.com)

This marketing website is a static informational site with minimal tracking. We may use essential cookies required for the basic operation of the site, including remembering your selected language. We do not currently use third-party advertising or behavioural tracking cookies. If we implement analytics or additional tracking technologies here in the future, we will obtain your prior consent before setting any non-essential cookie, disclose its purpose and duration, and offer a straightforward way to withdraw that consent.

11.2 Member Portal & NR-BOS

The Member Portal and NR-BOS are authenticated applications, unlike the marketing website, and use cookies and equivalent local storage that are strictly necessary for them to function: maintaining your logged-in session, authentication tokens, and security measures such as CSRF protection. These are essential to the service and cannot be disabled without losing the ability to log in. We do not currently use analytics or advertising cookies in the Member Portal or NR-BOS; if that changes, the same consent-first commitment above applies there exactly as it does on the marketing website.

You may control and delete cookies through your browser settings at any time. Please note that disabling essential cookies will prevent you from logging in to the Portal or NR-BOS, and may affect the marketing website's functionality.

12 Children's Privacy

Our website, consulting services, and software products are directed exclusively at adults conducting professional and business activities. We do not knowingly collect personal data from individuals under the age of 18. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will take appropriate steps to delete that information.

13 Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, applicable legislation, or operational procedures. Material changes will be communicated by:

  • Updating the “Last Updated” date and the “What changed” note at the top of this page
  • Where appropriate, notifying active clients by email
  • Posting a notice on our website

We encourage you to review this policy periodically. Your continued use of our website, Member Portal, or software products following any update constitutes acceptance of the revised policy.

14 Supervisory Authority

If you have concerns about how we handle your personal data and you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority:

Integritetsskyddsmyndigheten (IMY) — Swedish Authority for Privacy Protection

Box 8114, 104 20 Stockholm — Phone: +46 8 657 61 00 — Website: www.imy.se

15 Contact Us Regarding This Policy

If you have any questions, concerns, or requests relating to this Privacy Policy or our data practices, please contact us directly:

Data Protection Enquiries

Email us with the subject line “Privacy Policy Inquiry” and we will respond promptly.

info@nordicriser.com