Legal

Privacy Policy

How Nordic Riser AB collects, uses, and protects your personal information in accordance with the EU General Data Protection Regulation (GDPR).

📅 Last Updated: 25 March 2026

1 Introduction

Nordic Riser AB ("we", "our", or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or engage with our advisory services.

This policy is designed to comply with the EU General Data Protection Regulation (GDPR) and applicable data protection legislation. By using our website or submitting an inquiry, you acknowledge that you have read and understood this policy.

2 Data Controller

Nordic Riser AB is the data controller responsible for your personal information collected through our website and services.

Nordic Riser AB
Email: info@nordicriser.com
Website: www.nordicriser.com

For all data protection matters, please contact us using the details above with the subject line "Data Protection Inquiry".

3 Information We Collect

3.1 Information You Provide Directly

We collect information that you voluntarily provide to us, including:

  • Contact Information: Name, email address, phone number
  • Professional Information: Business type, professional background, business objectives
  • Consultation Request Data: Purpose of consultation and description of your situation as submitted via our contact form
  • Communication Data: Information contained in emails and other correspondence with our team

3.2 Information Collected Automatically

When you visit our website, we may automatically collect:

  • Technical Data: IP address, browser type, operating system, device information
  • Usage Data: Pages visited, time spent on pages, navigation paths
  • Cookies: Small data files stored on your device (see Section 9)

4 How We Use Your Information

We process your personal data only for the purposes outlined below, each supported by a lawful basis under GDPR:

Purpose Legal Basis (GDPR)
Responding to consultation requests and inquiries Contract performance / Legitimate interest
Providing strategic advisory services Contract performance
Communicating about our services and engagement progress Contract performance / Consent
Improving our website and service quality Legitimate interest
Coordinating with third-party professionals (legal, accounting) Contract performance / Legitimate interest
Compliance with legal and regulatory obligations Legal obligation

We will not sell, rent, or trade your personal information to third parties. We will not use your data for purposes incompatible with those stated above.

5 Data Sharing and Disclosure

5.1 Professional Service Partners

Where required to deliver our services, we may share relevant information with qualified third-party professionals, including:

  • Legal counsel and specialist advisors engaged in connection with your matter
  • Accounting and tax professionals involved in business formation or compliance
  • Technology providers supporting our website hosting and communications infrastructure

All third parties are required to maintain appropriate security measures and are permitted to process your data only as directed by us and within the scope of their professional obligations.

5.2 Legal Requirements

We may disclose your personal information when required to do so by law, regulation, legal process, or a legitimate governmental request.

5.3 International Data Transfers

We primarily process data within the EU/EEA. In the event that data is transferred outside the EU/EEA, we ensure that appropriate safeguards are in place — such as Standard Contractual Clauses or applicable adequacy decisions — prior to any such transfer.

6 Data Security

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encrypted communication channels for the transmission of sensitive information
  • Secure server infrastructure and data storage systems
  • Access controls and authentication procedures for internal systems
  • Regular review and updating of security practices
  • Staff awareness of data protection obligations

While we take all reasonable precautions, no method of electronic transmission or storage is entirely secure. We cannot guarantee absolute security, but we are committed to protecting your data to the highest practicable standard.

7 Data Retention

We retain your personal information only for as long as is necessary to fulfil the purposes outlined in this policy and to comply with our legal obligations:

  • Active Client Data: Duration of the engagement plus 7 years (in accordance with applicable accounting and record-keeping legislation)
  • Inquiry Data (non-converted): 2 years from the date of last contact
  • Website Analytics Data: Maximum 26 months
  • Consent Records: Until consent is withdrawn, plus a reasonable period thereafter for record-keeping purposes

Upon expiry of the applicable retention period, personal data is securely deleted or anonymised.

8 Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights in relation to your personal data:

Right of Access

Request a copy of the personal data we hold about you.

Right to Rectification

Request correction of inaccurate or incomplete data.

Right to Erasure

Request deletion of your data in certain circumstances ("right to be forgotten").

Right to Restrict Processing

Request that we limit how we use your data in specified circumstances.

Right to Data Portability

Receive your data in a structured, machine-readable format where applicable.

Right to Object

Object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Withdraw any consent given at any time, without affecting prior processing.

Right to Complain

Lodge a complaint with the relevant supervisory authority (see Section 12).

To exercise any of the above rights, please contact us at info@nordicriser.com with the subject line "Data Subject Request". We will respond within one calendar month as required by GDPR.

9 Cookies and Tracking Technologies

Our website is a static informational site with minimal tracking. We may use essential cookies required for the basic operation of the site. We do not currently use third-party advertising or behavioural tracking cookies.

If we implement analytics or additional tracking technologies in the future, we will:

  • Obtain your prior consent before setting any non-essential cookies
  • Provide clear information about each cookie's purpose and duration
  • Offer straightforward mechanisms to manage or withdraw your cookie preferences

You may control and delete cookies through your browser settings at any time. Please note that disabling certain cookies may affect the functionality of the website.

10 Children's Privacy

Our services are directed exclusively at adults conducting professional and business activities. We do not knowingly collect personal data from individuals under the age of 18. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will take appropriate steps to delete that information.

11 Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, applicable legislation, or operational procedures. Material changes will be communicated by:

  • Updating the "Last Updated" date at the top of this page
  • Where appropriate, notifying active clients by email
  • Posting a notice on our website

We encourage you to review this policy periodically. Your continued use of our website following any update constitutes acceptance of the revised policy.

12 Supervisory Authority

If you have concerns about how we handle your personal data and you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority:

Integritetsskyddsmyndigheten (IMY)
Swedish Authority for Privacy Protection
Box 8114, 104 20 Stockholm
Phone: +46 8 657 61 00
Website: www.imy.se

13 Contact Us Regarding This Policy

If you have any questions, concerns, or requests relating to this Privacy Policy or our data practices, please contact us directly:

Data Protection Enquiries

Email us with the subject line "Privacy Policy Inquiry" and we will respond promptly.

info@nordicriser.com