NordicSync AS

Privacy Policy

Last updated: 30 July 2026

This privacy policy explains how NordicSync AS processes personal data when you use our website or send us an inquiry.

Who is the controller?

NordicSync AS is the controller for personal data processed through this website.

NordicSync AS, organisation number 838 058 302, Riskestien 52, 1525 Moss, Norway. Website: https://www.nordicsync.no.

What information do we process?

When you submit the contact form, we process the information you provide, such as your name, email address, phone number, company name, customer type, selected service, package or add-ons and the content of your message.

To deliver and protect the website, we may also process limited technical information such as the time, page address, browser information and IP address. The contact form rate limit uses a temporary technical key derived from the IP address solely to detect misuse.

Purposes and legal bases

We process contact information to answer your inquiry, clarify your needs, prepare an offer, follow up possible cooperation and provide customer support. The legal basis is Article 6(1)(b) GDPR when processing is necessary to take steps before a possible contract.

We process necessary technical information to secure the website, prevent spam and misuse and document relevant business communication. The legal basis is our legitimate interest under Article 6(1)(f) GDPR. We may also process information when necessary to comply with a legal obligation under Article 6(1)(c) GDPR.

Processors and sharing

NordicSync AS does not sell personal data. We provide access only when necessary to deliver and secure the service.

Vercel is used for website hosting, delivery and technical security. Resend is used to send the contact inquiry and an automatic email reply. The information may also be processed by NordicSync's email provider when the message is received and followed up. Providers process information under contract and our instructions where they act as processors.

When you consent to the relevant categories, Google Analytics 4 from Google is used for visitor analytics and Meta Pixel from Meta is used for ad measurement and audiences. These providers may receive technical identifiers and information about how the website is used.

Transfers outside the EEA

Vercel, Resend, Google, Meta or their subprocessors may process information outside the EEA. When such a transfer takes place, it must rely on a valid transfer mechanism, such as an adequacy decision, the EU Standard Contractual Clauses or another lawful basis, together with necessary safeguards.

How long do we keep information?

An inquiry that does not lead to a customer relationship is normally deleted or anonymised no later than 12 months after the last relevant contact. Information forming part of an offer, customer relationship, dispute or legally required documentation may be kept longer for as long as the purpose or legal obligation applies.

The temporary key used for local contact form rate limiting expires after 15 minutes. Technical logs held by hosting and email providers are kept according to provider settings and applicable data processing agreements.

Cookies and analytics

The website uses the necessary nordicsync_cookie_consent_v1 cookie to store your choices for 180 days. It contains the selected categories, version and time of the choice and is not used for tracking.

To produce anonymous consent statistics, we store a random browser ID together with the choice, language and time for up to 400 days. We do not store names, email addresses, IP addresses or contact-form content in these statistics, and the ID is not used to identify people.

If you consent to analytics, Google Analytics 4 is activated. The service may process page views, approximate geographic area, referral source and device and browser information. Google Analytics may set the _ga and _ga_<container-id> cookies with a default duration of up to two years.

If you consent to marketing, Meta Pixel is activated. The service records page views and technical identifiers to measure ads and make it possible to reach previous visitors. Meta may set the _fbp and _fbc cookies; _fbp normally lasts up to 90 days.

Analytics and marketing are off by default and are activated only after voluntary consent under Article 6(1)(a) GDPR and section 3-15 of the Norwegian Electronic Communications Act. You can change or withdraw consent at any time through “Cookie settings” in the website footer. Withdrawal does not affect the lawfulness of processing already carried out.

Your rights

You may request access to, correction or deletion of your personal data. Where the relevant conditions are met, you may also request restriction, object to processing or request data portability.

You may complain to the Norwegian Data Protection Authority if you believe the processing breaches data protection rules. More information is available at https://www.datatilsynet.no.

Security and automated decisions

We use technical and organisational measures to protect information, including contact form validation, spam controls, request limiting and access controls at service providers.

Information from the contact form is not used for automated decisions or profiling that produces legal or similarly significant effects.

Contact

For privacy questions or to exercise your rights, contact NordicSync AS at info@nordicsync.no or phone +47 48 42 20 75.

Changes to this policy

We update this privacy policy when our processing or services change. The latest version is published on this page with an updated date.

Privacy Policy | NordicSync AS