Privacy Policy
Last Updated: January 19, 2026
Contact Email: support@nordiclys.com
1. Introduction & Scope
NordicLys (“we”, “our”, or “us”) is committed to protecting your privacy and personal data. This Privacy Policy explains how personal data is collected, used, stored, and protected when you access or use the NordicLys platform (“the Platform”), including live chat, messaging, and peer-support features.
This Policy applies to all users and is designed in accordance with:
- GDPR (EU Regulation 2016/679)
- Norwegian Personal Data Act (Personopplysningsloven)
- Swedish Data Protection Act (Dataskyddslagen)
- EU Digital Services Act (DSA)
2. Data Controller
NordicLys is the data controller within the meaning of GDPR Article 4(7).
Contact: support@nordiclys.com
3. Personal Data We Collect
3.1 Data You Provide
- Account information (email, username, authentication credentials; passwords are stored as a password hash).
- Profile information you choose to share (optional).
- User-generated content (posts, messages, and live chat communications).
- Support requests and reports (including safety reports and inquiries).
- Communications with NordicLys.
3.2 Automatically Collected Data
- IP address and approximate location (derived from IP for security purposes).
- Device and browser information (e.g., operating system, browser type).
- Log data and timestamps (usage, access, security events).
- Cookies and similar technologies.
Important: Please avoid sharing identifying information (e.g., full name, address, phone number, or other sensitive identifiers) in public areas. If you choose to share personal or sensitive information, you do so at your own discretion.
4. Purpose Limitation & Use of Data
We process personal data solely for explicit and legitimate purposes, including:
- Operating and maintaining the Platform.
- Enabling peer-support communication, messaging, and live chat.
- Safety, moderation, and abuse prevention.
- Responding to reports, support requests, and user inquiries.
- Improving platform functionality, performance, and security.
- Complying with legal and regulatory obligations.
We do not sell personal data and do not use personal data for advertising profiling.
5. Special Category Data (GDPR Article 9)
Because NordicLys is an emotional peer-support platform, content shared may include information about emotional state, mental health, or personal experiences that may constitute special category personal data under GDPR Article 9.
We process such data only when you voluntarily share it, and solely based on your explicit consent under Article 9(2)(a) GDPR, for the purposes described in Section 4.
You may withdraw consent at any time by deleting your content or contacting us. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
6. Legal Basis for Processing
We process personal data on the basis of:
- Consent (GDPR Art. 6(1)(a) and Art. 9(2)(a) where applicable).
- Performance of a contract (GDPR Art. 6(1)(b)) to provide the Platform and its features.
- Legal obligations (GDPR Art. 6(1)(c)) where required by law.
- Legitimate interests (GDPR Art. 6(1)(f)) such as platform security, moderation, fraud prevention, and service improvement, balanced against user rights.
7. Live Chat & Messaging
Live chat and private messaging data is processed to deliver the service and stored securely for limited periods.
- Messages are not actively monitored in real time by default.
- Moderators may access and review communications only when reasonably necessary for safety, moderation, abuse prevention, or compliance with legal obligations, including in response to user reports or credible concerns.
- NordicLys does not use live chat for automated decision-making or profiling.
8. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy and in accordance with applicable law. We apply the following retention limits:
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion |
| User content (posts/messages) | Until deleted by the user or anonymized |
| Chat logs (safety-related) | Up to 12 months |
| Technical logs | Up to 6 months |
| Legal records | As required by law |
9. Data Sharing & Processors
We do not sell personal data. Personal data may be shared with:
- Hosting and infrastructure providers (EU/EEA-based where possible).
- Secure messaging / service providers necessary to operate core functionality.
- Security and moderation providers where required for platform safety.
- Public authorities where legally required.
All service providers processing personal data on our behalf act under written data processing agreements in accordance with GDPR Article 28.
10. International Data Transfers
If personal data is transferred outside the EU/EEA, we ensure appropriate safeguards, such as:
- European Commission adequacy decisions, or
- Standard Contractual Clauses (SCCs) and supplementary measures where necessary.
11. Automated Decision-Making & AI
NordicLys does not engage in automated decision-making producing legal or similarly significant effects under GDPR Article 22.
If we introduce automated tools in the future (for example, for moderation assistance), we will update this Policy accordingly and provide appropriate transparency.
12. Security Measures
We implement appropriate technical and organizational measures in line with GDPR Article 32, including:
- Encryption in transit and at rest (where appropriate).
- Role-based access controls and least-privilege access.
- Secure authentication mechanisms.
- Ongoing monitoring and periodic security reviews.
No method of transmission or storage is 100% secure; however, we work to maintain safeguards appropriate to the nature of the data.
13. Personal Data Breaches
In the event of a personal data breach, we will notify the relevant supervisory authority without undue delay where required by law, and affected users will be informed where legally required.
14. Your Rights
You may have the right to:
- Access your personal data.
- Rectify inaccurate or incomplete data.
- Request erasure (“right to be forgotten”).
- Restrict or object to certain processing.
- Data portability where applicable.
- Withdraw consent at any time where processing is based on consent.
To exercise your rights, contact us at support@nordiclys.com. We will respond within the timeframes required by applicable law.
You also have the right to lodge a complaint with a supervisory authority, including:
- Datatilsynet (Norway)
- IMY – Integritetsskyddsmyndigheten (Sweden)
- Your local authority within the EU/EEA
15. Children
NordicLys is not intended for individuals under 18. We do not knowingly process personal data of minors. If we learn that we have collected personal data of a minor, we will delete it promptly.
16. Cookies
We use cookies in compliance with EU ePrivacy rules to maintain secure sessions and improve performance. Please review our Cookie Policy for more details and consent management.
17. Digital Services Act (DSA)
We process personal data for content moderation, reporting mechanisms, and transparency obligations under the EU Digital Services Act. We do not use profiling for trust and safety decisions.
18. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated where required. The latest version will be posted on this page with an updated “Last Updated” date.
19. Contact
If you have questions about this Privacy Policy or our data handling practices, please contact:
NordicLys
Email: support@nordiclys.com