Privacy Policy

Privacy Policy - tps.XYZ

🔐 PRIVACY POLICY

Last Updated: January 19, 2026

1. Introduction & Scope

NordicLys (“we”, “our”, or “us”) is committed to protecting your privacy and personal data. This Privacy Policy explains how personal data is collected, used, stored, and protected when you access or use the NordicLys platform (“the Platform”), including live chat, messaging, and peer-support features.

This Policy applies to all users and is designed in accordance with:

  • EU General Data Protection Regulation (GDPR)

  • Norwegian Personal Data Act (Personopplysningsloven)

  • Swedish Data Protection Act (Dataskyddslagen)

  • EU Digital Services Act (DSA)


2. Data Controller

NordicLys is the data controller within the meaning of GDPR Article 4(7).

📧 Contact: support@nordiclys.com


3. Categories of Personal Data

3.1 Data Provided by You

  • Account information (email, username, authentication credentials)

  • Profile information (optional)

  • User-generated content (posts, messages, live chat communications)

  • Support requests and safety reports

  • Communications with NordicLys

3.2 Automatically Collected Data

  • IP address and approximate location

  • Device, browser, and operating system data

  • Log files, timestamps, and usage data

  • Cookies and similar technologies


4. Purpose Limitation & Use of Data

We process personal data solely for explicit and legitimate purposes, including:

  • Operating and maintaining the Platform

  • Enabling peer-support communication and live chat

  • Safety, moderation, and abuse prevention

  • Compliance with legal and regulatory obligations

  • Improving platform performance and security

We do not use personal data for advertising profiling or resale.


5. Special Category Data (GDPR Article 9)

NordicLys may process personal data revealing emotional state, mental health, or personal experiences, which may constitute special category data.

Processing occurs only when you voluntarily share such information, and solely based on your explicit consent under Article 9(2)(a) GDPR, for the purposes listed in Section 4.

You may withdraw consent at any time without affecting the lawfulness of prior processing.


6. Legal Bases for Processing

Personal data is processed on the basis of:

  • Consent (Art. 6(1)(a), Art. 9(2)(a))

  • Performance of a contract (Art. 6(1)(b))

  • Legal obligation (Art. 6(1)(c))

  • Legitimate interests (Art. 6(1)(f)), including platform security and moderation, balanced against user rights


7. Live Chat & Messaging

Live chat and private messaging data:

  • Is processed to deliver the service

  • Is stored securely for limited periods

  • Is accessed by moderators only when required for safety, abuse prevention, or legal compliance

  • Is not subject to automated decision-making or profiling

Messages are not monitored in real time by default.


8. Data Retention

We apply strict retention limits:

Data TypeRetention Period
Account dataUntil account deletion
User contentUntil deleted by user or anonymized
Chat logs (safety-related)Up to 12 months
Technical logsUp to 6 months
Legal recordsAs required by law

9. Data Sharing & Processors

We do not sell personal data.

Personal data may be shared with:

  • Hosting and infrastructure providers

  • Secure messaging service providers

  • Moderation and safety service providers

  • Public authorities where legally required

All processors act under written data processing agreements in accordance with GDPR Article 28.


10. International Transfers

Where personal data is transferred outside the EU/EEA, we apply appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs)

  • Adequacy decisions by the European Commission


11. Automated Decision-Making & AI

NordicLys does not engage in automated decision-making producing legal or significant effects under GDPR Article 22.

If automated tools are introduced in the future (e.g. for moderation assistance), this Policy will be updated accordingly.


12. Security Measures

We implement state-of-the-art technical and organizational measures under GDPR Article 32, including:

  • Encryption at rest and in transit

  • Role-based access controls

  • Secure authentication mechanisms

  • Continuous monitoring and regular security audits


13. Personal Data Breaches

In the event of a personal data breach:

  • We will notify the relevant supervisory authority without undue delay

  • Affected users will be informed where required by law


14. Your Rights

You have the right to:

  • Access personal data

  • Rectify inaccurate data

  • Request erasure

  • Restrict or object to processing

  • Data portability

  • Withdraw consent at any time

  • Lodge a complaint with a supervisory authority:

    • Datatilsynet (Norway)

    • IMY – Integritetsskyddsmyndigheten (Sweden)


15. Children

NordicLys is not intended for individuals under 18. We do not knowingly process personal data of minors.


16. Cookies

We use cookies in compliance with EU ePrivacy rules. Details are provided in our separate Cookie Policy.


17. Digital Services Act (DSA)

We process personal data for content moderation, reporting mechanisms, and transparency obligations under the EU Digital Services Act. No profiling is used for trust and safety decisions.


18. Changes to This Policy

We may update this Policy periodically. Material changes will be communicated as required.


19. Contact

📧 support@nordiclys.com
NordicLys

© 2026 NordicLys