🔐 PRIVACY POLICY
Last Updated: January 19, 2026
1. Introduction & Scope
NordicLys (“we”, “our”, or “us”) is committed to protecting your privacy and personal data. This Privacy Policy explains how personal data is collected, used, stored, and protected when you access or use the NordicLys platform (“the Platform”), including live chat, messaging, and peer-support features.
This Policy applies to all users and is designed in accordance with:
EU General Data Protection Regulation (GDPR)
Norwegian Personal Data Act (Personopplysningsloven)
Swedish Data Protection Act (Dataskyddslagen)
EU Digital Services Act (DSA)
2. Data Controller
NordicLys is the data controller within the meaning of GDPR Article 4(7).
📧 Contact: support@nordiclys.com
3. Categories of Personal Data
3.1 Data Provided by You
Account information (email, username, authentication credentials)
Profile information (optional)
User-generated content (posts, messages, live chat communications)
Support requests and safety reports
Communications with NordicLys
Account information (email, username, authentication credentials)
Profile information (optional)
User-generated content (posts, messages, live chat communications)
Support requests and safety reports
Communications with NordicLys
3.2 Automatically Collected Data
IP address and approximate location
Device, browser, and operating system data
Log files, timestamps, and usage data
Cookies and similar technologies
IP address and approximate location
Device, browser, and operating system data
Log files, timestamps, and usage data
Cookies and similar technologies
4. Purpose Limitation & Use of Data
We process personal data solely for explicit and legitimate purposes, including:
Operating and maintaining the Platform
Enabling peer-support communication and live chat
Safety, moderation, and abuse prevention
Compliance with legal and regulatory obligations
Improving platform performance and security
We do not use personal data for advertising profiling or resale.
5. Special Category Data (GDPR Article 9)
NordicLys may process personal data revealing emotional state, mental health, or personal experiences, which may constitute special category data.
Processing occurs only when you voluntarily share such information, and solely based on your explicit consent under Article 9(2)(a) GDPR, for the purposes listed in Section 4.
You may withdraw consent at any time without affecting the lawfulness of prior processing.
6. Legal Bases for Processing
Personal data is processed on the basis of:
Consent (Art. 6(1)(a), Art. 9(2)(a))
Performance of a contract (Art. 6(1)(b))
Legal obligation (Art. 6(1)(c))
Legitimate interests (Art. 6(1)(f)), including platform security and moderation, balanced against user rights
7. Live Chat & Messaging
Live chat and private messaging data:
Is processed to deliver the service
Is stored securely for limited periods
Is accessed by moderators only when required for safety, abuse prevention, or legal compliance
Is not subject to automated decision-making or profiling
Messages are not monitored in real time by default.
8. Data Retention
We apply strict retention limits:
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion |
| User content | Until deleted by user or anonymized |
| Chat logs (safety-related) | Up to 12 months |
| Technical logs | Up to 6 months |
| Legal records | As required by law |
9. Data Sharing & Processors
We do not sell personal data.
Personal data may be shared with:
Hosting and infrastructure providers
Secure messaging service providers
Moderation and safety service providers
Public authorities where legally required
All processors act under written data processing agreements in accordance with GDPR Article 28.
10. International Transfers
Where personal data is transferred outside the EU/EEA, we apply appropriate safeguards, including:
Standard Contractual Clauses (SCCs)
Adequacy decisions by the European Commission
11. Automated Decision-Making & AI
NordicLys does not engage in automated decision-making producing legal or significant effects under GDPR Article 22.
If automated tools are introduced in the future (e.g. for moderation assistance), this Policy will be updated accordingly.
12. Security Measures
We implement state-of-the-art technical and organizational measures under GDPR Article 32, including:
Encryption at rest and in transit
Role-based access controls
Secure authentication mechanisms
Continuous monitoring and regular security audits
13. Personal Data Breaches
In the event of a personal data breach:
We will notify the relevant supervisory authority without undue delay
Affected users will be informed where required by law
14. Your Rights
You have the right to:
Access personal data
Rectify inaccurate data
Request erasure
Restrict or object to processing
Data portability
Withdraw consent at any time
Lodge a complaint with a supervisory authority:
Datatilsynet (Norway)
IMY – Integritetsskyddsmyndigheten (Sweden)
15. Children
NordicLys is not intended for individuals under 18. We do not knowingly process personal data of minors.
16. Cookies
We use cookies in compliance with EU ePrivacy rules. Details are provided in our separate Cookie Policy.
17. Digital Services Act (DSA)
We process personal data for content moderation, reporting mechanisms, and transparency obligations under the EU Digital Services Act. No profiling is used for trust and safety decisions.
18. Changes to This Policy
We may update this Policy periodically. Material changes will be communicated as required.
19. Contact
📧 support@nordiclys.com
NordicLys
© 2026 NordicLys