NordPass Business and NordLocker Business

Data Processing Agreement

NordLayer

NordStellar

NordStellar Privacy Policy

Effective from: April 22, 2024

  1. PROCESSING OF PERSONAL DATA – NORD’S ROLE AS DATA PROCESSOR
    • Account information. On behalf of our Customers, we process End Users’ names, email, professional information (position, represented entity’s information) account registration, login information, subscription information, device information (e.g., device name, IP address, OS).
    • Authentication information. When you create an account on our platform or log in to our Services, we collect and process certain login credentials, which are required to verify your identity and provide you with access to our Services. This may include your email address, username, password, and any additional information you choose to provide during the registration process. We use this information solely for user authentication.
    • Single Sign-On. If you use Single Sign-On (SSO) functionality, allowing you to log in to our platform using existing credentials from third-party authentication services such as Google, Apple or Microsoft, we may collect and process certain personal information from the third-party service provider to facilitate your login process and provide you with access to our platform or Services. This may include your name, email address, profile picture, and other basic information provided by the authentication service. We use this information solely for the purpose of authentication, and we do not share your SSO credentials or personal data with any third parties.

    1. PROCESSING OF PERSONAL DATA – NORD’S ROLE AS DATA CONTROLLER

      We collect (directly from you, third parties or your interactions, use, and experiences with our Services/Website) and use the information for the following purposes:

      • Personal information. In order to conclude and perform a business agreement with the Customer, we may process Customer's representatives' contact information (full name, telephone number, and/or email address) and professional information (position, represented entity's information).

      • Payment data. If you have provided payment information to us, such as basic billing information belonging to a natural person (date of purchase, IP address, postal (ZIP) code, billing address), we will process this information (i) to verify payment's information and prevent fraudulent payments for the Services; (ii) to collect payments to the extent that doing so is necessary to complete a transaction.
      • Country details. When making a purchase as a natural individual, we process the information on the country the purchase takes place. This information is necessary for VAT calculation purposes.

      • Access logs. To ensure Website support and security we collect access logs, such as your IP address, operating system, and browser information. This information is essential for fighting DDoS attacks, scanning, and similar hacking attempts. We also use this information to help us design our site better, help diagnose problems with our server, and administer our Website.
      • Information received from analytics service providers. To analyze and improve our Website and users' experience, we use analytics service providers (e.g., Google Analytics) to help us collect aggregated information that does not directly identify you, but provides us with various statistics, such as, which pages visitors visit the most and for how long they stay there. We may also see the following: your device's IP address, device type, browser information, geographic location (country only), preferred language, the title of the page being viewed, screen size and resolution, out links, referrers, page and website speed. For the collection of such information, our service providers mostly use cookies.
      • Cookies. Cookies, pixels, and other similar technologies are usually small text or image files that are placed on your device when you visit our Website. Some cookies are essential for our Website to operate smoothly; others are used to improve the Website's functionality, analyze aggregated usage statistics to improve the Website's performance, and for advertising purposes. Our Website may include social media features, such as the Facebook like and/or share buttons, to help you share our content more easily. These features may collect information about your IP address and which page you are visiting on our Website, and they may set a cookie to make sure the feature functions properly. We also use affiliate cookies to identify the Customers referred to our Website by our partners so that we can grant the referrers their commission. You can check our Cookie Policy for more information.

      • Communication optimization data. We use various tools to help us optimize our email campaigns. These tools may track actions you perform with an email, such as open rates, click-through rates or unsubscribes from further communication. We may also be able to see the user device’s operating system (e.g., Windows, Mac, iOS, Android).
      • Social media. When you interact with us via social media, we may process information available on your social media profile, also your inquiry or post information, and other information you provide us with.
      • Other communication means. When you contact us to inquire about our Services, we process your full name, email address, entity’s information you contact on behalf of (if provided), and/or other information you provide us with.

      • Information related to marketing activities. We may receive certain data about you (i) directly from you, if you subscribe to marketing communications, complete surveys, or sign up for our events or webinars, publicly available material prepared by Nord or (ii) from certain advertisers and other partners which we use for advertising purposes. Those partners help us deliver more relevant ads and promotional messages to you, which may include interest-based advertising (also known as online behavioral advertising) and account-based advertising. We may also receive your personal data from the organizers of events that you and Nord participate in, or promotions that we sponsor or participate in. Such data may include your contact and professional data (e.g., name, company, position, email address, preferences, and/or interests), cookie id, mobile device id, and inferences about your interests and preferences. We use this information in order to send you offers, surveys, and other marketing content (in line with applicable law) and to manage your participation in our events or seminars. You can easily opt-out of future marketing communications using the opt-out link provided in the emails sent to you.

      1. GROUNDS FOR PROCESSING OF PERSONAL DATA
        • To fulfill contractual obligations. The information provided might be required for the performance of a contract, i.e., (i) to provide Services and customer support; (ii) to process purchase transactions; (iii) to ensure the secure, reliable, and robust performance of our Services and Website.
        • To ensure legal obligation. We might be required to use your information as per legal requirements, e.g., to keep and process records for tax purposes and accounting.
        • Your consent. We might use your information where you have given your consent to us, i.e., (i) to send marketing communication (unless applicable law permits us to contact you without prior consent); (ii) to communicate with you and manage your participation in our contests, offers, referrals, or promotions. Please note that although we may also process your personal data for marketing purposes when applicable law permits us to contact you without your separate consent, if you choose not to receive marketing communication from us (i.e., if you opt out), we will honor your request.
        • Legitimate interest. We sometimes may process your personal data under the legitimate interest, i.e., (i) to properly administer business communication with you; (ii) to detect, prevent, or otherwise address fraud, abuse, security, or technical issues with our Services and Website; (iii) to protect against harm to the rights, property, and safety of Nord, our Customers, End Users, or third parties; (iv) to improve or maintain our Services and provide new products and features; (v) to receive knowledge of how our Website and application are being used.

        1. SHARING YOUR PERSONAL DATA
          • Service providers. We use third-party service providers to help us with various operations, such as IT, servers, marketing, customer support, data storage, website customization, website analytics, accounting, legal, agency, and others. As a result, some of these service providers may process your personal data.
          • Partners. Sometimes our partners, for example, distributors, resellers, managed service providers, and app store partners might also process your personal data. In such cases, the procedures established by them (e.g., terms of service and privacy policies) will apply to such relationships.
          • Other Nord group companies. We share your personal data with other Nord group companies to carry out our daily business operations and to enable us to maintain and provide our Services to you. In accordance with applicable law, we may also share your contact information with Nord group companies for the marketing of their products’ purposes (you have a right to object to such transfer at any time).
          • Protection of our rights. We may disclose your data to establish or exercise our legal rights or defend against any legal claims or other complaints. We may also share such information if we believe it is necessary to investigate, prevent, or take action regarding illegal activities, suspected fraud, and violations of Agreements.
          • Business transfers. We may share your personal data in those cases where we sell or negotiate to sell our business or go through a corporate merger, acquisition, consolidation, asset sale, reorganization, or similar event. In these situations, Nord will continue to ensure the confidentiality of your personal data.
          • Requests from law enforcement institutions. Any request for data should follow an appropriate official legal process recognized by the laws of incorporation (e.g., mutual legal assistance treaty, letters rogatory). We carefully review each request to make sure it satisfies laws applicable to our company, laws of requesting country, international norms, and our internal policies.

          1. CHOICES RELATED TO YOUR PERSONAL DATA
            • Delete: request us to erase your personal data;
            • Access: know and access personal data Nord has collected about you;
            • Rectify: rectify, correct, update, or complement inaccurate/incomplete personal data Nord has about you;
            • Object: object to the processing of your personal data which is done on the basis of our legitimate interests (e.g., for marketing purposes);
            • Portability: request us to provide you with a copy of your personal data in a structured, commonly used and machine-readable format or to transmit (if technically feasible) your personal data to another controller (only where our processing is based on your consent, and carried out by automated means);
            • Restrict: restrict the processing of your personal data (when there is a legal basis for that);
            • Withdraw consent: withdraw your consent where processing is based on the consent you have previously provided;
            • Lodge a complaint: exercise your rights by contacting us directly or, if all else fails, by lodging a complaint with a supervisory authority.

            1. DATA SECURITY
              1. DATA RETENTION
                1. COUNTRY-SPECIFIC PROVISIONS
                  1. MINORS’ DATA
                    1. CONTACT US

                      1. OTHER TERMS