NordDelta Academy
⚙️Industrial Automation ☀️Solar & Renewable Energy 🚁Drone Technology 🤖Robotics & Cobots 🌐Industrial IoT
View all courses →
Corporate University About Blog Contact
Sign In Start Learning →
Browse by domain
⚙️ Industrial Automation ☀️ Solar & Renewable Energy 🚁 Drone Technology 🤖 Robotics & Cobots 🌐 Industrial IoT View all courses →
🏢 Corporate Training 🎓 University Partners ℹ️ About 📝 Blog ✉️ Contact
Sign In Start Learning →
Legal

Privacy Policy

NordDelta Technologies AB  ·  Effective date: 1 January 2025  ·  Last updated: 1 January 2025

Contents

1. Introduction 2. Data We Collect 3. How We Use Your Data 4. Legal Basis (GDPR) 5. Data Sharing 6. Data Retention 7. Your Rights 8. International Transfers 9. Security 10. Cookies 11. Contact & DPO

1. Introduction

NordDelta Technologies AB ("NordDelta Academy", "we", "us", "our"), a company registered in Sweden (Organisation number: 559XXX-XXXX), operates the online learning platform available at norddelta.academy. We are committed to protecting the privacy and personal data of all individuals who interact with our services.

This Privacy Policy explains what personal data we collect, why we collect it, how we process it, and what rights you have under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Swedish Act on Supplementary Provisions to the EU Data Protection Regulation (2018:218).

By registering an account or using our platform, you acknowledge that you have read and understood this policy. If you do not agree, please do not use our services.

2. Data We Collect

2.1 Personal Data You Provide

  • Account information: full name, email address, password (hashed), job title, company name, and country of residence provided at registration.
  • Profile information: optional professional background, LinkedIn profile URL, and profile photograph.
  • Payment information: billing name, billing address, and VAT number. Card details are processed directly by our payment processor (Stripe) and are never stored on our servers.
  • Communications: messages sent to our support team, consultation booking forms, and responses to surveys.
  • Corporate/Team data: for Team and Enterprise customers, we process employee names and email addresses provided by the account administrator for user provisioning.

2.2 Usage Data Collected Automatically

  • IP address, browser type and version, operating system, and device identifiers.
  • Pages visited, course modules accessed, time spent per module, quiz results, and completion status.
  • Referring URL and search terms used to find our platform.
  • Timestamp of logins and session duration.

2.3 Cookies and Tracking Technologies

We use first-party cookies and Google Analytics 4 to understand how learners use our platform. We do not use advertising networks or third-party retargeting cookies. See our Cookie Policy for full details.

3. How We Use Your Data

  • Service delivery: to create and manage your account, grant access to purchased courses, issue completion certificates, and provide customer support.
  • Payment processing: to process subscriptions and one-time purchases, issue invoices, and manage refunds.
  • Platform improvement: to analyse learning patterns, identify content gaps, fix technical issues, and develop new course material.
  • Communication: to send transactional emails (purchase confirmations, password resets, certificate issuance) and, with your consent, educational newsletters and product updates.
  • Legal compliance: to comply with Swedish and EU tax law, respond to lawful requests from authorities, and enforce our Terms of Service.
  • Security: to detect and prevent fraudulent account activity, abuse, and unauthorised access.

We do not use your data for automated decision-making that produces legal or similarly significant effects.

4. Legal Basis for Processing (GDPR Article 6)

Processing Purpose Legal Basis
Account creation and course access Performance of a contract (Art. 6(1)(b))
Payment processing and invoicing Performance of a contract (Art. 6(1)(b))
Tax record-keeping (7 years) Legal obligation (Art. 6(1)(c))
Marketing emails and newsletters Consent (Art. 6(1)(a)) — withdraw at any time
Platform analytics and improvement Legitimate interests (Art. 6(1)(f))
Fraud prevention and security Legitimate interests (Art. 6(1)(f))

5. Data Sharing

We do not sell, rent, or trade your personal data to any third party. We share data only with trusted sub-processors that are necessary to operate our platform:

  • Stripe, Inc. — payment processing (EU Standard Contractual Clauses in place).
  • Amazon Web Services EMEA SARL — cloud hosting infrastructure (data stored in EU-West regions).
  • Google LLC — Google Analytics 4 for platform analytics (data pseudonymised; IP anonymisation enabled).
  • Postmark / ActiveCampaign — transactional and marketing email delivery.
  • Intercom, Inc. — in-platform customer support chat.

All sub-processors are bound by data processing agreements (DPAs) that comply with GDPR Article 28. We may disclose personal data to law enforcement or regulatory authorities when required by applicable law or court order.

We will never sell your personal data. This is an absolute commitment, not merely a current policy.

6. Data Retention

  • Active accounts: personal data is retained for the duration of your account and for 2 years after the last login, unless earlier deletion is requested.
  • Financial records: invoices and payment records are retained for 7 years as required by Swedish accounting law (Bokföringslagen 1999:1078).
  • Certificate records: completion data supporting issued certificates is retained indefinitely to allow ongoing verification.
  • Support communications: retained for 2 years from the date of last interaction.
  • Analytics data: Google Analytics data is retained for 14 months (GA4 default maximum for event-level data).
  • Marketing consent records: retained until withdrawal of consent plus 1 year for audit purposes.

7. Your Rights Under GDPR

As a data subject in the European Economic Area, you have the following rights. To exercise any of them, contact our DPO at privacy@norddelta.academy. We will respond within 30 days.

  • Right of access (Art. 15): request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16): request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17): request deletion of your personal data where no overriding legal basis exists for continued processing.
  • Right to data portability (Art. 20): receive your personal data in a structured, machine-readable format (JSON or CSV) and transmit it to another controller.
  • Right to object (Art. 21): object to processing based on legitimate interests, including profiling. We will cease processing unless compelling legitimate grounds override your interests.
  • Right to restrict processing (Art. 18): request that we limit how we use your data while a dispute is resolved.
  • Right to withdraw consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.

You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se or with the supervisory authority in your country of residence.

8. International Transfers

Our primary data storage is located within the European Economic Area (AWS eu-west-1, Ireland). Where we use sub-processors based in the United States (such as Stripe and Google), transfers are governed by EU Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914, supplemented by transfer impact assessments as required.

We do not transfer personal data to countries without an adequacy decision or appropriate safeguards unless explicitly required by law.

9. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. These measures include:

  • TLS 1.2+ encryption for all data in transit.
  • AES-256 encryption for data at rest.
  • Bcrypt password hashing with per-user salts (passwords are never stored in plaintext).
  • Role-based access controls limiting staff access to personal data on a need-to-know basis.
  • Regular penetration testing and vulnerability scanning.
  • SOC 2 Type II-certified infrastructure (AWS).

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the IMY within 72 hours and affected individuals without undue delay as required by GDPR Article 33–34.

10. Cookies

We use cookies to keep you logged in, remember your preferences, and understand how learners navigate our platform. We use Google Analytics 4 for anonymised usage analytics. We do not use advertising cookies or third-party tracking pixels.

For full details including a cookie table and opt-out instructions, please read our Cookie Policy.

11. Contact & Data Protection Officer

For all privacy-related enquiries, to exercise your data subject rights, or to reach our Data Protection Officer:

  • Email: privacy@norddelta.academy
  • Post: NordDelta Technologies AB, Attn: Data Protection Officer, [Street Address], Stockholm, Sweden

We aim to respond to all requests within 30 calendar days. Where requests are complex or numerous, we may extend this period by a further two months, in which case we will notify you within the initial 30-day period.

This policy was last reviewed and updated on 1 January 2025. We will notify registered users of material changes via email at least 30 days before they take effect.

© 2025 NordDelta Technologies AB  ·  Privacy  ·  Terms  ·  Cookies