Privacy Policy
On this page
Who is responsible for your personal data
The controller is:
- Dios Investment AB (Nordicrank)
- Company registration number: 559150-4260
- Address: Bäckåkersvägen 4, 432 48 Varberg, Sweden
- Email for privacy questions: [email protected]
This policy explains how we process personal data when you use the portal at portal.nordicrank.com, buy services from us, contact our support or publish content for us as a Publisher.
Our customers are businesses. The personal data we process therefore mainly relates to contact persons and users at our customers and Publishers.
What data we collect
Data you provide
- Account: name, email address, password (stored only as a cryptographic hash) and two-factor authentication settings.
- Billing profile: company name, contact person, billing email, address, country, company registration number and VAT number. A copy of the billing details is stored with each order so that the record does not change afterwards.
- Orders: target URL, anchor text, article instructions, notes, messages between you and us, feedback on drafts and files you upload.
- Settings and workspaces: saved websites, projects, currency preference, your own domains added for analysis and keywords you search for in the search results tool.
- Support: what you write in the support form or in emails to us.
- Newsletter preference: whether you have opted out of newsletters, and when.
We do not collect telephone numbers in the portal.
Data created when you use the portal
- Login and security: time of your last login, IP address and browser information (user agent) for your active sessions, and IP addresses in temporary blocks against repeated attempts.
- Country at registration: we determine which country your IP address belongs to when you first log in and store only the country code, for example SE. The lookup uses a database hosted on our own server (DB-IP Lite). Your IP address is not sent to any external service for this purpose.
- VAT check: the result of checking your VAT number in the EU VIES register.
- Payments: payment details from Stripe, such as amount, status, VAT and any refund. We never receive your full card number.
- Email delivery: logs of which transactional emails have been sent to you and whether they bounced or were reported as spam.
- Notifications: which notifications have been shown to you in the portal.
- Terms acceptance: which version of the Terms of Use and this policy you accepted, and when.
Data about Publishers
Publishers do not have an account on the portal. They receive a personal link to handle an assignment. We store the Publisher's email address, name if provided, and communications relating to the assignment.
Tracking
We use analytics and marketing cookies as described in the section on cookies. They are set as soon as you open the portal, and you can reject them at any time.
Why we process your data and on what legal basis
| Purpose | Data | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Creating and managing your account | Account, settings | Contract (Art. 6(1)(b)). If you represent a business: legitimate interest in performing the contract with that business (Art. 6(1)(f)) | While the account exists. Inactive accounts are deleted or anonymised 24 months after the last login |
| Receiving and delivering orders | Orders, messages, files, billing profile | Contract, or legitimate interest as above | Order data while the account exists, then as required for accounting. Uploaded files are deleted 90 days after the order is completed |
| Payment, invoicing and bookkeeping | Billing profile, payment data, order summary | Legal obligation (Art. 6(1)(c)) under the Swedish Bookkeeping Act and VAT Act | 7 years from the end of the calendar year in which the financial year ended |
| Checking VAT numbers | VAT number, company name, country | Legal obligation | As for accounting records |
| Sending transactional emails about orders, drafts and security | Name, email, order details | Contract or legitimate interest | Email logs: 12 months |
| Protecting accounts and the portal against intrusion and misuse | IP address, user agent, login time, country, failed attempts | Legitimate interest in security (Art. 6(1)(f)) | Session data: 90 days after the session expires. Blocks against repeated attempts: minutes to hours |
| Detecting fraud and determining market | Country at registration, billing country | Legitimate interest | While the account exists |
| Monitoring compliance with the acceptable use rules | Logs of portal use, IP address | Legitimate interest in protecting our service and business | 90 days, or longer if needed for a specific incident |
| Checking passwords against known data breaches | The first characters of the password hash | Legitimate interest in security | Not stored |
| Support | Content of the request, name, email | Legitimate interest in responding to you | 24 months after the request is closed |
| Analysing your own domains and keywords | Domains and keywords you enter | Contract | While you keep them saved. Temporary search results that are not saved are deleted after 30 days |
| Monitoring published links | Article URL, target URL, anchor text | Contract | During the Guarantee Period and for as long as you keep the link in the link monitor |
| Newsletters about similar services | Name, email, customer status | Legitimate interest and the customer exemption in Section 19, second paragraph, of the Swedish Marketing Practices Act (marknadsföringslagen 19 § andra stycket) | Until you unsubscribe or the account is closed |
| Analytics and marketing via cookies | See the section on cookies | Legitimate interest in understanding how the portal is used and measuring our marketing (Art. 6(1)(f)). You can object at any time by rejecting the cookies | As stated in the cookie table |
| Proving acceptance of terms | Version, time, account | Legitimate interest in being able to demonstrate what was agreed | 10 years after the account is closed |
| Handling legal claims | Relevant data listed above | Legitimate interest | Until the claim is finally resolved |
Where we rely on legitimate interest, we have balanced our interest against your privacy. You can obtain a description of that assessment by contacting us.
Newsletters
If you are a customer, we may send you newsletters about services similar to those you have already bought. We do this under the customer exemption in Swedish marketing law.
- At registration, you see a pre-ticked newsletter box. If you untick it, we will not send you newsletters. The box is not a request for consent; it gives you the opportunity to object from the outset.
- Every newsletter contains a one-click unsubscribe link. You can also write to [email protected].
- Unsubscribing does not affect emails about your orders and account.
Once newsletters are enabled, they will be sent via Bento (Backpack Internet Pty. Ltd., Australia), which processes data in Australia and the USA under Standard Contractual Clauses. See the section on recipients.
Cookies and browser storage
We use cookies and similar technologies under the Swedish Electronic Communications Act (lagen (2022:482) om elektronisk kommunikation). Strictly necessary cookies are always used. Analytics and marketing cookies are currently set as soon as you open the portal, and you can reject them at any time; once you reject them they are removed and no longer set.
Strictly necessary
| Name | Purpose | Duration |
|---|---|---|
| nr_consent | Stores your cookie choices, the version of the cookie notice you responded to and when. Shared between nordicrank.com and portal.nordicrank.com, so one choice applies to both | 1 year |
| Login cookie (Better Auth) | Keeps you logged in and protects the session | 30 days, renewed while in use. If you choose not to be remembered, it is deleted when you close the browser |
| nr-currency | Remembers which currency you want to see prices in | 1 year |
| nr_view_as_user_id | Used only by Nordicrank administrators to view the portal as a specific customer when providing support | 8 hours |
The portal also stores functional data in your browser's local storage (localStorage): shopping cart, checkout draft (including billing details you have entered), table view, selected project and currency preference. This data stays on your device and is only used to make the portal work.
Analytics (until you reject them)
| Name | Service and provider | Purpose | Duration |
|---|---|---|---|
| _ga | Google Analytics 4, Google Ireland Limited | Distinguishes visitors for usage statistics | 2 years |
| _ga_<id> | Google Analytics 4, Google Ireland Limited | Keeps track of the session for usage statistics | 2 years |
Google Analytics runs in Consent Mode v2. Analytics storage is enabled unless you have rejected analytics cookies; when you reject them it is switched to denied and the Google Analytics cookies are deleted. Advertising signals to Google are always denied, as we do not use Google Ads. Page addresses are sent without query details.
Marketing (until you reject them)
| Name | Service and provider | Purpose | Duration |
|---|---|---|---|
| _fbp | Meta Pixel, Meta Platforms Ireland Limited | Identifies the browser to measure and target advertising | 90 days |
| _fbc | Meta Pixel, Meta Platforms Ireland Limited | Stores the click identifier when you arrive from an ad on Meta | 90 days |
Bento (Backpack Internet Pty. Ltd.) may be used for email marketing once it is enabled. It is not active yet.
Your choices
When you first visit the portal, a banner tells you that we use cookies for analytics and marketing. Choose "Reject" to turn them off, "OK" to keep them, or "Settings" to choose by category. You can change your choice at any time via the "Cookie settings" link in the footer. When you reject a category, its scripts stop, its cookies are deleted and nothing is loaded on later visits. Your choice also applies on nordicrank.com. If we change the cookie notice materially, we will show the banner again.
No analytics or marketing tracking is used in the Nordicrank administration area, or on pages opened through personal links, such as draft review, publishing, password reset and email verification links.
Who receives your data
We do not sell personal data. We only share it with the recipients below.
Processors
These providers process data on our behalf and on our instructions under data processing agreements.
| Provider | Service | Location | Safeguard for transfers |
|---|---|---|---|
| Hetzner Online GmbH | Servers and database for the portal | Helsinki, Finland (EU) | No transfer outside the EU/EEA |
| Cloudflare, Inc. | Storage of uploaded files (R2) and DNS | Files stored in the EU (R2 EU jurisdiction). DNS runs on Cloudflare's global network. Company based in the USA | EU-U.S. Data Privacy Framework and Standard Contractual Clauses |
| Postmark (AC PM LLC, part of ActiveCampaign, LLC) | Sending transactional emails | USA | EU-U.S. Data Privacy Framework, with Standard Contractual Clauses as fallback |
| Resend (Plus Five Five, Inc.) | Backup for transactional emails | Sending region eu-west-1 (Ireland). Company and main processing in the USA | EU-U.S. Data Privacy Framework and Standard Contractual Clauses |
| Internal communication and notification tools used by our staff | Internal alerts to our staff about new accounts, orders and support requests | USA | EU-U.S. Data Privacy Framework |
| Fortnox AB | Invoicing and bookkeeping | Sweden | No transfer outside the EU/EEA |
| Google Ireland Limited (Google Analytics 4), unless you reject analytics cookies | Usage statistics | Ireland, with processing by Google LLC in the USA | EU-U.S. Data Privacy Framework, with Standard Contractual Clauses as fallback |
| Bento (Backpack Internet Pty. Ltd.) (coming soon) | Newsletters and, unless you reject marketing cookies, tracking | Australia and the USA | Standard Contractual Clauses |
Providers receiving limited data
The following services are used to deliver features of the portal. In normal cases they receive no data about you as a person, only domains, keywords or URLs.
| Provider | What is sent | Location |
|---|---|---|
| Ahrefs Pte. Ltd. | Domains you add for analysis | Singapore |
| Majestic-12 Ltd | Domains for link data | United Kingdom (adequacy decision) |
| DataForSEO OU | Keywords and market in the search results tool | Estonia (EU) |
| IndexChex | URLs of published articles, for indexing checks | Not specified by the provider |
| Have I Been Pwned (Superlative Enterprises Pty Ltd) | The first five characters of the password hash, never the password | Australia, hosted in the USA |
| Frankfurter | No personal data, only retrieval of exchange rates | Not applicable |
| Supabase Pte. Ltd. | Stores our inventory of websites and prices, no customer data | EU (Stockholm) |
Independent controllers
- Stripe (Stripe Payments Europe Ltd, Ireland) handles card payments, VAT calculation and receipts. Stripe is an independent controller for card data and fraud prevention, among other things, and may transfer data to the USA under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses. See Stripe's privacy policy.
- Meta Platforms Ireland Limited is joint controller with us for data collected through the Meta Pixel, unless you have rejected marketing cookies. We are jointly responsible for collecting the data on the portal and sending it to Meta; Meta is solely responsible for its further processing. Our arrangement with Meta is set out in Meta's Controller Addendum. Data may be transferred to Meta Platforms, Inc. in the USA under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses. You can exercise your rights with us or with Meta; see Meta's privacy policy.
- The European Commission (VIES) receives VAT numbers when they are checked.
- Publishers receive the article content, target URL and anchor text in order to publish. We do not give Publishers your contact details unless needed for the assignment.
- Public authorities where we are required by law, such as the Swedish Tax Agency.
- Advisers such as auditors and lawyers, under a duty of confidentiality.
Transfers outside the EU/EEA
Where a provider is located outside the EU/EEA, we ensure the transfer has a legal basis under the GDPR, primarily the provider's certification under the EU-U.S. Data Privacy Framework or the European Commission's Standard Contractual Clauses, supplemented by any additional safeguards required. You can obtain a copy of the safeguards by contacting us.
Automated decisions
We do not make decisions based solely on automated processing that have legal effects on you. VAT is calculated automatically based on country and VAT number, but this concerns the business and can be corrected by us if something goes wrong.
How we protect your data
We protect data with measures including encrypted transmission, hashed passwords, optional two-factor authentication, restricted staff access, limits on repeated login attempts and logging of administrative changes.
Your rights
You have the right to:
- access the data we hold about you and receive a copy,
- have inaccurate data corrected,
- have data erased if it is no longer needed or we have no legal basis to keep it. Data we must keep under the Bookkeeping Act is not erased until the retention period has expired, but we restrict its use,
- restrict processing while we investigate an objection or a request for correction,
- receive your data in a machine-readable format and transfer it (data portability), where processing is based on contract or consent,
- object to processing based on legitimate interest. You can always object to direct marketing, and we will then stop,
- withdraw consent at any time, without affecting processing that has already taken place.
To exercise your rights, write to [email protected]. We respond within one month. We may need to verify your identity before disclosing data.
Coming soon: you will be able to download your data and delete your account yourself in the portal. If the account has orders, we pseudonymise the data instead of deleting it and keep the accounting records for the period required by law.
Complaints
If you are unhappy with how we process your personal data, please contact us first. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), www.imy.se, or with the supervisory authority in the EU country where you live or work.
Changes to this policy
We update this policy when our processing changes. The latest version is always available on this page, with its date and version number at the top. We will notify you of material changes by email or in the portal.