Privacy Notice
Nordlabs AS · Org. nr. [TBD] · Oslo, Norway
This Privacy Notice explains how Nordlabs AS ("Nordlabs", "we", "our") collects, uses, and protects personal data in connection with the Claros platform and nordlabs.ai.
1. Who we are
Nordlabs AS is a Norwegian company registered in Oslo. We are the data controller for personal data collected via nordlabs.ai. For personal data processed on behalf of our customers within Claros, we act as data processor — our customers are the data controllers.
2. What data we collect
Website visitors (nordlabs.ai)
- Analytics data via Plausible (EU-hosted, cookieless, no personal identifiers)
- Contact form submissions: name, email, company, message
- Demo booking data: name, email, company (via Cal.com)
Claros customers and users
- Account data: name, work email, organisation
- Usage data: feature usage, session logs (for support and product improvement)
- Customer Data: content submitted to the Service — governed by our DPA, not this Notice
3. Legal basis for processing
We process personal data on the following legal bases under GDPR:
- Contract — processing necessary to provide the Service to customers
- Legitimate interests — analytics and product improvement, security monitoring
- Consent — marketing communications, where applicable
- Legal obligation — compliance with applicable law
4. How we use data
We use collected data to: provide and maintain the Service; respond to enquiries; improve the product; comply with legal obligations; and detect and prevent fraud or abuse.
We do not sell personal data. We do not use Customer Data to train AI models.
5. Data sharing
We share data with sub-processors necessary to provide the Service (hosting, AI inference, analytics). A current list of sub-processors is available at /legal/subprocessors/. We do not share personal data with third parties for their own marketing purposes.
6. Data retention
We retain personal data for as long as necessary to provide the Service or as required by law. Customer Data is deleted within 30 days of account closure, unless a longer retention period is required by law or agreed in the DPA.
7. Data residency
Personal data processed via Claros SaaS is hosted in EU data centers (Hetzner Cloud, Germany and Finland). We do not transfer personal data to the United States for core platform operation. When AI features are enabled, data may be processed by AI providers — see our sub-processor list for details.
8. Your rights
Under GDPR, you have the right to: access your personal data; correct inaccurate data; request deletion; restrict processing; data portability; and object to processing based on legitimate interests. To exercise these rights, contact contact@nordlabs.ai.
You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) at datatilsynet.no.
9. Cookies
nordlabs.ai uses Plausible Analytics, which is cookieless and collects no personal identifiers. No cookie consent banner is required. For full details, see the Cookie Policy.
10. Changes to this notice
We may update this Privacy Notice from time to time. Material changes will be communicated by email to registered customers or by prominent notice on the website. Continued use of the Service after changes take effect constitutes acceptance.
11. Contact
For privacy questions or to exercise your rights: contact@nordlabs.ai
For security-related privacy concerns: security@nordlabs.ai
This is a draft document. Final privacy notice will be reviewed by legal counsel before publication.