Legal

Privacy Policy

Last updated: 5 June 2026

NorrLab AB ("NorrLab", "we", "us") respects your privacy. This policy explains what personal data we collect when you visit norrlab.com or contact us, why we collect it, and the rights you have under the EU General Data Protection Regulation (GDPR).

1. Data controller

NorrLab AB, org.nr 559238-5990, Adelgatan 2, 211 22 Malmö, Sweden, is the data controller for personal data processed via this website.

Contact: info@norrlab.com.

2. What we collect

Contact data you give us. When you email us or fill in a form, we receive your name, email address, company (if provided) and the content of your message.

Technical data. When you visit the site, our hosting provider logs technical information such as IP address, browser type, referring URL and the pages you request. This data is used to operate the site, prevent abuse and produce aggregated statistics.

Cookies and similar technologies. See our Cookie Policy for details. Non-essential cookies are only set if you give consent.

3. Why we process your data (legal basis)

To answer your enquiries and provide our services — legal basis: performance of a contract or steps prior to entering one (Art. 6(1)(b) GDPR).

To operate, secure and improve the website — legal basis: legitimate interest in running a safe, working site (Art. 6(1)(f) GDPR).

To comply with legal obligations such as accounting and tax — legal basis: legal obligation (Art. 6(1)(c) GDPR).

To set optional analytics or marketing cookies — legal basis: consent (Art. 6(1)(a) GDPR).

4. How long we keep your data

Enquiry messages: up to 24 months after our last contact, then deleted unless a client relationship is established.

Client records: for the duration of the engagement and seven (7) years after, per the Swedish Bookkeeping Act (Bokföringslagen).

Server logs: typically up to 90 days unless required longer for security investigations.

5. Who we share data with

We do not sell your personal data. We share it only with processors that help us run the business, including hosting, email, analytics and accounting providers. Each processor is bound by a Data Processing Agreement (DPA).

Where data is transferred outside the EU/EEA, we rely on the European Commission's Standard Contractual Clauses and apply supplementary measures where required.

6. Your rights

You have the right to access, rectify, erase, restrict or object to our processing of your personal data, and the right to data portability. Where processing is based on consent, you may withdraw that consent at any time without affecting prior processing.

To exercise any of these rights, contact info@norrlab.com. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) — imy.se.

7. Security

We apply appropriate technical and organisational measures to protect personal data, including TLS in transit, access controls and least-privilege principles. No system is perfectly secure, but we work to keep risk to a minimum.

8. Changes to this policy

We may update this policy from time to time. Material changes will be announced on this page with a revised "last updated" date.

© norrlab — selling complex products made simpleLinkedIn