Home

Privacy Policy

This policy explains what personal information Nordhal Defence ApS holds about you, why we hold it, who else sees it, and what you can ask us to do about it. It covers our website at nordhal.dk, our company email, and the Nordhal collaboration workspace at cloud.nordhal.dk.

We have tried to write it in ordinary language rather than legal boilerplate. If any part of it is unclear, email us and we will explain it properly.

Who we are

Nordhal Defence ApS decides what personal information is collected and why. In data protection law that makes us the data controller.

CompanyNordhal Defence ApS
CVR number46502027
VAT numberDK46502027
Registered addressAlsion 2, 6400 Sønderborg, Denmark
Emailcontact@nordhal.dk
Phone+45 81 94 19 27
DirectorJustin Sykes (registered as direktør with the Danish Business Authority)

Nordhal Defence ApS is wholly owned by Nordhal Holding ApS (CVR 46498836), registered at the same address.

We are a small company and we have not appointed a data protection officer. Anything on this page can be raised at contact@nordhal.dk, which reaches a person rather than a queue.

Who this policy is for

It applies to four groups of people.

  • Visitors to our website. Anyone who opens nordhal.dk.
  • People who contact us. By email, by phone, or through LinkedIn.
  • Collaborators. Anyone we give an account on our collaboration workspace at cloud.nordhal.dk. Today that is students working with us on university course projects, including the Expert in Teams and the Mechatronics Design and Build courses at the University of Southern Denmark. In future it will also cover interns, thesis students, contractors, advisers and employees. Where this policy says collaborator, it means all of them. Each of these is a different kind of relationship and each is set up by its own separate written agreement with us.
  • Business contacts. People we deal with professionally at navies, defence agencies, suppliers, universities, funding bodies and partner companies.

If your work with us is part of a university course, your university also handles your personal data for its own purposes as the course provider. That side of it is covered by the university's own privacy policy, not by this one. This policy covers what Nordhal Defence does.

What we collect, and why

If you visit our website

Our web host records standard technical information for every visit, including your IP address, the type of browser and device you used, and which pages you opened. That happens at the server and is not something a cookie does.

We would also like to use Google Analytics to see how many people visit and which pages they read. That only happens if you allow it. When you first open the site you get a strip at the bottom of the page with two buttons, and until you press one of them the Google Analytics code is not loaded and no analytics cookie is set. We use the numbers only to understand whether the site is working and what people find useful.

We do not run advertising on the site, and we do not use advertising or profiling cookies. Our cookie policy lists every cookie by name.

If you contact us

We keep your name, your email address, your phone number if you give us one, and what you wrote or what we discussed. If the contact is a professional one, a short factual note about it may go into our business contact records.

If you have an account on cloud.nordhal.dk

What we holdWhy
Your name, and the username on the accountSo that everyone in a shared folder knows who is who
Your email addressTo send you your account details, password resets, and notifications about shared folders
Your passwordStored using one way encryption, which means the system can check a password you type without ever holding the password itself. Nobody at Nordhal Defence can read it, including an administrator
The files you upload, and their earlier versionsBecause that is what the system is for. Nextcloud keeps a version history so an accidental overwrite can be undone
A record of file activityWho created, edited, renamed, moved, shared or deleted which file, and when. This is how a shared workspace stays usable, and how we work out what happened when something goes missing
Technical logsYour IP address, sign in times, and which app or browser you used. Kept for security and for fixing problems

For students, the email address we hold is normally the one your university issued to you. We do not ask for a private email address and we do not need one. If you would rather we used a different address, tell us and we will change it.

If you are a business contact

We keep your name, job title, organisation, work email address, work phone number, and factual notes about our professional dealings with you. Nothing about your private life. You can ask us at any time what we hold about you, and we will send it.

What we do not collect

  • We do not ask for and do not knowingly use special categories of personal data. Nothing about health, religion, political opinions, ethnicity, trade union membership, sex life or biometrics. We cannot rule out that something of that kind ends up inside a file somebody uploads, which is exactly why we ask you to keep it out of the workspace.
  • We do not make automated decisions about you, and we do not profile you.
  • We do not sell personal data to anyone, ever.
  • We do not offer our services to children and we do not knowingly collect information about them. Everyone we give a workspace account to is a university student or an adult working with us.

What allows us to do this

Data protection law requires a lawful basis for every use of personal data. Ours are these.

What we doLawful basis
Running the collaboration workspace and the projects on itWhere you have a written agreement with us, performing that agreement (Article 6(1)(b)). Where you do not, our legitimate interest in getting the company's engineering work done, keeping it organised, and being able to tell who changed which shared file (Article 6(1)(f))
Replying to you when you contact usOur legitimate interest in answering people who write to us (Article 6(1)(f)), or steps taken at your request before entering into a contract (Article 6(1)(b))
Keeping business contact recordsOur legitimate interest in knowing who we deal with at customers, suppliers, universities and funding bodies, and in being able to pick a conversation up where it left off (Article 6(1)(f)). We hold work contact details and factual notes only
Website analytics cookiesYour consent. The cookies section below explains how to switch analytics off
Keeping accounting and tax recordsLegal obligation, under the Danish Bookkeeping Act and tax law (Article 6(1)(c))

Legitimate interest is not a free pass. For each of the uses above we have asked whether we actually need the data for that purpose, whether there is a less intrusive way to do the same job, and whether anyone would reasonably be surprised or harmed by it. We hold only what the purpose needs. You have the right to object to any of it, and the rights section below explains how.

The collaboration workspace, in more detail

This section is mainly for students, interns and anyone else who holds an account. It is worth reading before you upload anything.

  • The workspace runs on Nextcloud, hosted for us by Hetzner Online GmbH on servers in Falkenstein, Germany. Our written agreement with them says the processing takes place only inside the European Union or the wider European Economic Area, and that their technical and customer support is provided from inside the EU. Hetzner uses subcontractors in the United States and Singapore for their American and Asian server locations. We do not use those locations.
  • A folder shared with your group is visible to everyone else in that group, and to Nordhal Defence. Assume your teammates can see anything you put there.
  • Your personal folder is visible to you and to a Nordhal Defence administrator. It is not visible to other students.
  • An administrator can see file names, file activity and sign in records, and can open files stored on the system. This is normal for any company system, but you should know it. Treat the workspace as a work system and keep personal material off it.
  • An administrator can reset your password but cannot read it.
  • If you install the Nextcloud desktop app, copies of the shared files are stored on your own computer. Those copies are outside our control. Please delete them when the project ends, as your agreement with us requires.
  • Some material in the workspace is confidential, and some of it is subject to export control rules. Your non-disclosure agreement with us, and any separate instructions you are given, govern what you may do with it. That is a different matter from this privacy policy, and both apply at the same time.

Who else sees your data

We use a small number of service providers. In data protection terms these are our processors. They act on our instructions and may not use your data for their own purposes.

ProviderWhat they do for usWhere
Hetzner Online GmbHHosts the collaboration workspace and sends its system emailsFalkenstein, Germany (EU)
HostingerHosts nordhal.dk and our company emailEuropean Union
Google Ireland LimitedWebsite analyticsIreland, with transfer to the United States

We have a signed data processing agreement with Hetzner Online GmbH, as Article 28 of the GDPR requires, and we hold their written description of their security measures. Google Analytics is covered by Google's own data processing terms. We are confirming the same paperwork with our web host and will update this page when that is settled.

Beyond those providers, we share personal data only where the law requires it, for example with a public authority acting within its powers, or where we need to in order to bring or defend a legal claim.

Where your data is stored

Workspace files and workspace logs stay on servers in Germany, and our agreement with the host keeps the processing inside the European Union or the European Economic Area. The website and company email are hosted in the European Union.

The transfer we know of outside that area is website analytics data, which reaches Google in the United States. Google relies on the EU and US Data Privacy Framework and on the European Commission's standard contractual clauses for that. If you switch analytics off, that transfer does not happen.

If we ever need to move personal data outside the European Economic Area for anything else, we will only do it where Chapter V of the GDPR allows it, meaning an adequacy decision, standard contractual clauses, or another recognised safeguard, and we will say so on this page.

AI tools

Nordhal Defence is an engineering company and we use AI assistants as ordinary working tools when writing code and documents. The one we use on company files is Anthropic's Claude, running on a company computer. Where a shared project folder is synced to that computer, the assistant can read what is in it while we work on the project.

What the assistant is given is processed on Anthropic's systems rather than inside the workspace. We keep personal data out of what we send it, beyond whatever is already sitting in the project files. Approving a new AI tool for use on company files is a decision we take deliberately, and we check what the provider is allowed to do with the content before we point it at anything sensitive.

If you hold an account, please do not upload personal information about other people, material that belongs to somebody else, or anything under export control, unless we have agreed it with you in writing first. And if there is something you would rather was not handled this way, tell us before you upload it and we will keep it out of the synced folders.

How long we keep things

WhatHow long
Workspace accounts for students and internsWe may keep your account open for up to one month after your course or placement with us ends, in case the work carries on or you still need something from it. At the end of that month we close the account and delete the personal files in it, unless we have agreed in writing with you that you are continuing with us.
Work you produced for Nordhal DefenceProject work, designs, code and documents made as part of the collaboration stay with the company under your agreement with us, and closing your account does not delete them. Who owns that work is a separate question from data protection. Where one of those files happens to contain personal data, this policy applies to that data in the normal way.
Technical and sign in logsThe workspace activity record is kept while the account exists and goes when the account is deleted. Server logs are kept by our hosting provider for a short period for security and fault finding, then overwritten. We do not keep a separate copy of our own
Email correspondenceWhile the relationship is live, and afterwards for as long as we might reasonably need it to answer a question or deal with a claim about the work. Reviewed and cleared out periodically
Business contact recordsUntil you ask us to remove you, or until a review shows we no longer deal with you or your organisation. We review these at least every three years rather than letting them sit forever. Where a separate legal duty makes us keep a document, for example an invoice, that duty comes first and we will tell you which one
Accounting recordsFive years from the end of the financial year, as the Danish Bookkeeping Act requires

When we delete something, copies may survive for a short while in backups and in the system's deleted files area before those are cleared in turn.

How we look after it

  • Everyone gets their own account. We do not use shared logins.
  • Folders are shared only with the group that needs them, and at the lowest level of access that still works.
  • Everything travelling between you and the workspace is encrypted in transit.
  • Our hosting provider's data centres are certified to ISO 27001, and we hold their written description of their security measures. Under that description, encrypting the stored files themselves is the customer's job rather than theirs, so files sitting in the workspace are not separately encrypted on the server. Treat the workspace as a work system, not a vault.
  • Company computers use full disk encryption.
  • If personal data is ever breached, we will look into it without delay. Where the law requires us to report it, we will report it to the Danish Data Protection Agency, within 72 hours of finding out where that is possible. Where the breach is likely to put the people affected at high risk, we will tell them too. Not every incident has to be reported, but the assessment gets made every time.

Your rights

You have the following rights over your personal data. They are free to use, and using them will never count against you.

  • Access. Ask what we hold about you and get a copy.
  • Correction. Have anything wrong or incomplete fixed.
  • Erasure. Ask us to delete what we hold, where we have no continuing reason to keep it.
  • Restriction. Ask us to pause using it while a dispute about it is sorted out.
  • Objection. Object to any use we base on legitimate interest, including our business contact records.
  • Portability. Where we hold data you gave us yourself, handle it by computer, and rely on your consent or on a contract with you, you can get it back in a machine readable form or have it sent to someone else. This one does not stretch to everything we hold.
  • Withdraw consent. Where we rely on consent, take it back at any time. That does not undo what was lawful before you withdrew it.

If you think we have got something wrong and we have not put it right, you can complain to the Danish Data Protection Agency:

Datatilsynet
Carl Jacobsens Vej 35, 2500 Valby, Denmark
dt@datatilsynet.dk · +45 33 19 32 00
www.datatilsynet.dk

We would much rather you came to us first, but the right to complain is yours either way.

Cookies and analytics

Our cookie policy is the full list: every cookie by name, who sets it, what it is for, how long it lasts and whether we need your permission. The short version is below.

One cookie is strictly necessary and is set either way: it remembers the cookie choice you made, so we do not ask again on every page. It lasts twelve months and it does not track you.

The only other cookies come from Google Analytics, which counts visits and shows which pages get read. It does not tell us your name and we make no attempt to work out who you are. It does still collect your IP address and a random identifier for your browser, and information of that kind can count as personal data about you even when nobody has put a name to it. That is why we ask first.

You can change your answer whenever you like, and refusing is as easy as agreeing:

  • Open cookie settings and press Necessary only. We delete the Google Analytics cookies straight away.
  • Block or delete cookies for nordhal.dk in your browser settings. That clears your saved choice too, so we will ask again next time.
  • Install the Google Analytics opt out browser add on, which turns it off on every site you visit, not just ours.

We ask again after twelve months in any case. We do not use advertising cookies, social media pixels or a tag manager.

Changes to this policy

We will update this page whenever what we do changes. The date at the top always tells you when it last changed. If we change something that materially affects people who hold an account with us, we will email them rather than rely on you noticing.

Contact

Nordhal Defence ApS, Alsion 2, 6400 Sønderborg, Denmark
contact@nordhal.dk · +45 81 94 19 27

See also our cookie policy and our legal notice.