Privacy Policy at NORRIQ – how we collect and process personal data

Privacy Policy

At NORRIQ, we take the protection of your personal data seriously. Here you can read how we collect, process and store personal data, and what rights you have under the GDPR.

Privacy Policy


1. Introduction
NORRIQ operates this website from its office in Valby, Denmark.
We take a proactive approach to protecting our users’ privacy and ensure that the necessary measures are in place to safeguard users’ information throughout their visit. This privacy policy describes how we collect and process personal data.
We comply with applicable EU data protection law, including the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Danish Data Protection Act (Databeskyttelsesloven).


2. Data controller
The data controller responsible for the processing of your personal data is:
NORRIQ A/S
Paradisæblevej 4
DK-2500 Valby, Denmark
CVR no.: 29194645
Email: info@norriq.dk


3. Collection of personal data
3.1 Information you provide to us
If you download materials, sign up for newsletters, events or webinars, or contact us via this website, you may provide us with personal data such as:
•    Name
•    Company
•    Email address
•    Phone number
•    Job title
•    Other relevant information related to your enquiry


3.2 Information collected automatically
When you visit our website, we may automatically collect information such as:
•    IP address
•    Browser type
•    User behaviour on the website
This information is collected via cookies and similar technologies (see our Cookie Policy).


4. Purposes and legal basis for processing
We process your personal data for the following purposes, on the legal bases indicated:
•    To administer our website and services – legitimate interests (Article 6(1)(f) GDPR)
•    To respond to enquiries – legitimate interests, or performance of a contract where applicable (Article 6(1)(f) or (b) GDPR)
•    To send newsletters and marketing communications – your consent (Article 6(1)(a) GDPR)
•    To manage registrations for events and webinars – performance of a contract or your consent (Article 6(1)(b) or (a) GDPR)
•    To analyse and improve our services and marketing activities – legitimate interests, or your consent for non-essential cookies (Article 6(1)(f) or (a) GDPR)
•    To comply with legal obligations – Article 6(1)(c) GDPR
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may request further information about this assessment by contacting us.


5. Marketing and communication
If you have given your consent, we may contact you with:
•    Newsletters
•    Invitations to events and webinars
•    Relevant content and marketing
You may withdraw your consent at any time by:
•    Using the unsubscribe link in our emails
•    Contacting us directly
Withdrawing your consent does not affect the lawfulness of processing carried out before the withdrawal.


6. Sharing of data
We do not sell or rent your personal data.
We may share data with:
•    Trusted suppliers (data processors)
•    Business partners
•    Public authorities, where required by law
In some cases, data may be transferred outside the EU/EEA. In such cases, we ensure appropriate safeguards in accordance with Chapter V of the GDPR, including the use of the European Commission’s Standard Contractual Clauses (SCCs) and, where relevant, supplementary measures.


7. Use of systems and data processors
We use external systems to manage marketing, webinars and analytics, including:
•    ActiveCampaign (email marketing, marketing automation and segmentation)
•    Demio (management of webinars and registrations)
•    Google Analytics (analysis of user behaviour on the website)
•    LinkedIn (advertising, targeting and remarketing)
•    Google Ads (advertising, conversion measurement and remarketing)
•    Meta Platforms (advertising, targeting and remarketing)
•    Leadfeeder (identification of company visits to the website)
•    Microsoft Dynamics 365 (management of customer relationships and sales activities)
These suppliers process data on our behalf and are subject to data processing agreements that meet the requirements of Article 28 GDPR. Some of these providers are based outside the EU/EEA, in which case transfers are made subject to the safeguards described in section 6.


8. Retention of data
We do not store your personal data longer than necessary for the purposes for which it was collected.
As a general rule:
•    Marketing data is retained for up to 5 years after your most recent activity
•    Support and enquiry data is retained as required for follow-up, documentation and analysis
We may retain data for up to 5 years where necessary to:
•    Comply with legal obligations and handle any disputes
After this period, the data is deleted or anonymised.


9. Security
We have implemented appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, alteration, disclosure or destruction. These measures are reviewed and updated on a regular basis.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Danish Data Protection Agency, and where required, affected individuals, in accordance with Articles 33 and 34 GDPR.


10. Your rights
Under the GDPR, you have the following rights:
•    The right to be informed about the processing of your personal data
•    The right of access to your personal data
•    The right to rectification of inaccurate or incomplete data
•    The right to erasure (the “right to be forgotten”)
•    The right to restriction of processing
•    The right to object to processing, including for direct marketing purposes
•    The right to data portability
•    Rights related to automated decision-making and profiling
•    The right to withdraw consent at any time, where processing is based on consent
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you.
To exercise any of these rights, please contact us using the details in section 12. We will respond within one month, unless the request is complex, in which case we may extend this period by up to two further months and inform you accordingly.
If you are dissatisfied with our processing of your data, you have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet, www.datatilsynet.dk).


11. Children’s privacy
Our website and services are directed at business users and are not intended for children under the age of 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us so that we can delete the information.


12. Contact
If you wish to access, update or delete your data, or exercise any of the rights described above, please contact:
NORRIQ A/S
Paradisæblevej 4
DK-2500 Valby
Denmark
Email: info@norriq.dk


13. Updates
We continuously review our processing and protection of data. This privacy policy may therefore be amended from time to time. The version in force at any given time will be available on our website. Material changes will be communicated through the website or by direct notification where appropriate.

Last updated: May 2026