Privacy Policy

This Privacy Policy explains how Nordman Algorithms collects, uses, and protects personal data. We process personal data in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR).

Last Updated: April 22, 2026

1
Introduction

Nordman Algorithms is a trade name of Nordman Algorithms OÜ (Reg. No. 14435535), registered in Tallinn, Estonia.

2
Data Controller
Legal name Nordman Algorithms OÜ
Address Vesivärava 50-201, 10152 Tallinn, Estonia
3
What Data We Collect
3.1 Information you provide

We collect personal data when you:

  • Contact us via forms (Contact / Request a Quote)
  • Subscribe to updates
  • Request access to products
  • Communicate with support

Collected data may include email address and name. We do not intentionally collect phone numbers or sensitive personal data.

3.2 Product & license data

When using our software, we may process:

  • Email address (for license verification)
  • License status
  • Basic usage data (e.g., activation or usage events)

This data is used solely for license validation, software functionality, and technical support.

3.3 Technical & analytics data

We may collect:

  • IP address
  • Browser and device information
  • Pages visited
  • Session duration and interactions

This is collected via Google Analytics (via Google Tag Manager). Analytics tools are loaded only after user consent via Cookiebot. Data collected by Google Analytics may be used by Google for analytics and advertising purposes in accordance with Google’s Privacy Policy.

3.4 Transaction data

Payments are processed by third-party providers: PayPal and bank transfer / invoice. We do not store card details or payment credentials.

3.5 Email communications data

When we send transactional or marketing emails, we may process:

  • Email address
  • Name (where provided)
  • Email open and click events (for transactional confirmation only)

This data is processed via Brevo (formerly Sendinblue) under a Data Processing Agreement. Marketing emails are sent only where user consent has been provided.

4
Cookies & Tracking Technologies

We use cookies for:

  • Service functionality (session cookies)
  • User preferences
  • Security (anti-bot protection)

We also use:

  • Google Analytics (loaded after consent)
  • Cookiebot (consent management)
  • Cloudflare Turnstile (form protection — always active, may process limited technical data such as IP address)
  • Google Maps (lazy-loaded after user interaction)

Cookies are managed through our cookie consent system. You can customize your preferences or withdraw consent at any time via our Cookie settings. For a full list of cookies used, see our Cookie Policy.

5
How We Use Your Data

We use personal data to:

  • Provide access to software and services
  • Validate licenses
  • Process purchases and subscriptions
  • Send transactional emails via Brevo (based on contractual necessity) and marketing communications via Brevo (only where user consent has been provided)
  • Provide customer support
  • Improve website performance
  • Ensure security and prevent abuse

We do not use personal data for automated financial decision-making.

6
Legal Basis (GDPR)

We process data under the following legal bases as defined by GDPR Article 6:

  • Contractual necessity (Art. 6(1)(b)) — processing your name, email, and license data to fulfill your order, deliver software access, and provide support
  • Legitimate interests (Art. 6(1)(f)) — security monitoring, fraud prevention, abuse detection, and service performance improvement
  • Legal obligations (Art. 6(1)(c)) — retaining transaction records as required by applicable tax and accounting law
  • Consent (Art. 6(1)(a)) — placing analytics cookies and sending marketing communications; consent may be withdrawn at any time without affecting prior processing
7
Data Sharing

We do not sell or rent personal data.

We may share data with trusted service providers acting on our behalf:

  • Google (Analytics, Maps)
  • PayPal (payment processing)
  • Brevo (transactional and marketing email communication)
  • Kinsta / Google Cloud (hosting infrastructure)
  • Cloudflare (security and form protection)

We may disclose personal data where required by law or regulatory authorities.

8
Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy:

  • Contact form submissions and support communications — up to 2 years
  • License and product data — for the duration of the active license plus 1 year
  • Legal and compliance obligations — as required by applicable law

Users may request deletion of their data at any time by contacting us.

9
Your Rights (GDPR)

You have the right to:

  • Access your personal data
  • Request correction of inaccurate data
  • Request deletion of your data
  • Restrict or object to processing
  • Request data portability
  • Withdraw consent at any time

To exercise any of these rights, please contact us at contact@nordman-algorithms.com. We will respond within 30 days.

You also have the right to lodge a complaint with a supervisory authority. As Nordman Algorithms OÜ is registered in Estonia, the competent authority is:

Authority Andmekaitse Inspektsioon (AKI) — Estonian Data Protection Inspectorate
Website www.aki.ee
Email info@aki.ee
10
Data Storage & International Transfers

Data may be stored within the EU and/or transferred outside the European Economic Area (EEA), including via infrastructure providers such as Google Cloud (via Kinsta).

Where data is transferred outside the EEA, appropriate safeguards are implemented, including Standard Contractual Clauses (SCCs). Key providers with whom Data Processing Agreements (DPAs) are in place include:

  • Google LLC — Analytics and hosting infrastructure (Google Cloud DPA)
  • Brevo SAS — Email communications (Brevo DPA)
  • Cloudflare, Inc. — Security and form protection (Cloudflare DPA)
11
Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals, as defined under GDPR Article 22.

Our software products operate on user-defined logic and parameters. All trading decisions remain the sole responsibility of the user.

12
Third-Party Services

Our website includes links to external platforms (WhatsApp, Telegram, and social media networks). When you use these services, their own privacy policies apply. We are not responsible for their data practices.

13
Data Security

We implement reasonable technical and organizational measures to protect personal data, including access restrictions, secure infrastructure, and controlled data handling. Access to personal data is limited to authorized personnel only.

14
Children’s Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us and we will take steps to remove it.

15
Updates to This Policy

This Privacy Policy may be updated from time to time. We will notify users of material changes by posting the updated policy on this page. We recommend reviewing this page periodically.

16
Contact

For any questions related to this Privacy Policy or your personal data, please contact us:
contact@nordman-algorithms.com