GDPR
1. Definitions and Interpretation
In this Policy the following terms shall have the following meanings:
“Account”: means collectively the personal information, Payment Information and
credentials used by Users to access Material and / or any communications System on the
Web Site;
“Content”: means any text, graphics, images, audio, video, software, data compilations and
any other form of information capable of being stored in a computer that appears on or
forms part of this Web Site;
“Cookie”: means a small text file placed on your computer by Nordaurai Oy when you
visit certain parts of this Web Site. This allows us to identify recurring visitors and to
analyse their browsing habits within the Web Site.
“Data”: means collectively all information that you submit to the Web Site. This includes,
but is not limited to, Account details and information submitted using any of our Services
or Systems;
“Service”: means collectively any online facilities, tools, services or information
that Nordaurai Oy makes available through the Web Site either now or in the future;
“System”: means any online communications infrastructure that Nordaurai Oy makes
available through the Web Site either now or in the future. This includes, but is not limited
to, web-based email, message boards, live chat facilities and email links;
“User” / “Users”: means any third party that accesses the Web Site and is not employed
by Nordaurai Oy and acting in the course of their employment; and
“Website”: means the website that you are currently using (www.nordaurai.com) and
any sub-domains of this site (e.g. subdomain.nordaurai.com) unless expressly excluded
by their own terms and conditions.
Nordaurai Oy may, from time to time, employ the services of other parties for dealing with
matters that may include, but are not limited to, payment handling, delivery of purchased
items, search engine facilities, advertising and marketing. The providers of such services do
not have access to certain personal Data provided by Users of this Web Site. Any Data used
by such parties is used only to the extent required by them to perform the services
that Nordaurai Oy requests. Any use for other purposes is strictly prohibited.
Furthermore, any Data that is processed by third parties must be processed within the
terms of this Policy and in accordance with the Data Protection Act 1998.
2. Company Information
• Business Name: Nordaurai Oy Ltd
• Registration: Registered in Helsinki, Finland
• Email: info@nordaurai.com
3. What Data We Collect
We collect the following categories of personal data:
3.1 Identification & Contact Information
• Full name
• Email address
• Date of birth
• Job title and profession (corporate clients)
• Company name (corporate clients)
3.2 Account & Subscription Data
• Login credentials
• Training assessments and responses
3.3 Payment Information
• Credit/debit card details (processed via Stripe)
• Billing address
• Transaction history
Note: We do not store full card details.
3.4 Technical & Usage Data
• IP address
• Browser type and version
• Operating system
• Visited pages, session duration, clickstream data
4. Third-Party Platforms
We integrate with the following platforms that may process your data:
Platform Purpose Privacy Policy Link
Drimify Delivering gamified learning Drimify Policy
Stripe Secure payment processing Stripe Policy
Zoom Hosting live training sessions Zoom Policy
Calendly Scheduling coaching/training sessions Calendly Policy
5. Cookies & Tracking Technologies
We use cookies to:
• Ensure website functionality (essential cookies)
• Analyze user behavior (analytical cookies)
• Remember preferences (functional cookies)
• Deliver personalized content or ads (marketing cookies)
You may manage cookie preferences via our cookie banner or through your browser. Learn
more at www.aboutcookies.org.
6. Legal Basis for Data Processing (Under GDPR)
Purpose Legal Basis (GDPR Article 6)
Account setup, training access Performance of a contract (Art. 6(1)(b))
Customer service, session reminders Legitimate interest (Art. 6(1)(f))
Marketing communications Consent (Art. 6(1)(a)) – opt-in required
Payment and billing Legal obligation & contract (Art. 6(1)(b)(c))
Analytics and cookies Consent (Art. 6(1)(a))
You may withdraw consent at any time without affecting prior lawful processing.
7. Your GDPR Rights
As an EU/EEA data subject, you have the following rights:
Right Description
Access Request access to your personal data
Rectification Request correction of incorrect/incomplete data
Erasure Request deletion of your data (in applicable
circumstances)
Restriction of Processing Temporarily halt processing under certain conditions
Data Portability Receive data in a structured format for
transfer
Object Object to processing based on legitimate interests
Withdraw Consent Withdraw consent for processing based
on prior agreement
To exercise your rights, email us at info@nordaurai.com. We respond within 30 days.
8. Data Retention
Data Type Retention Period
Account/login info Training period + 12 months
Billing & payment data Up to 6 years (per Finnish law)
Assessment/training responses 12 months post-training
Contact messages/inquiries 12 months
Data is securely deleted or anonymized when no longer necessary.
9. Data Sharing & International Transfers
We only share data with GDPR-compliant service providers for:
• Online course hosting
• Secure payments
• Scheduling and video conferencing
• Gamified learning delivery
10. Security Measures
We prioritize your data protection through:
• Encryption (at rest and in transit)
• Access Controls (authorized staff only)
• Routine Audits (technical and procedural)
All third-party platforms also follow high security standards and are GDPR-compliant.
11. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services,
legal requirements, or data processing practices.
• The updated version will be indicated by an updated “Last updated” date at the top of the
page.
• We recommend reviewing this page periodically to stay informed about how we protect
your data.
If significant changes are made, we will notify you via email (if applicable) or through a
prominent notice on our platform.
12. Contact Information
If you have questions about this Privacy Policy or your personal data:
Email: info@nordaurai.com