Last updated 24 September 2026

Privacy Policy

This policy explains how North Design & Communication processes personal data when you visit north.nu, contact us or authorize access to a Google service.

1. Data controller

North Design & Communication AB, Swedish company registration number 559085-1308, is the controller for the processing described here.

Questions about privacy and personal data can be sent to tobias@north.nu.

2. Data we process

When you contact us by form or email, we process the information you provide, such as your name, company, email address, needs, message and other information required to handle your request.

The website may also process limited technical information, such as visited pages, referring website, browser, operating system, country and logs needed for operation, security and aggregated visitor statistics.

3. Why we process data

We use the data to answer enquiries, prepare proposals, take steps before entering into a contract, perform contracts, deliver services, improve the website and prevent abuse or technical problems.

Processing is based on pre-contractual or contractual necessity, our legitimate interests in communicating with customers and maintaining a secure website, and legal obligations where applicable.

4. Contact forms and service providers

The contact form is handled through Netlify Forms. Data may also be processed in our email, hosting and project services when required to answer or fulfil a request. Providers may only process data under our instructions and applicable agreements.

Some providers, including Netlify and Google, may process data outside the EU/EEA. Where this occurs, applicable safeguards are used, such as the European Commission’s Standard Contractual Clauses or an adequacy decision.

5. Analytics, cookies and external resources

We use a self-hosted instance of Plausible Analytics for aggregated, cookie-free visitor statistics. Plausible does not create advertising profiles or use persistent identifiers to track visitors across websites.

The website loads certain visual symbols from Google Fonts. Google may receive technical data such as your IP address and browser information when these resources are loaded. The website currently uses no marketing cookies.

6. Google API data

After explicit approval through Google OAuth, North’s internal tools may access Google Ads accounts for keyword research, account verification and related marketing analysis. We use only the Google data required for the requested function.

OAuth credentials are stored securely. Google data is not sold, used to build advertising profiles or shared with third parties except where necessary to provide the function or comply with law. Access can be revoked at any time through your Google Account.

North Design & Communication AB’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7. Retention

We retain enquiries while they are needed for the conversation and normally for no more than 24 months after the latest contact. Customer relationship data is retained while the agreement is active and afterwards where required for documentation, legal claims or statutory obligations. OAuth credentials are deleted or made unusable when access is revoked or no longer needed.

8. Your rights

You may request access to, correction or deletion of your data. You may also object to processing, request restriction and, in some cases, receive your data in a portable format. Consent can be withdrawn at any time where processing relies on consent.

Contact us at tobias@north.nu. You may also lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

9. Changes

We may update this policy as our services or legal requirements change. The current version is always available on this page.