We take the protection of your personal data seriously. This policy explains what data we process when you use nordlydigital.com, on what legal basis, and what rights you have. It applies to all language versions of this website.
1. Controller
The controller responsible for data processing on this website is:
nordly digital, Klaus H. Mähleke, 07640 Ses Salines, Islas Baleares, España.
Email: hello@nordlydigital.com. Phone: +49 176 600 33 138.
2. Hosting and server log files
This website is hosted on a server within the European Union. When you visit the site, the web server automatically processes technical access data such as your IP address, the date and time of the request, the page requested, the referring page, and your browser and operating system. This processing is necessary for the secure and stable operation of the website and is based on our legitimate interest (Art. 6 (1) (f) GDPR). These log files are deleted after 14 days at the latest.
3. Contact form and email
When you send us an enquiry through the contact form or by email, we process the data you provide, namely your name, your email address, your company if you enter one, the topic, and your message. We use this data solely to receive and answer your enquiry. The legal basis is the initiation or performance of a contract (Art. 6 (1) (b) GDPR) and, where an enquiry is not contractual, our legitimate interest in responding to it (Art. 6 (1) (f) GDPR).
To deliver your enquiry to us, the message is sent by email through our email provider, which acts as a processor on our behalf under Art. 28 GDPR. A copy of the submission is stored on our server so that we can process it. We delete this data once your enquiry has been handled, unless statutory retention obligations require us to keep it longer.
4. No cookies, no third party tracking
This website sets no cookies for analytics or advertising and embeds no third party tracking, analytics or advertising services. Your chosen language is stored only in your own browser (localStorage) so that the site can remember it. This information never reaches our server.
We measure how this website is used with our own cookieless solution on our own server. It is described in section 5.
5. Web analytics
We measure the use of this website ourselves, with our own software on our own server inside the European Union. No third party analytics service is embedded, and no third party receives this data.
The measurement works without cookies. Nothing is stored on your device, no cookie, no localStorage entry, no other identifier, and nothing already stored on your device is read out. Because there is neither storage on your device nor access to information stored there, this measurement requires no consent and therefore no consent banner. The rule that applies to us is Spanish, Art. 22(2) of Ley 34/2002 (LSSI), by which Spain implemented Art. 5(3) of the ePrivacy Directive.
For each page view we record: the path of the page requested without the query string, the domain of the referring page, the browser family, the device class (desktop, tablet, mobile), the country, which we determine from your IP address using a local database on our own server with no third party involved, a coarse bucket for the width of your browser window, campaign parameters contained in the address (utm_source, utm_medium, utm_campaign) where present, the time spent on the page in seconds, clicks on links leading away from this website (of which only the target domain is stored), and events that we trigger in the page ourselves.
We also record a technically derived identifier. It is a hash over the calendar day (UTC), this website, your IP address and your browser identifier. It stays the same throughout one day and takes a different value the next day. This identifier is pseudonymous: it does not allow us to identify you, and we do not combine it with any other data. Your IP address and your full browser identifier are used only briefly in memory to derive it and are discarded afterwards. They are not stored.
The purpose of the processing is to understand which content is used and to improve the website on that basis. The legal basis is our legitimate interest in measuring reach (Art. 6 (1) (f) GDPR).
Individual events are stored for at most 180 days and are then deleted without replacement.
You may object to this processing at any time under Art. 21 GDPR. An informal message to hello@nordlydigital.com is enough.
6. Recipients of your data
We do not sell your data. It is processed by us and by the processors we rely on to run the site, namely our hosting provider and our email provider, each bound by a data processing agreement. Any transfer beyond this happens only where we are legally obliged to make it.
7. Storage period
We store personal data only for as long as it is needed for the purpose it was collected for, or for as long as statutory retention periods require. After that it is deleted.
8. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Where processing is based on your consent, you may withdraw it at any time with effect for the future. To exercise these rights, contact us at hello@nordlydigital.com.
9. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority, for example the Spanish Agencia Española de Protección de Datos (AEPD, www.aepd.es) or the supervisory authority in your country of residence.
10. Changes to this policy
We may update this privacy policy to reflect changes in our processing or in legal requirements. The version published on this page always applies.