Privacy Policy
Last updated: 15 June 2026
norppa.io provides this Privacy Policy in several languages for convenience. In case of any conflict or ambiguity, the English version prevails.
norppa.io (we, us, our) is committed to protecting personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Finnish data protection law. This Privacy Policy describes what personal data we collect, why we collect it, how we use it, and your rights as a data subject.
norppa.io is a business-to-business (B2B) service. We do not knowingly collect data from or about consumers.
Questions or requests regarding this policy: [email protected]
1. Data Controller
The data controller for personal data processed in connection with the norppa.io service is:
- Legal entity: Norteris Oy
- Business ID: 3621127-2
- Trading name: norppa.io
- Registered address: Sturenkatu 26, 00510 Helsinki, Finland
- Contact: [email protected]
2. Personal Data We Process
2.1 Customer account data
When you subscribe to norppa.io we process:
- Business email address (used for authentication and alerts)
- Company name and VAT / business ID (for invoicing and sanctions screening of your own organisation)
- Billing contact details (processed by our EU payment processor in Ireland, and for annual invoices by our EU business bank in Finland)
2.2 Service usage data
- Supplier domain names and business identifiers you submit for monitoring
- Findings generated by our intelligence pipeline relating to submitted domains
- Self-assessment questionnaire (SAQ) answers
- Report download history and portal activity logs
2.3 Technical data
- IP address and browser metadata collected at login (session security)
- Session tokens stored in the EU (short-lived, not linked to browsing behaviour)
2.4 Cookies
We use only strictly necessary cookies:
- Session cookie: a short-lived authentication token stored in your browser to maintain your login session after you sign in. Strictly necessary for the service to function; does not track browsing behaviour.
We do not use analytics, advertising, tracking, or third-party cookies, and therefore display no cookie-consent banner.
2.5 Data found during scanning
Our intelligence pipeline may retrieve publicly available data that incidentally contains personal data: for example, email addresses published in WHOIS records, data breach compilations, or paste sites. This data is processed solely to generate security findings for your account and is not used for any other purpose. We do not build profiles of individuals.
3. Legal Basis for Processing
- Contract performance (Art. 6(1)(b) GDPR): processing necessary to deliver the service you have subscribed to.
- Legal obligation (Art. 6(1)(c) GDPR): invoicing, tax records, and responding to lawful authority requests.
- Legitimate interests (Art. 6(1)(f) GDPR): service security, abuse prevention, and aggregated analytics to improve our platform. We have assessed that these interests do not override your fundamental rights.
4. Data Retention
- Active subscription: all account and finding data retained for the duration of your subscription.
- After cancellation: data retained for 90 days to allow you to retrieve reports, then deleted.
- Billing records: retained for 7 years in accordance with Finnish accounting law (Kirjanpitolaki 1336/1997).
- Security logs: retained for 12 months.
5. Sub-processors and Data Transfers
We use a limited set of sub-processors, all operating within the EU/EEA. A complete list naming each entity is available on request, and we give at least 30 days' notice before adding or replacing one.
- EU infrastructure provider (US parent, EU-region data storage): content delivery, session management, and report storage: all customer data stored in EU data centres. Standard Contractual Clauses (SCCs, 2021/914) in place for any incidental administrative access by the US parent entity.
- EU payment processor (Ireland): card payment processing and subscription management for self-service plans. Processing within the EU; independent controller for billing data. No transfer to a third country.
- EU business bank / invoicing provider (Finland): business banking and manual invoicing of annual subscriptions paid by bank transfer. Independent controller for payment and bank-transfer data. EU only.
- EU transactional email provider (France): transactional and notification email delivery (authentication links, alert notifications, customer communications). EU data residency; encrypted in transit (TLS). No transfer to a third country.
All customer finding data, scan results, and reports are stored within the EU (Frankfurt region). In the ordinary course, no personal data is transferred outside the EU; any incidental administrative access by a US-parent infrastructure entity is covered by Standard Contractual Clauses (EU 2021/914).
6. Your Rights
Under GDPR you have the right to:
- Access the personal data we hold about you (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure (“right to be forgotten”) where no legal obligation requires retention (Art. 17)
- Restriction of processing in certain circumstances (Art. 18)
- Data portability in a machine-readable format (Art. 20)
- Objection to processing based on legitimate interests (Art. 21)
We do not make solely automated decisions that produce legal or similarly significant effects concerning individuals (Art. 22 GDPR).
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. If you believe your rights have been violated, you may lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi).
7. Security
We implement appropriate technical and organisational security measures including access controls, encryption of data in transit (TLS), and infrastructure isolation. Our assessment infrastructure operates from stable external IP addresses and is not directly reachable from the internet. We conduct internal security reviews on a scheduled basis. For full details, see our Security page.
8. Changes to This Policy
We may update this policy. Material changes will be communicated by email to active subscribers at least 30 days before taking effect. The current version is always available at norppa.io/privacy.