Privacy Policy
We run a content delivery network, which means data passes through our servers on its way to someone's browser. This page explains exactly what we keep, why, for how long, and what you can ask us to do about it.
Last updated 24 August 2026
Who we are
NordicCDN ApS (company registration number DK38158724) is the operator of NordicCDN, a content delivery network and website acceleration platform. We are established in Γ rslev, Denmark, in the European Union.
Our registered address is BakkegΓ₯rdsvej 7, 5792 Γ rslev.
For anything in this policy you can reach us at privacy@nordiccdn.com.
Our two roles
In short: we decide what happens to our customers' account data. We do not decide what happens to the data of people visiting our customers' websites β we only handle it on the customer's instructions.
Data protection law distinguishes between a controller (who decides why and how data is processed) and a processor (who acts on someone else's instructions). We are both, in different contexts:
- Controller β for the personal data of our own customers and prospective customers: your account, your billing, the emails you send us, and how you use our dashboard.
- Processor β for the personal data of people who visit a website delivered through NordicCDN. Our customer is the controller there; we process the traffic on their behalf under a data processing agreement.
If you are a visitor to a website that happens to use NordicCDN and want your data removed, please contact the operator of that website. They are the controller, and we act on their instructions. If you cannot reach them, write to us and we will help you get to the right place.
Data we collect as a controller
Account data
When you create an account we store your name, email address, a hashed password, your team or organisation name, and any team members you invite. Passwords are stored as one-way hashes; we never see or store them in plain text.
Configuration data
The zones, domains, cache rules, firewall rules and other settings you create. This is your configuration, not personal data as such, but it is stored against your account.
Billing data
Your bandwidth usage, invoices and payment history. Card details are handled entirely by our payment processor, Stripe β they never touch our servers. We store only the last four digits, card brand and expiry so you can tell your payment methods apart.
Support and enquiries
If you email us or use the contact form, we keep your message, your email address, and any company name you supplied, so we can reply and keep track of the conversation. The form also records the IP address it was submitted from, purely as an anti-abuse measure.
Product usage
Login times, IP addresses used to sign in, browser sessions, and an activity log of significant actions taken in your account (creating a zone, purging a cache, adding a team member). This exists for security and for your own audit trail.
Prospective customers
We maintain a small business-development list built from publicly available sources: public web performance data about websites, and public business-registry information about the companies behind them. This concerns businesses rather than private individuals, and any personal element (such as a company contact address published in a business registry) is processed on the basis of our legitimate interest in offering a relevant service. You can ask us to remove a business at any time by writing to privacy@nordiccdn.com, and we will do so without asking why.
Data we process on behalf of customers
In short: we log requests so our customers can see their traffic and so we can stop attacks. We do not build profiles, we do not track people across sites, and we sell nothing.
When someone visits a website delivered through NordicCDN, our edge servers process the request in order to deliver it. That involves the following:
| What | Why it exists |
|---|---|
| IP address | Required to route the response back, to choose the nearest edge, and to detect and block abuse. |
| Requested host and path, HTTP method, status code, bytes transferred, response time | Traffic analytics and troubleshooting for the site owner. |
| User agent and referrer | Analytics, bot detection, and choosing the right image format for the browser. |
| Country, derived from the IP address | Geographic analytics and country-based firewall rules configured by the site owner. |
| Cookies present on the request | Only inspected to decide whether a page may be served from cache β for example, a logged-in or cart cookie means the page is fetched fresh from the origin instead. The contents are not stored. |
| Firewall and security events | Where a request triggered a rate limit, a firewall rule or an abuse block, we record the IP address and what it did, so the block can be applied and appealed. |
We do not use this data for advertising, we do not combine it across our customers to profile individuals, and we do not sell it to anyone. Ever.
Where a customer enables our translation feature, page content is sent to our own translation infrastructure inside our network to be translated, and the translated page is cached. It is not sent to any third-party translation service.
Why we process it β and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the service you signed up for | Performance of a contract |
| Billing and accounting | Contract, and legal obligation for tax records |
| Security, abuse prevention and keeping the network up | Legitimate interest in operating a secure service |
| Answering your emails and support requests | Contract, or legitimate interest for non-customers |
| Service announcements and outage notices | Legitimate interest β you cannot opt out of security notices while you have an account |
| Marketing emails, if we ever send them | Consent, withdrawable at any time |
| Business development towards companies | Legitimate interest, subject to objection |
How long we keep it
Request logs are the largest category of data we handle, and we keep them for a deliberately short time. They age out automatically:
- Raw request logs, which contain IP addresses β 7 days, then permanently deleted.
- Hourly aggregates, which contain no IP addresses β 90 days.
- Daily aggregates, which contain no IP addresses β 365 days.
For everything else:
- Account data β for as long as your account is open, then deleted or anonymised within 90 days of closure.
- Invoices and accounting records β five years after the end of the financial year, because Danish bookkeeping law requires it.
- Support conversations and contact form messages β up to 24 months, so we have context if you come back with the same question.
- Security blocks β until the block expires, plus a short window so repeat offenders can be recognised.
Where your data lives
Our control plane, database and analytics storage are hosted in the European Union. Account data, billing data and support conversations do not leave the EU.
Our edge network is global by design β that is the point of a CDN. A request from Singapore is answered by a server in Singapore, and the log line for that request is generated there before being shipped back to our EU analytics store. Customers who need traffic to stay within Europe can restrict their zone to European edges.
Where a transfer outside the EU or EEA does occur, it is covered by the European Commission's Standard Contractual Clauses.
How we protect it
- Everything is served over TLS. Certificates are issued and renewed automatically, so nothing expires by accident.
- Passwords are stored as salted one-way hashes and two-factor authentication is available on every account.
- Access to production systems is limited to the people who need it, over authenticated connections, and is logged.
- Our own edge security layer blocks scanning and abuse before it reaches customer origins.
- Data is backed up regularly, and backups are held in the EU under the same protections as live data.
If a personal data breach ever occurs that is likely to result in a risk to people's rights, we will notify the relevant supervisory authority within 72 hours and tell affected customers without undue delay.
Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and get a copy of it.
- Rectify anything that is wrong or incomplete.
- Erase your data, where we have no overriding reason to keep it (invoices, for example, we are legally required to retain).
- Restrict or object to processing based on our legitimate interests.
- Port your data to another provider in a machine-readable format.
- Withdraw consent at any time, where processing is based on consent.
Write to privacy@nordiccdn.com and we will respond within one month. There is no charge, and we will not ask you to justify the request.
If you are unhappy with how we handled it, you can complain to your local data protection authority. In Denmark that is Datatilsynet (datatilsynet.dk). We would rather you told us first, though β most things are a misunderstanding we can fix the same day.
Children
NordicCDN is a service for businesses and developers. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
We update this policy when what we actually do changes. The revision date at the top always reflects the last substantive change. For anything material β a new category of data, a new processor, a new purpose β we will email account holders before it takes effect rather than quietly editing the page.
Contact us
Privacy questions, data requests and complaints: privacy@nordiccdn.com.
Anything else: our contact page.
NordicCDN ApS, BakkegΓ₯rdsvej 7, 5792 Γ rslev, Denmark.