Skip to content
NodeCE

NodeCE

Privacy notice

This notice explains which personal data NodeCE processes, why we process it, and the rights available to you.

On this page
  1. Full privacy information
  2. 1. Data controller
  3. 2. When this notice applies
  4. 3. Personal data and sources
  5. 4. Purposes and legal bases
  6. 5. Our legitimate interests
  7. 6. Recipients and processors
  8. 7. Transfers outside the EU and EEA
  9. 8. Retention
  10. 9. Security
  11. 10. Your rights
  12. 11. Information you must provide
  13. 12. Automated decision-making
  14. 13. Changes to this notice

Controller

Controller and contact

NodeCE is provided by NodeiWest AB.

Contact us

Data

Personal data we process

  • Contact details and information you submit through forms or email
  • Customer, agreement, and support information
  • Technical information in security and server logs

Processing

Purposes and legal bases

  • Answer questions, book demonstrations, and prepare quotations
  • Deliver and administer agreed services
  • Protect, troubleshoot, and prevent misuse
  • Comply with legal obligations

Sharing

Recipients and transfers

Suppliers may process data for operations, hosting, email, support, and security. Transfers outside the EU/EEA must use a permitted transfer mechanism.

Time

Retention

We retain personal data for as long as necessary for each purpose or as required by law, an agreement, or legal claims.

GDPR

Your rights

  • Access and information
  • Correction, erasure, and restriction
  • Objection and data portability
  • Withdraw consent
  • Lodge a complaint with IMY

Full privacy information

This privacy notice explains how NodeiWest AB processes personal data when you visit nodece.se, contact us, or use NodeCE services. It applies from 27 July 2026.

We process personal data only for specified purposes and to the extent necessary. The data involved depends on how you interact with us and which services you or your organization use.

1. Data controller

NodeiWest AB, Swedish company registration number 559169-4210, with postal address Blixtfyrsvägen 4, 423 40 Torslanda, Sweden, is the controller for the processing described in this notice.

You can contact us with privacy questions, questions about our processing, or a request to exercise your rights by writing to kontakt@nodece.se or to the postal address above.

2. When this notice applies

This notice applies when you visit nodece.se, send a message through our contact form or by email, book a demonstration, request a quotation, enter into or administer an agreement, or use a customer portal, licence, support function, or other NodeCE service.

When NodeiWest AB processes personal data on a customer’s behalf, such as information that the customer enters into a service, the customer is normally the controller and NodeiWest AB is the processor. That processing is governed by the customer’s instructions and a data processing agreement.

3. Personal data and sources

We primarily obtain information directly from you. We may also receive work-related information from your employer or organization, for example when an administrator creates an account for you. Technical information may be generated automatically when our systems are used.

Depending on the interaction, we may process your name, employer or organization, role, email address, telephone number, billing and agreement information, messages, support cases, account and licence information, and technical information such as IP address, timestamp, browser, device information, and requested resource.

We process contact details and messages to answer questions, book demonstrations, and prepare quotations. When you may personally become a party to the agreement, the legal basis is taking steps at your request before entering into a contract. In other cases, such as when you represent a company, the basis is our legitimate interest in communicating with current and prospective customers.

We process account, licence, agreement, and support information to provide, administer, and support NodeCE. The legal basis is performance of a contract when you are the contracting party and otherwise our legitimate interest in performing and administering the agreement with the organization you represent.

We process technical information and logs to keep the website and services secure, available, and operational, troubleshoot errors, and prevent and investigate misuse or incidents. The legal basis is our legitimate interest in protecting our services, customers, and users.

We also process information where necessary to comply with legal obligations, including accounting, tax, and authority requirements. If we request consent for optional processing in the future, we will state the purpose when consent is given, and you may withdraw that consent at any time.

5. Our legitimate interests

Where we rely on legitimate interests, we have determined that the processing is necessary to communicate with business customers and interested parties, administer business relationships, provide support, improve our services based on specific requests, and protect our systems from faults, intrusion, and misuse.

We balance those interests against your right to privacy and limit what information is used, who has access, and how long it is kept. You have the right to object to processing based on legitimate interests.

6. Recipients and processors

Personal data may be shared with suppliers that support our operations, hosting, email, support, security, finance, and legal advice. Suppliers that process data on our behalf may do so only under our instructions and are subject to data protection and confidentiality terms.

We may disclose information to public authorities, courts, advisers, or other recipients where required by law or necessary to establish, exercise, or defend legal claims. We do not sell personal data.

7. Transfers outside the EU and EEA

If a supplier needs to process personal data outside the EU or EEA, we ensure that a permitted transfer mechanism and appropriate safeguards are in place. These may include an adequacy decision or the European Commission’s standard contractual clauses, together with supplementary measures where necessary.

Contact us if you would like more information about the safeguards used for particular processing or where a copy is available.

8. Retention

We retain information for as long as necessary for each purpose. Contact, demonstration, and quotation information is erased or anonymized when the conversation has ended and the information is no longer needed for follow-up or to manage possible legal claims.

Account, licence, agreement, and support information is kept during the agreement and afterwards for as long as needed for termination, support history, security, or legal claims. Technical logs are kept for a limited period determined by security and troubleshooting needs.

Accounting information covered by Swedish bookkeeping requirements is retained for seven years after the end of the calendar year in which the financial year ended. Information may be retained longer where another law requires it or for the duration of an ongoing legal claim.

9. Security

We use technical and organizational safeguards appropriate to the nature and risk of the processing. Measures may include access controls, restricted permissions, logging, backups, updates, and procedures to prevent, detect, and respond to incidents.

Only people who need the information for their work should have access to it. No transmission or storage can be guaranteed to be entirely risk-free, but we continually work to maintain protection appropriate to the risks.

10. Your rights

You have the right to information about our processing and to request access to the personal data we process about you. You may also request correction of inaccurate data and, where the conditions are met, erasure or restriction of processing.

You may object to processing based on legitimate interests. Where processing is based on consent, you may withdraw that consent without affecting the lawfulness of earlier processing. The right to data portability applies in certain cases where processing is automated and based on consent or a contract.

We may need to verify your identity before handling a request. If you believe that personal data is being processed incorrectly, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY). You are also welcome to contact us first so that we can try to resolve the matter.

11. Information you must provide

Sending a general contact request is voluntary, but we need the contact details and information necessary to respond. Some account, agreement, and billing information must be provided so that we can enter into or perform an agreement and provide the service. If necessary information is missing, we may be unable to handle the request or provide the requested service.

12. Automated decision-making

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the processing described in this notice.

13. Changes to this notice

We may update this notice when our services, processing, or legal requirements change. The current version is always available on nodece.se. If a change is material, we will provide appropriate notice in light of the circumstances.

Last updated: 27 July 2026.