Norrsken Foundation and/or its affiliated entities are responsible for the processing of your Personal Data as described in this Policy, and, unless otherwise specified, act as the controller of such Personal Data. That means that Norrsken determines “why” and “how” your Personal Data is collected and used. The Norrsken foundation ecosystem that controls your Personal Data may differ depending on where you reside and/or where you interact with us under GDPR or RDPP. A reference to “Norrsken”, “we”, “our” or “us” is a reference to the relevant Norrsken entity that is the controller of your Personal Data.
Norrsken respects your privacy and is committed to maintaining your trust by protecting your personal data. This Global Privacy Policy (“Policy”) describes how Norrsken collects, uses, shares or otherwise processes data (either in isolation or in combination with other information) that enables you to be directly or indirectly identified (“Personal Data”) and explains the rights you may have in relation to your Personal Data. This Policy is intended to help you understand how Norrsken processes your Personal Data when you:
- Interact with us on our website, online forms, email and other that might display or link to this Policy;
- Use our products and services, including our software and technology platform and applications made available for use online or through mobile devices, where we act as a controller of your Personal Data
- Receive communications from us or otherwise communicate with us;
- Access our locations and use the resources on premises such as WiFi and other amenities as a member, service provider or an attendee to an event hosted or co-hosted by Norrsken;
- Subscribe to receive our newsletters, updates or other communications;
- Participate in surveys, research or other similar data collection activities facilitated by Norrsken;
- Are employed by or affiliated with an organization or institution that uses our products and services where your Personal Data has been shared with us in our capacity as a controller (e.g., to authorize your access to your employer, educational institution or an another organization’s account);
- Or access our locations as a member, guest, service provider or an attendee to an event hosted or co-hosted by Norrsken
Please read this Privacy Policy carefully and revisit this page from time to time to review any changes that may have been made. (We may amend this Privacy Policy at any time by posting the amended terms on this website. All amended terms automatically take effect on the date set out in the posted Privacy Policy, unless otherwise specified.)
For the purposes of this Privacy Policy, the following definitions apply:
- “Applicable Law” The law is applicable to individuals and institutions worldwide that process personal data of individuals in a given jurisdiction, irrespective of their location or citizenship. This encompasses those established or residing within the jurisdiction and those operating outside but processing the personal data of individuals within that specific region;
- “Personal Data” means any information relating to an identified or identifiable natural person (hereinafter “Data Subject”). For clarity, an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of such a natural person, photos, videos and Voice recording;
- “Controller” means the natural or legal person, authority, organization or other agency that makes decisions individually or together with other parties regarding the purposes and means for processing personal data;
- “Processing” means an operation or activity or set of operations or activities performed on personal data whether or not by automated means;
- “Processor” is a natural or legal person, authority, organization or other agency that processes Personal Data on behalf of the Controller;
- “Sub-processor” is the contractual partner of the Processor, engaged to carry out specific processing activities on behalf of the Processor;
- “Third Party” means a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor, Sub-processor, and persons who, under the direct authority of the Controller, Processor or Sub-processor, are authorized to process Personal Data;
This Policy does not address, and we are not responsible for the privacy, data, or other practices of any entities other than the Norrsken Foundation ecosystem (except as otherwise provided in this Policy). In addition, we are not responsible for the privacy, data collection, use, disclosure, or security policies or practices of other organizations, or any other app developer, app provider, social media platform provider, operating system provider, wireless service provider or device manufacturer, including with respect to any Personal Data you disclose to other organizations through their software and technology platform and applications or our social media pages.
What are cookies?
Cookies are small text files that are placed on your computer or mobile device when you visit a website. They are widely used to make websites work more efficiently and to provide information to website owners.
How we use cookies
We use cookies for various purposes, including:
- Authentication: We use cookies to recognize you when you visit our website and authenticate your access to certain features.
- Preferences: Cookies help us remember your preferences, such as language settings, font size, and other display preferences, to enhance your browsing experience.
- Analytics: We use cookies to analyze how visitors use our website, track user behavior, and gather statistical information about our website’s performance. This helps us improve our website and tailor it to our users' needs.
- Marketing: Cookies may be used to deliver personalized advertisements and promotional content based on your browsing activities and interests.
Types of cookies we use
- Essential Cookies: These cookies are necessary for the operation of our website. They enable core functionality, such as navigating between pages and accessing secure areas. Without these cookies, our website may not function properly.
- Performance and Analytics Cookies: These cookies allow us to analyze how visitors use our website, track user behavior, and gather statistical information about our website’s performance. We use this data to improve our website and enhance the user experience.
- Functionality Cookies: These cookies remember your preferences and choices to provide a personalized experience on our website.
- Targeting and Advertising Cookies: These cookies are used to deliver relevant advertisements and promotional content based on your browsing activities and interests. They may also be used to measure the effectiveness of advertising campaigns.
Third-party cookies
We may allow third-party service providers to use cookies on our website for various purposes, including analytics and personalized advertising. These third parties may collect information about your online activities over time and across different websites.
Your choices
Most web browsers are set to accept cookies by default. However, you can choose to block or delete cookies through your browser settings. Please note that blocking or deleting cookies may impact your browsing experience and limit certain features on our website.
To manage your cookie preferences, you can modify your browser settings or use opt-out mechanisms provided by third-party advertisers and analytics providers.
Updates to this policy
We may update this Cookie Policy from time to time to reflect changes in our practices and applicable laws. We encourage you to review this Policy periodically for any updates.
This Cookie Policy aims to ensure transparency and compliance with the personal data protection law under GDPR or RDPP. By using our website, you consent to the use of cookies as described in this Policy.
As an impact ecosystem, we gather various forms of personal data concerning your interactions with us and the products and services you utilize. The diverse categories of personal data we may collect are outlined in the table below. It's important to recognize that not all categories may be relevant to your situation.
- Contact Information
Data such as your name, email address, physical address, phone number, employer or educational institution name and your title or role (as that information relates to your use of our products and services) and other contact information. - Supplemental Identification (ID) Information
Data such as your government-issued identity document, photo and other information collected for identity, age verification and fraud prevention purposes. - Account Information
Data associated with your Norrsken account, such as username, password, profile picture and designated Norrsken “home” location. Activity & Usage Information Data associated with your activity and use of our products and services, including Membership. - Activity & Usage Information
Data associated with your membership activity and use of our workspaces such as keycard and/or mobile key access data (i.e. date and time of arrival or scan at access point), desk, office and room booking data, credit usage data, desk location data and other information relating to your membership activity and use of our workspaces and membership products and services. - Security Information
Data such as your image and video footage captured by closed circuit television (CCTV), your access data logs, data collected about you in connection with security incidents that involve you and other information relating to the safety and security of our locations. - Event Information
Data collected for purposes of registration and participation in events and webinars, such as but not limited to attendee badge information (e.g., name, title and company name and image), email address, photographs and videos captured during events. - Device, Internet & Network Activity Information
Data from which your device could be identified, such as device ID or other unique identifiers, or about your device, such as browser type, your geolocation information (taken through your mobile device’s GPS signal, browser’s WIFI signal or Bluetooth technology, if your device settings allow for this), IP address, MAC address, data and other information relating to your device and activity on and use of our websites, mobile applications, emails and online content, to the extent such data is considered Personal Data under applicable data protection laws. - Other Voluntary Personal Data
Data such as the content of your communications with us, including interactions with customer support and our social media channels, communication platforms within the house, participation in surveys, questionnaires, contests or other promotional offers, data you provide when you sign up to receive news, or other marketing communications from us or our partners and any other information you voluntarily provide to us. - Other Sensitive Personal Data
Data collected with your consent and used as necessary to perform reasonably expected services or as required by law. Unless specifically requested, we ask that you not provide any Sensitive Personal Information.
- Directly from You
We collect most of your Personal Data directly from you. The categories of Personal Data that we collect depends on how you interact with us. For example, you may provide us Personal Data when you sign-up or activate a Norrsken membership, contact us or inquire about our products or services, access our locations as a member or guest, use our mobile applications, participate in surveys, interact with our websites, attend or take part in events or provide services to us. You may not always be required to provide Personal Data that we request. However, you should be aware that if you do not provide Personal Data that we request, we may not be able to provide you with our products or services or respond to your requests for which the provision of such Personal Data is necessary. - From Automated Means, Devices and Our Network
We may automatically collect your Personal Data, which we may observe or detect without directly asking you to provide the information to us. As is common practice among businesses that operate online and through technology, this will mainly include information gathered automatically through your activity on and use of our websites, mobile applications, emails and online content. This information includes Device, Internet and Network Activity Information and other information collected through cookies, web beacons and other similar technologies. - From Other Sources
We may also collect your Personal Data from other sources as described below. - Activity & Usage Information
Data associated with your membership activity and use of our workspaces such as keycard and/or mobile key access data (i.e. date and time of arrival or scan at access point), desk, office and room booking data, credit usage data, desk location data and other information relating to your membership activity and use of our workspaces and membership products and services. - Security Information
Data such as your image and video footage captured by closed circuit television (CCTV), your access data logs, data collected about you in connection with security incidents that involve you and other information relating to the safety and security of our locations. - Event Information
Data collected for purposes of registration and participation in events and webinars, such as but not limited to attendee badge information (e.g., name, title and company name and image), email address, photographs and videos captured during events. - Device, Internet & Network Activity Information
Data from which your device could be identified, such as device ID or other unique identifiers, or about your device, such as browser type, your geolocation information (taken through your mobile device’s GPS signal, browser’s WIFI signal or Bluetooth technology, if your device settings allow for this), IP address, MAC address, data and other information relating to your device and activity on and use of our websites, mobile applications, emails and online content, to the extent such data is considered Personal Data under applicable data protection laws. - Other Voluntary Personal Data
Data such as the content of your communications with us, including interactions with customer support and our social media channels, communication platforms within the house, participation in surveys, questionnaires, contests or other promotional offers, data you provide when you sign up to receive news, or other marketing communications from us or our partners and any other information you voluntarily provide to us. - Other Sensitive Personal Data
Data collected with your consent and used as necessary to perform reasonably expected services or as required by law. Unless specifically requested, we ask that you not provide any Sensitive Personal Information.
Source and situation (examples)
- Your Employer, Educational Institution or Other Organization
To invite you to activate your membership or account and to authorize your access to your employer’s, educational institution’s or other organization’s, as applicable, account for contracted products and services, if your membership or account is associated with your employer, educational institution or another organization’s contract for our products and services. - Nomination, Recommendation or Reference
To refer you to use our products and services. - Service Providers and Consultants
To assist with the provision and promotion of our products and services and performance of business-related functions (e.g., payment partners and merchants, advertising and marketing partners). - Event Sponsors (those who host events in Norrsken and those we host ourselves)
To manage registration and participation in events hosted at our locations. - Other Third Parties
To facilitate your use of our products and services.
We will only use your Personal Data where we have your consent or a legal basis to process the same. Most commonly, we will use your Personal Data in the following circumstances: Where we need to undertake certain processes in order to enter an agreement with you, and where we need to perform the agreement, we have entered with you; Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests. Legitimate Interest means the interest of our business in conducting and managing our business to enable us to give you the best service or product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests; and/or where we need to comply with a legal obligation. We have set out below, in a table format, a description of all the ways we plan to use your Personal Data and the basis we rely on to do so. We have also identified what our legitimate interests are where appropriate. Note that we may process your Personal Data for more than one lawful ground.
Additionally, not all categories may be applicable depending on the specific use case being implemented
- Registration and On-boarding
Contact Information, Supplemental ID Information
- Compliance with a legal obligation
- Necessary for the performance of our contractual/agreement obligations or to take steps to enter into an agreement with you
- Our legitimate interests in operating our business and providing membership services to you
- Prior consent obtained for the use and processing of your Personal Data.
- Provision of the Membership Services
Contact Information, Account Information- Compliance with a legal obligation
- Necessary for the performance of our contractual obligations to you
- Our legitimate interests in operating our business and providing membership services to you
- KYC (Know Your Customer)
Identification Information- Compliance with a legal obligation
- Our legitimate interests in operating our business and providing membership services to you
- Business Operation and Maintenance
Technical Data, Contact Information- Our legitimate interests in operating our business and providing membership services to you
- Includes troubleshooting, incident management, data analysis, product and system testing, system maintenance, support, and reporting
- Customer Relationship Management
Contact Information, Communication History
- Necessary for the performance of our contractual obligations to you
- Our legitimate interests in operating our business and providing membership services to you
- Prior consent obtained for the use and processing of your Personal Data
- Business Development
Contact Information, Usage Data- Our legitimate interests in operating our business and providing membership services to you
- Prior consent obtained for the use and processing of your Personal Data
- Includes data analytics to improve our website, API, products, services, customer relationships, and experiences
- Business Management
Business-related Information- Compliance with a legal obligation
- Our legitimate interests in operating our business and providing our services to you
- Marketing
Contact Information, Marketing Preferences- Our legitimate interests in operating our business and providing membership services to you
- Prior consent obtained for the use and processing of your Personal Data
- Includes marketing of our products & services, recommendations of other products & services, promotions, campaigns, etc.
How we share your personal data
We consider the protection of your Personal Data to be a vital part of our relationship with you; therefore, we do not sell your Personal Data to third parties. There are, however, certain circumstances in which we may disclose, transfer or share your Personal Data with certain third parties (“Third Parties”) as set forth in this Policy. These Third Parties can be categorized as follows:
- Norrsken Foundation Ecosystem. We may share your Personal Data with other Norrsken Houses and entities affiliated with Norrsken foundation for purposes consistent with this Policy. Norrsken foundation shall process your Personal Data in accordance with this Policy
- Our Service Providers. We use third-party companies, vendors, agents and contractors (“Service Providers”) to perform services or business-related functions on our behalf or to assist us with the provision of our products and services. We may share your Personal Data with such Service Providers as necessary for them to perform or provide services on our behalf.
- Organizers, Hosts and Sponsors. We may share your Personal Data with organizers, hosts and sponsors (“Sponsors”) when you register for, attend or take part in events, webinars, programs, promotions or contests associated with such Sponsors. For example, if you input your name and email address into a web form for an event, webinar, program, promotion or contest, the associated Sponsor will receive that information. Sponsors that receive your information may send you communications, which may be subject to their own privacy policy. We are not responsible for the privacy or data security practices of such Sponsors, which may differ from those explained in this Policy. You should refer to the Sponsor’s privacy policy and direct any privacy or data security questions directly to them.
- Our Professional Advisors. We may share your Personal Data with our professional advisors, including our lawyers, bankers, auditors and insurers who provide consultancy, legal, banking, auditing, insurance and accounting services to us. Our professional advisors are subject to appropriate obligations of confidentiality (whether contractual or statutory) with respect to Personal Data.
- Other Third-Party Disclosures. We may share your Personal Data: (i) at your direction or with your consent, (ii) if required to do so by law in order to, for example, respond to a subpoena or request from law enforcement, a court or a government agency (including in response to public authorities to meet national security or law enforcement requirements) or (iii) in the good faith belief that such action is necessary to: (a) comply with a legal obligation, (b) protect or defend: our rights, interests or property or that of our employees, members, customers and other third parties, (c) prevent or investigate possible wrongdoing in connection with our products and services, (d) enforce our terms and conditions, policies and agreements, (e) act in urgent circumstances to protect the personal safety of you, other individuals or the public or (f) protect against legal liability.
N.B: We will only share your personal data in these ways in accordance with data protection legislation.
International transfers of personal data
Norrsken’s products and services are available around the world. To make that possible, your Personal Data may be transferred to, accessed by and stored by us and Third Parties in different locations, which may include jurisdictions outside your own. These jurisdictions may have data protection laws that differ from the laws where you reside, and in some cases, may not be as comprehensive or protective. However, we take appropriate steps in ensuring that personal data is secure and handled in accordance with applicable data protection laws.
How long we shall retain your personal data
- We will only retain your Personal Data for as long as reasonably necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your Personal Data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect of our relationship with you.
- To determine the appropriate retention period for Personal Data, we consider the amount, nature and sensitivity of the Personal Data, the potential risk of harm from unauthorized use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
- In some circumstances, we may anonymize your Personal Data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
Subject to legal and contractual exceptions, you have rights under applicable laws in relation to your Personal Data. These are listed below:
- Right to be informed that we are collecting your personal information and how we are processing it;
- Right to rectify your personal data where it is inaccurate or incomplete;
- Right to withdraw your consent to the processing of your personal data. However, such withdrawal does not affect the lawfulness of the processing of personal data based on consent before its withdrawal. Please note that we may continue processing your personal data for legitimate interests or legal grounds;
- Right to object to processing of all or part of your personal data. However, we may decline your request if we are obliged by law or entitled to do so;
- Right of erasure of your personal data held by us, noting that we may continue to retain your information if we are entitled to do so or obliged by law;
- Right to access your personal data in our possession;
- Right to not be subjected to profiling or automated decision making in regards to processing of your Personal Data. However, we may decline your request if we are obliged by law or entitled to do so;
- Right to request your personal data to be processed in a restricted manner. Note that we may continue processing data and reject the request if we are entitled to or are legally obliged;
- Right to data portability in a manner we may deem appropriate such as electronic format.
- We may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Data (or to exercise any of your other rights). This is a security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
- We try to respond to all legitimate requests within 30 days. Occasionally it could take us longer if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
N.B: You will not be discriminated against for exercising any of your rights described in this Policy. Please note that these rights may be subject to further conditions; limitations and/or exemptions under applicable data protection laws. If any of the rights listed above are not provided under law for your jurisdiction, we have absolute discretion in providing you with these rights.
How to Exercise Your Rights
To exercise your applicable rights, please contact us by completing this form. To protect your privacy and maintain security, we may ask you to provide certain information to verify your identity and residence before granting you access to your Personal Data or complying with your request. We will contact you if we need additional information in order to process your request. If we are unable to verify your identity or rights to the data, we may not be able to provide you with data rights until you are able to provide us with proper documents. Where permitted by law, we reserve the right to charge an appropriate fee to cover administrative costs incurred in responding to your request, for instance, if your request is manifestly unfounded or excessive. Under certain data protection laws, you may designate an authorized agent to make requests on your behalf to exercise your rights. Before accepting such a request from an agent, we will require the agent to provide proof you have authorized it to act on your behalf, and we may need you to verify your identity directly with us.
The security of all your Personal Information is important to us. To the best of our ability, we are taking appropriate technical or organizational measures to protect your Personal Information against unauthorized access or unlawful processing and accidental loss, destruction or damage. While we strive to protect your Personal Information, we cannot guarantee the absolute security or 100% warrant of any information you share with us.
Children and personal data
Our products and services are not directed at children. We do not knowingly collect Personal Data from children under the age of 16, or such other applicable age of consent for privacy purposes in relevant individual jurisdictions, unless (a) we have obtained consent from a parent or guardian, (b) such collection is subject to a separate agreement with us or (c) the visit by a child is unsolicited or incidental.
Non-compliance with the privacy policy
In the event of non-compliance with the provisions outlined in this Privacy Policy, NORRSKEN retains the right to terminate any existing agreements and reject any applications for information that are inconsistent with the terms specified herein. By accessing or using our services, you acknowledge and agree that NORRSKEN has the authority to exercise its rights in response to any violation of this Privacy Policy.
How to contact us
In case you would like to contact us with reference to the terms of this privacy policy, or in order to exercise any of your rights in relation to your Personal Data, you can reach us via dpo@norrskenfoundation.org