Skip to content

Privacy policy

Privacy Policy

How NorDok handles your personal data.

Last updated: 3 May 2026.

1. Data controller

The data controller for personal data processed via this service is:

NorDok
Dannesbovej 2A
5690 Tommerup
Denmark
CVR: 44759217
E-mail: mail@nordok.net

2. What data we collect

We process the following categories of personal data:

  • Account data: name, e-mail, password hash, language preference, profile photo (optional).
  • Business profile (marina-admins only): company name, CVR / tax ID, billing address, contact phone, invoice e-mail, EAN number (optional).
  • Boat data (optional, M13): boat name, type, length, draft, mooring marina. You choose whether to share these.
  • Content you submit: reviews, photos, guestboard posts, marina edits.
  • Technical data: IP address, user-agent, session identifiers, log entries (kept for security and abuse prevention).
  • Marina-admin pivot data: which user manages which marina (used for authorization).

3. Legal basis

We rely on the following legal bases under GDPR / the Danish Persondataforordning:

  • Contract (Art. 6(1)(b)): account creation, premium subscriptions, invoicing, support.
  • Consent (Art. 6(1)(a)): analytics cookies, optional newsletter, optional boat profile.
  • Legitimate interest (Art. 6(1)(f)): security logs, abuse prevention, service improvement, fraud detection.
  • Legal obligation (Art. 6(1)(c)): bookkeeping retention under the Danish Bogføringslov.

4. Retention periods

  • Account data: kept until you delete your account.
  • Invoices and billing data: kept for 5 years from the end of the financial year (Bogføringsloven §10).
  • Session and security logs: 90 days, then deleted or anonymised.
  • Reviews and public content: remain published until you delete them or your account.
  • Marketing consent and audit log: retained as long as the consent is active plus 2 years for proof of consent.

5. Third-party processors

We share personal data with the following sub-processors who act on our instructions. See the subprocessors page for the full list and details.

  • Stripe Payments Europe Ltd. (Ireland) — payment processing for premium subscriptions.
  • Mailgun (Sinch) (EU region) — transactional e-mail delivery.
  • Hostinger International Ltd. — hosting and infrastructure.
  • Cloudflare Inc. — Turnstile anti-bot challenge on public forms.
  • cvrapi.dk / Erhvervsstyrelsen (Virk) — public CVR lookup for marina-admin signup.
  • Open-Meteo — weather forecast (only marina coordinates, no user data).

6. Your rights

You have the following rights under GDPR. Contact mail@nordok.net to exercise them and we respond within 30 days:

  • Access to your personal data (Art. 15).
  • Rectification of inaccurate data (Art. 16).
  • Erasure (Art. 17) — note that bookkeeping data may be retained for 5 years.
  • Restriction of processing (Art. 18).
  • Data portability — export of your data in a machine-readable format (Art. 20).
  • Objection to processing based on legitimate interest (Art. 21).
  • Withdrawal of consent at any time, without affecting prior lawful processing.

7. Complaints

If you believe our processing of your personal data is unlawful, you can complain to the Danish Data Protection Agency:

Datatilsynet
Carl Jacobsens Vej 35
2500 Valby
Denmark
Web: datatilsynet.dk

8. Changes

We may update this privacy policy. Material changes are announced on the site and, where required, by e-mail. The "Last updated" date at the top reflects the most recent revision.