Legal
Privacy policy
Draft – this text has not yet been reviewed by a lawyer and may change before launch. Placeholders are shown in [square brackets].
Last updated
1. Who is responsible
The controller for the personal data described here is [Company Name AB], corporate identity number [xxxxxx-xxxx], [Street address, postcode, city], Sweden.
For anything to do with your personal data, email privacy@nadirsignal.com.
2. What we collect
When you join the waitlist we store:
- your email address (required);
- your trading experience, if you choose to give it;
- campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content) if you reached the site through a tagged link;
- the time you signed up;
- the version of the consent text you agreed to.
We do not store your IP address in the waitlist database. We do not buy data about you or combine the waitlist with other sources.
3. Why, and on what legal basis
We use your email address to tell you when Nadir launches and to send you information about the launch. Trading experience and campaign parameters help us understand who is interested and which channels work.
The legal basis is your consent (Article 6(1)(a) GDPR). You can withdraw it at any time by emailing privacy@nadirsignal.com or by using the unsubscribe link in our emails. Withdrawing does not affect processing that took place before.
4. How long we keep it
We keep your data until you withdraw your consent or ask us to delete it, and no longer than [12 months after launch – to be decided]. After that it is deleted. Backups of the database are kept for at most 14 days.
5. Server logs
Like most websites, our web server writes technical access logs: time, requested address, status, browser type and a shortened IP address (the last part is removed). We use them to keep the service secure and to fix errors, based on our legitimate interest (Article 6(1)(f) GDPR). The logs are deleted automatically after 14 days.
To stop abuse, the server counts requests per visitor for a few minutes. That count exists only in memory and is never stored.
6. Analytics
Only if you allow it, we count page views with our own analytics on our own server. No cookies, no identifiers, no third parties. For each day we store the page and the domain of the website that linked to it – nothing that identifies you. You can change your choice at any time under “Analytics settings” at the bottom of every page.
8. Who can access the data
The data is stored on a server rented from Hetzner Online GmbH, Germany ([server location, e.g. Falkenstein or Nuremberg, Germany / Helsinki, Finland]), which acts as our data processor under a data processing agreement. The data does not leave the EU/EEA. We do not sell your data or share it with anyone else.
To send the launch email we may use an email service provider. It will be named here before it is used.
9. Your rights
Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw your consent. Email privacy@nadirsignal.com and we will reply within one month.
10. Complaints
If you think we handle your personal data incorrectly, please contact us first. You also have the right to lodge a complaint with the Swedish supervisory authority:
Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm, Sweden
www.imy.se · imy@imy.se
11. Security
All traffic is encrypted with HTTPS. The server is hardened, only reachable through a firewall and administered with key-based login only. The waitlist can only be read from the server itself – there is no admin page on the web.
12. Changes
If we change this policy we update the date above. If a change affects how we use your email address, we will tell you by email before it takes effect.