How Norraz handles personal data for the current service scope.
Trigger Check is currently available only to business customers. This notice does not claim that Swedish consumer-law review is complete because consumer purchasing is excluded from this launch.
1. Controller and contact
LingMa Konsult AB, organisation number 559087-3104, trading as Norraz, is the data controller where it determines the purposes and means of processing for the Norraz website, enquiries, Trigger Check submissions, Decision Review customer material, quotations, delivery and customer communications.
Address: Box 40008, 974 21 Luleå, Sweden.
Privacy and data-rights requests: privacy@norraz.se. Security reports: security@norraz.se.
2. Data Norraz may receive
- contact details and correspondence;
- non-sensitive decision descriptions submitted through Trigger Check;
- commercial records such as quotations, contracts and invoices;
- customer working material supplied after scope and handling requirements are agreed;
- website analytics only after explicit analytics consent;
- publication authorization or withdrawal correspondence.
Do not submit special-category personal data, confidential project material, security credentials or information about identifiable employees in the public form.
3. Proposed purposes and legal bases
Norraz expects to use personal data to respond to requests, assess product fit and capacity, prepare and perform agreed services, maintain required business records, protect the service, handle legal claims and, where separately authorized, prepare a sanitized publication.
Legal review required: the final notice must confirm the lawful basis for each purpose, including contract steps, legal obligations, legitimate interests and consent where applicable.
4. Analytics choice
Google Analytics is off by default. The analytics script is loaded only after an explicit choice to allow analytics. Rejecting analytics does not restrict website or product access. The choice can be reopened or revoked using the Privacy settings button.
The account-specific Google Analytics contract, retention, linking and transfer configuration remains unverified. No advertising purpose is approved.
5. Service providers and current status
Norraz may use service providers for website hosting, business communications, form delivery, payments, analytics, private data storage and approved AI-assisted processing.
Where personal data is disclosed to a service provider, the relevant contractual, privacy, security, retention and international-transfer requirements must be reviewed before that processing is approved.
Some provider and account-specific reviews remain open. Commercial features that depend on unresolved provider controls remain disabled or restricted until the applicable review is complete; this B2B checkout does not expand the approved data boundary.
6. Owner-approved retention targets
- general enquiries and non-customer contacts: delete or anonymize within 12 months after the last meaningful contact;
- Trigger Check submissions that are unpaid or not pursued: delete or anonymize within 90 days after submission;
- completed Trigger Check and Decision Review working material: delete or anonymize within 24 months after final delivery or contract end;
- accounting, signed contract and legal-hold records: retain separately for the applicable statutory or legal period.
These are Norraz policy targets, not statutory GDPR periods. Provider-level automation and an auditable deletion process still require verification.
7. Publication
Private working material is not published. Any client-related publication requires separate authorization and creation of a sanitized public snapshot. Authorization correspondence remains private. Withdrawal requests are assessed promptly and the public snapshot can be withdrawn through the existing publication process without exposing the underlying private record.
8. Data rights
Norraz's owner-approved service target is to acknowledge a request within five business days and provide a substantive response or completion within one month, unless a lawful extension applies. Identity information will be requested only where reasonably necessary, including when there are reasonable doubts about the requester's identity.
Send requests to privacy@norraz.se. The final legally reviewed notice must describe applicable access, correction, deletion, restriction, objection, portability and supervisory-authority rights.
9. International transfers and safeguards
Some providers may process data outside Sweden or the EEA. Norraz will not claim a verified transfer mechanism until the relevant account, contract, DPA, subprocessors and configuration have been reviewed. This remains a commercial go-live dependency.
10. Changes and approval
This notice is dated 23 August 2026. It remains subject to Swedish privacy review and must be updated when provider or processing facts change. Consumer purchasing is excluded; no completed Swedish consumer-law review is claimed.
