Effective Date: 2025-08-11
Last Updated: 2025-08-11
Wisteria Inc. ("we", "our", "us") operates the NordiQ platform, which includes NordiQ Archive - your trusted solution for secure, compliant, long-term data protection. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our NordiQ services.
The NordiQ platform is designed exclusively for business-to-business (B2B) enterprise use. While our clients are organizations, this policy also applies to individual users of those organizations who interact with the NordiQ ecosystem.
By accessing or using NordiQ services, you acknowledge that you have read and understood this Privacy Policy.
We collect the following information when you or your organization's administrator set up and use the NordiQ platform:
When you access our services, we automatically collect certain technical information to maintain security and service integrity:
When you successfully log in with 2FA, you may choose to mark your device as "trusted" to reduce the need for repeated 2FA challenges.
We use your personal and technical information to:
We process your data to operate, maintain, and improve the NordiQ platform, including:
We use your contact details to:
Under the General Data Protection Regulation (GDPR), we process your personal data based on the following lawful bases:
We process account information, authentication data, and service usage details to deliver the NordiQ platform services you have contracted with us to provide - including NordiQ Archive for secure, compliant document management.
We process IP addresses, device information, and "trusted device" identifiers to protect accounts against unauthorized access and fraud. This includes risk-based 2FA: When a login is attempted from an unrecognized IP or device, we may require additional verification to protect your account.
The "trusted device" cookie is considered a strictly necessary cookie under the ePrivacy Directive and does not require prior consent, as it is essential to reduce friction while maintaining security.
We may process and retain logs or audit trails where required by applicable laws, including data protection, financial reporting, or other regulatory requirements.
We will obtain your consent if we ever process your data for purposes not covered above, such as optional analytics or marketing communications.
Your data is stored on secure servers located in Canada, with backups maintained in the same region. We select hosting providers that comply with applicable data protection laws, including GDPR for EU clients and PIPEDA for Canadian clients.
If you are located in the European Union or another jurisdiction with data transfer restrictions, we ensure that any cross-border transfers comply with legal requirements. This may include:
We may share your data with trusted third-party service providers (subprocessors) who assist us in operating our services, such as:
We only share the minimum data necessary for the service to function, and all subprocessors are contractually bound to comply with our security and privacy requirements.
We do not sell, rent, or trade your personal data to any third parties.
We retain your personal data only for as long as necessary to provide our services and comply with legal obligations. Specifically:
We implement appropriate technical and organizational measures to protect your data, including:
In the unlikely event of a data breach affecting your personal information, we will:
You have the right to request access to the personal data we hold about you and to request correction of any inaccurate or incomplete information. To do so, please contact us using the details provided below.
Where applicable, you may request a copy of your personal data in a commonly used, machine-readable format. This enables you to transfer your data to another service provider.
You may request the deletion of your personal data, subject to any legal or contractual obligations that require us to retain certain data. Upon such request, we will securely delete your data within a reasonable timeframe.
You have the right to object to or request restriction of the processing of your personal data where applicable under law. We will consider such requests and respond accordingly.
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
To exercise any of your rights, please contact our Data Protection Officer at:
Email: general@nordiqarchive.com
We will respond to your request within the timeframe required by applicable law.
We use cookies and similar technologies to enhance the security and functionality of NordiQ Apps. The only cookies we deploy are:
Trusted Device Cookies: These contain a randomly generated identifier that helps us recognize devices where you have successfully completed two-factor authentication (2FA). This reduces the frequency of repeated 2FA prompts while maintaining account security.
These cookies are classified as strictly necessary and do not require your consent under applicable privacy laws. We do not use cookies or trackers for marketing, advertising, or analytics by default.
You can manage or delete cookies through your browser settings. However, disabling strictly necessary cookies may impair your ability to use certain security features, including trusted device recognition and 2FA convenience.
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our Data Protection Officer (DPO) at:
Email: general@nordiqarchive.com
We aim to respond to all inquiries promptly and transparently.
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service features. We will notify you of significant changes by email or via the NordiQ Apps platform.
Please review this policy periodically to stay informed of how we protect your data.