Privacy policy
It is important to us to ensure that all processing of personal data is conducted in accordance with applicable data protection laws and regulations. The purpose of this Privacy Notice is to help you understand what information NODES AS (hereafter “we” or “NODES”) collects, why we collect it and how you can manage your rights. NODES will process any personal data received in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
We also provide information about the use of analytics tools and cookies on our website and how you can manage your preferences for these activities.
How we collect and use your personal data
Personal data is any information related to an identified or identifiable natural person. This includes, for example, details such as names, mailing addresses, email-addresses, telephone numbers as well as behavioural data such as orders you place on our trading platforms or the IP-address you use when you connect to our website or our trading platforms.
The types of personal data that we collect and how we use that information depends on your relationship with NODES:
Visitors of our website:
- We collect information that is transmitted by you and your device (including your IP-address) to provide you with the service you request from our website. Some information is processed only during your visit to the website, while information submitted through website forms and information collected through cookies, analytics tools and security mechanisms may be retained for a limited period to support the operation, security, maintenance and improvement of our website. Information provided through forms used to contact us or download publications may also be retained as necessary to respond to your request and manage our relationship with you. We also collect anonymous and aggregated information about visits to our website for statistical purposes. The information is used to:
- Provide you with information from our website (cf. GDPR article 6 (1) (f))
- Transmit and reply to requests made through the forms on our website used to get in contact with us (cf. GDPR article 6 (1) (f))
- Understand how users interact with and use our website (cf. GDPR article 6 (1) (f))
Registered users of our platforms:
We collect your contact information (incl. your name, email and telephone number), information about the customer you are trading under (typically your employer), account credentials and security information necessary to authenticate users and protect the trading platforms, and the device you are using to connect to our platforms as well as activities conducted on our platforms such as initiating and completing orders or managing your preferences. This may include records of orders, transactions, user actions, platform interactions, authentication events and related audit information.
The information is used to:
- Provide our services to you and the customer you are trading under (cf. GDPR article 6 (1) (b))
- Issue notifications and other important communications to you (cf. GDPR article 6 (1) (f))
- Provide information about orders and transactions to the customer you are trading under (cf. GDPR article 6 (1) (f)) and to regulatory authorities when required by law (cf. GDPR article 6 (1) (c))
- Ensure adequate security of personal data and the confidentiality, integrity and availability of the platforms
- Maintain records of orders, transactions, user actions, platform interactions and related audit information necessary to operate the trading platform, support customers, comply with legal and regulatory obligations and maintain platform security.
- Detect, prevent and investigate unauthorised access, misuse, fraud, security incidents and other activity that may affect the security, integrity or availability of our services.
Business contacts:
We collect contact information and business relationship information about individuals working for our customers, prospective customers, suppliers and other business partners when and to the extent necessary to conduct our business.
This information may include contact details, employer and role information, business communications, meeting records, customer relationship information, participation in events, account management records and other information reasonably necessary to establish, maintain and manage our business relationship with you or your organisation.
We may obtain such information directly from you, from your employer or organisation, through business meetings and interactions, at events, from customers and suppliers, or from publicly available professional sources.
The information is used to:
- Provide services to you and/or your employer, including ensuring we comply with our contractual obligations (cf. GDPR article 6 (1) (f))
- Communicate and provide relevant information to you (cf. GDPR article 6 (1) (f))
- Market events or our services in general to you, subject to your marketing preferences (cf. GDPR article 6 (1) (a) and (f))
- Maintain records in our customer relationship management, customer service and business management systems to administer and support our relationships with customers, prospective customers, suppliers and other business partners.
- Document communications, meetings, requests, commercial interactions and service-related matters relevant to our business relationship.
- Send information about events, news, products, services and business opportunities that may be relevant to your professional role, subject to applicable law and your communication preferences.
You may opt out of receiving marketing communications at any time by following the instructions included in the communication or by contacting us using the contact details provided below.
Cookies
- This website might install cookies on your computer. Cookies are small files collecting data on the use of the website in an anonymised form. Our cookies do not collect sensitive data such as your name or address.
- If you prefer to block or delete our cookies, you can control that through our cookie control functionality. Some of the functionality of our website will be lost if you delete all cookies. By not adjusting your cookie settings on the cookie control page or in your browser, you are deemed to consent to cookies according to Norwegian electronic communication act section 2-7b.
Disclosure to third parties
NODES does not disclose personal data to third parties, with the following exceptions:
- NODES may disclose information to authorities and other third parties when necessary to comply with legal obligations or to fulfil statutory rights
- When trading on NODES trading platforms, NODES may disclose orders, transactions and other relevant data to our customer (your employer/organisation)
- For pilot projects, conducted for participants to gain experience of flexibility trading, NODES may also share information with the Network Operator or other party who has commissioned the pilot.
- NODES may also disclose personal data to external service providers as data processors in accordance with section 4 below.
Use of data processors
When providing services to our customers, we may use external service providers to process personal data on our behalf as data processors. Such data processors are subject to strict requirements regarding the processing and safeguarding of personal data and may not use personal data for other purposes than providing the agreed services to NODES. In addition, the data processors must comply with specific requirements and obligations for data processors under applicable data protection law.
Examples of data processors used by NODES may include providers of cloud infrastructure, customer relationship management systems, communication, collaboration and document management services, analytics services and information technology support services. Some of these data processors may transfer data outside of the EU/EEA-area. If so, such transfers are subject to appropriate safeguards in the form of standard data protection clauses adopted by the EU commission or other transfer mechanisms recognised under applicable data protection law, cf. GDPR article 46 (2) (c) and (f).
How long we retain your personal data
Personal data is only kept for as long as necessary to achieve the purpose(s) for which they are processed. The criteria for determining the retention period includes:
- The nature of your relationship with us and how the data was collected
- The nature and sensitivity of the personal data
- The purposes for which the personal data is being used
- The existence of any legal obligations to retain the personal data
Where possible, personal data will be deleted, anonymised or securely archived when it is no longer required for the purposes for which it was collected. Certain information may be retained for longer periods were required to comply with legal, regulatory, accounting, audit, security or contractual obligations, or to establish, exercise or defend legal claims.
Your rights
If you have questions regarding our privacy practices, wish to obtain additional information regarding our processing of personal data, or wish to make a privacy-related complaint, you may contact our Privacy Officer using the details below.
Under applicable data protection laws and regulations, you have a right to:
- Be informed if your personal data is being used (“Right to Information”)
- Find out if an organization is using or storing your personal data, and to get copies of your data (“Right of Access”)
- Challenge the accuracy of personal data held about you by an organization and get your data corrected (“Right to Rectification”)
- Ask an organization to delete personal data that it holds about you (“Right to Erasure”)
- Limit the way an organization use your data (“Right to Restriction”)
- Get your personal data from an organization in a way that is accessible (“Right to Data Portability”)
- Object to the processing or use of your personal data in some circumstances (“Right to Object”)
In addition, you have a right to withdraw your consent if processing is based upon your consent (“Right to Withdraw Consent”) and to lodge a complaint with both NODES and the data protection authorities.
To exercise any of your rights, please contact us at . To facilitate the efficient handling of your rights, we ask that you are as specific as possible in your request.
Contact
NODES has designated a Privacy Officer responsible for overseeing compliance with applicable privacy and data protection requirements.
In case of queries concerning the collection, use or other processing of your personal data, including exercising of your individual rights, please contact our Privacy Officer at: