LAST UPDATED 26.01.2026
Privacy Policy and Notice
North Propulsion ApS
About this policy
1.1 This Privacy Policy provides information on how North Propulsion ApS, Danish Company reg. no. (CVR): 43802194, (herein: “North Propulsion”, “we”, “us”, “our”) use your personal data and the measures we have put in place in order to safeguard our customers’, contractors’, suppliers’, vendors’ and other third parties’ personal data in accordance the General Data Protection Regulation (2016/679 of 27 April 2016) (the “GDPR”).
Personal data
2.1 Categories of personal data
2.1.1 Personal data is any information about a natural person from which that person can be identified. North Propulsion may process different kinds of personal data, in particular:
- Identity Data, including first name, last name, username or similar unique identifier, title, date of birth and gender.
- Contact Data, including billing address, delivery address, email address and telephone numbers or similar contact data.
- Financial Data, including bank account and payment card details.
- Transaction Data, including details about payments to and from you and other details of products and services you have purchased from us.
- Technical Data, including internet protocol (IP) address, login data, browser type and version, time zone location, operating system and platform, user ID, MAC ID and other technology on the devices used to access our services.
- Purchaser Data, including purchases or orders made by you, services you have requested, your interests and your preferences.
- Other IT-related Data, including electronic logs regarding persons use of IT-resources, marketing and communications data, analytics, tracking data on interactions with North Propulsion’s services and our website.
2.1.2 North Propulsion does not collect or process any Special Categories of Personal Data about you without your explicit consent (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, or genetic information, biometric data for identification purposes, or information about criminal offences), cf. GDPR, article 9(2)(a).
2.1.3 If you enter into an employment relationship with North Propulsion, we may, however, in certain cases process Special Categories of Personal Data about you, if the processing is necessary for the purpose of carrying out obligations in the field of employment, social security or social protection as stipulated by law, cf. GDPR, article 9(2)(b). Employees may find additional information relating hereto in North Propulsion’s internal GDPR Policy.
2.2 Purposes
2.2.1 Any processing of personal data by North Propulsion pursuant to this Privacy Policy has the following purposes:
- Administration of customers, contractors, suppliers, vendors and other third parties which enter a commercial relationship with North Propulsion
- IT administration and information security administration
- To fulfill obligations in commercial relationships, including placement of orders, delivery of products, completing payments, and providing digital services related hereto
- Administration of CRM-information (Customer Relationship Management)
- Support the recruitment process (e.g. registering applications and CVs etc.)
Legal basis for processing
3.1 We only process personal data when there is a legal basis to do so in accordance with the GDPR. Depending on the specific circumstances, the processing of personal data is done on the following legal basis:
3.1.1 In accordance with GDPR, article 6(1)(a), when the processing of is based on explicit consent of the data subject. Such consent may be withdrawn at any time by contacting us via the contact details provided at the end of this Privacy Policy.
3.1.2 In accordance with GDPR, article 6(1)(b), when the processing is necessary for the performance of a contract to which the data subject is a party, or when the processing is necessary in order to take steps at the request of the data subject prior to entering into a contract.
3.1.3 In accordance with GDPR, article 6(1)(c), when the processing is necessary to comply with applicable legislation, e.g. disclosure to the Danish tax authorities for the purpose of tax withholdings, or in connection with KYC and credit checks if you are a customer or prospective customer.
3.1.4 In accordance with GDPR, article 6(1)(f), when the processing is necessary for the purposes of the legitimate interests where such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data in accordance with the GDPR.
3.2 In Schedule 1 to this Privacy Policy you will find particular processing examples which illustrate how we determine the purposes and legal basis for processing different types of personal data.
Data subjects’ rights
4.1 As a data subject, you have a number of rights according to the GDPR, which you may invoke at any time, free of charge, by contacting us pursuant to Section 10 of this Privacy Policy. These rights include:
4.1.1 The right of access (GDPR, article 15). All data subjects have the right to obtain and access the personal data that we process about them, provided, however, that such right to access is not restricted by legislation, protection of other persons’ privacy and consideration for our business practices, know-how, business secrets and internal assessments.
4.1.2 The right of rectification (GDPR, article 16). All data subjects have the right to have any inaccurate personal data about them rectified, with the restrictions that follow from legislation.
4.1.3 The right to erasure (GDPR, article 17). All data subjects have the right, in certain circumstances, to have personal data relating to them be erased before our usual time limit for erasure.
4.1.4 The right to restrict processing (GDPR, article 18). All data subjects have the right, in certain circumstances, to restrict the processing of their personal data. By invoking the right to restriction, we may only process this personal data for purposes of establishing, exercising or defending legal claims or protecting a natural person or important public interest, or if the data subject consents to said processing.
4.1.5 Right to data portability (GDPR, article 20). All data subjects have the right to receive personal data that they have provided us with in a machine-readable format. This right applies to personal data processed only by automated means and on the basis of consent or of fulfilling a contract.
4.1.6 The right to object (GDPR, article 21). All data subjects have the right to object to the processing of personal data based on legitimate interests. For objections to processing for other purposes, we will conduct a legitimate interest balancing test and consider whether to support the objection.
Disclosure of personal data
5.1 In compliance with this Privacy Policy, we may disclose your personal data to any of our employees, officers, insurers, professional advisers, agents, suppliers or subcontractors, if relevant in their work and insofar as reasonably necessary for the purposes set out in this Privacy Policy.
5.2 We also disclose personal data as we believe to be necessary and appropriate:
- To the extent that we are required to do so by law;
- In connection with any ongoing or prospective legal proceedings; or
- In order to establish, exercise or defend our rights (including providing information to others for the purposes of protecting our legal rights, privacy, safety or property, and that of our affiliates, you or others).
5.3 Except as provided for in this Privacy Policy, we will not provide your personal data to third parties.
Data transfers outside the EU/EEA
6.1 At North Propulsion, all processing of personal data is conducted exclusively within the EU/EEA. This ensures that all personal data remains subject to the GDPR and the high standards of data security and individual rights it entails.
6.2 As of now, we only engage subcontractors and data processors that guarantee data processing within the EU/EEA, and we have implemented technical and organizational measures to ensure that personal data is not transferred to third countries.
6.3 Should a need for transfers to third countries arise in the future, such transfers will occur solely on the basis of a valid transfer mechanism under GDPR, Chapter V, and only following a prior assessment and update of this Policy. We continuously follow the guidelines and recommendations of the Data Protection Authority to ensure ongoing lawful and secure processing.
Erasure and retention of personal data
7.1 We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected said data for, including the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect of our relationship with you.
7.2 To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
Data security
8.1 We have technical and organizational measures in place to protect personal data from unlawful or unauthorized destruction, loss, change, disclosure, acquisition or access. North Propulsion will evaluate the existing security measures on an ongoing basis.
8.2 Personal data is held securely using a range of security measures including, as appropriate, physical measures such as locked filing cabinets and servers with limited access located in secured facilities, technical security arrangements such as restricted access through approvals and passwords, as well as policies, procedures and guidance to maintain these arrangements taking into account the risk to the rights and freedoms of data subjects.
Data breach procedure
9.1 We have a duty to protect any personal data processed pursuant to this Privacy Policy. Therefore, in the event of a data breach, North Propulsion and its employees will comply with the following:
9.1.1 In the event of a data breach, we may have an obligation to report it to the Danish Data Protection Authority within 72 hours. The minimum requirements for reporting such data breach are laid out in GDPR, article 33, and will be strictly abided by.
9.1.2 In the case that the data breach causes a high risk for any affected data subjects, we will notify the individuals in question in addition to the Danish Data Protection Authority. In such cases, the minimum requirements laid out in GDPR, article 34, will be strictly abided by.
Contact
10.1 Please contact North Propulsion via e-mail at privacy@northpropulsion.com if:
- If you have any questions, comments or complaints relating to this Privacy Policy or our processing of personal data; or
- If you are a data subject and wish to invoke one or more of your rights as described in this Privacy Policy.
Complaints procedure
11.1 All data subjects have the right to claim that North Propulsion are not complying with the Privacy Policy or the GDPR. Any such complaint will be handled fairly, effectively and in a timely manner and can be made by contacting North Propulsion pursuant to Section 10 above.
11.2 Apart from complaining directly to North Propulsion, you are also entitled to complain to the Danish Data Protection Authority (“Datatilsynet”). The Authority’s contact information for the purpose of lodging a complaint can be found on their website, www.datatilsynet.dk/english/contact-us.
Changes to this policy
12.1 North Propulsion reserves the right to, at its sole discretion, update and amend this Privacy Policy. If we consider any such changes significant, you will receive prior notice of such changes.