This Privacy Policy explains how Nord Nem Technologies ApS (“CloudOptify”, “we”, “us”) collects, uses, shares, and protects personal data when you visit cloudoptify.com, sign up for and use the CloudOptify platform at app.cloudoptify.com (the “Service”), or otherwise interact with us. It also explains the rights you have over your data under the EU General Data Protection Regulation (“GDPR”) and how to exercise them.
1. Who we are
The data controller for the personal data described in this policy is:
Nord Nem Technologies ApS
CVR no.: 46621549
Copenhagen, Denmark
Email: contact@nordnemtechnologies.com
2. Controller and processor — two roles
CloudOptify handles data in two distinct roles, and your rights differ depending on which applies:
- We are the controller for data about you as a person: your account and profile details, billing records, support conversations, website analytics, and marketing preferences. This policy covers that data.
- We are a processor for the cloud cost and resource data your organization connects to the Service (Azure and AWS billing data, resource metadata, tags). That data belongs to your organization; we process it only to provide the Service and only on your organization’s instructions. If you have a question about data your employer connected to CloudOptify, your employer is the controller and the right first point of contact.
3. Data we collect
Account data. When you sign up we collect your name, work email address, and company name. Authentication is handled by Microsoft Entra External ID — we never see or store your password.
Billing data. Subscriptions are processed by Stripe. We receive and store your billing contact, plan, invoices, and payment status. We do not store card numbers — those are handled entirely by Stripe.
Cloud connection data. To provide the Service, your organization connects Azure and/or AWS accounts. Connection credentials (service principal secrets, access keys, or role identifiers) are encrypted at rest and used exclusively for the access described in our Security overview — read-only analysis and, only if you enable it, automatic setup of billing exports in your environment. This data is organizational rather than personal, but resource metadata may incidentally contain personal data (for example, an email address inside a resource tag) — which we process as processor per Section 2.
Support data. If you open a support ticket or email us, we keep the conversation and any attachments you provide so we can help you and improve the Service.
Usage and log data. We collect technical logs (IP address, browser type, timestamps, pages/endpoints accessed, error events) to keep the Service secure, diagnose problems, and prevent abuse.
Cookies and similar technologies. See Section 6.
4. Why we use your data, and on what legal basis
- Providing the Service — creating and administering your account, running cost analysis, sending service emails (receipts, alerts you configure, security notices). Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Billing and bookkeeping — invoicing, payment processing, and retaining accounting records as required by the Danish Bookkeeping Act.Legal basis: contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).
- Security and abuse prevention — log analysis, rate limiting, access auditing, incident investigation.Legal basis: legitimate interest (Art. 6(1)(f)) in keeping the Service and our customers’ data safe.
- Product improvement — aggregated, privacy-respecting usage statistics to understand what works. Legal basis: legitimate interest (Art. 6(1)(f)).
- Optional analytics and marketing cookies — only if you accept them in the cookie banner. Legal basis: consent (Art. 6(1)(a)), withdrawable at any time.
- Communications you request — demo requests, sales conversations, replies to your enquiries. Legal basis: legitimate interest or steps prior to a contract (Art. 6(1)(b), (f)).
We do not sell personal data, and we do not use your data or your organization’s cloud data to train external AI models.
5. Who we share data with
We share personal data only with service providers (“sub-processors”) that help us run CloudOptify, under data processing agreements that bind them to confidentiality and GDPR-level protection:
- Microsoft Azure — hosting of the platform, databases, and encrypted storage.
- Microsoft Entra External ID — sign-in and identity management.
- Stripe — subscription payments, invoicing, and receipts.
- Transactional email delivery — sending the service emails described above.
- Analytics — privacy-focused, cookieless site analytics; plus optional analytics/marketing tools that load only with your cookie consent.
We may also disclose data where required by law, to enforce our Terms of Service, or as part of a merger, acquisition, or asset sale (in which case this policy continues to apply to your data).
6. Cookies
The website uses a consent banner that separates cookies into three categories:necessary (always on — they store your cookie choices and keep the site working), analytics, and marketing. Analytics and marketing cookies are set only after you opt in, and you can change or withdraw your choices at any time via the cookie settings link in the banner. Our core site analytics are cookieless and do not track you across sites.
7. International transfers
The Service is hosted on Microsoft Azure. Some sub-processors (for example Stripe) may process data in the United States or other countries outside the EU/EEA. Where that happens, transfers are protected by an adequacy decision (such as the EU–US Data Privacy Framework) or the European Commission’s Standard Contractual Clauses, together with additional safeguards where appropriate.
8. How long we keep data
- Account and organization data — for as long as your account is active.
- After cancellation — cloud connection credentials (secrets and access keys) are purged immediately when a subscription ends. Remaining organization data enters a limited grace period so you can reactivate, after which it is permanently deleted. We confirm the timeline by email as part of offboarding.
- Invoices and accounting records — 5 years from the end of the financial year, as required by the Danish Bookkeeping Act.
- Support tickets and logs — kept only as long as needed for support, security, and troubleshooting purposes, then deleted or anonymized.
9. How we protect data
Security measures include encryption in transit (TLS) and at rest, encrypted storage of cloud credentials, strict per-tenant data isolation, least-privilege access controls, scoped and revocable API tokens, and audited, approval-gated support access to customer environments. A fuller description is on our Security page. No system is perfectly secure; if we become aware of a personal data breach affecting you, we will notify you and the relevant authority as required by the GDPR.
Support access to your environment. Our support staff cannot see your organization’s data by default. If a support case requires it, a staff member submits an access request stating the reason and duration; access is granted only after one of your organization’s approvers explicitly approves it, is time-limited, and can be revoked by you at any time. Every step — who requested, who approved, when, and what was accessed — is recorded in an audit log visible to your organization, and unactioned requests expire automatically.
10. Your rights
Under the GDPR you can, at any time:
- request access to the personal data we hold about you;
- have inaccurate data rectified;
- request erasure (“right to be forgotten”);
- request restriction of processing;
- receive your data in a portable format (data portability);
- object to processing based on legitimate interests; and
- withdraw consent for consent-based processing (such as optional cookies) without affecting prior processing.
To exercise any of these rights, email:hello@cloudoptify.com. We respond within one month. You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) or your local supervisory authority.
11. Children
CloudOptify is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.
12. Changes to this policy
We may update this policy as the Service evolves. Material changes will be announced on this page (and, for significant changes affecting registered users, by email) with an updated “Last updated” date. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy.
13. Contact
Questions about privacy or this policy:hello@cloudoptify.com. Security reports: security@cloudoptify.com.