Privacy Policy
This policy explains how Norrsyn AI handles personal data across our website, public AI demonstrations, business outreach, client projects, and continuing support.
Who we are
Norrsyn AI Handelsbolag, trading as Norrsyn AI, is an AI automation agency based in Gothenburg, Sweden. We design and maintain voice agents, messaging agents, lead operations, booking workflows, integrations, public demonstrations, and related automation systems for service businesses.
For personal data that we determine the purpose and means of processing, Norrsyn AI is the data controller.
Scope and our different roles
This policy applies to people who visit our website, use a public demo or free tool, submit a form, respond to our business outreach, book a call, communicate with us, or participate in a client project.
When Norrsyn is the controller
We act as controller for our website operations, business contacts, outreach, sales, project administration, security, billing, and support.
When Norrsyn is a processor
When we handle calls, messages, leads, bookings, recordings, transcripts, or customer records on behalf of a client, the client normally decides why and how that data is used. In that situation, the client is the controller and Norrsyn acts as its processor or service provider under the applicable agreement and documented instructions.
If you interacted with an agent operated for one of our clients, contact that business first about your data. We will assist the client where required.
Personal data we handle
Website visitors and prospects
- name, business name, job role, work email, phone number, location, and preferred contact method;
- information submitted through forms, email, social media, booking pages, discovery calls, or other communications;
- business needs, call-handling challenges, requested services, budget or timing information, and sales notes;
- website activity, cookie choices, IP address, browser and device details, timestamps, referral information, and security logs.
Public demos and free tools
- voice audio, speech transcripts, text messages, scenario selections, and conversation events;
- contact or booking details that you choose to enter;
- session identifiers, verification results, usage limits, technical logs, and abuse-prevention signals;
- calculator inputs and results where those inputs can be connected to you or your business contact record.
Clients and project participants
- contract, billing, project, support, and stakeholder contact information;
- business rules, knowledge-base content, services, schedules, service areas, policies, escalation contacts, and approved integration details;
- access records, test results, incident reports, change requests, handover records, and support communications;
- client-controlled call, message, lead, booking, and customer data processed through the delivered system.
Please do not submit passwords, payment-card details, government identifiers, medical information, or other highly sensitive personal data through a public demo or general contact form.
Where personal data comes from
We receive personal data directly from you when you contact us, use a form, book a call, participate in a demo, communicate during a project, or use a delivered system.
For business outreach, we may obtain limited professional contact information from company websites, business directories, social profiles, public records, referrals, or business-data providers. We use this information only for relevant business-to-business communication and keep it linked to the source where practical.
Clients may also provide personal data about their employees, contractors, customers, or prospective customers when necessary for a project. Clients are responsible for having an appropriate legal basis and giving required notices for that data.
Why we use data and our legal bases
To answer enquiries, run discovery, prepare demos, scope work, create offers, and arrange calls. We rely on steps requested before a contract and our legitimate interest in conducting business.
To onboard clients, configure systems, test integrations, monitor performance, provide support, invoice, and maintain records. We rely on contract performance, legitimate interests, and legal obligations.
To provide requested interactions, create short-lived sessions, prevent abuse, and improve reliability. We rely on the requested service and our legitimate interests in secure product demonstration.
To contact relevant organisations about services that may fit their operations. We rely on legitimate interests. You can object or opt out at any time.
To authenticate access, detect misuse, investigate incidents, enforce terms, protect systems, and meet legal duties. We rely on legitimate interests and legal obligations.
Where required, we rely on consent for non-essential cookies, analytics, or marketing communications. Consent can be withdrawn at any time.
Public AI demos and voice data
Our public demonstrations may process voice, text, scenario choices, and technical data through Norrsyn systems and third-party AI or communications providers. Voice may be converted to text so the agent can understand and respond.
If a feature records or retains audio or a transcript beyond the active session, we will provide an appropriate notice where required. Demo interactions may be monitored to investigate failures, prevent abuse, control costs, and improve the demonstration.
Public demos are evaluation tools. Do not use them for emergencies, regulated advice, confidential business information, or sensitive personal data. Demo businesses, people, bookings, and handoffs may be fictional.
Client projects and delivered agents
Project-specific processing is defined in the applicable agreement, scope of work, data-processing terms, intake documents, and approved system configuration. These documents may set out the categories of data, subprocessors, retention rules, security measures, handoff conditions, and deletion or return requirements.
We process client-controlled data only as needed to deliver, test, support, secure, and maintain the agreed service. We do not use one client’s confidential customer data to market another client or to build unrelated contact lists.
Clients remain responsible for informing their callers and users, selecting lawful collection fields, configuring retention, handling rights requests, and obtaining any consent required for call recording or other regulated processing.
Cookies, verification, and analytics
We may use essential cookies or local storage to operate the website, remember security and consent settings, enable forms or demos, and maintain a session. These technologies are necessary for requested functionality.
We may also use optional analytics or marketing technologies. Where consent is required, these technologies remain disabled until you choose to allow them. You can revisit your choices through the website’s cookie controls.
Security providers, including bot-verification services, may process IP address, browser, device, interaction, and risk information to distinguish legitimate visitors from automated abuse.
Who receives personal data
We share personal data only when necessary for the purposes described in this policy. Recipients may include:
- website hosting, content-management, security, consent-management, and bot-verification providers;
- voice, telephony, transcription, AI-model, messaging, and communications providers;
- calendar, email, CRM, spreadsheet, automation, notification, database, and cloud-infrastructure providers selected for a project;
- payment, accounting, legal, insurance, and professional advisers;
- a client for whom we operate an agent or workflow;
- authorities or other parties where disclosure is required by law, needed to protect rights and security, or connected to a business reorganisation.
Provider access is limited to what is reasonably necessary. Providers may apply their own privacy notices when they act as independent controllers. We do not sell personal data.
International transfers
Some service providers or project integrations may process data outside Sweden, the EEA, or the country where the person is located. When EEA personal data is transferred to a country without an adequacy decision, we use an appropriate transfer mechanism where required, such as the European Commission’s Standard Contractual Clauses, together with supplementary safeguards where appropriate.
How long we keep data
We keep personal data only for as long as necessary for the relevant purpose, including to provide services, manage the relationship, resolve disputes, maintain security, and meet accounting or other legal obligations.
- Enquiries and outreach: kept while the opportunity remains relevant, then deleted, anonymised, or placed on a limited suppression list where needed to respect an opt-out.
- Demo data: generally kept for a limited period based on session, security, troubleshooting, and provider settings. A project-specific demo may use different documented rules.
- Client project records: kept during the relationship and afterwards where necessary for support, contractual records, legal claims, accounting, or compliance.
- Client-controlled operational data: retained according to the client’s instructions, the applicable agreement, and the configured systems.
- Security logs: retained for a limited operational period unless an incident requires longer preservation.
When data is no longer required, we delete it, anonymise it, or securely isolate it until deletion is technically completed.
Security
We use technical and organisational measures appropriate to the size and risk of the processing. Measures may include encrypted connections, restricted access, role separation, scoped credentials, secret management, logging, rate limits, verification, backups, testing, incident handling, and documented rollback procedures.
No online service is completely secure. Clients are responsible for protecting credentials they control, reviewing access, approving business rules, and promptly telling us about suspected misuse or security incidents affecting a delivered system.
Your data-protection rights
Depending on the law that applies, you may have rights to information, access, correction, deletion, restriction, portability, and objection. Where processing is based on consent, you may withdraw consent without affecting earlier lawful processing.
You may object at any time to direct marketing. To opt out of outreach, reply to the message or email info@norrsynai.com. We may keep minimal suppression information so we do not contact you again by mistake.
We may need information to verify your identity before completing a request. Rights can be limited in some circumstances, including where data must be retained by law or is needed to establish, exercise, or defend legal claims.
If Norrsyn processes data only for a client, we may direct your request to that client and assist them under their instructions.
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection, IMY, or another competent supervisory authority. Information about IMY is available at imy.se.
AI, routing, and automated processing
Our systems may use AI or rules to understand a request, produce a response, classify intent, qualify a lead, select a workflow, route a message, or suggest a next action. These outputs can be inaccurate and should be reviewed where they affect an important business or personal decision.
Norrsyn does not use website or demo data to make decisions based solely on automated processing that produce legal or similarly significant effects about individuals. A client using a delivered system is responsible for deciding whether its own use involves such processing and for providing any required information and safeguards.
Children
Our website, demos, and services are intended for businesses and adults. They are not directed to children. Do not intentionally submit a child’s personal data through our public features. Clients whose services involve children must discuss suitable safeguards with us before implementation.
Changes to this policy
We may update this policy when our services, providers, security practices, or legal obligations change. The revised version will show a new last-updated date. We may provide additional notice when a change is material and it is appropriate to do so.
Contact us
Questions, objections, and data-rights requests can be sent to:
Norrsyn AI HandelsbolagTrading as Norrsyn AI
Organisation number: 969803-1664
Postal address: Lisa Sass Gata, Hisings Backa, Gothenburg, Sweden - 422 45
Gothenburg, Sweden
Email: info@norrsynai.com
