Nordic BioNet
  • English (EN)
  • Norsk (NO)
  • Nederlands (NL)
  • Français (FR)
  • What We Do
  • Contact
    • English (EN)
    • Norsk (NO)
    • Nederlands (NL)
    • Français (FR)
  • Log In

Privacy Policy

Last updated: 2026-09-20

1. Who is responsible for your data

Nordic BioNet is in the process of becoming a limited company in Norway. Until that registration is complete, the two founders, Eduard Poort, Walter Berkouwer, are responsible for the personal data described in this policy. They are the data controllers.

  • Contact: privacy@nordicbionet.com

We have not appointed a data protection officer. Our activity does not require one under the GDPR.

2. What this policy covers

This policy applies to the visitors of this website - the people who read our pages and who write to us through the contact form.

It does not apply to the data we hold about partners and suppliers in the course of our business. If you are a contact at such a company and want to know what we hold, write to the address above and we will answer.

3. What we collect, and why

3.1 Messages you send through the contact form

When you send us a message through the contact form, we receive your name, your email address, the subject you have selected, and the text of the message. The form also records the language of this site at the moment you write, and the date and time of your message.

Purpose: to read your message, to answer it, and to follow up if it leads to a business relationship.

Legal basis: Article 6(1)(b) of the GDPR, when we act on a request you have made before a contract, and otherwise Article 6(1)(f), our legitimate interest in answering questions about our work.

How long we keep it: we store a message for twelve months after we have last dealt with you, after which we delete it. A message that becomes part of a business relationship is kept for as long as that relationship runs and for the period Norwegian accounting law requires for business records.

Spam protection: the form carries a hidden field and a timing check to detect automated submissions. Neither collects any data about you, and neither sends anything to a third party.

3.2 Your visits to our pages

We record which page is opened, and when. We also note the browser that opens the page and, if you arrived from another page, its address. We do this on our own servers.

We do not store your IP address. We do not store the session identifier of your browser. We do not store anything that lets us recognise you on a later visit.

Purpose: to see which pages are read, so we can tell whether the work on this site is worth continuing.

Legal basis: Article 6(1)(f) of the GDPR - our legitimate interest in knowing whether our site works and is read.

How long we keep it: twelve months. A scheduled task deletes the older records automatically.

We do not use Google Analytics. We do not use any other external analytics service. We do not follow visitors across websites.

3.3 Server logs

The web servers that host this site, and the reverse proxy in front of them, note every request that reaches them: your IP address, the date and time, the address requested, the response code, and the browser that sent the request.

Purpose: to operate the site, to find faults, and to detect and respond to attacks.

Legal basis: Article 6(1)(f) of the GDPR - our legitimate interest in keeping the site working and safe.

How long we keep it: the proxy logs are rotated weekly and five weeks' worth are kept. The application logs are capped by size and are replaced as they grow. In both cases the older copies are removed automatically.

3.4 What we do not do

  • We do not use third-party advertising or analytics tracking.
  • We do not sell or rent personal data.
  • We do not make automated decisions about you that have legal or similarly significant effects.
  • This site loads no third-party content: scripts, styles and icons are hosted on our own server, so no other company sees your request when you read these pages.

4. Cookies

We set a single technical cookie, named "session", which keeps the contact form working and protects it against cross-site request forgery. It is gone when you close your browser.

We do not set advertising, analytics, or profiling cookies. No third party sets a cookie through our site. Because a single technical cookie is all we use, we do not ask for your consent for cookies. You can refuse or delete cookies through your browser, in which case the contact form may stop working.

5. Who else can see your data

Nobody, unless the law asks us to. This site runs on our own hardware. We have no third-party host, no external analytics service, and no external spam-protection service. When a public authority requires a disclosure we make it - otherwise the data stays with us.

6. Where your data is held

Our servers are located in Israel. On 31 January 2011 the European Commission adopted Decision 2011/61/EU, which found that Israel offers an adequate level of protection for personal data.

Your data therefore receives, in Israel, a level of protection that the European Commission has judged equivalent to the protection in the European Union. No additional transfer safeguard is required.

7. Your rights

Under the GDPR you have the right to ask us to:

  • confirm whether we hold data about you, and to receive a copy of it;
  • correct data that is inaccurate or incomplete;
  • delete your data;
  • restrict the processing we are doing on it;
  • carry your data to a new controller - a portable, interoperable format;
  • object to processing that we do on the basis of our legitimate interest. Where you object, we stop unless we can demonstrate a reason that overrides your interests and your rights.

To exercise one of these rights, write to privacy@nordicbionet.com. We will answer within one month.

If you are not satisfied with our answer, you may bring the matter to your supervisory authority. In Norway this is the Datatilsynet, and their website is datatilsynet.no.

8. Security

We serve this site over HTTPS. We protect our forms against cross-site request forgery. We do not store visit IP addresses in our analytics. Access to the message database is limited to the staff who need it. No system is fully secure, and we cannot guarantee that every transmission across the internet is safe from interception.

9. Changes to this policy

We may change this policy. The date at the top shows the current version. Where a change affects what we do, and in which way, we will say so on this page.

10. Contact

Nordic BioNet
privacy@nordicbionet.com

© 2026 Nordic BioNet. All rights reserved. · Privacy Policy · Terms of Use