Legal
Privacy Policy
What we collect when you process payments through Nord, why we need it, who else ever sees it, and how you get it back or get it erased.
last updated · 12 september 2026
DATA
What we collect
Account details you give us at onboarding, transaction metadata we process on your behalf, and technical logs from the API edge. Full card numbers never touch our own systems.
USE
Why we process it
To route and settle payments, score risk in the authorization path, meet anti-money-laundering duties, and keep the service available. We do not sell personal data and we do not use it to train models for anyone else.
BASIS
Our lawful basis
Contract performance for anything you asked us to do, legal obligation for financial record keeping, and legitimate interest for fraud prevention and platform security.
SHARE
Who else sees it
Acquirers and card networks that must receive the transaction, cloud and monitoring vendors bound by written processing terms, and regulators when the law compels disclosure. Nobody else.
KEEP
How long we hold it
Transaction records for the period financial regulation requires, typically ten years. Technical logs for ninety days. Account data until you close the account, then only through any residual retention duty.
MOVE
Where it lives
Data stays in the region you choose at onboarding. Transfers outside it happen only under standard contractual clauses or an adequacy decision, and the route is listed in your data processing agreement.
RIGHTS
What you can ask for
Access, correction, deletion, portability, and objection to processing. Ask through the address below and we answer inside thirty days without charging you for it.
COOKIES
Cookies and tracking
Strictly necessary cookies for session and fraud checks are always on. Analytics cookies run only after you accept them, and you can withdraw that consent at any time from the footer.
Questions about your data?
A named person answers inside thirty days, at no charge, in the language you wrote in.