Privacy
Privacy policy
How Kaada Nordic MarTech (Org nr. 936 289 835) collects, uses and protects information when you use PressImpact. Last updated 3 February 2026.
Who is the data controller
The data controller for PressImpact is Kaada Nordic MarTech.
Organisasjonsnummer: 936 289 835 · Registered in Oslo, Norway.
For any privacy question, email privacy@nordicmartech.com. We respond within 30 days.
What personal data we collect
PressImpact is designed to work with the minimum viable personal data. We collect only what is necessary to deliver the service:
- Email address you enter to receive a report
- Campaign inputs you type into the calculator
- Language and currency preferences you set
- Standard technical metadata (IP, browser user-agent) that arrives with every request
We do not use tracking pixels, third-party analytics cookies, or advertising trackers.
A single first-party cookie remembers your language and currency on this device. That's it.
How we use the data
Campaign inputs are used to compute your ROI report and generate the executive summary.
Your email is used only to deliver the report you requested and — if you opt in — to send occasional product updates.
Technical metadata keeps the service secure and helps debug errors.
We do not sell, rent, or share your data with advertisers.
Legal basis (GDPR)
- Contract (Art. 6(1)(b)) — delivering the service you requested.
- Legitimate interest (Art. 6(1)(f)) — keeping the service secure and improving accuracy.
- Consent (Art. 6(1)(a)) — optional product-update emails, withdrawable via the unsubscribe link in every message.
Retention
Reports and their inputs are retained for up to 90 days from creation, then automatically expire.
After expiry the shareable URL returns a 410 response.
- Emails used for a single report: purged 30 days after that report expires.
- Log data: rotated after 30 days.
- Product-update subscribers: retained until you unsubscribe.
Sub-processors
A small set of EU-hosted sub-processors runs the service:
- MongoDB Atlas (Frankfurt) — report storage
- Brevo (Paris) — transactional email
- European Central Bank public API — currency reference rates
- Anthropic — AI narrative engine (US, under Standard Contractual Clauses)
- Stripe — payments
Data processing agreements are in place where required by GDPR.
Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you
- Correct or update it
- Have it deleted
- Restrict or object to processing
- Withdraw any consent you have given
- Lodge a complaint with a supervisory authority
To exercise any of these, email privacy@nordicmartech.com with the email address associated with your reports.
In Norway, the relevant supervisory authority is Datatilsynet (datatilsynet.no).
International transfers
Primary storage and processing happens inside the EU/EEA.
Some sub-processors (notably the AI narrative engine) process data in the United States under Standard Contractual Clauses approved by the European Commission.
We minimise the data sent to those processors — the AI narrative engine only receives your computed numbers, not your email address.
Changes to this policy
We update this page if we materially change how personal data is handled.
The latest version is always available at this URL.
Material changes: subscribed users are notified by email at least 14 days in advance.