Last updated: 23 September 2026
This Privacy Policy explains how Nabto ApS, CVR number 30708059, Åbogade 15, 8200 Aarhus N, Denmark ("Nabto", "we", "us", "our") collects and processes personal data when you use the Nabto platforms (Nabto Edge, Nabto WebRTC and Nabto 4), including our cloud console at console.cloud.nabto.com (together, the "Service"), whether you sign up online or contract with us under an Order Form, and when we bill and support you as our customer.
This policy covers the Service. For our public marketing website, see the separate Website Privacy Policy at https://downloads.nabto.com/assets/legal/website-privacy-policy.html.
The Service involves two different roles and your rights depend on which applies:
The role follows the purpose, not the vendor or the tool. Data about your account users, your account and your use of the Service that we process in order to administer, bill, secure and improve the Service is controller data. Data of your End Users that we process in order to deliver, relay and troubleshoot connectivity, including when you send it to us in a support request, is processor data under the DPA.
If you are unsure which role applies to a given set of data, contact us at privacy@nabto.com.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and administering your account | Performance of a contract where you are our customer as a natural person (Art. 6(1)(b)); our legitimate interest in administering the contract with your employer or principal where you act for a company (Art. 6(1)(f)) |
| Providing, maintaining and securing the Service | Performance of a contract / legitimate interest (Art. 6(1)(b) / (f)) |
| Measuring usage and billing you | Performance of a contract where you are our customer as a natural person (Art. 6(1)(b)); our legitimate interest in administering the contract with your employer or principal where you act for a company (Art. 6(1)(f)) |
| Processing payments | Performance of a contract where you are our customer as a natural person (Art. 6(1)(b)); our legitimate interest in administering the contract with your employer or principal where you act for a company (Art. 6(1)(f)) |
| Keeping accounting and tax records | Legal obligation (Art. 6(1)(c)) |
| Detecting and preventing fraud and abuse | Legitimate interest (Art. 6(1)(f)) |
| Service-related and (with consent where required) marketing communications | Legitimate interest / consent (Art. 6(1)(f) / (a)) |
The legitimate interests we rely on above are administering and billing the contract, securing the Service and communicating with the customer's designated contacts.
4.1 If you pay by card, we use Stripe, Inc. and its affiliates ("Stripe") to process payments. When you enter payment details, they are provided directly to Stripe; we do not receive or store your full card number.
4.2 We receive limited information from Stripe needed to manage your subscription and billing, such as the card brand, last four digits, expiry, payment status and billing address.
4.3 Stripe processes your data as its own controller for certain purposes (such as fraud prevention and regulatory compliance) under its own privacy policy at https://stripe.com/privacy.
4.4 If you pay by invoice, we process your billing contact details and remittance data in our invoicing and accounting systems. No card data is involved.
We share personal data with:
We do not sell your personal data.
Some sub-processors may process personal data outside the EU/EEA, including in the United States. Where this occurs, we rely on an appropriate transfer mechanism such as the EU Standard Contractual Clauses or the EU-US Data Privacy Framework. You may request details of the safeguards by contacting us.
| Data | Retention | Trigger |
|---|---|---|
| Account and identity data | 30 days, then deleted | Closure of the Account or expiry of the Order Form; on a switch under the Terms of Service the 30 days start when the transition period ends. This matches the retrieval period in the Terms of Service. |
| Contract and order data | The term of the Agreement and three years after it | Expiry or termination of the Agreement. Three years is the general limitation period for claims under the Danish Limitation Act (forældelsesloven); we keep a record longer only while a claim is pending or another law requires it. |
| Billing, invoice and accounting records | Five years | The end of the financial year the record belongs to, under the Danish Bookkeeping Act. |
| Authentication logs and audit logs | 13 months | The date of the logged event. |
| Connection and relay metadata used for billing | The term of the Agreement, then deleted with the Account data | The same trigger as the Account and identity data. |
| Diagnostic logs (request traces, error logs and TURN session logs containing network addresses) | 180 days | The date the log entry is written. |
| Aggregated usage metrics without personal data | 13 months | The date of the measurement. |
| Support communications | Three years | Closure of the ticket. |
| IP-derived approximate location in operational notifications | For as long as the notification is retained in our messaging tool, at most 12 months | The date of the notification. |
Backup copies expire within 35 days of the deletion of the live data. If you ask us to delete data earlier, we carry out the deletion in the live systems without undue delay and the backup copies expire on that cycle.
Data we process as your processor is retained and deleted in accordance with the DPA and your instructions.
We apply technical and organizational measures appropriate to the risk, including encryption in transit, access controls, authentication safeguards, logging and regular review. No system is completely secure and we cannot guarantee absolute security.
Where Nabto is the controller, you have the right to:
Some data, such as accounting records, must be retained by law and cannot be erased on request until the retention period ends.
To exercise your rights, contact us at privacy@nabto.com. Where Nabto acts as your processor, requests from End Users should be directed to you as the controller; we will assist you as set out in the DPA.
You may also lodge a complaint with the Danish Data Protection Agency (Datatilsynet, www.datatilsynet.dk) or your local supervisory authority.
We may update this policy from time to time. We will post the updated version with a revised "Last updated" date and, for material changes, notify you by email or by notice in the console.
Nabto ApS
Åbogade 15, 8200 Aarhus N, Denmark
Email: privacy@nabto.com
CVR: 30708059