Platform Privacy Policy

Last updated: 23 September 2026

This Privacy Policy explains how Nabto ApS, CVR number 30708059, Åbogade 15, 8200 Aarhus N, Denmark ("Nabto", "we", "us", "our") collects and processes personal data when you use the Nabto platforms (Nabto Edge, Nabto WebRTC and Nabto 4), including our cloud console at console.cloud.nabto.com (together, the "Service"), whether you sign up online or contract with us under an Order Form, and when we bill and support you as our customer.

This policy covers the Service. For our public marketing website, see the separate Website Privacy Policy at https://downloads.nabto.com/assets/legal/website-privacy-policy.html.


1. Controller and processor roles (important)

The Service involves two different roles and your rights depend on which applies:

The role follows the purpose, not the vendor or the tool. Data about your account users, your account and your use of the Service that we process in order to administer, bill, secure and improve the Service is controller data. Data of your End Users that we process in order to deliver, relay and troubleshoot connectivity, including when you send it to us in a support request, is processor data under the DPA.

If you are unsure which role applies to a given set of data, contact us at privacy@nabto.com.


2. Personal data we process as controller

3. Why we process this data and our legal basis

PurposeLegal basis (GDPR Art. 6)
Creating and administering your accountPerformance of a contract where you are our customer as a natural person (Art. 6(1)(b)); our legitimate interest in administering the contract with your employer or principal where you act for a company (Art. 6(1)(f))
Providing, maintaining and securing the ServicePerformance of a contract / legitimate interest (Art. 6(1)(b) / (f))
Measuring usage and billing youPerformance of a contract where you are our customer as a natural person (Art. 6(1)(b)); our legitimate interest in administering the contract with your employer or principal where you act for a company (Art. 6(1)(f))
Processing paymentsPerformance of a contract where you are our customer as a natural person (Art. 6(1)(b)); our legitimate interest in administering the contract with your employer or principal where you act for a company (Art. 6(1)(f))
Keeping accounting and tax recordsLegal obligation (Art. 6(1)(c))
Detecting and preventing fraud and abuseLegitimate interest (Art. 6(1)(f))
Service-related and (with consent where required) marketing communicationsLegitimate interest / consent (Art. 6(1)(f) / (a))

The legitimate interests we rely on above are administering and billing the contract, securing the Service and communicating with the customer's designated contacts.

4. Payments

4.1 If you pay by card, we use Stripe, Inc. and its affiliates ("Stripe") to process payments. When you enter payment details, they are provided directly to Stripe; we do not receive or store your full card number.

4.2 We receive limited information from Stripe needed to manage your subscription and billing, such as the card brand, last four digits, expiry, payment status and billing address.

4.3 Stripe processes your data as its own controller for certain purposes (such as fraud prevention and regulatory compliance) under its own privacy policy at https://stripe.com/privacy.

4.4 If you pay by invoice, we process your billing contact details and remittance data in our invoicing and accounting systems. No card data is involved.

5. Who we share data with

We share personal data with:

We do not sell your personal data.

6. International transfers

Some sub-processors may process personal data outside the EU/EEA, including in the United States. Where this occurs, we rely on an appropriate transfer mechanism such as the EU Standard Contractual Clauses or the EU-US Data Privacy Framework. You may request details of the safeguards by contacting us.

7. How long we keep your data

DataRetentionTrigger
Account and identity data30 days, then deletedClosure of the Account or expiry of the Order Form; on a switch under the Terms of Service the 30 days start when the transition period ends. This matches the retrieval period in the Terms of Service.
Contract and order dataThe term of the Agreement and three years after itExpiry or termination of the Agreement. Three years is the general limitation period for claims under the Danish Limitation Act (forældelsesloven); we keep a record longer only while a claim is pending or another law requires it.
Billing, invoice and accounting recordsFive yearsThe end of the financial year the record belongs to, under the Danish Bookkeeping Act.
Authentication logs and audit logs13 monthsThe date of the logged event.
Connection and relay metadata used for billingThe term of the Agreement, then deleted with the Account dataThe same trigger as the Account and identity data.
Diagnostic logs (request traces, error logs and TURN session logs containing network addresses)180 daysThe date the log entry is written.
Aggregated usage metrics without personal data13 monthsThe date of the measurement.
Support communicationsThree yearsClosure of the ticket.
IP-derived approximate location in operational notificationsFor as long as the notification is retained in our messaging tool, at most 12 monthsThe date of the notification.

Backup copies expire within 35 days of the deletion of the live data. If you ask us to delete data earlier, we carry out the deletion in the live systems without undue delay and the backup copies expire on that cycle.

Data we process as your processor is retained and deleted in accordance with the DPA and your instructions.

8. Security

We apply technical and organizational measures appropriate to the risk, including encryption in transit, access controls, authentication safeguards, logging and regular review. No system is completely secure and we cannot guarantee absolute security.

9. Your rights

Where Nabto is the controller, you have the right to:

Some data, such as accounting records, must be retained by law and cannot be erased on request until the retention period ends.

To exercise your rights, contact us at privacy@nabto.com. Where Nabto acts as your processor, requests from End Users should be directed to you as the controller; we will assist you as set out in the DPA.

You may also lodge a complaint with the Danish Data Protection Agency (Datatilsynet, www.datatilsynet.dk) or your local supervisory authority.

10. Changes to this policy

We may update this policy from time to time. We will post the updated version with a revised "Last updated" date and, for material changes, notify you by email or by notice in the console.

11. Contact us

Nabto ApS
Åbogade 15, 8200 Aarhus N, Denmark
Email: privacy@nabto.com
CVR: 30708059