Effective Date: 11/05/2025
Last Updated: 11/05/2025

At NORD SMS, we are committed to protecting the privacy and personal data of our users and customers. This Privacy Policy explains how we collect, process, store, and protect your data, in full compliance with Regulation (EU) 2016/679 (GDPR).


1. Who We Are

NORD SMS is a service operated by WizWorks OÜ, based in Estonia.
We act as a data processor for customer messaging operations, and as a data controller for your user account and platform interactions.


2. What Personal Data We Collect

We may collect the following types of data:

  • Identity data: name, company name, email address, phone number
  • Login credentials: email and password (encrypted)
  • Payment information (processed securely via third-party providers)
  • Campaign data: SMS content, recipient lists (uploaded by you)
  • Technical data: browser, IP address, device type, log files

3. How We Use Your Data

We use your data for the following purposes:

  • To provide access to our platform and manage your account
  • To process your SMS campaigns and recipient lists
  • To monitor service quality and prevent abuse (e.g. spam detection)
  • To respond to customer support requests
  • To send platform updates or billing information (if you opt-in)

We never sell or rent your data to third parties without your consent.


4. Legal Basis for Processing

We process your data under the following legal grounds:

  • Performance of a contract: access to the NORD SMS platform
  • Legal obligations: e.g. tax, fraud prevention
  • Legitimate interest: platform improvement and security
  • Consent: marketing communication, optional data

5. Your Rights (GDPR)

As a user located in the European Economic Area (EEA), you have the right to:

  • Access your personal data
  • Correct inaccurate or outdated data
  • Request data deletion (right to be forgotten)
  • Limit or object to processing
  • Request a copy of your data (data portability)

To exercise your rights, email: [email protected]


6. Data Retention

We retain user data only as long as necessary to provide our services or as required by law (e.g. billing).
Recipient and campaign data may be deleted automatically after [30/90] days unless otherwise requested.


7. Cookies & Tracking

Our platform may use cookies for login sessions, language preferences, and analytics.
You can disable cookies in your browser settings, but this may limit some platform functionality.


8. Third-Party Services

We use secure and GDPR-compliant providers for:

  • Payment processing (e.g. Stripe, PayPal)
  • Hosting (e.g. AWS EU/Hetzner)
  • Email delivery (e.g. Mailgun, SendGrid)

We ensure these partners meet strict confidentiality and security standards.


9. Data Security

We use SSL encryption, role-based access control, and secure infrastructure to protect your data from loss, misuse, or unauthorized access.


10. International Transfers

If your data is transferred outside the EU/EEA, we ensure it is protected by appropriate safeguards such as Standard Contractual Clauses (SCC) or adequacy decisions by the European Commission.


11. Contact Us

For any privacy-related questions, requests, or complaints:
[email protected]

You also have the right to file a complaint with your local Data Protection Authority (DPA).