Privacy policy
Written to be read. If anything here is unclear, ask us and we will explain it in plain language — and probably rewrite the paragraph.
1. Overview
NordicCast provides a licensed television service: live channels, on-demand films and series, sport and the apps that play them. This policy explains what personal data we collect when you visit https://nordiccast.com, contact us, or use the platform; why we process it; who else can see it; and the rights you have over it under the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act.
Three commitments underpin everything below. We do not sell personal data. We do not run third-party advertising or tracking scripts in our player. We do not require you to accept optional cookies in order to use the site.
2. Who we are
The data controller is NordicCast AS, Storgata 12, 0155 Oslo, Norway, organisation number NO 924 118 730 MVA.
For anything relating to personal data, write to admin@nordiccast.com with "Privacy" in the subject line, or call +47 22 00 18 40. Our privacy lead reads that inbox directly.
We are the controller for your account and viewing data. Where a broadcaster requires aggregate audience reporting as a condition of the licence, we provide it only in anonymised, aggregated form — never in a way that identifies you. Section 11 covers business customers who need a data processing agreement.
3. Data we collect
3.1 Information you give us
- Contact form: your name, e-mail address, optional phone number, country, chosen subject and the message itself.
- Newsletter: your e-mail address and the page you subscribed from.
- Account: name, e-mail, password (stored only as a salted hash), billing details and company information where relevant.
- Viewing activity: the channels and titles you play, where you paused and which device you played them on, so that continue-watching, favourites and parental controls work across your screens.
3.2 Information collected automatically
- Technical data attached to form submissions: your IP address, browser user-agent string and the timestamp. We store these to prevent spam and abuse, and to be able to investigate malicious traffic.
- Server logs: request paths, response codes and timings, retained briefly for security and debugging.
- Measurement: aggregate page views, if you accept the optional measurement cookie described in section 6.
3.3 Playback and quality data
Each stream reports its bitrate, buffering events and the edge location that served it, so that we can spot a failing source before you do. Your IP address is hashed with a salt that rotates every 24 hours before this reaches our analytics pipeline, and the raw address is discarded; we derive only approximate region and device platform from the hashed record. We never build cross-site profiles, and we never pass viewing data to advertising networks.
4. Why we process it
- To reply to the message you sent us, and to keep a record of that correspondence.
- To provide, bill for and support the NordicCast platform.
- To deliver your audio quickly and reliably, worldwide.
- To detect, investigate and block spam, fraud and attacks on the service.
- To produce the aggregate analytics you see in your dashboard.
- To send the newsletter, if and only if you asked for it.
- To meet accounting, tax and other legal obligations.
5. Legal basis
- Contract (Art. 6(1)(b)): providing the service you signed up for, including hosting, delivery and billing.
- Legitimate interests (Art. 6(1)(f)): responding to enquiries, securing the platform against abuse, and improving the product. We have assessed that these interests do not override your rights.
- Consent (Art. 6(1)(a)): the newsletter and the optional measurement cookie. You can withdraw consent at any time without affecting anything that happened before.
- Legal obligation (Art. 6(1)(c)): retaining invoices and accounting records for the period Norwegian law requires.
6. Cookies
We use as few cookies as we can get away with. There are exactly two categories.
6.1 Strictly necessary
NORDICCAST_SID— the session cookie that keeps you signed in to the admin area and protects forms against cross-site request forgery. It expires when you close the browser and cannot be disabled, because the site does not function without it.nc-themeandnc-cookie-consent— stored in your browser's local storage, not sent to our servers. They remember your light/dark preference and your cookie choice.
6.2 Optional measurement
If you press "Accept all" on the cookie banner, we set one first-party measurement cookie that counts page views in aggregate. It contains no advertising identifier, is never shared, and is deleted after 12 months. Choosing "Necessary only" leaves the site fully functional — you lose nothing except our ability to count you.
You can clear cookies and local storage at any time from your browser's settings. Doing so resets your theme and consent choices.
7. Sharing & processors
We never sell personal data and we never share it for advertising. We do use a short, deliberately boring list of sub-processors to run the service:
- Hosting & storage — EU data centres in Stockholm and Frankfurt.
- Content delivery — an edge network that caches streams close to the people watching them.
- Transactional e-mail — the SMTP provider that delivers notifications and password resets.
- Payments — a PCI-DSS certified processor. We never see or store your full card number.
- Error monitoring — an EU-hosted service that receives stack traces with personal data stripped.
Each sub-processor is bound by a written data processing agreement. The current list, with company names and locations, is available on request from admin@nordiccast.com. We give 30 days' notice before adding a new one.
We will also disclose data where we are legally required to — for example a valid court order — and will tell you unless we are legally barred from doing so.
8. International transfers
Personal data is stored and processed inside the European Economic Area. Where a sub-processor requires a transfer outside the EEA, we rely on the European Commission's Standard Contractual Clauses together with a transfer impact assessment and, where appropriate, supplementary technical measures such as encryption with keys we control. Enterprise customers can contractually pin all storage and processing to a named region.
9. How long we keep it
- Contact messages: 24 months from the last reply, then deleted. You can ask us to delete yours sooner.
- Newsletter subscriptions: until you unsubscribe, plus 30 days to honour the suppression.
- Account data: for the life of the account, then 90 days so you can change your mind, then deleted.
- Audio and show content: until you delete it, or 30 days after an account closes.
- Aggregate analytics: retained indefinitely in a form that cannot identify an individual.
- Security and access logs: 30 days, except records of an active investigation.
- Invoices and accounting records: five years, as required by Norwegian law.
10. How we protect it
- TLS 1.2+ on every connection, with HSTS enabled.
- Encryption at rest for databases, audio storage and backups.
- Passwords stored only as bcrypt hashes with a per-password salt — we cannot read them, and neither can an attacker who steals the database.
- Parameterised database queries throughout, plus output escaping on every page, to eliminate injection and cross-site scripting.
- Role-based internal access on a strict need-to-know basis, with mandatory two-factor authentication for staff.
- Quarterly third-party penetration tests and continuous dependency scanning.
- Documented incident response. Where a breach is likely to risk your rights, we notify the Norwegian Data Protection Authority within 72 hours and tell affected users directly.
11. Your rights & the DPA
Under the GDPR you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have your data deleted where no legal obligation requires us to keep it.
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive your data in a structured, machine-readable format. In the dashboard this is a single "Export everything" button.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — at any time, for anything based on consent.
Write to admin@nordiccast.com and we will respond within 30 days, free of charge. If you are not satisfied, you may complain to the Norwegian Data Protection Authority (Datatilsynet) or to the supervisory authority in your own country.
Data processing agreement: if you take NordicCast for a business — a hotel, a bar, a care home — and we process personal data on your behalf, our standard DPA, including the Standard Contractual Clauses and the sub-processor list, is available on request and is signed as part of every commercial contract.
12. Children
NordicCast is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it promptly.
13. Changes to this policy
We update this policy when the way we handle data genuinely changes. The "last updated" date at the top always reflects the current version. For material changes we e-mail account holders at least 30 days before the new version takes effect, and keep the previous version available on request.
14. Contact the privacy team
NordicCast AS
Storgata 12, 0155 Oslo, Norway
E-mail: admin@nordiccast.com
Phone: +47 22 00 18 40
Organisation number: NO 924 118 730 MVA
Prefer a form? Use the contact page and pick "Security & privacy" as the subject — it routes straight to the right person.