Privacy Policy

Privacy Policy

Last updated: April 19, 2026

Nordic Forest Echoes respects your privacy. This page explains what data may be collected, why it may be used, and what rights you have.

1. Who is responsible for your data?

Nordic Forest Echoes
Contact: [email protected]

2. What data may be collected?

  • Name and email address, if you choose to share them
  • Messages you send through email or forms
  • Basic technical data (for example IP address, browser type, device information, and page interactions)

3. Why is this data used?

  • To reply to messages and requests
  • To run, secure, and maintain the website
  • To understand aggregate website usage and improve content and performance
  • To prevent misuse and handle technical issues
  • To meet legal obligations where required

4. Legal basis (GDPR)

Data is processed based on one or more of the following:

  • Consent (for non-essential cookies and analytics)
  • Legitimate interests (for support, security, and essential website operations)
  • Legal obligation (when required by law)

If processing is based on consent, you can withdraw consent at any time.

5. Cookies

This website uses cookies for core functionality and to remember cookie preferences.

Necessary cookies may be used without consent. Non-essential cookies are only used when required consent has been given.

6. Analytics (Matomo)

This website uses Matomo analytics to understand aggregate usage patterns and improve the website.

  • Matomo is self-hosted by Nordic Forest Echoes infrastructure.
  • Analytics tracking is loaded only after cookie consent (opt-in).
  • No advertising or profiling use is intended.

7. Email and contact forms

If you contact Nordic Forest Echoes, your message details may be used to respond and manage the conversation.

Email delivery is handled via SMTP service providers. This can involve processing by third-party email infrastructure.

8. How long is data kept?

Data is kept only as long as needed for the purpose it was collected for, or as required by law.

This usually means:

  • Contact messages are kept as long as needed to handle your request
  • Technical logs are kept for a limited period for security and maintenance
  • Analytics data retention is limited to what is needed for trend analysis and operations

9. Is data shared?

Personal data is not sold.

Data may be processed by trusted service providers only when needed to run the site (for example hosting, email delivery, backup, or security services).

10. International transfers

Some providers may process data outside the EU/EEA. When this happens, appropriate safeguards are used where required.

11. Security

Reasonable technical and organisational measures are used to protect personal data.

12. Your rights

Depending on applicable law, you may have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion
  • Restrict or object to processing in some cases
  • Withdraw consent where consent is the legal basis
  • Lodge a complaint with a supervisory authority

In Sweden, the supervisory authority is IMY (Swedish Authority for Privacy Protection).

13. External links and embedded services

This website may link to third-party websites. Their privacy practices are governed by their own policies.

14. Changes to this policy

This policy may be updated over time. The latest version is always published on this page.

15. Contact

Questions about privacy or personal data handling:
Privacy and legal matters: [email protected]