Privacy Policy

Privacy Policy

Noord Ark AB, company registration number 559546-8348 · Version 3 · Effective 11 August 2026

Version: 3 Effective date: 11 August 2026 Last updated: 11 August 2026 Language: English. This is the master version. If a version in another language is published and the two conflict, the English version applies. Controller: Noord Ark AB, company registration number 559546-8348

1. Introduction

1.1 This Privacy Policy explains how Noord Ark AB, company registration number 559546-8348 ("Noord", "we", "us", "our"), collects and uses personal data about you. 1.2 Noord is the controller for the processing described here. That means we decide why and how your personal data is used, and we are responsible to you for it under data protection law. 1.3 We process personal data in accordance with Regulation (EU) 2016/679 (the "GDPR"), the Swedish Act (2018:218) containing supplementary provisions to the GDPR, and the Swedish Electronic Communications Act (2022:482) as regards cookies and similar technologies. 1.4 This Privacy Policy is information, not a contract and not a consent form. Reading or accepting it does not mean you have consented to anything. Where we need your consent, we ask for it separately and specifically, and you can withdraw it at any time (see section 13). 1.5 If we need information from you and you do not provide it, we explain the consequence in section 5 for the activity concerned. In most cases it simply means we cannot provide that service or answer that question.

2. Who this Privacy Policy applies to

2.1 This Privacy Policy applies to everyone whose personal data we process — not only to people who attend a retreat. Depending on your situation we may refer to you as a visitor, a user, a customer or a participant. Where we simply say "you", we mean whichever applies. 2.2 It covers, in particular:

  • visitors to www.noorddarkness.com and our booking pages;
  • people who make an enquiry by email, contact form, telephone or social media;
  • prospective customers, including people who book an introductory call or ask about availability;
  • participants who book and attend a darkness retreat;
  • customers who purchase additional services, such as preparatory wellness calls or coaching sessions;
  • users of the Noord Companion, our AI chat assistant (see section 7);
  • newsletter and marketing recipients;
  • people who interact with us through social media or other third-party platforms;
  • contact people at suppliers, partners and corporate customers. 2.3 It does not apply to third-party websites or platforms we link to, or that you are redirected to. Those providers have their own privacy policies.

3. Controller and contact details

Controller: Noord Ark AB, Company registration number 559546-8348, Mailbox 2347, 111 75 Stockholm, Sweden Email: hello@noorddarkness.com Website: www.noorddarkness.com Data protection officer: Noord has not appointed a data protection officer. Please use the email address above for any question about personal data. Supervisory authority: Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm — imy@imy.sewww.imy.se

4. Where we get your personal data from

4.1 Most of what we hold comes directly from you — when you fill in a form, book a retreat, complete a health declaration, write to us, or type a message into the Noord Companion. 4.2 We also receive personal data from other sources:

  • automatically from your device when you visit our website, through server logs and — with your consent where required — cookies and similar technologies (see section 16 and our Cookie Policy);
  • from payment providers, which confirm that a payment has been made and give us limited transaction details;
  • from whoever booked on your behalf, for example an employer arranging a retreat for you or someone buying you a gift voucher;
  • from social media platforms, when you interact with our pages or message us;
  • from public sources, such as company registers, when we verify a corporate customer. 4.3 Where we obtain personal data about you from someone other than you, we will tell you within a reasonable period and in any event within one month, unless you already have the information or an exception in Article 14(5) GDPR applies.

5. What we do with your personal data

5.1 This section sets out, for each significant activity, what we process, where it comes from, why, on what legal basis, who receives it, whether it leaves the EEA and how long we keep it.

Website and general online activity

5.2 Website visits and server logs

Personal data: IP address, approximate location derived from it, browser and device type, operating system, pages requested, referring page, timestamps, and error and security event records. Source: Collected automatically from your device and by our hosting provider’s systems. Purpose: Delivering the website, keeping it available and secure, detecting and investigating attacks, abuse and technical faults, and producing aggregate traffic statistics. Article 6 legal basis: Article 6(1)(f) — our legitimate interest in running a secure, working website. The data is limited, kept briefly and not used to build profiles about you. Recipients: MissHosting (website hosting); the providers of our website security and performance tools. Transfers outside the EEA: No. Our website hosting is in Sweden. Retention: Server and security logs are kept for a short period only — normally no more than 90 days — and then deleted or overwritten. We do not treat these logs as anonymous: an IP address with a timestamp is personal data.

5.3 Cookie consent records

Personal data: Your cookie choices, a consent identifier, the version of the banner and text shown to you, and the date and time. Source: Collected from your device when you respond to the cookie banner. Purpose: Applying your choices, and being able to show that valid consent was obtained and when it was changed or withdrawn. Article 6 legal basis: Article 6(1)(c) — our legal obligation to demonstrate consent under Article 7(1) GDPR, read with the Electronic Communications Act (2022:482), 9 ch. 28 §. Storing the record itself is strictly necessary and so does not require separate consent. Recipients: Complianz (our consent management tool, operating on our own website). Transfers outside the EEA: No. Retention: Kept only as long as needed to demonstrate compliance, after which we ask you again. Our current setting is stated in the Cookie Policy.

Noord Companion

Section 7 describes the Noord Companion in full. The two tables here summarise the processing.

5.4 Noord Companion — messages and generated responses

Personal data: The messages you type, the responses generated for you, the conversation context used to produce them, timestamps and a session identifier. Any personal data you choose to include in a message. Source: Provided by you when you use the Companion. Purpose: Answering your questions about our retreats, services, practical arrangements and booking process, and helping you find the right information. Article 6 legal basis: Article 6(1)(f) — our legitimate interest in providing information about our services and operating a working assistant on our website. Article 6(1)(b) where your questions concern steps taken at your request before entering into a contract with us. We do not treat your use of the Companion as consent. Article 9 condition: None. The Companion is not designed or intended to receive health information or other special-category data, and you should not enter it. See section 7.6. Recipients: Arkus AI AB (the platform on which our agent runs, acting as our processor); Microsoft, which provides the AI model service through Azure OpenAI; Arkus’s other subprocessors, listed and kept current at arkus.ai/subprocessors. Transfers outside the EEA: Arkus’s hosting environment is in the European Union. Where a transfer outside the EEA does occur, it is covered by the European Commission’s Standard Contractual Clauses. Retention: Conversations are retained while Noord remains a customer of Arkus, and deleted from active systems within 30 days after that relationship ends. Copies may persist in encrypted backups until those backups expire. See section 7.8. Is it mandatory?: No. The Companion is entirely optional — you can email us instead and get the same information from a person.

5.5 Noord Companion — technical and security logs

Personal data: Session and request identifiers, timestamps, technical error information, and request and response metadata. Source: Generated automatically when the Companion is used. Purpose: Keeping the Companion available and secure, investigating faults, and preventing abuse and excessive use. Article 6 legal basis: Article 6(1)(f) — our legitimate interest in operating a secure and reliable service. Recipients: Arkus AI AB and its subprocessors; MissHosting; Noord personnel who administer the website plugin. Transfers outside the EEA: As for 5.4. Retention: As for 5.4.

Enquiries, bookings and the retreat

5.6 Enquiries and correspondence

Personal data: Your name, email address, telephone number, the content of your message and our reply, and anything you attach. Source: Provided by you. Purpose: Answering your question, keeping a record of what was asked and advised, and following up. Article 6 legal basis: Article 6(1)(b) where your enquiry concerns a booking you are considering or have made; otherwise Article 6(1)(f) — our legitimate interest in replying to people who contact us. Article 9 condition: If you volunteer health information in an enquiry we use it only so far as necessary to answer you, and we ask you not to send health details by ordinary email. Where health information becomes relevant to a legal claim we rely on Article 9(2)(f). Recipients: Our email, form and email-delivery providers. Transfers outside the EEA: Possible, depending on the provider. Any such transfer is covered by an adequacy decision or Standard Contractual Clauses. Retention: Enquiries that do not lead to a booking: 12 months from our last contact. Enquiries connected to a booking are kept with the booking record.

5.7 Bookings and contract administration

Personal data: Name, contact details, booking reference, retreat dates, room and package selected, dietary preferences, arrival and travel information, gift voucher details, and correspondence about the booking. Source: Provided by you, or by the person or organisation booking on your behalf. Purpose: Entering into and performing your agreement with us, sending confirmations and welcome material, planning and running the retreat, and handling rebooking, transfer and cancellation. Article 6 legal basis: Article 6(1)(b) — performing our contract with you and taking steps at your request before it is made. Where a company books on your behalf, Article 6(1)(f) — our legitimate interest in administering that booking. Recipients: Our booking system provider; our email and email-delivery providers; payment providers (see 5.9). Transfers outside the EEA: Possible, depending on the provider. Any such transfer is covered by an adequacy decision or Standard Contractual Clauses. Retention: For the duration of your agreement with us and then for as long as a claim may be brought — normally up to 12 months after the retreat ends — except where accounting law requires longer (see 5.9) or a dispute is ongoing. Is it mandatory?: Yes, for the fields marked as required in the booking form. Without them we cannot make or administer a booking.

5.8 Health declaration and retreat safety assessment

Personal data: Information about your physical and psychological health, medication, allergies and dietary needs, previous experience of comparable environments, emergency contact, and anything else you tell us in the health declaration or the introductory conversation. Source: Provided by you in the health declaration and the mandatory introductory conversation. Purpose: Assessing whether a darkness retreat is safe and suitable for you, adapting meals and practical arrangements, and being able to respond properly if something happens during the retreat. Article 6 legal basis: Article 6(1)(b) — the safety assessment is a necessary part of the service you have contracted for. Article 6(1)(f) as regards our interest, and that of other participants, in a safe retreat environment. In an acute situation, Article 6(1)(d) — protecting someone’s vital interests. Article 9 condition: Article 9(2)(a) — your explicit consent, which we ask for separately in the health declaration form and do not bundle with acceptance of our General Terms or this Privacy Policy. In an acute situation where you cannot give consent, Article 9(2)(c) — vital interests. Recipients: Only Noord personnel who need it to carry out the safety assessment or run the retreat; the provider of the system in which the declaration is collected; emergency services if an acute situation arises. Transfers outside the EEA: No. Retention: Kept for the shortest period that still allows us to answer a safety-related claim — normally up to 12 months after the retreat ends — and then deleted. Is it mandatory?: Yes. If you do not complete the health declaration, or you withdraw your consent to our use of the health information in it, we cannot carry out the safety assessment and you cannot take part. Withdrawing consent does not affect anything we did before you withdrew it.

5.9 Payments, invoicing and accounting

Personal data: Name, contact and billing details, amount, currency, date, payment method type, transaction and reference numbers, refund and gift voucher records, and invoicing details for corporate customers. We do not receive or store full card numbers. Source: From you, and from the payment provider you use. Purpose: Taking payment, issuing receipts and invoices, processing refunds, handling chargebacks and disputes, and keeping accounting records. Article 6 legal basis: Article 6(1)(b) — performing our contract; Article 6(1)(c) — the Swedish Accounting Act (1999:1078) and tax law; Article 6(1)(f) — fraud prevention and handling disputes. Recipients: Adyen and Stripe, which act as independent controllers for their own payment processing under their own privacy policies; our accounting firm and accounting software provider; the Swedish Tax Agency where required. Transfers outside the EEA: Payment providers may process data outside the EEA under their own safeguards, including Standard Contractual Clauses. Retention: Seven years from the end of the calendar year in which the financial year ended, as the Accounting Act requires.

5.10 Introductory calls, wellness calls and coaching

Personal data: Booking and scheduling data, notes made during or after a session, and anything you choose to share during it. Source: Provided by you. Purpose: Delivering the optional service you booked, and preparing for and following up the session. Article 6 legal basis: Article 6(1)(b) — performing the agreement for that service. Article 9 condition: If you share health information during a session and we record it, we do so on the basis of Article 9(2)(a) explicit consent, asked for at the time. We keep session notes to the minimum necessary. Recipients: Our scheduling and video-meeting providers; the coach or practitioner delivering the session, who is bound by confidentiality. Transfers outside the EEA: Possible, depending on the provider. Any such transfer is covered by an adequacy decision or Standard Contractual Clauses. Retention: Session notes are kept for 12 months after the session unless you ask us to keep them longer.

Communication, marketing and feedback

5.11 Newsletter and marketing

Personal data: Name, email address, subscription status and source, and whether a message was opened or a link clicked. Source: Provided by you when you subscribe, or arising from your customer relationship with us. Purpose: Sending newsletters, offers and information about our retreats and services, and understanding whether our mailings are useful. Article 6 legal basis: Article 6(1)(a) — your consent, if you are not already a customer. Article 6(1)(f) — our legitimate interest in marketing similar services to existing customers, in line with the Marketing Act (2008:486). You can unsubscribe or object at any time, free of charge, using the link in every message, and we act on it immediately. Recipients: Mailchimp (Intuit), our email marketing provider. Transfers outside the EEA: Yes — Mailchimp processes data in the United States. The transfer is covered by the EU–US Data Privacy Framework and, where applicable, Standard Contractual Clauses. Retention: Until you unsubscribe or object, after which we keep only a minimal record so that we do not contact you again. We review inactive subscribers every 24 months. Is it mandatory?: No.

5.12 Surveys and feedback

Personal data: Your responses, and your name and contact details if you give them. Source: Provided by you. Purpose: Understanding how our services are experienced and improving them. Article 6 legal basis: Article 6(1)(f) — our legitimate interest in improving what we offer. Taking part is voluntary, and you can answer anonymously where the survey allows it. Recipients: Our survey and form providers. Transfers outside the EEA: Possible, depending on the provider. Any such transfer is covered by an adequacy decision or Standard Contractual Clauses. Retention: Identifiable responses for 12 months. Aggregated results, which cannot be traced to you, may be kept longer.

5.13 Social media

Personal data: Your profile name and public profile information, the content of your comments and messages to us, and platform-generated statistics about our pages. Source: From you, and from the platform. Purpose: Replying to you, maintaining our presence on the platforms, and understanding in aggregate how our content performs. Article 6 legal basis: Article 6(1)(f) — our legitimate interest in communicating with people who contact us and promoting our services. Recipients: The platform operator, which also processes your data for its own purposes as a controller under its own privacy policy. Transfers outside the EEA: Determined by the platform. Most major platforms transfer data outside the EEA under their own safeguards. Retention: Messages and comments stay on the platform under its rules. Where we copy something into our own records we keep it with the related enquiry or booking.

5.14 Photography, audio and video

Personal data: Images, audio and video in which you appear or can be heard, and your name if it is used alongside the material. Source: Recorded by us, or by a photographer or film-maker we engage. Purpose: Marketing and communication in our own digital channels and, where the consent request says so, in press and partner channels. Article 6 legal basis: Article 6(1)(a) — your separate, informed, written consent. It is entirely voluntary and refusing has no effect on your participation. Article 9 condition: Where material would reveal health information, we obtain Article 9(2)(a) explicit consent for that use specifically. Recipients: Our marketing and design suppliers, and the platforms where the material is published. Transfers outside the EEA: Determined by the platforms on which material is published. Retention: Until you withdraw consent, after which we remove it from our own channels without undue delay. Material already published or shared by others outside our control — a re-post, or a printed article — may not be fully recoverable, and we will tell you so honestly. Is it mandatory?: No.

Administration, claims and business contacts

5.15 Complaints, disputes and legal claims

Personal data: The complaint or claim and supporting material, correspondence, booking and payment records, and health declaration material where relevant to the claim. Source: From you, from our own records, and from any authority or body involved. Purpose: Investigating and answering complaints, establishing, exercising or defending legal claims, and taking part in proceedings before the National Board for Consumer Disputes (ARN) or a court. Article 6 legal basis: Article 6(1)(f) — our legitimate interest in handling complaints and defending claims; Article 6(1)(c) where we must respond to an authority. Article 9 condition: Article 9(2)(f) — establishing, exercising or defending legal claims, where health information is relevant. Recipients: Our legal advisers and insurers; ARN, a court or an authority where proceedings are brought. Transfers outside the EEA: No. Retention: Until the matter is finally resolved and then for the applicable limitation period.

5.16 Supplier, partner and corporate contacts

Personal data: Name, job title, employer, business contact details and correspondence. Source: From you, from your employer, or from public sources. Purpose: Managing the business relationship, contracts, orders and invoices. Article 6 legal basis: Article 6(1)(b) where you are the counterparty personally; otherwise Article 6(1)(f) — our legitimate interest in administering the relationship with the organisation you represent. Recipients: Our accounting, contract, email and email-delivery providers. Transfers outside the EEA: Possible, depending on the provider. Any such transfer is covered by an adequacy decision or Standard Contractual Clauses. Retention: For the duration of the relationship and then for the applicable limitation and accounting periods.

6. Special-category (sensitive) personal data

6.1 Some personal data has extra protection under Article 9 GDPR. It includes data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to identify someone uniquely, and data about health, sex life or sexual orientation. 6.2 We process special-category data in one situation as a matter of course: the health declaration and retreat safety assessment described in section 5.8. It may also arise if you volunteer health information in an enquiry or during a coaching session, or where health information becomes relevant to a legal claim. 6.3 For each of those, section 5 states the Article 6 legal basis and the Article 9 condition separately. They are different requirements and both must be met. An Article 6 basis alone is not enough to process health data, and Article 9 consent does not remove the need for an Article 6 basis. 6.4 Where we rely on your explicit consent under Article 9(2)(a), that consent is:

  • separate — asked for on its own, not bundled into acceptance of our General Terms or this Privacy Policy;
  • specific — tied to a stated purpose and category of information;
  • informed — we tell you what will be processed, by whom, for how long, and what happens if you decline;
  • recorded — we keep a record of when and how it was given, so that we can demonstrate it;
  • withdrawable — you can withdraw it at any time, as easily as you gave it, by contacting us. Withdrawal does not affect processing carried out beforehand. 6.5 Calling something wellness or friskvård does not stop information being health data. Where we ask about your physical or psychological condition, we treat the answer as health data. 6.6 The Noord Companion is not intended to process special-category data and we do not rely on any Article 9 condition for it. Section 7.6 explains what to do, and what we do, if such information is entered anyway. 6.7 Research. We do not currently use personal data for research. If that changes, we will ask for your separate, specific and informed consent at the time, tell you exactly what the study involves, and make clear that taking part is voluntary and can be withdrawn without any effect on your retreat.

7. Noord Companion and AI processing

7.1 What the Noord Companion is

The Noord Companion (the "Companion") is an AI chat assistant on our website. When you open it and type a message:

  • your message is received by a plugin we developed for our WordPress website;
  • our server sends the message, with the technical information needed to route it, to an AI agent we have configured on the platform operated by Arkus AI AB;
  • the agent processes it using an AI model and generates a response;
  • the response is returned to the website and shown to you. Your browser does not communicate with Arkus directly — the request goes through our own server. We may change the AI model or the agent’s configuration from time to time. If a change affects the information in this section, we will update it.

7.2 You are interacting with an AI system

You are interacting with an AI system, not a human being. The Companion is not a member of our staff, not a therapist, not a counsellor and not a healthcare provider. Responses are generated automatically and may be incorrect, incomplete, out of date or inappropriate to your situation. Nothing the Companion says is:

  • medical care, therapy, psychological treatment, diagnosis or clinical assessment;
  • emergency, crisis or suicide-prevention assistance;
  • professional advice of any kind, or a binding statement of our terms, prices or availability. If you need urgent help, contact the emergency services — in Sweden and across the EU, 112 — or a qualified healthcare provider. If you want a binding answer about a booking, email hello@noorddarkness.com and a person will reply. We tell you that you are interacting with an AI system before or at the start of your first interaction, and we link to this Privacy Policy from the Companion. Article 50 of Regulation (EU) 2024/1689 (the EU AI Act) requires this disclosure for AI systems that interact directly with people.

7.3 What is transmitted

When you use the Companion, the following goes from your device to us and on to Arkus:

  • the text of your message, as you typed it;
  • the conversation context needed to produce a coherent reply — earlier messages in the same conversation;
  • technical routing information, including a session identifier and timestamps. Your messages and the responses may contain personal data — about you, and about other people if you mention them. Please read section 7.6 before typing anything you would not want stored.

7.4 Why we process it, and on what legal basis

We process Companion data to answer your questions about our retreats and services, to guide you to the right information and booking route, to keep the Companion secure and working, and to investigate faults and abuse. Our legal basis is Article 6(1)(f) GDPR — our legitimate interest in providing information about our services and running our website securely — and, where your questions concern a booking you are considering, Article 6(1)(b). We do not treat your use of the Companion, or your acceptance of this Privacy Policy, as consent under Article 6(1)(a). Separate consent is needed for any non-essential cookies or similar technologies, which is dealt with in our Cookie Policy.

7.5 Who receives it

Arkus AI AB: Company registration number 559239-8811, Hagaesplanaden 1, 113 68 Stockholm, Sweden. Operates the platform on which our agent runs, as our processor under a data processing agreement. Arkus processes the data only to provide, secure, maintain and support the service. Microsoft: Provides the AI model service through Azure OpenAI, which runs OpenAI models in Microsoft’s Azure environment. Microsoft may process messages and responses to generate the reply and for content filtering, security and abuse monitoring under its own terms. That monitoring can involve limited review by authorised personnel. Arkus’s other subprocessors: Arkus engages further providers for hosting, storage, authentication, tracing and observability. The current list, with their locations, is published and kept up to date at arkus.ai/subprocessors. Arkus gives us advance notice of changes. MissHosting: Hosts our website and therefore handles the request as it passes through. Noord personnel: Authorised staff administer the plugin and our Arkus account.

7.6 Please do not enter sensitive information

The Companion is not designed or intended to receive health information or other special-category data, and we do not rely on any Article 9 GDPR condition for it. Please do not enter into the Companion:

  • information about your physical or mental health, medication, diagnoses or treatment;
  • your Swedish personal identity number (personnummer) or any other national identity number;
  • card numbers, bank details or other financial information;
  • passwords, login details or access codes;
  • personal data about other people, unless you have their authority to share it;
  • anything else you would not want stored or read by someone else. If you need to tell us something about your health, do it in the health declaration or the introductory conversation, where it is handled under section 5.8 with the right protections — not in the Companion. If sensitive information is entered anyway, we will delete it from the records under our control as soon as we reasonably can after becoming aware of it, unless we are required to keep it. The Companion does not ask for health information and is configured not to invite it.

7.7 Age

The Companion is intended for adults and should not be used by anyone under 18. Please do not use it if you are younger than that.

7.8 Storage, retention, access and use

What is stored. Messages, generated responses, conversation context, timestamps, session identifiers and technical activity logs are stored on the Arkus platform. How long. Conversations are retained while Noord remains a customer of Arkus. When that relationship ends, Arkus deletes the data from its active systems within 30 days. Copies may remain in encrypted backups until those backups expire in the normal cycle, and stay protected in the meantime. Who can access it. Authorised Arkus personnel may access conversation data where necessary to provide, secure, maintain and support the service. They are bound by confidentiality, given access only where their role requires it, and their access is logged. Microsoft may review content flagged by its abuse-monitoring systems, as described in 7.5. Authorised Noord staff can access the Arkus account. Training. Arkus does not use your messages or the generated responses to train, retrain or fine-tune any AI model, whether its own or a third party’s. This is a contractual commitment, not just a statement of practice. Improvement. Arkus may use technical usage data, and information that has been aggregated or de-identified so that it does not identify you, to operate and improve its platform.

7.9 Where processing takes place, and international transfers

Arkus’s hosting environment for this data is in the European Union, and the model service is provided through Microsoft Azure within the EU. Where a transfer outside the EEA does occur, it is covered by the European Commission’s Standard Contractual Clauses, incorporated into our agreement with Arkus, or by another mechanism permitted under Chapter V GDPR. You can ask us for a copy of the safeguards using the contact details in section 3.

7.10 Your rights over Companion conversations

You can use the Companion without creating an account. That has a practical consequence: we may hold nothing that links a conversation to you as an identified person. To ask for access to, deletion of, or restriction of a conversation, email hello@noorddarkness.com and give us as much of the following as you can:

  • the approximate date and time of the conversation, and your time zone;
  • a short description of what it was about;
  • any reference shown to you in the Companion. If we cannot identify the conversation from that, Article 11(2) GDPR allows us to decline — we will say so and explain why. We will not ask you to send us identity documents simply to locate a conversation you had anonymously. Where we have genuine doubts about the identity of someone making a request about identified data, we may ask for further information under Article 12(6) GDPR, but only what is proportionate.

7.11 Automated decision-making

The Companion does not make decisions about you that produce legal effects or similarly significantly affect you within the meaning of Article 22 GDPR. It does not decide whether you may book, attend or be refused a retreat. People make those decisions.

8. Who we share personal data with

8.1 We do not sell your personal data. We share it only as described here, or where we are required to by law, by a decision of an authority, or in connection with legal, administrative or debt-recovery proceedings to which we are a party. 8.2 We share with three kinds of recipient, and the difference matters for your rights: Processors: Suppliers that process personal data only on our instructions and under a written data processing agreement — hosting, booking, email, survey, marketing and AI platform providers. We remain responsible to you for what they do. Independent controllers: Organisations that decide for themselves how to use data you give them — payment providers and social media platforms. Their own privacy policies apply, and we cannot answer for them. Recipients required by law: Authorities, courts and dispute bodies where we are obliged to provide information, and our advisers and insurers in connection with a claim.

8.3 Before engaging a processor we put in place an agreement under Article 28 GDPR covering processing only on documented instructions, confidentiality, security, conditions for engaging further providers, assistance with your rights and with breach notification, and deletion or return of data at the end of the engagement. 8.4 You can ask us at any time for the identity of the providers we use for a particular activity, using the contact details in section 3.

9. Transfers outside the EU/EEA

9.1 Most of our processing takes place inside the EEA. Our website hosting is in Sweden, and Companion messages are processed in the European Union. 9.2 Some providers do process personal data outside the EEA, or can access it from outside for support purposes. This applies in particular to our email marketing provider, and may apply to social media platforms and to some email, survey and video-meeting tools. 9.3 Where personal data is transferred outside the EEA we rely on one of the following:

  • an adequacy decision of the European Commission, including the EU–US Data Privacy Framework where the recipient is certified under it;
  • the European Commission’s Standard Contractual Clauses, with any additional measures needed;
  • another mechanism permitted by Chapter V GDPR. 9.4 You can ask us for a copy of the safeguards that apply to a particular transfer, using the contact details in section 3.

10. How long we keep personal data

10.1 We keep personal data only for as long as we need it, or for as long as the law requires. The period, or the criteria we use to set it, is stated for each activity in section 5. The main rules are: Category: Accounting records Period: Seven years from the end of the calendar year in which the financial year ended.

Category: Booking and customer records Period: For the agreement and normally up to 12 months after the retreat, longer if a dispute is ongoing.

Category: Health declarations Period: Normally up to 12 months after the retreat, then deleted.

Category: Enquiries not leading to a booking Period: 12 months from last contact.

Category: Session notes from calls and coaching Period: 12 months.

Category: Marketing data Period: Until you unsubscribe or object, then a minimal suppression record only.

Category: Server and security logs Period: Normally no more than 90 days.

Category: Companion conversations Period: While Noord remains a customer of Arkus; deleted within 30 days after that ends.

Category: Complaints and legal claims Period: Until finally resolved, then for the applicable limitation period.

10.2 When personal data is no longer needed we delete it or anonymise it securely. Information is only "anonymised" if it can no longer be linked to you by any means reasonably likely to be used. If re-identification remains possible it is pseudonymised, not anonymous, and this Privacy Policy still applies to it.

11. Security

11.1 We take appropriate technical and organisational measures to protect personal data against unauthorised access, unlawful processing, accidental loss, alteration, disclosure or destruction. These include access on a need-to-know basis, confidentiality undertakings for staff and suppliers, logging, encryption of data in transit, and periodic review. 11.2 Health declaration data is subject to stricter access limits than other data and is held separately from general customer records. 11.3 No system can be guaranteed completely secure and we do not claim otherwise. What we commit to is applying measures appropriate to the risk and correcting weaknesses when we find them. 11.4 If a personal data breach occurs we will notify IMY within 72 hours where Article 33 GDPR requires it, and tell you without undue delay where Article 34 requires it.

12. Automated decision-making and profiling

12.1 We do not carry out automated decision-making, including profiling, which produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22(1) GDPR. 12.2 The Noord Companion generates responses automatically but does not make decisions about you — see section 7.11.

13. Your rights

13.1 You have the following rights over the personal data we hold about you. Some apply only in particular circumstances, which we explain. Right: Access (Art. 15) What it means and when it applies: You can ask whether we process personal data about you and, if so, receive a copy together with information about the processing.

Right: Rectification (Art. 16) What it means and when it applies: You can have inaccurate data corrected and incomplete data completed. Tell us what the correct information is.

Right: Erasure (Art. 17) What it means and when it applies: You can ask us to delete data that is no longer needed, where you withdraw the consent it was based on and there is no other basis, where you successfully object, or where processing was unlawful. We may refuse where the law requires us to keep it — accounting records, for example — or where we need it to establish or defend a legal claim.

Right: Restriction (Art. 18) What it means and when it applies: You can ask us to limit processing to storage only: while we check accuracy you dispute, instead of erasure where processing was unlawful, where you need the data for a legal claim although we no longer do, or while we consider an objection.

Right: Objection (Art. 21) What it means and when it applies: Where we process on the basis of legitimate interests, you can object at any time on grounds relating to your situation. We must then stop unless we can show compelling legitimate grounds that override your interests, or the processing concerns legal claims.

Right: Objection to direct marketing (Art. 21(2)) What it means and when it applies: An absolute right. If you object to direct marketing we stop immediately, with no balancing exercise. Every marketing email also has an unsubscribe link.

Right: Portability (Art. 20) What it means and when it applies: Where processing is based on consent or on a contract with you and is automated, you can receive the data you provided in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible.

Right: Withdraw consent (Art. 7(3)) What it means and when it applies: Where processing is based on consent you can withdraw it at any time, as easily as you gave it. Withdrawal does not affect what was done beforehand.

Right: Complain (Art. 77) What it means and when it applies: You can lodge a complaint with a supervisory authority — in Sweden, IMY. See section 15.

14. How to exercise your rights

14.1 How to ask. Email hello@noorddarkness.com, or write to us at the address in section 3. There is no special form — a plain email is enough. 14.2 Identity. We only ask for extra information to verify who you are where we have genuine doubts, and then only the minimum necessary. Where we can, we verify using the email address or booking reference already on your record rather than asking for documents. 14.3 Helping us find it. It helps if you tell us what your request relates to — a booking reference, an approximate date, or which service is concerned. This is a request, not a condition: we will not refuse a valid request because you did not narrow it down. 14.4 Time limit. We respond without undue delay and in any event within one month of receiving your request. Where a request is complex, or where you have made several, we may extend that by up to two further months. If we do, we will tell you within the first month and explain why. 14.5 Cost. Responding is free of charge. Article 12(5) GDPR allows us to charge a reasonable administrative fee, or to refuse, only where a request is manifestly unfounded or excessive, in particular because it is repetitive. If we ever take that position we will explain our reasons and tell you that you can complain to IMY and seek a judicial remedy. The burden of showing that a request meets that threshold is ours. 14.6 If we refuse. We will tell you within one month, explain why, and inform you of your right to complain to IMY and to a judicial remedy. 14.7 Telling others. Where we rectify, erase or restrict personal data we inform each recipient it was disclosed to, unless that proves impossible or involves disproportionate effort. We will tell you who they are if you ask. 14.8 Companion conversations. If your request concerns a conversation with the Noord Companion and you do not have an account with us, please read section 7.10 first — it explains what helps us find it and what the limits are.

15. Complaints to the supervisory authority

15.1 If you think we process your personal data in breach of data protection law, you can lodge a complaint with a supervisory authority — in Sweden, Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, imy@imy.se, www.imy.se. You can also complain to the authority in the EU country where you live or work, or where you believe the infringement took place. 15.2 You are welcome to contact us first so we have a chance to put things right, but you do not have to, and it does not affect your right to complain.

16. Cookies and similar technologies

16.1 Our website uses cookies and similar technologies such as local storage. How they work, which categories we use, how to give and withdraw consent, and the full list are set out in our separate Cookie Policy. 16.2 Non-essential technologies are only used where you have consented through the cookie banner. You can change or withdraw your choices at any time through the Cookie Settings control on our website. Withdrawing is as easy as consenting. 16.3 Where cookies and similar technologies also involve processing personal data, that processing is described in this Privacy Policy.

17. Children

17.1 Our retreats and services are directed at adults, and we do not knowingly collect personal data from children. 17.2 The Noord Companion should not be used by anyone under 18 — see section 7.7.

18. Changes to this Privacy Policy

18.1 We review this Privacy Policy at least once a year, and whenever there is a significant change in our processing, our technology, our suppliers or the law. 18.2 The current version is always on our website, with its version number and effective date at the top. 18.3 Where a change is material — a new purpose, a new category of recipient, a change of legal basis, or a significant change to the Companion — we will draw attention to it before it takes effect, by a notice on the website and, where we hold your contact details and the change affects you, by email. Where a change requires your consent we will ask for it separately. 18.4 We keep superseded versions internally so we can show what applied at any given time.

19. Version history

Version: 1–2 Date: To 9 June 2025 Summary: Earlier Swedish Integritetspolicy.

Version: 3 Date: 11 August 2026 Summary: English master version. Controller corrected to Noord Ark AB, 559546-8348. Scope extended beyond retreat participants. New section on the Noord Companion and AI processing. Processing set out activity by activity with Article 6 and Article 9 grounds stated separately. New sections on international transfers and retention. Data-subject rights procedure corrected. Security consolidated.