Introduction

NKT Orderbase (Logistics Information & Internal Orders) is committed to protecting your personal data and respecting your privacy. This policy explains how we collect, use, store, and protect your information in accordance with the General Data Protection Regulation (GDPR).

Data We Collect

We collect and process the following types of personal data:

  • User Account Information: Name, email address, role, and authentication data
  • Order Information: Order details, descriptions, comments, and related metadata
  • Communication Data: Comments, feedback, and support requests
  • System Usage Data: Login timestamps, actions performed, and audit logs
  • File Attachments: Documents and files uploaded to orders and requests

How We Use Your Data

Your personal data is used for the following purposes:

  • Managing orders, requests, and logistics operations
  • Facilitating communication between team members
  • Providing user authentication and authorization
  • Generating reports and analytics for operational improvements
  • Maintaining audit logs for security and compliance
  • Sending notifications about order updates and system activities

Data Storage & Security

All personal data is stored securely using industry-standard encryption and security measures:

  • Database: PostgreSQL database with encrypted connections
  • Cloud Storage: Azure Blob Storage for file attachments with access controls
  • Authentication: Azure AD integration with multi-factor authentication support
  • Access Control: Role-based permissions limiting data access to authorized personnel
  • Backups: Regular encrypted backups for data recovery

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy:

  • Active User Data: Retained while your account is active
  • Order Data: Retained for operational and historical purposes
  • Audit Logs: Retained for security and compliance purposes
  • Automated Cleanup: Our GDPR admin tool allows authorized personnel to remove outdated data

Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

Right to Access

Request a copy of the personal data we hold about you

Right to Rectification

Request corrections to inaccurate or incomplete data

Right to Erasure

Request deletion of your personal data (Right to be Forgotten)

Right to Restriction

Request limitation on how we process your data

Data Portability

Request your data in a structured, machine-readable format

Right to Object

Object to certain types of data processing

GDPR Management Tools

We have implemented comprehensive GDPR compliance tools within the system:

  • PII Search: Search for personal identifiable information (emails, phone numbers, names) across all system data
  • Selective Redaction: Redact specific PII while preserving surrounding context
  • Bulk Operations: Perform multiple redactions simultaneously
  • Audit Logs: Complete audit trail of all GDPR actions and data access
  • Automated Cleanup: Policy-based automated removal of outdated data

How to Exercise Your Rights

To exercise any of your GDPR rights, including the Right to be Forgotten, please contact us:

Subject Line: GDPR Request

Please include your name, email address, and a detailed description of your request. We will respond to your request within 30 days as required by GDPR regulations.

Questions or Concerns

If you have any questions about this GDPR policy, how we handle your data, or wish to report a data protection concern, please contact our technical support team at:

Last Updated: November 4, 2025