GDPR Policy & Data Protection
Learn how we protect your personal data and your rights under GDPR
Introduction
NKT Orderbase (Logistics Information & Internal Orders) is committed to protecting your personal data and respecting your privacy. This policy explains how we collect, use, store, and protect your information in accordance with the General Data Protection Regulation (GDPR).
Data We Collect
We collect and process the following types of personal data:
- User Account Information: Name, email address, role, and authentication data
- Order Information: Order details, descriptions, comments, and related metadata
- Communication Data: Comments, feedback, and support requests
- System Usage Data: Login timestamps, actions performed, and audit logs
- File Attachments: Documents and files uploaded to orders and requests
How We Use Your Data
Your personal data is used for the following purposes:
- Managing orders, requests, and logistics operations
- Facilitating communication between team members
- Providing user authentication and authorization
- Generating reports and analytics for operational improvements
- Maintaining audit logs for security and compliance
- Sending notifications about order updates and system activities
Data Storage & Security
All personal data is stored securely using industry-standard encryption and security measures:
- Database: PostgreSQL database with encrypted connections
- Cloud Storage: Azure Blob Storage for file attachments with access controls
- Authentication: Azure AD integration with multi-factor authentication support
- Access Control: Role-based permissions limiting data access to authorized personnel
- Backups: Regular encrypted backups for data recovery
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy:
- Active User Data: Retained while your account is active
- Order Data: Retained for operational and historical purposes
- Audit Logs: Retained for security and compliance purposes
- Automated Cleanup: Our GDPR admin tool allows authorized personnel to remove outdated data
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
Right to Access
Request a copy of the personal data we hold about you
Right to Rectification
Request corrections to inaccurate or incomplete data
Right to Erasure
Request deletion of your personal data (Right to be Forgotten)
Right to Restriction
Request limitation on how we process your data
Data Portability
Request your data in a structured, machine-readable format
Right to Object
Object to certain types of data processing
GDPR Management Tools
We have implemented comprehensive GDPR compliance tools within the system:
- PII Search: Search for personal identifiable information (emails, phone numbers, names) across all system data
- Selective Redaction: Redact specific PII while preserving surrounding context
- Bulk Operations: Perform multiple redactions simultaneously
- Audit Logs: Complete audit trail of all GDPR actions and data access
- Automated Cleanup: Policy-based automated removal of outdated data
How to Exercise Your Rights
To exercise any of your GDPR rights, including the Right to be Forgotten, please contact us:
Please include your name, email address, and a detailed description of your request. We will respond to your request within 30 days as required by GDPR regulations.
Questions or Concerns
If you have any questions about this GDPR policy, how we handle your data, or wish to report a data protection concern, please contact our technical support team at:
Last Updated: November 4, 2025