Privacy
Privacy policy
Last updated: 24 August 2026
This policy explains how NORVION processes business contact details, technical project information, uploaded files and first-party funnel analytics on norvionpower.com.
1. Controller and contact
NORVION, a Critical Power company headquartered in the Netherlands, is the controller for the processing described in this policy. Privacy and data-rights requests can be sent to project@norvionpower.com.
2. Data we process
When you contact us, we may process your name, company, country, role, business email, optional phone number, request type and correspondence.
For project assessment we may process facility and application details, required power, phases, redundancy, autonomy, project timing, current UPS brand, technical notes and files such as specifications, spreadsheets, drawings, single-line diagrams or images. Please provide only information necessary for the assessment.
The site records limited first-party events, a random visitor and session identifier, language, device category, landing page, referrer and campaign parameters. These events do not contain the form values you enter.
3. Purposes and legal bases
We use the data to answer requests, assess project or pilot fit, prepare technical questions and preliminary configurations, discuss partnerships, manage the sales and pilot pipeline, protect the forms against abuse, operate the website and measure qualified business outcomes.
Depending on the interaction, the legal basis is steps taken at your request before a contract, performance of a contract, your consent, compliance with legal obligations, or NORVION’s legitimate interests in secure website operation and relevant B2B relationship management. You may object to processing based on legitimate interests.
4. Analytics, identifiers and cookies
NORVION uses first-party visitor and session identifiers stored in the browser to understand the path from a page visit to a technical request, pilot application or partner enquiry. We do not use this information for cross-site advertising or sell it to advertising networks.
No third-party advertising tracker is currently configured. If optional marketing or non-essential analytics cookies are introduced, consent will be requested where required.
5. Recipients and hosting
Requests are stored in protected server storage and uploaded files are kept outside the public website. The website is hosted on HostVDS infrastructure in Latvia. Access is limited to authorised NORVION personnel and providers that need the data for hosting, security, project assessment, communications or legal compliance.
NORVION does not sell personal data. Service providers act under appropriate contractual and confidentiality obligations.
6. International transfers
Project work may involve authorised teams in the Netherlands and Uzbekistan, while hosting is located in Latvia. If personal data is transferred outside the European Economic Area, NORVION uses an applicable legal transfer mechanism and additional safeguards where required.
7. Retention
Inactive or unqualified enquiries are reviewed after 24 months from the last meaningful contact and deleted or anonymised when no continuing business, engineering or legal need exists. Technical files for enquiries that do not progress are normally reviewed after 12 months.
Records connected with an active project, pilot, contract or legal obligation may be retained for the relationship and for up to seven years afterwards where required for contractual, accounting, warranty or legal records. First-party funnel analytics are normally retained for up to 13 months; routine security logs are normally retained for up to 30 days unless needed to investigate an incident.
8. Security
Measures include encrypted transport, access-controlled CRM and storage, restricted file types and sizes, anti-spam checks, server hardening and backups. No online service can guarantee absolute security. If you believe data was sent in error or exposed, contact us promptly.
9. Your rights and complaints
Subject to applicable law, you may request access, correction, deletion, restriction or portability, object to processing, and withdraw consent. Withdrawal does not affect processing that was lawful before withdrawal. We may request reasonable proof of identity and authority to act for a company.
You may also complain to the competent supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens.
10. Automated decisions, children and changes
The website does not make solely automated decisions with legal or similarly significant effects. The service is intended for a professional B2B audience and not for children.
We may update this policy when the product, infrastructure, processing or law changes. The current revision date is shown above.
