// REGULATORY_PROTOS

LEGAL
FRAMEWORK

// DATA_SHIELD_PROTOCOL

PRIVACY POLICY

Effective Date: January 1, 2026 | Last Updated: January 1, 2026

1. DATA CONTROLLER IDENTIFICATION

The data controller responsible for processing your personal data is NorthBridgeWork, registered at 411 04, Kungsgatan 14, Goteborg, Sweden. For all data-related inquiries, contact our designated Data Protection Officer at [email protected].

2. CATEGORIES OF PERSONAL DATA COLLECTED

We collect and process the following categories of personal data through our digital infrastructure:

  • /// Identity Data: Full name, professional designation, and organizational affiliation provided via contact forms.
  • /// Contact Data: Email address, telephone number, and postal address submitted during service inquiries or payment processing.
  • /// Technical Data: IP address, browser type and version, operating system, device identifiers, and access timestamps collected automatically upon site访问.
  • /// Transaction Data: Payment records, invoice details, and service engagement history processed through our Stripe payment gateway.

3. LEGAL BASES FOR PROCESSING

Your personal data is processed under the following legal bases as defined by the EU General Data Protection Regulation (GDPR):

  • /// Article 6(1)(a) — Consent: Where you have provided explicit consent for specific processing activities.
  • /// Article 6(1)(b) — Contractual Necessity: Processing required for the performance of a contract or pre-contractual measures at your request.
  • /// Article 6(1)(f) — Legitimate Interest: Processing necessary for our legitimate business interests, including service improvement, fraud prevention, and network security, provided such interests do not override your fundamental rights.

4. DATA RETENTION PERIODS

Personal data is retained only for the duration necessary to fulfill the purposes for which it was collected: Contact form submissions are retained for 24 months from the date of last interaction. Transaction records are retained for 7 years in compliance with Swedish financial record-keeping obligations. Technical logs are purged after 12 months. Upon expiration of the retention period, data is securely deleted or irreversibly anonymized.

5. DATA RECIPIENTS AND THIRD-PARTY DISCLOSURE

Your data may be disclosed to the following categories of recipients: Stripe Inc. (payment processing, subject to their Data Processing Agreement), cloud infrastructure providers operating under Standard Contractual Clauses, and Swedish tax authorities where legally mandated. We do not sell, rent, or trade personal data to third parties for marketing purposes.

6. INTERNATIONAL DATA TRANSFERS

Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including EU Standard Contractual Clauses (SCCs) and adequacy decisions as recognized by the European Commission.

7. YOUR DATA SUBJECT RIGHTS

Under the GDPR, you possess the following rights regarding your personal data:

  • /// Right of Access (Article 15): Request a copy of all personal data we hold about you.
  • /// Right to Rectification (Article 16): Request correction of inaccurate or incomplete data.
  • /// Right to Erasure (Article 17): Request deletion of your data where no legal retention obligation applies.
  • /// Right to Restriction (Article 18): Request limitation of processing in specific circumstances.
  • /// Right to Data Portability (Article 20): Receive your data in a structured, machine-readable format.
  • /// Right to Object (Article 21): Object to processing based on legitimate interests or direct marketing.

To exercise any of these rights, submit a written request to [email protected]. We will respond within 30 days of receipt.

8. DATA PROTECTION SUPERVISORY AUTHORITY

If you believe your data protection rights have been infringed, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten), Box 3075, 351 30 Växjö, Sweden.

// COOKIE_TELEMETRY_POLICY

COOKIES POLICY

Effective Date: January 1, 2026 | Last Updated: January 1, 2026

1. COOKIE DEPLOYMENT OVERVIEW

NorthBridgeWork deploys cookies and analogous tracking technologies to maintain operational integrity, enhance user experience, and generate anonymized analytics. This policy details the nature, purpose, and duration of all cookies deployed across our digital infrastructure.

2. ESSENTIAL COOKIES (STRICTLY NECESSARY)

These cookies are mandatory for the fundamental operation of our website. They enable core functionalities such as session management, security token validation, and load balancing. Without these cookies, the site cannot function as intended.

  • /// session_id: Maintains your session state across page requests. Duration: Session. Legal basis: Legitimate interest.
  • /// csrf_token: Prevents cross-site request forgery attacks on form submissions. Duration: Session. Legal basis: Legitimate interest.
  • /// nbw_cookie_consent: Records your cookie consent preference. Duration: 12 months. Legal basis: Consent.

3. ANALYTICS COOKIES (OPTIONAL)

Analytics cookies collect anonymized data about site usage patterns, page performance metrics, and navigation behavior. This data is aggregated and cannot be used to identify individual users. Analytics cookies are only deployed upon your explicit consent.

  • /// _ga / _gid: Google Analytics identifiers for traffic analysis. Duration: 24 months / 24 hours. Deployed only with consent.

4. COOKIE MANAGEMENT

You may modify your cookie preferences at any time by accessing the cookie consent banner displayed upon your initial visit. Additionally, most web browsers allow you to control cookies through their settings. Blocking essential cookies may impair site functionality.

5. UPDATES TO THIS POLICY

We reserve the right to update this Cookies Policy to reflect changes in technology, legislation, or our operational practices. Material changes will be communicated through the cookie consent mechanism upon your next visit.

// RETURN_VECTOR_CLAUSE

REFUND POLICY

Effective Date: January 1, 2026 | Last Updated: January 1, 2026

1. GENERAL REFUND PRINCIPLES

NorthBridgeWork operates a milestone-based delivery model. All payments are tied to specific, pre-defined deliverables within the project scope. Refund eligibility is assessed against the completion status of contractual milestones at the time of the refund request.

2. ELIGIBILITY CRITERIA

  • /// Pre-Execution Cancellation: If cancellation occurs before any project work has commenced, a full refund of all advance payments will be issued within 14 business days.
  • /// Partial Completion: Where a project is cancelled after partial milestone completion, a pro-rata refund will be calculated based on the percentage of uncompleted deliverables relative to the total project scope.
  • /// Post-Delivery: Once a milestone has been delivered and accepted (including a 5-business-day review window), that milestone payment becomes non-refundable.

3. NON-REFUNDABLE ITEMS

The following are excluded from refund eligibility: Third-party licensing fees already disbursed on the client's behalf. Infrastructure setup costs for provisioned servers or domains. Consultation and audit fees for completed diagnostic sessions. Rush-fee surcharges for expedited delivery.

4. REFUND REQUEST PROCEDURE

Refund requests must be submitted in writing to [email protected], referencing the original invoice number and specifying the grounds for the refund. All requests are reviewed within 5 business days. Approved refunds are processed to the original payment method within 14 business days of approval.

5. DISPUTE RESOLUTION

In the event of a refund dispute, both parties agree to attempt resolution through good-faith negotiation for a period of 30 days before initiating formal proceedings. Any unresolved disputes shall be submitted to the competent courts of Gothenburg, Sweden, in accordance with Swedish consumer protection legislation.

// OPERATIONAL_TERMS

TERMS OF SERVICE

Effective Date: January 1, 2026 | Last Updated: January 1, 2026

1. ACCEPTANCE OF TERMS

By accessing, browsing, or utilizing any services provided by NorthBridgeWork (411 04, Kungsgatan 14, Goteborg, Sweden), you acknowledge and agree to be bound by these Terms of Service. If you do not agree with any provision herein, you must discontinue use of our services immediately.

2. SCOPE OF SERVICES

NorthBridgeWork provides web development, digital infrastructure engineering, and related technology consulting services. The specific scope, deliverables, timelines, and pricing for each engagement are defined in individual Service Agreements or Statements of Work executed between the parties.

3. INTELLECTUAL PROPERTY

Upon full payment of all applicable fees, the client receives a perpetual, non-exclusive license to use all deliverables produced under a Service Agreement. Source code ownership transfers to the client upon final payment, excluding any pre-existing frameworks, libraries, or proprietary tools developed by NorthBridgeWork that are incorporated into the deliverables. Such components are licensed to the client in perpetuity for use within the scope of the specific project.

4. CLIENT OBLIGATIONS

The client shall: Provide timely access to necessary systems, accounts, and documentation. Designate a primary point of contact with decision-making authority. Review and provide feedback on deliverables within the agreed review windows. Ensure that all content, imagery, and materials provided for use in the project do not infringe third-party intellectual property rights.

5. CONFIDENTIALITY

Both parties agree to maintain the confidentiality of proprietary information exchanged during the engagement. This obligation survives termination of the Service Agreement for a period of 3 years. Confidential information shall not be disclosed to third parties without prior written consent, except as required by law.

6. LIMITATION OF LIABILITY

NorthBridgeWork's total aggregate liability under any Service Agreement shall not exceed the total fees paid by the client under that agreement. In no event shall NorthBridgeWork be liable for indirect, incidental, consequential, special, or punitive damages, including but not limited to loss of profits, data, or business opportunities.

7. FORCE MAJEURE

Neither party shall be liable for delays or failures in performance resulting from causes beyond its reasonable control, including but not limited to acts of God, natural disasters, war, terrorism, pandemics, government actions, power failures, or internet infrastructure disruptions.

8. GOVERNING LAW AND JURISDICTION

These Terms of Service are governed by the laws of Sweden. Any disputes arising from or relating to these terms or the services provided by NorthBridgeWork shall be subject to the exclusive jurisdiction of the courts of Gothenburg, Sweden.

9. AMENDMENTS

NorthBridgeWork reserves the right to modify these Terms of Service at any time. Material changes will be communicated via email to active clients or posted prominently on our website at least 30 days before taking effect. Continued use of our services following the effective date of any modifications constitutes acceptance of the updated terms.