nomonkey.work
Privacy

Privacy Policy for nomonkey.work AB

Last updated: August 2026

1. Controller and Data Protection Officer

Controller responsible for data processing:

nomonkey.work AB
c/o Frederick Kuhrt
Trösslingstorp 2
695 96 Tived, Sweden
Email: nomonkeywork@pm.me

Company registration number: 559596-2720
Registered seat: Örebro län, Laxå kommun

nomonkey.work AB is registered with the Swedish Companies Registration Office (Bolagsverket). Full registration details are available on request.

Data Protection Officer

nomonkey.work AB has not appointed a Data Protection Officer, as none is legally required. For any questions about data protection, please contact us directly at:

Email: nomonkeywork@pm.me

As an IT service provider, we regularly process personal data in the course of our work. We place great importance on protecting your data and complying with applicable data protection requirements.

2. General Information on Data Processing

2.1. Scope of processing of personal data

We process personal data of our users only to the extent necessary to provide our services. The processing of personal data generally only takes place with the user's consent or on the basis of a legal permission.

2.2. Legal basis for the processing

Where we obtain consent for processing personal data, Art. 6(1)(a) GDPR serves as the legal basis. Where processing is necessary for the performance of a contract, Art. 6(1)(b) GDPR serves as the legal basis.

As an IT service provider, we are also required to enter into data processing agreements with our clients pursuant to Art. 28 GDPR.

3. Data Processing in Connection with our IT Services

3.1. Processing on behalf of a controller

In the course of our services as an IT service provider (development, platform ownership, consulting), we process personal data on behalf of our clients. This includes, in particular:

For these processing activities we enter into data processing agreements (DPAs) with our clients pursuant to Art. 28 GDPR. These agreements govern the handling of personal data, the instructions we are bound by, and the technical and organizational measures applied.

3.2. Technical and organizational measures

We implement extensive technical and organizational measures to protect personal data, including:

We use modern development environments such as GitHub and Vercel, which maintain their own security and data protection standards.

3.3. Disclosure of data to third parties

Personal data is disclosed to third parties only within the scope of applicable legal requirements. As an IT service provider, we work with various subcontractors and technology partners (e.g. cloud providers, hosting services). These are carefully selected and are also contractually bound to comply with the GDPR.

In particular, we use the following service providers:

Data processing agreements are concluded with all service providers.

4. Processing of Contact Data and Communication

4.1. Contacting us by email or contact form

When you contact us by email or via the contact form, the data you provide (name, email address, company, message) is stored by us in order to respond to your inquiry. Processing is based on Art. 6(1)(b) GDPR or on our legitimate interest pursuant to Art. 6(1)(f) GDPR.

We delete the data arising in this context once storage is no longer necessary, or restrict its processing if statutory retention obligations apply.

4.2. Advisory calls

As part of our free founder calls and advisory sessions, we process personal data for scheduling and conducting the consultation. The legal basis is Art. 6(1)(b) GDPR.

5. Your Rights as a Data Subject

As a data subject, you have the following rights:

To exercise your rights, please contact us at the email address above or use our contact form.

You also have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data. The competent authority for Sweden is:

Integritetsskyddsmyndigheten (IMY)
Box 8114
104 20 Stockholm, Sweden
Email: imy@imy.se
Website: www.imy.se

6. Retention Period

Personal data is stored only for as long as necessary for the stated purposes, or as required by statutory retention periods. For contractual relationships with clients, commercial and tax law retention periods apply. Once these periods expire, the data is deleted, unless it is still required for the performance or initiation of a contract.

7. Transfer of Data to Third Countries

Personal data is transferred to third countries (outside the EU/EEA) only where necessary in connection with data processing services and where the legal requirements of Art. 44 et seq. GDPR are met. This includes, in particular, entering into Standard Contractual Clauses issued by the EU Commission or ensuring an adequate level of data protection at the recipient.

In particular, the use of cloud services and development tools (GitHub, Vercel) may result in a transfer of data to third countries (e.g. the USA). In these cases we ensure an adequate level of data protection through appropriate safeguards (Standard Contractual Clauses, Data Privacy Framework).

8. Data Protection in AI Integration

When implementing AI systems and agentic workflows for our clients, we pay particular attention to data protection. We ensure that:

We rely on production-ready, auditable AI solutions and avoid vendor lock-in.

9. Cookies and Analytics

Our website does not use tracking cookies or analytics tools. Only technically necessary cookies required for the operation of the website are used. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interest in the functionality of the website).

10. Changes to this Privacy Policy

We reserve the right to amend this privacy policy in order to adapt it to changes in the law or to changes in our services. The current version is always available on our website.

11. Contact

If you have questions about data protection, wish to exercise your rights as a data subject, or have questions about our data processing agreements, you can contact us at any time:

nomonkey.work AB
c/o Frederick Kuhrt
Trösslingstorp 2
695 96 Tived, Sweden
Email: nomonkeywork@pm.me
Email (data protection): nomonkeywork@pm.me


Supplementary Note for Clients (Data Processing)

For clients who engage us as a data processor:

As an IT service provider, we are legally required to enter into data processing agreements (DPAs) with our clients pursuant to Art. 28 GDPR. These agreements govern:

We provide our clients with our DPA template on request and support them in preparing Data Protection Impact Assessments (DPIAs) pursuant to Art. 35 GDPR.


Note on legal validity: This privacy policy was prepared on the basis of the GDPR and Swedish data protection law (Dataskyddslagen). It does not constitute legally binding advice. For a complete legal review, we recommend consulting a lawyer specializing in IT law or data protection law with knowledge of the Swedish legal framework.

Summary of Key Points

Controllernomonkey.work AB, c/o Frederick Kuhrt, Trösslingstorp 2, 695 96 Tived, Sweden
Company registration number559596-2720
Data protection contactnomonkeywork@pm.me
Supervisory authorityIntegritetsskyddsmyndigheten (IMY), Stockholm
Legal basesArt. 6(1)(a), (b), (f) GDPR
Data processing agreementsDPA under Art. 28 GDPR with all clients
Data disclosureGitHub, Vercel, cloud providers (with DPA)
CookiesTechnically necessary only, no tracking cookies
Data subject rightsAccess, rectification, erasure, restriction, portability, objection