Last updated: August 2026
Controller responsible for data processing:
nomonkey.work AB
c/o Frederick Kuhrt
Trösslingstorp 2
695 96 Tived, Sweden
Email: nomonkeywork@pm.me
Company registration number: 559596-2720
Registered seat: Örebro län, Laxå kommun
nomonkey.work AB is registered with the Swedish Companies Registration Office (Bolagsverket). Full registration details are available on request.
nomonkey.work AB has not appointed a Data Protection Officer, as none is legally required. For any questions about data protection, please contact us directly at:
Email: nomonkeywork@pm.me
As an IT service provider, we regularly process personal data in the course of our work. We place great importance on protecting your data and complying with applicable data protection requirements.
We process personal data of our users only to the extent necessary to provide our services. The processing of personal data generally only takes place with the user's consent or on the basis of a legal permission.
Where we obtain consent for processing personal data, Art. 6(1)(a) GDPR serves as the legal basis. Where processing is necessary for the performance of a contract, Art. 6(1)(b) GDPR serves as the legal basis.
As an IT service provider, we are also required to enter into data processing agreements with our clients pursuant to Art. 28 GDPR.
In the course of our services as an IT service provider (development, platform ownership, consulting), we process personal data on behalf of our clients. This includes, in particular:
For these processing activities we enter into data processing agreements (DPAs) with our clients pursuant to Art. 28 GDPR. These agreements govern the handling of personal data, the instructions we are bound by, and the technical and organizational measures applied.
We implement extensive technical and organizational measures to protect personal data, including:
We use modern development environments such as GitHub and Vercel, which maintain their own security and data protection standards.
Personal data is disclosed to third parties only within the scope of applicable legal requirements. As an IT service provider, we work with various subcontractors and technology partners (e.g. cloud providers, hosting services). These are carefully selected and are also contractually bound to comply with the GDPR.
In particular, we use the following service providers:
Data processing agreements are concluded with all service providers.
When you contact us by email or via the contact form, the data you provide (name, email address, company, message) is stored by us in order to respond to your inquiry. Processing is based on Art. 6(1)(b) GDPR or on our legitimate interest pursuant to Art. 6(1)(f) GDPR.
We delete the data arising in this context once storage is no longer necessary, or restrict its processing if statutory retention obligations apply.
As part of our free founder calls and advisory sessions, we process personal data for scheduling and conducting the consultation. The legal basis is Art. 6(1)(b) GDPR.
As a data subject, you have the following rights:
To exercise your rights, please contact us at the email address above or use our contact form.
You also have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data. The competent authority for Sweden is:
Integritetsskyddsmyndigheten (IMY)
Box 8114
104 20 Stockholm, Sweden
Email: imy@imy.se
Website: www.imy.se
Personal data is stored only for as long as necessary for the stated purposes, or as required by statutory retention periods. For contractual relationships with clients, commercial and tax law retention periods apply. Once these periods expire, the data is deleted, unless it is still required for the performance or initiation of a contract.
Personal data is transferred to third countries (outside the EU/EEA) only where necessary in connection with data processing services and where the legal requirements of Art. 44 et seq. GDPR are met. This includes, in particular, entering into Standard Contractual Clauses issued by the EU Commission or ensuring an adequate level of data protection at the recipient.
In particular, the use of cloud services and development tools (GitHub, Vercel) may result in a transfer of data to third countries (e.g. the USA). In these cases we ensure an adequate level of data protection through appropriate safeguards (Standard Contractual Clauses, Data Privacy Framework).
When implementing AI systems and agentic workflows for our clients, we pay particular attention to data protection. We ensure that:
We rely on production-ready, auditable AI solutions and avoid vendor lock-in.
Our website does not use tracking cookies or analytics tools. Only technically necessary cookies required for the operation of the website are used. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interest in the functionality of the website).
We reserve the right to amend this privacy policy in order to adapt it to changes in the law or to changes in our services. The current version is always available on our website.
If you have questions about data protection, wish to exercise your rights as a data subject, or have questions about our data processing agreements, you can contact us at any time:
nomonkey.work AB
c/o Frederick Kuhrt
Trösslingstorp 2
695 96 Tived, Sweden
Email: nomonkeywork@pm.me
Email (data protection): nomonkeywork@pm.me
For clients who engage us as a data processor:
As an IT service provider, we are legally required to enter into data processing agreements (DPAs) with our clients pursuant to Art. 28 GDPR. These agreements govern:
We provide our clients with our DPA template on request and support them in preparing Data Protection Impact Assessments (DPIAs) pursuant to Art. 35 GDPR.
Note on legal validity: This privacy policy was prepared on the basis of the GDPR and Swedish data protection law (Dataskyddslagen). It does not constitute legally binding advice. For a complete legal review, we recommend consulting a lawyer specializing in IT law or data protection law with knowledge of the Swedish legal framework.
| Controller | nomonkey.work AB, c/o Frederick Kuhrt, Trösslingstorp 2, 695 96 Tived, Sweden |
|---|---|
| Company registration number | 559596-2720 |
| Data protection contact | nomonkeywork@pm.me |
| Supervisory authority | Integritetsskyddsmyndigheten (IMY), Stockholm |
| Legal bases | Art. 6(1)(a), (b), (f) GDPR |
| Data processing agreements | DPA under Art. 28 GDPR with all clients |
| Data disclosure | GitHub, Vercel, cloud providers (with DPA) |
| Cookies | Technically necessary only, no tracking cookies |
| Data subject rights | Access, rectification, erasure, restriction, portability, objection |