Nordkastell
Apps Client Pricing Log in Early access
Apps Client Pricing Log in Early access

Privacy policy

Nordkastell gives each customer a server of their own. Your workspace data lives on that server, and we only hold what we need to sell you the service and keep it running.

Last updated
26 September 2026
Operated by
H5 Förnyelsebyrå AB

Contents

  1. In short
  2. Who is responsible
  3. What we collect and why
  4. This website
  5. Data on your server
  6. The Snacka apps
  7. Google Calendar in Alma
  8. Other companies involved
  9. How long we keep data
  10. Your rights
  11. Security
  12. Transfers outside the EEA
  13. Changes and contact

In short

  • Your messages, files, calendars and other workspace content are stored on your own server, not in a shared Nordkastell database.
  • We hold your customer account and basic health figures from your server, not your content.
  • We do not sell personal data, use it for advertising, or use it to train AI models.

Who is responsible

Nordkastell is operated by H5 Förnyelsebyrå AB. We are the data controller for this website and for your customer account.

For everything inside your workspace, your organisation is the controller and we are your processor. You decide who gets access and what goes in. We handle it only to run the server and apps you asked for. A data processing agreement is available on request.

What we collect and why

Our own systems hold:

  • Your customer account: name, email address and role. Passwords are stored in a form that cannot be read back.
  • Sign-in sessions: the IP address and browser a session started from. Sessions expire on their own.
  • Sign-in with Google or GitHub, if you use it: the name, email address and picture on that account.
  • Early-access requests: what you fill in on the form: name, email, phone, company, team size, the apps you are interested in, what you mainly want to use them for, your preferred region, your timeline, your interest in AI, what you use today and whether and from what you want help moving. We also keep the request's status, our own notes on it, and the invitation code we send you.
  • Server health: figures like CPU, memory and disk use, and a log of what we have done on your server, such as installing or updating an app. Numbers, not content.
  • Billing, once it starts: which plan and apps you pay for, and your invoices.

We process your account and server data to deliver the service you signed up for (our contract with you). Health monitoring and security logs rest on our legitimate interest in running a service that works. An early-access request rests on your consent, which you can withdraw at any time by writing to us. Invoices are kept because bookkeeping law requires it.

This website

This site uses no cookies and no third-party trackers, which is why there is no cookie banner. We count visits ourselves, on our own server.

For each visit we store the page, the site you came from, the language, your country, your browser type and device type, and how long the page was open. We never store your IP address, and nothing is saved on your device. Visits cannot be linked from one day to the next. If your browser sends Do Not Track or Global Privacy Control, we collect nothing.

Data on your server

Your workspace is a server we set up and manage for you. Everything your team puts into the apps is stored on that server, and it is not copied into any central Nordkastell system. Passwords or keys you give an app, for example to connect a calendar or a mailbox, are stored there too.

Because we manage the server, our staff can reach it to install and update apps and to fix problems. We use that access to run the machine, not to read what is on it.

When we diagnose a fault, our staff can fetch the latest lines of your server's logs through our platform: up to 1,000 lines per app, plus the logs of the web server and of our agent on the machine. Logs can contain personal data, such as email or IP addresses. The platform shows them to our staff and does not store them.

Email

Email from your workspace, such as sign-in links, password resets, invitations to the workspace and Alma's meeting invitations, is sent by our platform through Loopia. A meeting invitation from Alma can go to people outside your workspace, and it carries their name and address, the host's name, the meeting's title and proposed times, any note the host wrote, and links to answer. The platform passes each message on and does not store it.

AI features

The AI app is optional. Nothing goes to an AI provider until your workspace installs it and connects an AI account, either a person's own Claude or ChatGPT account or a workspace AI key. From then on, what the AI works on is sent to Anthropic (for Claude) or OpenAI (for ChatGPT), both in the USA:

  • What people ask Reda, and the workspace content Reda reads to answer them, such as messages, calendars or hours it looks up on their behalf.
  • Students' answers in a Tempa exam, when the teacher uses automatic grading, together with the question and its marking guide. The student's name is not sent.
  • Incoming email, when the workspace sets up an email assistant in the AI app.

What the provider does with that data is governed by its own terms for the connected account.

The playground

The playground, our public demo workspace, is shared by every visitor and wiped every night. Do not put anything real in it.

The Snacka apps

Snacka, our chat and video call app, also comes as a phone app for iPhone and Android and as a desktop app for Windows, Mac and Linux. The apps connect to your workspace's own server, the same one the web version uses, and you sign in with the account your workspace gave you. Everything under data on your server applies to them too. This section covers what is different about an app.

What the apps ask for

On a phone or a Mac, the system asks you before the app can use the camera, the microphone or notifications, and you can change your answer in its settings.

  • Camera: for video calls, and in the phone app for taking a photo to send in a message.
  • Microphone: for calls.
  • Notifications: to tell you about new messages and calls, as described below.
  • Photos and files: the phone app opens the phone's own picker when you attach a photo or a file, or choose a profile picture, and only what you pick is sent. It never reads your photo library on its own.
  • For calls on Android, the app also uses Bluetooth for headsets, keeps the phone awake, and shows an incoming call over the lock screen.

The apps do not ask for your location or your contacts.

What is stored on your device

The phone app keeps your sign-in in the phone's own cookie storage, as a browser does. Signing out ends that session on your workspace's server.

In the phone's secure storage (the Keychain on an iPhone, encrypted storage on Android) it keeps your workspace's address, a random ID for this installation of the app, your choice of light or dark theme, the emoji you used recently, which conversation with Reda you had open last (for a day), and messages you have written that have not been sent yet, until they are.

To open quickly, the app keeps a copy of the channel list and the workspace's member list, with names, email addresses and pictures, in its cache. Images, videos and files you open are cached too. Signing out deletes the copy of the lists and any unsent messages. Cached images and files stay until the phone clears its cache or you remove the app. Messages themselves are only held in memory while the app runs, and drafts are saved on your workspace's server, not on the phone.

The desktop app keeps your workspace's address in its settings, and otherwise stores what the web version stores in a browser: your sign-in, a random ID for the installation, the camera, microphone and speaker you chose, your layout, theme and language, and the browser's cache.

Notifications on phones

To make a phone show a notification, it has to go through Apple (on an iPhone) or Google (on Android). A message notification carries what you see on the lock screen: the sender's name, the channel's name and the whole text of the message. The Snacka phone app asks for permission to show notifications when someone signs in, and message notifications only go to a phone that allows them.

Calls work differently on an iPhone. The app registers for incoming calls as soon as someone signs in, without asking, so a call to that person always goes through Apple, with the caller's name.

The phone's notification address is stored on your workspace's server, with your account. Every phone notification passes through our platform on its way to Apple or Google, because the platform holds the app's credentials with them. The platform sees the notification as it is sent, together with the phone's notification address and its unread count, passes it on and does not store it. No other push service is involved. Notifications in the desktop app are shown by your computer itself, and browser notifications are encrypted so the browser maker cannot read them.

Calls

The sound and video of a call go between the app and your workspace's own server, which passes them on to the others in the call. If a network blocks a direct connection, they go through a relay that also runs on your server. They never pass through another company.

Calls are encrypted on the way to and from your server. They are not end-to-end encrypted, because the server has to pass them on. Calls are not recorded or transcribed. Outside voice channels, the conversation keeps a note of the call: who started it, who joined and how long it lasted, or that it was missed.

On an iPhone, incoming calls use the phone's own call screen, and can show up among the recent calls in the Phone app, like calls from other apps.

Other apps inside the phone app

The phone app can open your workspace's other apps, like Alma or Tida. It shows them inside Snacka, signed in as you with a one-time code from your workspace, so you do not have to sign in again. They are the same web apps you would open in a browser, on the same server. Links that lead anywhere else open in your phone's browser. In the desktop app, the other apps open in windows of their own.

Link previews

When a message contains a link, your workspace's server fetches the page's title and picture to show a preview. The app then loads the picture straight from that site, which sees your IP address, as it would if you opened the link.

Updates

Each time the phone app starts, it asks Expo (USA) whether there is an update to its code. Expo sees the phone's IP address, the app's version, a random ID that Expo's software creates for the installation, and, if the app crashed the last time it ran, the error message from that crash. Larger updates come through the App Store or Google Play.

The desktop app checks our platform for updates when it starts and every few hours, and downloads them from GitHub (USA). Both see your computer's IP address. Updates are signed, and the app only installs one we have signed.

No tracking

The apps contain no analytics, advertising or tracking tools, and no crash reporting of our own. Apart from what Expo sees when the phone app checks for updates, only your workspace's server learns anything about how the app runs: while the app is connected, the server knows which installation it is and which version it runs, so it does not send a notification to a phone you are using right then.

Google Calendar in Alma

Alma is our shared team calendar. A member can choose to connect their Google account, so their calendar shows up next to their colleagues' and they can create and change events from Alma. Nothing happens until they approve it on Google's consent screen.

What Alma accesses and stores

Alma asks for the account's email address and for read and write access to its calendars. Write access is needed to create meetings, move them and answer invitations. Alma does not touch contacts, mail, files or anything else on the Google account.

For the calendars the member picks, Alma stores the calendar's name and colour, the account's email address, and a copy of the events from 90 days back to a year ahead: each event's title, description, location, start and end, organiser, and guest list with the guests' names, email addresses and replies. Calendars the member does not pick are never stored. All of this, including the sign-in tokens from Google, is kept on your own workspace server, and the tokens are encrypted there with a key that never leaves that server. During sign-in the browser passes through our platform for a moment on its way back to your server; we store nothing from it.

What Alma writes back to Google

Alma writes only to calendars the member picked and that Google lets them change. It creates, changes and deletes events and answers invitations when the member does so in Alma, and when an event has guests it asks Google to send them the invitation, as Google Calendar itself would.

Who else sees it

Colleagues in the workspace see the titles and times of events in the calendars a member chooses to share with the team. The description, location and guest list are shown only to the member. Each member can also subscribe to the team calendar from their own calendar app through a private link, which carries the same titles and times with each person's name; the company behind that calendar app, such as Google or Apple, fetches it. A booking page a member sends to someone outside the workspace shows only the free times the member offered.

Disconnecting

A member can disconnect Google in Alma's settings at any time. Alma then asks Google to revoke its access, and deletes the stored events, calendars and tokens straight away. The same happens when the person is removed from the workspace. Access can also be withdrawn at myaccount.google.com/permissions; Alma then can no longer reach the calendar, and disconnecting in Alma deletes the copy it already has.

Google API Services Limited Use

Nordkastell's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only for the calendar features the member connected it for. It is never sold, never used for advertising, never used to develop, improve, or train generalized AI and/or ML models, and not shared with anyone except as needed for those features, for security or where the law requires it. No one at Nordkastell reads it unless the member asks us to, or security or the law requires it.

Other companies involved

These help us run every workspace:

  • Hostup (Sweden): Runs the servers workspaces live on.
  • deSEC (Germany): DNS, which points your workspace's addresses at your server.
  • Let's Encrypt (USA): Issues the certificates that keep connections to your workspace secure.
  • Loopia (Sweden): Sends the email from our platform and from your workspace, such as sign-in links, password resets, invitations and Alma's meeting invitations. Each message passes through our platform, which does not store it.
  • GitHub (USA): Hosts the app software your server downloads when an app is installed or updated, and the desktop app's downloads and updates.
  • A European payment provider: Takes payment once billing starts. We will name the provider here before then. Card details go to the provider, never to us.

These receive nothing until someone on your team chooses to use the feature behind them:

  • Apple (USA / EU) and Google (USA / EU): Deliver notifications to phones with the Snacka app. What they carry is described under notifications on phones above.
  • Expo (USA): Delivers updates to the Snacka mobile app, for people who install it. What it sees is described under the Snacka apps above.
  • Anthropic (USA) or OpenAI (USA): Run the AI features when your workspace connects an AI account. What is sent is described under AI features above.
  • Google, iCloud or another calendar server: When someone connects their calendar to Alma.
  • Your own mail server: When you set up an email assistant in the AI app.
  • GitHub (USA): When your workspace connects a code repository, or someone signs in to their customer account with GitHub.
  • Google (USA / EU): When someone signs in to their customer account with Google.
  • Slack (USA): Only while an import from Slack that you started is running.

How long we keep data

Workspace data stays as long as you keep it. You decide what is deleted, and we never wipe a server's disks without asking you first.

Your customer account and invoices are kept while you are a customer.

Early-access requests: Ask us and we will delete yours.

Your rights

Under the GDPR you can ask us for a copy of your personal data, to correct it, to delete it (where we are not required to keep it), to get it in a machine-readable form, to restrict how we use it while a question about it is settled, and to stop processing we base on our legitimate interest. We answer within a month. You can also complain to the supervisory authority, which in Sweden is Integritetsskyddsmyndigheten (IMY).

If the data is inside a workspace, send the request to the organisation that runs it, since they are the controller. We will help them answer. How someone who uses Snacka asks for their account and data to be removed is described under deleting your account.

Security

  • All traffic is encrypted, with certificates renewed automatically.
  • Our staff log in to servers only with a key, never a password, and repeated failed attempts are blocked.
  • Your server's operating system gets security updates automatically.
  • After every app update we check that the app is healthy, and put the previous version back if it is not.

Found a vulnerability? Our security page says how to report it.

Transfers outside the EEA

Workspace data stays where your server is, which today is always Sweden. A few services we rely on are based in the USA: certificates, app and desktop downloads from GitHub, and the features your team chooses to turn on, like phone notifications or an AI provider. Where data leaves the EEA, it is covered by the European Commission's standard contractual clauses or an adequacy decision.

Changes and contact

We update this page when the product changes, and the date at the top shows when. If a change materially affects how we handle your data, we will tell you.

Questions, or a request under your rights: privacy@nordkastell.se.

© 2026 Nordkastell. All rights reserved.

Privacy policy | Terms of service | Support | Security | Delete account
English | Svenska