Introduction and scope
Norditech AB, Swedish company registration number 559266-7280 ("Norditech", "Incredible", "we", "us" or "our"), builds Incredible, a voice-first assistant that works across the applications already on your computer.
This Privacy Policy ("Policy") explains how we collect, use, share and otherwise process personal data about users, prospective users, website visitors, job applicants and business contacts ("you"). It applies to our websites, the Incredible desktop applications and browser extension, any other client we make available, our sales, support, marketing and recruitment activities, and any other product or service that links to this Policy (together, the "Services").
We process personal data in accordance with the EU General Data Protection Regulation (GDPR), the UK GDPR, the Swiss Federal Act on Data Protection, Canada's PIPEDA, applicable United States state privacy laws, and other data protection laws applicable to us ("Data Protection Laws").
If your employer or another organisation provided Incredible to you, that organisation is generally the controller of the data processed through the Services, and its own privacy notice governs. Our processing in that context is carried out on its instructions under a data processing agreement. See Section 2.
Some processing takes place solely on your device and the resulting data is never transmitted to us. That processing is not carried out by us and is not covered by this Policy.
Our role: controller and processor
We are a controller when we decide why and how personal data is processed — for individual and self-serve use of the Services, our websites, marketing, sales, support, recruitment, security, billing, and product analytics and improvement.
We are a processor where an organisation has agreed with us to provide the Services to its personnel and processes personal data through the Services on its own behalf. There we act on that organisation's documented instructions under a data processing agreement, which prevails over this Policy for that processing.
We may act in both roles at once: processor for the content an enterprise organisation processes through Incredible, controller for the data we collect to operate, secure, bill for and improve the Services.
What we collect
What we actually collect depends on how you use the Services and on the settings and consents you choose.
- Information you provide — account details such as name, email, settings and plan, billing details, correspondence with us, and application materials or business contact details. Payments are processed by our payment provider; we do not receive or store full payment card numbers.
- Records of what the assistant did — for each task, structured records of how it went: the outcome, how many steps it took, which capabilities and tools it used, how long each stage took, the model involved, error types, and where relevant the application or website it worked in. These records describe what happened, not what was said or shown: they do not contain your instructions, the assistant's replies, the contents of your screen, or the arguments passed to tools.
- Automatically collected data — usage and technical data such as feature events, session identifiers, device and application metadata, performance measurements, and crash and error reports. A crash report can include a technical snapshot of the application's state at the time of the fault, and so may incidentally contain fragments of what was being processed.
- Integration data — data accessed from third-party applications you connect, within the scopes you authorise.
We do not collect the content of your interactions unless you choose to send it to us. What you say, what the assistant replies, and what is on your screen are processed to carry out your instruction and are not kept by us afterwards. There are two ways you can choose otherwise:
- Turning diagnostics on. The app then sends us detailed technical bundles that do contain that content, so we can investigate problems. Diagnostics is off by default, nothing in it is collected until you switch it on, and switching it off deletes what we hold (Section 5.1).
- Sending us a session or a report yourself. When you report a problem or choose to share what happened in a particular session, what you send includes that content. You decide each time, and you can see what is included before you send it.
Because Incredible works inside the applications you are working in, what it processes to carry out an instruction — and what a diagnostics bundle contains, if you have turned diagnostics on — may incidentally include information about people other than you, or information you did not intend to share. If you use Incredible in an environment containing personal data about others, you are responsible for being permitted to do so; if you use it for work, your organisation is responsible for the lawfulness of that use. The Services are not designed for processing special category data, government identifiers, payment card data or credentials, and we ask you not to direct them at such data.
How we use data
We use the data described above to:
- provide, maintain and personalise the Services, including executing your instructions and maintaining your preferences;
- keep the Services safe and secure, including authentication, fraud and abuse prevention, and incident investigation;
- provide support and respond to your requests;
- bill and account for the Services and meet bookkeeping obligations;
- understand usage and improve the Services — working out what fails, how often and where, from the structured records described in Section 3, and from diagnostics where you have turned it on. You can turn the structured records off in the app's settings;
- communicate with you about the Services, and — with your consent or as otherwise permitted — for marketing;
- recruit, and manage relationships with business contacts;
- comply with law and establish, exercise or defend legal claims.
AI model training. We do not use identifiable personal data or customer content to train general-purpose AI models. We may use aggregated, anonymised or de-identified data, which no longer identifies you, for any lawful purpose, including improving our models and Services.
No sale. We do not sell personal data, and we do not share it for cross-context behavioural advertising.
Our offerings
The desktop app
Incredible runs on your device and interacts with the applications and windows you work in. To carry out an instruction it may interpret what is on your screen — the active application, window titles, on-screen text and the elements it needs to interact with. Context is captured in connection with instructions you initiate.
To offer useful suggestions, the app may also draw on the day's events from your calendar, the sender and subject line of recent messages where you have connected an email account, and a summary of which applications and sites you use, measured on your device. Message contents are not read for suggestions.
When you speak to Incredible, your audio is processed to understand and carry out your instruction, which may include transmission to speech-recognition providers. We do not create voice profiles and we do not use voice data to identify or authenticate you; we do not process biometric data for the purpose of uniquely identifying a person.
The app also collects usage data to keep the Services reliable.
Two separate controls in the app's settings govern this, and they work differently:
- Diagnostics is off by default and only collects anything if you turn it on. It is an explicit opt-in: when enabled, the app sends us detailed technical bundles that can include the content of your interactions and what was on your screen, so we can investigate problems. You can turn it off at any time, and we then delete what we hold. Separately, you can send us a single session or a problem report without turning diagnostics on; that sends the same kind of content, once, for the session you chose.
- Product improvement is on by default and you can turn it off. It governs the structured records described in Section 3 — outcomes, step counts, tools used, timings and error types — which we use to work out what to fix. It carries no content from your instructions or your screen. Turning it off stops us receiving it.
We do not offer end-to-end encryption and do not describe the Services as end-to-end encrypted. Data transmitted to us is encrypted in transit and at rest and is accessible to a limited number of authorised personnel (Section 9).
The browser extension
The Incredible browser extension is the browser control surface for the desktop app. It communicates only with the Incredible desktop app on your device over a local connection; the extension itself transmits no data to Norditech or any other server. Outside an active, user-initiated task session or teach recording, the extension does not access your tabs and does not read your browsing history. During an explicit teach recording, started and stopped by you and visibly indicated on the affected tabs, it observes your own interactions in those tabs; secure-field values such as passwords are redacted in the browser before leaving the page. The extension stores a single randomly generated identifier used only to distinguish browser profiles on your device; it contains no personal data and is removed with the extension.
Data the assistant handles in your browser reaches us, if at all, through the desktop app, and is then treated as described in this Policy.
Third-party integrations
Where you connect a third-party application, we access the data necessary to carry out the actions you request, within the scopes you authorise. You can review or revoke authorisations at any time. Your use of the third-party application remains governed by that provider's own terms and privacy notice. Where we access data from Google APIs, our use and transfer of that data adheres to the Google API Services User Data Policy, including the Limited Use requirements.
AI processing
Instructions and their context are processed by large language models and related AI services operated by third-party providers. Our providers process your data under agreements that prohibit them from using it to train their models. Incredible is an AI system and is identifiable as such in use. It acts on instructions you initiate and does not make decisions producing legal or similarly significant effects on you without your involvement.
Legal bases
Where the GDPR or UK GDPR applies, we rely on:
- Contract — providing the Services, executing your instructions, account administration, billing and support.
- Legitimate interests — securing the Services, preventing fraud and abuse, business communications and recruitment, and collecting structured records of how the Services perform in order to improve them, which you can turn off in the app. Where we rely on legitimate interests we have assessed that our interest is not overridden by your rights; you may object at any time (Section 10).
- Consent — where we ask for it, such as certain diagnostic collection and marketing. You may withdraw consent at any time without affecting prior processing.
- Legal obligation — bookkeeping (bokföringslagen 1999:1078), and responding to valid legal process.
We do not collect Swedish personal identity numbers (personnummer) or equivalent national identifiers except where clearly justified and permitted by law.
International transfers
We are established in Sweden and our primary infrastructure is located in the EU/EEA. Some of our service providers are located outside the EU/EEA. Where we transfer personal data to a country without an adequacy decision, we rely on appropriate safeguards such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, the Swiss Addendum, or the recipient's certification under the EU-US Data Privacy Framework, together with supplementary measures such as encryption and access restriction where required. You may request a copy of the relevant safeguards by contacting us.
Retention and security
We keep the data associated with your account for as long as your account exists. When your account is deleted, we delete or anonymise that data, except where we are required or permitted to retain it — in particular accounting records, which Swedish law requires us to keep for 7 years after the end of the calendar year in which the financial year ended, and data needed to establish, exercise or defend legal claims. Diagnostic data, which we collect only if you turn diagnostics on, is deleted 30 days after we receive it, and sooner if you turn diagnostics off — switching it off deletes what we already hold.
Not all data is tied to an account. Where it is not, we apply the following criteria:
- Marketing and business contacts — for as long as we have a business relationship with you or a legitimate interest in staying in touch. You can ask us to stop contacting you, or to delete your details, at any time, and we will.
- Job applications — for the duration of the recruitment process and the period in which a related legal claim could be brought, which under the Swedish Discrimination Act (2008:567) is two years after the process ends. We keep applications for future opportunities only with your consent.
- Website analytics — no longer than 13 months.
- Technical and security logs — up to 90 days, extended only where we need a specific log to investigate a security incident.
- Product analytics — the structured records of how the Services perform are kept for as long as they are useful for understanding and improving the product. Where they identify you, they are deleted when your account is deleted.
Backups and deletion. Our database provider keeps rolling backups covering the last 7 days, so data you delete — including on account deletion — disappears from those backups within a week. Some of the third-party services we use hold data under their own controls; where deletion there is not automatic, we action it as part of our deletion process.
Security. We maintain technical and organisational measures appropriate to the risk, including but not limited to encryption of data in transit and at rest, authentication and access controls that restrict access to those who need it, row-level separation of user data in our databases, and logging of access to systems holding personal data. If a personal data breach occurs, we will notify the relevant supervisory authority and affected individuals where the law requires it. No system is completely secure; keep your credentials confidential and notify us promptly of suspected unauthorised access.
Your rights
Subject to applicable law, you may access your personal data, rectify it, erase it, restrict processing, object to processing based on legitimate interests (and to direct marketing at any time), receive a portable copy, and withdraw consent. We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you.
To exercise a right, contact nikola@norditech.se. We may need to verify your identity, and we will respond within one month, extendable for complex requests. If we act as a processor for your organisation, direct your request to that organisation and we will assist it in responding.
Regional notes. You may lodge a complaint with a supervisory authority; ours is the Swedish Authority for Privacy Protection (IMY), Box 8114, 104 20 Stockholm, imy@imy.se. UK residents may complain to the ICO and Swiss residents to the FDPIC. Depending on your US state of residence you may have rights to confirm, access, correct, delete, obtain a copy, and opt out of sale, sharing and targeted advertising — we do not sell or share personal information as defined under those laws or use it for targeted advertising, and we will not discriminate against you for exercising your rights; denied requests may be appealed by replying to our decision and then to your state Attorney General. Canadian residents may withdraw consent subject to legal or contractual restrictions and may complain to the OPC. Where local law grants you further rights, those rights apply.
Children
The Services are not intended for individuals under 18, and we do not knowingly collect personal data from them. If you believe a minor has provided us with personal data, contact nikola@norditech.se and we will delete it.
Changes to this Policy
We may update this Policy to reflect changes in our practices, the Services or applicable law. We will post the updated Policy on our website and update the date at the top. Where changes materially reduce your rights, we will give reasonable advance notice by email or in-product notification before they take effect.
Contact
If you have any questions about this Policy or about how we handle your data, or if you want to exercise any of the rights in Section 10, contact us.
Privacy contact: Nikola Plantic Tomasic, Business Operations Lead — nikola@norditech.se
Norditech AB
Ståhlgatan 5, 561 44 Huskvarna, Sweden
Registration number 559266-7280
We will acknowledge your enquiry and respond without undue delay, and in any event within one month of receiving a request to exercise your rights.