Privacy
What Nordsynk stores and why
Nordsynk exists to authenticate Fortnox-backed MCP sessions and operate the integration safely. The website is not the primary product surface, but it still handles a small amount of identity and operational data.
Identity and account data
Nordsynk stores the internal Nordsynk user id, Fortnox tenant id, company name, organization number, last login timestamp, and when available the Fortnox-linked email address and Fortnox user identifier.
Session data
Nordsynk uses encrypted browser cookies to keep the web admin surface and the MCP authorization surface in sync across `nordsynk.se` and `mcp.nordsynk.se`. Those cookies contain the Nordsynk user id, tenant id, company name, and the approved Fortnox integration scopes needed to reuse the session safely.
Licensing and company connection state
For the Fortnox Marketplace rollout, Nordsynk caches company connection records and Fortnox seat-verification results so the service can decide whether a user should be allowed to connect.
Operational telemetry
Nordsynk records limited operational events such as OAuth activity, MCP tool names, durations, and success or failure state in its first-party Cloudflare telemetry stores. A strictly filtered, pseudonymous subset is mirrored to PostHog EU Cloud for product learning. Raw Fortnox records, company names, organization numbers, email addresses, free-form messages, OAuth material, and approval payloads are not included in that mirror.
Cookies and site analytics
Nordsynk uses Google Analytics 4 (measurement ID G-Y1VLVFJWVP) and PostHog EU Cloud to understand how the site and onboarding are used. Analytics storage is denied by default and PostHog does not start until you click Allow cookies. Before acceptance, Google receives only aggregated, cookieless Consent Mode pings without identifiers. After acceptance, PostHog records intentional product events and may record fully masked sessions on marketing and onboarding pages: all visible text, form inputs, and element attributes are masked, and dashboard, agency, operations, authentication callback, and approval pages are excluded. Raw accounting data is never included. Google Analytics events are retained for 14 months and processed by Google LLC in the United States under the EU Standard Contractual Clauses; PostHog data is processed in the EU. You can change your choice at any time via “Manage cookies” in the footer.
Support chat
If you message us through the support chat, we store the message, the page it was sent from, and the email address you provide. The message is also sent to our Slack channel so the team can follow the conversation and reply directly. When AI replies are enabled, message text is sent to the AI provider to generate a response. Slack and AI replies are shown in the chat.
Marketing and ad audiences
To reach companies similar to our customers, we may normalize and hash customer email addresses before sending the hash to advertising platforms such as Meta and Google. Hashing reduces direct exposure, but the hash remains personal data and is used for audience matching, measurement, suppression, and related advertising purposes described here. The legal basis is our legitimate interest in marketing the service; you can object at any time by emailing hello@nordbeam.io and we will exclude your address from future audiences.
Fortnox data access
Fortnox data is accessed through authenticated MCP sessions and Fortnox-issued OAuth tokens. Each user connects with their own Fortnox account, and access remains subject to that user's company permissions, product licenses, Nordsynk seat, and the approved integration scopes.
Privacy contact and updates
Nordsynk is provided by Nordbeam AB. Questions, access requests, correction requests, or deletion requests can be sent to hello@nordbeam.io. This notice may be updated when the service, Fortnox requirements, or supported MCP clients change.