Privacy policy

How we collect, process and safeguard your personal information across our offices in Stockholm and the United States.

Legal

Last updated: June 2026

Introduction

Nordische Vermögensverwaltung AB ("NVV", "we", "us" or "our") is committed to protecting the privacy and security of your personal data. This policy explains how we collect, use, store and protect your information when you visit our website, use our services or communicate with us.

We process personal data in accordance with the EU General Data Protection Regulation (GDPR), the Swedish Data Protection Act (Dataskyddslagen) and, where relevant to our activities in the United States, the applicable US data protection law.

Data controller

The data controller responsible for your personal data is Nordische Vermögensverwaltung AB, registered office Epicenter, Malmskillnadsgatan 44a, 111 57 Stockholm, Sweden. For any question about this policy or our data practices, please contact us at info@n-vv.com.

Information we collect

Depending on how you interact with us, we may collect the following categories of personal data:

  • Identity data — name, title and, where required for onboarding, date of birth.
  • Contact data — email address, telephone number and postal address.
  • Financial data — investment objectives, risk tolerance and portfolio information.
  • Technical data — IP address, browser type, device information and pages visited.
  • Communication data — correspondence, contact-form submissions and meeting notes.

We collect this information directly from you, through our website, or from third-party sources such as regulatory databases where this is lawfully permitted.

How we use your data

We process your personal data in order to:

  • provide discretionary management and advisory services;
  • respond to enquiries submitted through our website;
  • comply with legal and regulatory obligations, including anti-money-laundering (AML) and know-your-customer (KYC) requirements;
  • communicate with you about our services and relevant market developments;
  • maintain the security and performance of our website; and
  • pursue our legitimate business interests where these are not overridden by your rights.

Legal basis for processing

We rely on the following legal bases under Article 6 of the GDPR:

  • Performance of a contract — to enter into or perform our agreement with you;
  • Legal obligation — to meet financial, anti-money-laundering and tax-reporting requirements;
  • Legitimate interests — to operate, improve and secure our business;
  • Consent — where you have given it, for example to receive communications. You may withdraw consent at any time.

Data sharing and third parties

We do not sell your personal data. We may share it with custodian banks that hold client assets, competent regulatory authorities, professional advisers such as auditors and legal counsel, and technology providers acting under strict data-processing agreements. All recipients are required to protect your data and to process it only on our instructions.

International data transfers

Because we operate from offices in both the European Union and the United States, your personal data may be transferred between the European Economic Area and the United States. Where such transfers take place, they are protected by appropriate safeguards, such as the standard contractual clauses approved by the European Commission or an applicable adequacy mechanism.

Data retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, regulatory and accounting obligations. Client records are typically retained for a minimum of seven years after the end of the business relationship, while enquiries that do not lead to a relationship are generally retained for twelve months.

Your rights

Under the applicable data protection law you have the right to:

  • access the personal data we hold about you;
  • request rectification of inaccurate or incomplete data;
  • request erasure of your data in certain circumstances;
  • restrict or object to our processing;
  • receive your data in a portable, machine-readable format;
  • withdraw consent where processing is based on consent; and
  • lodge a complaint with a supervisory authority.

To exercise any of these rights, please contact us at info@n-vv.com.

Data security

We maintain robust technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. These include encrypted data transmission (TLS), access controls, regular security reviews and ongoing staff training. While no system can be entirely free of risk, we are committed to standards of security commensurate with the sensitivity of the information we handle.

Cookies and analytics

Our website uses only the essential cookies required for proper functionality, such as session management and remembering your language preference. We do not use advertising or tracking cookies. Session cookies are deleted when you close your browser, and the language-preference cookie is retained for thirty days. No personally identifiable information is stored in cookies.

Supervisory authority

If you are located in Sweden or the wider European Union, you have the right to lodge a complaint with a data protection supervisory authority. In Sweden, this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm. We would, however, welcome the opportunity to address your concerns directly before you approach the authority.

Changes to this policy

We may update this policy from time to time to reflect changes in our practices, legal requirements or regulatory guidance. Any material change will be communicated through our website, and the date of the most recent revision is shown at the top of this page. We encourage you to review this policy periodically.

Questions about your data?

Our team is happy to explain how we handle and protect your personal information.

Contact us