Privacy policy
Last updated: September 2026
SecureGate Card is a product of Nordic Byte LTD (Companies House no. 16978110), 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. This policy explains what personal data we process, for what purpose, and what rights you have under the UK GDPR and the Data Protection Act 2018.
What data we process
- Account data: name, email, master password (never in plain text; a key is derived locally and never reaches our servers).
- Vault content: passwords, notes and cards, encrypted end to end before leaving your device.
- Technical usage data: IP address, device type, access and audit logs, needed for the security of the service.
- Billing data (Team and Business plans): handled by Stripe; we do not store full card numbers.
- If you enable the message hub: metadata for the channels you connect (SMS, calls, Telegram, Slack, Discord, email), as authorised by you.
Why we process it
To provide the contracted service (contract performance), for platform security (legitimate interest) and, where applicable, to meet legal tax and accounting obligations.
Encryption and access
Vault content is encrypted on your device. Nordic Byte has no technical way to read your passwords in plain text. Access to the admin panel is restricted to strictly necessary staff and is recorded in the audit log.
Who we share data with
With infrastructure and payment providers strictly necessary to operate the service (hosting, Stripe for billing). We do not sell personal data to third parties or use it for advertising purposes.
Where it is stored
The servers that provide the service are operated by Nordic Byte LTD. If data is ever transferred outside the United Kingdom or the European Economic Area, the safeguards required by the UK GDPR will apply (standard contractual clauses or another valid mechanism).
How long we keep it
For as long as the account is active. If you cancel, we keep the minimum data required by legal obligations (for example, tax) and delete the rest within a reasonable period.
Your rights
Access, rectification, erasure, objection, restriction of processing and portability. You can exercise them by writing to info@nordicbyte.co.uk. You also have the right to complain to the UK data protection regulator, the Information Commissioners Office (ICO).
Changes to this policy
We may update this document. If the change is significant, we will notify you by email or from the dashboard itself.
Contact
Nordic Byte LTD — info@nordicbyte.co.uk