Privacy Policy
Feature Detail
Description
The Privacy Policy page discloses how Meander collects, stores, processes, and shares personal data from visitors and prospective customers on the sales website. It covers data gathered through contact forms, analytics, and demo booking flows, explains GDPR rights for data subjects, and identifies the data controller. The page must be written in plain language, linked from every page footer, and kept current as data practices evolve.
User Flow
Analysis
A GDPR-compliant Privacy Policy is a legal obligation for any website collecting personal data, including emails submitted via demo booking and contact forms. Non-compliance risks Datatilsynet fines and reputational damage, particularly since target customers are Norwegian non-profits handling sensitive data themselves. A clear policy builds buyer trust by demonstrating Norse takes data protection seriously — a differentiator when selling to health-adjacent and publicly funded organizations. It satisfies procurement checklists and reduces legal risk before any commercial relationship is established with prospective client organizations.
Implement as a static Next.js page served without authentication. Store content in MDX or a lightweight CMS so the legal team can update the policy without engineering involvement. The page must display a visible last-updated date, identify the data controller, list all processing purposes, and include a link to Datatilsynet. Use semantic HTML headings and lists to support screen readers. Link from the footer on every sales site page and from the demo booking form where personal data is first collected. A print-friendly stylesheet ensures buyers can generate a PDF for their procurement records.
Components (109)
Shared Components
These components are reused across multiple features
User Interface (12)
Service Layer (34)
Data Layer (22)
Infrastructure (38)
User Stories
No user stories have been generated for this feature yet.