Privacy Policy

Aligned with GDPR and Norway's Personal Data Act.

What we process

We process contact form data (name, email, message), consent records, security logs, and limited technical metadata required for website protection and abuse prevention.

Legal bases under GDPR

We rely on GDPR Article 6(1)(a) consent for optional cookies and Article 6(1)(f) legitimate interest for website security and communication handling. Where required, legal obligations are handled under Article 6(1)(c).

Retention and deletion

Contact messages are stored for up to 24 months, security logs for up to 12 months, and consent records for up to 12 months. Data is deleted or anonymized when no longer needed.

Data sharing and transfers

We do not sell personal data. Processors are bound by data-processing agreements. If transfers outside the EEA are necessary, we use appropriate safeguards such as Standard Contractual Clauses.

Your rights

You may request access, correction, erasure, restriction, portability, and objection. You can withdraw consent at any time without affecting prior lawful processing.

Complaints and authority

You may contact us first for resolution. You also have the right to lodge a complaint with Datatilsynet (Norwegian Data Protection Authority).

Security controls

We use HTTPS, role-limited access, logging, and periodic review of technical and organizational controls to reduce accidental or unauthorized access.

Last updated

Last updated: 08 April 2026.