Privacy Policy

Last updated: 8 June 2026

1. Introduction

The purpose of this privacy policy (the “Privacy Policy“) is to explain how we, DPPA AS, business registration no. 935 969 425 (the “Company“, “we” or “us“), process your personal data. It describes how we safeguard your personal data when you use our website, products and services, what data we collect, why we collect it, and how we use it when delivering our services, when you visit our website, or when you contact us for support.

If you have any questions about this Privacy Policy, how we process your personal data, or our privacy practices in general, please contact us at contact@dppa.no.

For information about your rights and how to exercise them, see section 6, “Your rights as a data subject”, below.

2. Our role

We are a data controller of personal data in relation to our customers, visitors to our website, potential customers who contact us (by email, social media, our website or otherwise), and job applicants. As a controller, we are responsible for ensuring that your personal data is processed lawfully in accordance with the Norwegian Personal Data Act, which implements the EU General Data Protection Regulation (collectively, “GDPR“), and that the processing is necessary for stated and relevant purposes.

For our own communications on social media, we act as a controller for the personal data we process for those purposes. The social media platforms are independent controllers for the personal data they process for their own purposes.

If we process personal data on behalf of a customer as part of delivering our services, we act as a data processor. In that case, the processing is governed by a separate data processing agreement entered into with the customer, not by this Privacy Policy.

3. What data do we collect and why?

3.1 General interaction

When you provide personal data about yourself to us, for example through a contact form on our website, by email, or when you purchase our services, we use this data to fulfil your request and to deliver our services.

For these purposes, we may process the following personal data:

– Name

– Phone number

– Email address

– Postal address

– Purchase and order information, including payment information

We only collect data that is necessary for the specific request or contract, and some fields may be optional.

The lawful basis for processing not described otherwise below is the performance of a contract with you, or taking steps at your request before entering into a contract, in accordance with GDPR art. 6(1)(b). For general inquiries that do not lead to a contract, we rely on our legitimate interest in responding to your request, in accordance with GDPR art. 6(1)(f).

We process and store your data only as long as necessary to fulfil your request or our contractual obligations. After that, we delete, pseudonymise or anonymise the data unless we are required to keep it longer under applicable law (for example, the Norwegian Bookkeeping Act). Specific retention periods are described in section 7.

3.2 When you visit our website

When you visit our website, our web server and a limited set of cookies automatically collect technical information from your device, including:

– IP address

– date and time of access

– the name and URL of the accessed file

– browser type and version

– other information sent by your browser (such as your operating system, access provider and approximate location).

We process this data to ensure a stable and secure connection to our website, to provide a user-friendly experience, to evaluate system security and stability, and for administrative purposes. The lawful basis is our legitimate interest in operating a secure and functioning website (GDPR art. 6(1)(f)).

You may also contact us through our website. To respond to your request or inquiry, we process your name, your email address, and any other personal data you choose to share with us.

For details on the cookies we use and their durations, see section 3.7 and our cookie policy at dppa.no/cookies.

3.3 Support

We offer support through different channels based on your choice:

– a contact form on our website, routed to an internal email address

– inquiries through our social media accounts

– inquiries by email.

To provide support, we may collect your name, email address, IP address, country of residence, relevant product or account information, and any other personal data you choose to share with us.

We use this data to answer your questions and handle your requests, comments or feedback. The processing is necessary for the performance of a contract with you or to take steps at your request (GDPR art. 6(1)(b)).

We keep support data for up to three years after your inquiry is resolved, in order to document our handling, unless we are required to retain it longer under applicable law (for example, the Norwegian Bookkeeping Act) or to manage a dispute. Some support requests may be handled by our service providers (for example email and helpdesk systems) acting as processors on our behalf.

3.4 Recruiting

In recruitment, we process personal data provided by the applicant (and, where relevant, received from recruitment platforms or referees) to assess your application and take steps at your request before entering into an employment contract. The lawful bases are taking steps at the data subject’s request prior to entering into a contract (GDPR art. 6(1)(b)) and/or the applicant’s consent (GDPR art. 6(1)(a)).

We typically process your contact details, CV and application information, education and work history, and information from interviews and assessments. We do not ask for, and do not wish to receive, special category personal data (such as health, ethnicity or political views) as part of a job application.

Ability and personality tests, as well as limited online searches, are carried out based on our legitimate interest in finding the right candidate (GDPR art. 6(1)(f)). We will only contact the applicant’s references with the applicant’s consent (GDPR art. 6(1)(a)).

We store your personal data for the duration of the relevant recruitment process. If we wish to store your personal data for future recruitment needs, we will ask for your consent. You can withdraw your consent at any time, after which we will no longer store your personal data for recruitment purposes. For candidates who are hired, separate procedures for storing personal data apply.

3.5 Social media

The Company is present on LinkedIn. Through this platform we can see posts, likes, followers, comments and messages directed to us, as well as aggregated statistics about visits, activity on our pages and the performance of any content. Our processing for these purposes is based on our legitimate interest in communicating with customers and potential customers (GDPR art. 6(1)(f)).

The roles of the parties are as follows:

– For personal data you provide directly on the platform (for example your profile information, posts and comments), the platform and the Company act as joint controllers.

– We do not download or store this information ourselves as a matter of course. However, if you contact us via direct message or comment and we need to follow up (for example on support or a complaint), we may retain copies of the relevant correspondence in our systems. Information left on the platform remains accessible to us for as long as we keep our account there. You can delete information about yourself at any time, for example by removing content or reactions you have posted. Your data will not be deleted simply because you stop following us.

Depending on the platform, it may process personal data outside the EU/EEA, including in the United States, as described in its own privacy policy. The basis for such transfers is the EU Standard Contractual Clauses. We encourage you to read the platform’s privacy policy for the processing it carries out as a controller.

3.6 Disputes

We may process personal data where necessary to handle disputes, complaints, audits or other legal claims — for example data relevant to assessing, establishing, exercising or defending a claim. We may share such data with our advisers, insurers, counterparties, courts or authorities where necessary. The lawful basis is our legal obligation to do so (GDPR art. 6(1)(c)), or our legitimate interest in establishing, exercising or defending legal claims and documenting our position (GDPR art. 6(1)(f)).

We process such data for as long as the dispute is ongoing, and for as long as necessary afterwards.

3.7 Cookies

A “cookie” (in Norwegian: *informasjonskapsel*) is a small text file placed on your browser, and thereby your device, when you visit a website. We use only a limited set of cookies that are necessary to make our website work and to support its performance.

We do not use cookies for advertising or for tracking you across websites.

The cookies we use fall into two categories:

Essential cookies, required for the website to function and to keep it secure (for example our contact form tool and core website services).

Performance cookies, used to deliver interactive and dynamic content.

The lawful basis for essential cookies is our legitimate interest in operating a secure and functioning website (GDPR art. 6(1)(f)). The current list of cookies, their providers and durations is maintained at dppa.no/cookies.

You can also use your browser settings to block or delete cookies, but some parts of the website may not work properly without essential cookies. Further information about managing cookies in common browsers is available from your browser provider:

Chrome · Safari · Safari Mobile · Firefox · Microsoft Edge

4. Where we process your data / third parties

4.1 Service providers

We use trusted service providers to help us operate and improve our services, for example for hosting, email and communication systems, customer support tools, and error reporting. These providers normally act as our data processors and only process personal data on our instructions and for our purposes. We have data processing agreements in place with them and require appropriate security measures.

We do not transfer your data to third parties unless there is a lawful basis for doing so, and we do not sell any personal data. Some third parties may process personal data for their own purposes (for example social media platforms). In those cases, the third party is responsible for that processing and its own lawful basis.

Our services are hosted on Microsoft Azure within the EU/EEA. For more detail on where and how your data is hosted and secured, see dppa.no/security-and-compliance.

4.2 Social media

As set out in section 3.5, we maintain a social media presence. The majority of the processing that takes place on the platform is carried out by the platform as a controller; please read its privacy policy for that processing.

4.3 Business transactions

We may share relevant personal data with third parties such as lawyers, advisers, buyers and prospective buyers in connection with a business transaction — for example a merger, acquisition or sale of shares (including transfers made as part of insolvency or bankruptcy proceedings). Non-disclosure agreements will protect any personal data shared for this purpose.

5. Security measures

Protecting your personal data is a high priority for us. Our services are hosted on Microsoft Azure, and we apply appropriate technical and organisational measures, including:

– encryption of all communication with our user interface and APIs using HTTPS with TLS;

– authentication via Microsoft Entra ID, with multi-factor authentication mandatory across critical services;

– access to production systems limited on a least-privilege basis, with regular access reviews;

– automated backups with multiple retention tiers and regular restore testing.

Our infrastructure provider, Microsoft Azure, maintains recognised security certifications, including ISO/IEC 27001 and SOC 1, 2 and 3. When we use service providers, we require them to apply suitable security measures.

If we detect a security or personal data breach, we assess and document it, take steps to limit harm, and report it internally to management. Where required by law, we notify the Norwegian Data Protection Authority (Datatilsynet) and, where the breach is likely to result in a high risk to your rights and freedoms, we notify you, in accordance with GDPR articles 33 and 34. Further detail is available at dppa.no/security-and-compliance.

6. Your rights as a data subject

Subject to applicable law, you may have certain rights in relation to our processing of your personal data, including:

– the right to be informed about how we collect and process your data (this Privacy Policy);

– the right to access a copy of, rectify, correct and update the personal data we hold about you;

– the right to restrict processing or have your data deleted, in certain cases;

– the right to data portability, in certain cases;

– the right to object to processing based on our legitimate interests, in certain cases;

– the right to withdraw any consent you have given, at any time.

Please contact us at contact@dppa.no to exercise any of the above, or if you consider that our processing of your personal data infringes applicable law.

If you consider that our processing infringes your rights, you have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) or your local data protection authority. We encourage you to contact us first so that we can try to resolve or clarify the issue.

7. How long do we store personal data?

We keep and use personal data only for as long as we have a lawful basis for doing so. That may mean days, months or years, depending on the type of data. Where possible, we have stated the storage period for each processing activity under the relevant description in this Privacy Policy.

Information from customer support and from data-subject (GDPR) requests is stored for three years. Any information we are obliged to store under the Norwegian Bookkeeping Act is stored in accordance with that Act.

8. Changes to this privacy policy

We may update this Privacy Policy in response to changing business practices, technology and legal requirements. Any such changes will be posted on our website. If we make a significant change in the way we use or share your personal data, we will notify you by email and/or through other prominent notice at least 30 days before the change takes effect.

Scroll to Top