Last updated August 9, 2026.
In brief
This statement explains how ProsessPilotene AS processes personal data when you use our websites, identity portal, the ProsessPilotene mobile app and associated APIs, or contact us through digital forms. We only collect data for specific purposes, restrict access, and delete or anonymize data when we no longer have a legitimate and lawful need for it.
Important processing you should be aware of: A logged-in user can save profile and organization information, messages, preferences, and consents. The app may synchronize saved items and topic selections, register an installation ID and a push token, and send usage data to Google Analytics when analytics is enabled. Errors and diagnostic data may be sent to Sentry. Queries submitted to the AI search are sent via Vercel AI Gateway to OpenAI. You should therefore not enter special categories of personal data, information subject to a duty of confidentiality, or other confidential information in searches, messages, feedback, or contact forms unless this is expressly necessary and agreed upon.
1. Data Controller and Contact Information
ProsessPilotene AS is the data controller when we determine the purposes and means of the processing.
- Company name: ProsessPilotene AS
- Organisation number: 897 658 372 VAT
- Business address: Skysstasjon 11B, 3rd floor, 1383 Asker
- Postal address: P.O. Box 86, 1371 Asker
- Email: support@prosesspilotene.no
- Phone: 66 90 19 00
Mark the email “Privacy” if your enquiry concerns your rights. Do not send your national identity number, health information, passwords or other confidential information by regular email.
When we process personal data solely on a customer's instructions as part of a consulting or managed service, the customer is normally the data controller and ProsessPilotene is the data processor. In such cases, the processing is governed by the customer's privacy policy and the data processing agreement with the customer.
2. The personal data we process, purposes and legal bases for processing
2.1 Visits to the websites
When you visit the websites, we process technical information such as your IP address, time of access, requested page, referring page, browser, device type, language, approximate region, and information about errors and performance. Essential cookies and local storage are used for purposes including security, session management, login, language, theme, and consent preferences.
The purpose is to provide and secure the services, prevent misuse, troubleshoot issues, and understand technical performance. The legal basis for processing is our legitimate interest in secure and stable operations, pursuant to Article 6(1)(f) of the General Data Protection Regulation. Non-essential analytics or tracking is based on consent, pursuant to Article 6(1)(a) and Section 3-15 of the Norwegian Electronic Communications Act. You can find details and change your preferences at /cookies.
2.2 Contact, events and marketing
When you submit a form or contact us, we may process your name, email address, telephone number, employer or company name, message, areas of interest, consent preferences, event details, and subsequent correspondence. The web form and app form will normally create an enquiry or lead in Microsoft Dynamics 365/Dataverse.
We use the information to respond to the enquiry, prepare for or follow up on a potential agreement, and manage events. The legal basis is Article 6(1)(b) where the processing is necessary prior to entering into or for the performance of a contract, and otherwise our legitimate interest in following up on enquiries, cf. point (f). Electronic marketing and newsletters are sent on the basis of valid consent where required, cf. point (a) and the Norwegian Marketing Control Act. You may unsubscribe or withdraw your consent at any time.
2.3 Account, login, profile and organizations
When you create or use an account, we may process your Auth0 user ID, selected login provider, verified email address, name, phone number, alternative email address, postal address, profile picture, language and theme preferences, login and security events, linked identities, organization affiliations, roles, invitations, and active organization selections. Profile and customer information is stored primarily in Auth0 and Microsoft Dynamics 365/Dataverse. A profile picture may also be made available via a time-limited, signed image URL, and Gravatar may be used to suggest a profile picture.
The purpose is to authenticate you, provide the appropriate access, manage your profile and organizations, and deliver the features you request. The legal basis is Article 6(1)(b). Security logging, access control, and abuse prevention are also based on our legitimate interests, cf. point (f). Information that must be retained to comply with legal requirements is processed under point (c).
2.4 Information in the mobile app
The app stores certain information on the device in encrypted or local storage: access, ID, and refresh tokens in secure storage; a random installation ID; saved articles; preferred topics; notification preferences; followed podcasts; listening progress; downloaded episodes; content for offline use; inbox data; language, theme, and text size. Local information normally remains until you remove it, log out where doing so clears account data, clear the app data, or uninstall the app.
When you are logged in, saved items, preferred topics, and notification preferences may be synced with your account. An installation ID and a push token, device platform, and registration time may be stored on the server to deliver notifications and podcast updates. Podcast subscriptions may be linked to the installation ID when you are logged out or to your account when you are logged in. The purpose and legal basis are to provide the features you request, cf. Article 6(1)(b). Push notifications also require permission in the operating system and can be turned off at any time.
2.5 Messages, tasks, notifications, support, and feedback
When you use the inbox, we may store an account or contact identifier, thread title, message text, sender name, direction, timestamp, read status, task status, links, and a reference to a related customer service case or CRM record. The messages are used to provide the inbox and follow up on enquiries and tasks, pursuant to Article 6(1)(b) and our legitimate interest in maintaining appropriate customer communication, pursuant to point (f).
Feedback submitted through the app or website may include the text you enter, your email address and name if you provide them or are logged in, as well as technical context. The “Send diagnostics” feature only sends data when you actively choose to do so and may then include a privacy-filtered log from the current app session, the app and build version, update channel, and the identity already associated with the Sentry session. This is used for support and troubleshooting based on our legitimate interest, cf. point (f).
2.6 Analytics, error reporting, and performance
The mobile app may send a random analytics ID, platform, screen views, and feature events to Google Analytics 4. The search term is not included in the analytics event; for searches, only the length of the query is recorded. Other events may include a content ID or title, such as for playback, saving, sharing, and the use of filters. In the app version available on 9 August 2026, analytics was enabled on first use and could be disabled in the settings. Non-essential analytics requires valid prior consent under Section 3-15 of the Electronic Communications Act and the General Data Protection Regulation; the solution must therefore be changed so that analytics is not enabled until such consent has been given.
Sentry is used for errors, crashes, performance, and voluntary feedback. Information may include stack traces, routes, device and operating system information, app version, performance metrics, and limited event context. For logged-in users, the contact ID, name, and email address may be linked to the event so that we can provide assistance. Default collection of personal data is disabled, and free-text fields are filtered for email addresses and values resembling phone numbers before being sent, to the extent permitted by the solution. The legal basis is our legitimate interest in security, stability, and troubleshooting, cf. Article 6(1)(f).
2.7 Search and AI-generated answers
When you use the “Ask” feature, we process the question, the selected language, relevant excerpts from our published content, the IP address for short-term rate limiting, and the generated answer. The question and excerpts are sent via Vercel AI Gateway to OpenAI to generate an answer. Answers may be cached for up to 24 hours under a key that is a cryptographic hash of the normalized question and language. IP-based rate-limit data is used in a rolling 60-second window, and an aggregate daily counter expires at the next midnight UTC.
The purpose is to provide the feature, limit misuse, and control costs. The legal basis is Article 6(1)(b) when you request an answer, and our legitimate interest in preventing misuse under point (f). Do not include personal data or confidential information in your question. The answers are not used to make automated decisions about you.
2.8 Job applications
When you apply for a job, we may process your name, contact details, CV, application, portfolio, attachments, qualifications, interview notes, references and correspondence. The purpose is recruitment and assessment prior to a potential employment contract, pursuant to Article 6(1)(b), and our legitimate interest in conducting a proper recruitment process, pursuant to point (f). Attachments uploaded to the website are stored in a private Azure container and are normally marked for deletion after 180 days. Other application information is normally deleted no later than one year after the process has concluded, unless you consent to longer retention or we need it for a legal claim.
2.9 Maps, videos, podcasts and external links
When you open maps, play content, or follow an external link, Google Maps, YouTube, Spotify, Apple, or other providers may receive your IP address, device information, and usage events in accordance with their own terms. They may be independent data controllers. We try to use privacy-friendly embeds where possible, but recommend that you read the provider’s privacy policy.
3. Where the information comes from
- you, when you register an account, complete your profile, or submit a form, message, job application, feedback, or search
- the login provider you choose, such as Auth0-connected social or passwordless connections
- your employer or organization, for example through an invitation, membership, or role change
- the device, browser, and infrastructure delivering the request
- our customer, financial, and support systems when the information is necessary to display or follow up on your customer relationship
- publicly available business information where relevant and lawful
4. Who we share information with
We do not sell personal data. We use service providers that process data on our behalf in accordance with agreements and our instructions, or that act as independent data controllers for certain functions. Depending on which functions you use, this may include:
- Microsoft for Dynamics 365/Dataverse, Azure storage, security, and other cloud services
- Auth0/Okta and the selected identity provider for login, account security, and organizational affiliation
- Vercel for hosting, network logs, performance, and AI Gateway
- Sanity and Cloudinary for published content and media delivery
- Neon and Upstash for the in-app inbox, synced settings, rate limiting, and short-lived response caching
- Sentry for error reporting, performance, diagnostics, and feedback
- Google for Analytics, Maps, and YouTube when these features are used
- OpenAI as the model provider for AI-generated responses via Vercel AI Gateway
- Expo, as well as Apple and Google, for app distribution, updates, and push notifications
- Gravatar for profile picture suggestions, and Spotify or Apple Podcasts when you open their services
- recruitment, communications, and professional advisers where necessary for the purpose
We may also disclose information to public authorities when required by law or when necessary to establish, exercise or defend legal claims.
5. Transfers outside the EEA
Several of our service providers operate internationally. Personal data may therefore be processed outside the EEA or be accessible to service providers established in third countries. Before any such transfer, we will ensure that there is a valid transfer mechanism under Chapter V of the General Data Protection Regulation, such as an adequacy decision, the EU–US Data Privacy Framework for certified recipients, or the European Commission’s Standard Contractual Clauses with the necessary supplementary measures. You may contact us for information about applicable transfers and how to obtain a copy of the relevant safeguards.
6. Storage and deletion
We determine the retention period based on the purpose, account status, most recent activity, statutory time limits, security requirements, and potential legal claims. The key rules are:
- Account, profile, and organization information is retained while the account or customer relationship is active. After termination, information that does not need to be retained for legal, security, or legal claims documentation purposes is deleted or anonymized.
- Contact and sales information is retained while the inquiry is being followed up. If the inquiry results in a customer relationship, the information becomes part of the customer records. Marketing information is retained until you withdraw your consent or opt out; a minimal opt-out record may be retained to respect your choice.
- Active message threads are marked for deletion after 90 days of inactivity. Open tasks are exempt until they are completed. Technical deletion markers and backups may remain for a limited period thereafter before being overwritten in accordance with operational procedures.
- Push tokens are retained until you disable or unregister notifications, the token becomes invalid, or the account/installation is deleted. Followed podcasts and synchronized preferences are retained until you remove them or delete the account.
- Local app data is retained on the device until you remove it, log out where the feature clears account data, clear the app data, or uninstall the app.
- AI responses are cached for up to 24 hours. IP-based rate limiting uses a 60-second window, and the aggregate daily counter expires at the next midnight UTC.
- Job application attachments are normally marked for deletion after 180 days. Other application information is normally deleted no later than one year after the process has concluded, unless another legal basis applies.
- Technical logs, analytics events, and error events are retained in accordance with the relevant provider’s documented settings and are reviewed regularly. Information required for security purposes or an ongoing incident may be retained for longer until the matter has been resolved.
7. Cookies, app storage, and permissions
From 1 January 2025, Section 3-15 of the Electronic Communications Act requires consent to non-essential cookies and similar technologies to meet the requirements of the General Data Protection Regulation. Consent must be freely given, specific, informed, unambiguous, demonstrable, and as easy to withdraw as it is to give. Strictly necessary technologies are exempt when they are required to provide a service you explicitly request.
On the website, you can manage your choices at /cookies. In the app, you can change analytics preferences and push notifications under settings, and you can also revoke system permissions in iOS or Android. Some local storage is necessary for login, security, offline content, and features you request.
8. Security
We use technical and organizational measures appropriate to the risk, including access controls, encrypted data transmission, secure token storage, private file containers, signed image URLs, environment separation, logging, rate limiting, backups, and privacy filtering of error data. No solution is entirely risk-free. If an incident may pose a risk to your rights, we will handle it and provide notification in accordance with the General Data Protection Regulation.
9. Your rights
When the conditions set out in the regulations are met, you may request access, rectification, erasure, restriction, and data portability. You may object to processing based on legitimate interests and may always object to direct marketing. If the processing is based on consent, you may withdraw it without affecting the lawfulness of the processing carried out before the withdrawal. You also have the right to lodge a complaint with the Norwegian Data Protection Authority.
Send the request to support@prosesspilotene.no and mark it “Privacy”. You can also initiate an account deletion request in the app where this feature is available. We may ask for the information necessary to verify your identity. We will respond without undue delay and normally within one month, subject to the exceptions and extensions permitted by law.
The Norwegian Data Protection Authority: P.O. Box 458 Sentrum, 0105 Oslo, telephone +47 22 39 69 00, www.datatilsynet.no.
10. Children and automated decision-making
The Services are not designed for children under the age of 13, and we do not knowingly request personal data from children. Contact us if you believe that a child has provided us with information without a valid legal basis. We do not use the information described here to make decisions that are based solely on automated processing and that produce legal effects or similarly significantly affect you.
11. Changes
We update this statement when the services, providers, or regulations change. The date at the top indicates the most recent material update. In the event of material changes that affect how we use information, we will provide notice in an appropriate manner on the website, in the app, or by email when necessary.
12. Legislation and official guidance
- The Personal Data Act and the General Data Protection Regulation (GDPR): https://lovdata.no/dokument/NL/lov/2018-06-15-38
- The Norwegian Data Protection Authority’s guidance on information and transparency: https://www.datatilsynet.no/rettigheter-og-plikter/virksomhetenes-plikter/informasjon-og-apenhet/
- The Norwegian Data Protection Authority’s guidance on legal bases for processing: https://www.datatilsynet.no/rettigheter-og-plikter/virksomhetenes-plikter/om-behandlingsgrunnlag/
- The Norwegian Data Protection Authority’s guidance on new cookie rules from 1 January 2025: https://www.datatilsynet.no/aktuelt/aktuelle-nyheter-2024/nye-cookie-regler-fra-1.-januar/
- The Norwegian Data Protection Authority's guidance on transfers outside the EEA: https://www.datatilsynet.no/rettigheter-og-plikter/virksomhetenes-plikter/overforing-av-personopplysninger-ut-av-eos/