This Privacy Policy has been prepared by SmartCraft Norway AS (“SmartCraft” or “we”) to provide you with information about our processing of personal data and the rights you have as a data subject under the General Data Protection Regulation (Regulation (EU) 2016/679) and Norwegian data protection legislation (collectively referred to as the “Data Protection Legislation”).
If you would like more information about the personal data we process about you, or wish to exercise any of your rights, please contact us.
Personal data means any information or assessment that can be linked to a natural person or a small group of people (the “Data Subject(s)”). Examples of personal data include name, national identity number, address, salary information, employment terms, telephone number and email address.
By processing personal data, we mean collection, storage, use, compilation, deletion and any other handling of personal data covered by the Data Protection Legislation.
This Privacy Policy applies to our processing of personal data about the following persons:
Contact persons at customers, suppliers and partners Persons involved in projects we work on Persons who participate in events organised by SmartCraft Norway, or who sign up for our newsletters Candidates for recruitment
SmartCraft Norway is the controller for the processing of your personal data, meaning that we determine the purposes and means of the processing of personal data. As controller, we are responsible for complying with the data protection legislation applicable at any time when we process your personal data. We will be the controller when we receive personal data from a customer in connection with projects we carry out for the customer, and process personal data on our own behalf.
When SmartCraft Norway provides services to customers, the customers are the controllers, while SmartCraft Norway will be the processor. If we process personal data as a processor, we will enter into a data processing agreement with the controller, cf. GDPR Article 28.
We collect and process the following personal data when we deliver our products to a customer and administer the customer relationship:
Contact information: If you are the customer’s contact person or a private customer (a customer who is a natural person), we will collect and process your full name, email address, postal address, telephone number and job title in order to establish and administer the customer relationship.
Billing information: We store information about the assistance we have provided to you, the time of our assistance and how you receive our invoices (for example by email, ordinary post or similar), whether and when the invoices/claims have been paid, and whether the claim has been referred for debt collection. We store the information for billing purposes and to perform our assignment for the customer. We also process billing information to comply with our statutory obligations.
Time registration and initial stamping: We store information about who creates/handles a deviation and when, as well as geographical position. Information about who completed a checkpoint/checklist and when, when a user registers hours and when an order is created, is collected automatically.
Name, date of birth, address and postal code, telephone number, email and fax, job description, language, department and team, next of kin, education, employee ID, start date of employment, probationary period in connection with employment, salary, hourly wage, additional rates, payment dates, working hours, personal notes and other relevant documents you wish to upload.
You are not required to register any of this information, but in most cases it will be appropriate and necessary for the company to obtain sufficient documentation for its projects in relation to the authorities (the Directorate for Building Control), as well as payroll processing (for those who have this). Information registered manually in the system by each individual user also affects how documentation is presented to the authorities.
Information collected automatically consists of actions you as a user perform within the system. Some of this information is used to sufficiently document the work carried out on a project.
We collect and process signatures, names and contact details in order to administer contracts we enter into with our suppliers, customers and partners, and to perform our assignment for the customer.
We collect and process the following personal data when we send emails about our events and seminars/webinars: Contact information: full name, email address, postal address, telephone number, job title and any employer, in order to send you information about events.
We collect, process and store the following personal data about applicants and other relevant candidates when recruiting employees: Contact information: full name, email address, postal address, telephone number, CV, references, job title and any employer, in order to recruit new employees.
When you visit our website, we will store certain cookies on your device.
Processing and storage of information through the use of cookies requires that the visitor is informed that cookies are used, informed about what information is processed, the purpose of the processing, who processes the information, and that you have consented to this, cf. Section 3-15 of the Norwegian Electronic Communications Act.
The use of cookies is governed by the Electronic Communications Act of 2025. Consent must be:
voluntary specific informed unambiguous given through an active action documentable possible to withdraw as easily as it was given
You can read more about our use of cookies on our websites.
If you are the customer’s contact person (for example because the customer is a legal entity), we will process your contact information because it is necessary for purposes related to SmartCraft Norway’s legitimate interests. This legitimate interest is the establishment and administration of the customer relationship we have with the customer for whom you are the contact person.
In the performance of consultancy services, we process personal data about persons other than the customer because it is necessary for purposes related to SmartCraft Norway’s legitimate interests. This legitimate interest is that the processing is necessary for us to deliver consultancy services to the customer. We consider that this interest is not incompatible with your privacy. If such case information contains special categories of personal data, we will process this information because it is necessary for the customer to establish, exercise or defend a legal claim.
We also process billing information to fulfil our statutory obligations under bookkeeping legislation.
We process the personal data described in section 5.1 for purposes related to SmartCraft Norway’s legitimate interests. We use the data we collect to provide you with the products and services we offer, which also includes using the data to improve and customise the user experience. We also use the data to communicate with you, for example regarding updates, new features, security or other information relevant to you.
We use the data for the following purposes:
Optimisation of the user experience: In order to deliver the system in a good and simple way for you as a user, we need data to make informed decisions about what should be changed and improved. This practice is necessary to fulfil the user agreement we have with you.
Support: We use data to answer questions and enquiries you have in connection with our products and services. This practice is necessary to fulfil the agreement we have with you.
System improvements: We continuously collect data to improve and develop our systems. In addition, data is used to maintain and improve performance, as well as to develop and add new features. We use data such as what you click on and how long you stay on a page in order to make good priorities for improving the system. This practice is necessary to fulfil the agreement we have with you.
Security: We use data to improve the security of our systems and to prevent fraud and security breaches. Error reports are used in such contexts so that we can at all times identify any security vulnerabilities that may arise.
Communication, marketing and advertising: We use data to deliver and personalise our communication with you. We may contact you internally in certain software via our chat function, by email or through our support pages to inform you about updates, new features and opportunities. Such communication is also used to inform you about any security breaches. Cookies are used to provide you with the most relevant advertising from us. You may unsubscribe from this type of communication at any time.
We consider that these interests outweigh your privacy interests.
We process the personal data described in section 5.1 for purposes related to SmartCraft Norway’s legitimate interests, namely recruiting and hiring relevant candidates for our company.
We use various service providers that provide IT services and other administrative services to us. We have entered into data processing agreements with these service providers, requiring the relevant companies to ensure that any personal data they process on our behalf is stored securely, is not disclosed to unauthorised parties, and is not used for other purposes.
We will not disclose your personal data to any parties other than those mentioned above, unless we are legally required to disclose this information.
We will delete or anonymise personal data when it is no longer necessary for the purpose for which it was collected, and in accordance with the following deletion routines:
Billing information and personal data related to this will be stored for the period required by statutory requirements, such as bookkeeping legislation.
Personal data specified in the section on events, which we have collected and use in connection with marketing activities, will be stored as long as there is a customer relationship, or, where relevant, until you withdraw your consent to this processing. We consider such a relationship to exist as long as, in recent years, you have received delivery of a product from us or participated in an event organised by SmartCraft Norway.
You have the following rights in connection with our processing of your personal data:
Access: You may contact us if you wish to know more about what personal data we process about you. Rectification: If the personal data we hold about you is inaccurate, you may require us to correct it. Erasure: You may ask us to delete your personal data, which we will respect and comply with, unless, for example, we are required to retain your personal data, or the relevant personal data is necessary to establish, exercise or defend a legal claim. Restriction of processing: In accordance with data protection legislation, you may also require that our processing of your personal data be restricted, provided that the conditions for this under data protection legislation are met. If processing is restricted, your personal data will only be stored. Objection to processing: You have the right to object to the processing of your personal data. Data portability: If we process personal data about you based on consent or to perform a contract, and the personal data is processed automatically, you may ask us to disclose the personal data to you or to a third party in a structured, commonly used and machine-readable format.
Please note that exceptions and limitations to the above rights may apply. For example, we cannot disclose personal data if this would conflict with a duty of confidentiality, or if we are legally obliged to store the information.
If you wish to exercise any of your rights, please contact us. Please note that we may need to ask you to identify yourself, or use another communication channel, as we may need to ensure that you are who you claim to be.
As controller for your personal data, we have the overall responsibility for ensuring that your personal data is processed and stored securely. This means that we must implement technical and organisational measures suitable to ensure satisfactory information security.
For security reasons, there is a limit to how much detail we can provide about the technical security measures we have implemented and established. We can, however, state that all our employees are subject to confidentiality obligations regarding your personal data where necessary, that we have implemented technical and organisational measures to ensure the integrity and availability of your personal data, and that such information does not go astray. When using artificial intelligence, we will assess any consequences for the protection of your personal data before personal data is processed by AI systems. In connection with the assessment of privacy consequences, we will use the classification of AI systems set out in the EU AI Act as a basis, so that the risk level of the AI systems determines the impact assessment.
The Norwegian Data Protection Authority is responsible for monitoring privacy regulations and supervising Norwegian companies’ processing of personal data. You may contact us at any time if you have complaints about our processing of your personal data. You may also complain to the Norwegian Data Protection Authority or a supervisory authority in the EU/EEA country where you live or work, or where the alleged infringement took place.
Contact information for the Norwegian Data Protection Authority can be found on its website. The website also contains further information about our obligations and your rights under applicable data protection legislation.
The applicable data protection legislation in force at any time is available on Lovdata. The Personal Data Act can be found there.
From time to time, we may revise this Privacy Policy as a result of changes to our processing of personal data or new data protection legislation. When the Privacy Policy is changed, an updated version will be published on our website.
We therefore recommend that you review the Privacy Policy from time to time when visiting our website. This Privacy Policy was last updated on 1 June 2025.
Please read these terms carefully before using SmartCraft Flow (hereinafter referred to as the “Solution”), as by using the Solution you accept these terms, which constitute a legal agreement. If you use the Solution as a representative of an organisation, you accept these terms on behalf of that organisation.
“You”, “the customer”, “user” or “your” means the person or organisation registered with us to use the Solution.
“We”, “our” or “us” means SmartCraft Norway AS, a company registered in Norway with organisation number 927150182 and registered address at Strandgata 3, 3513 Hønefoss, Norway, our employees, directors, affiliates and subsidiaries.
“The Solution” means our website and services collectively. The website refers to SmartCraftSpark.com and other websites that we may operate in the future, including all subdomains and websites associated with these domains.
We grant you a non-exclusive, non-transferable licence to use the Solution, provided that you comply with these terms.
You shall not use, attempt to use, permit or enable others to use the Solution to:
sell, sublicense, assign user rights or otherwise grant or transfer rights in the Solution or associated material to third parties, upload, make available or otherwise share information that (i) infringes the rights of third parties, including but not limited to intellectual property rights and personal data, or (ii) contains unlawful, harmful or otherwise offensive material, hack, circumvent technical limitations, create interfaces with the Solution, test the security or configuration of the Solution, or copy, modify, create adaptations or derivative works of the Solution, its content or associated material, or reverse engineer or otherwise attempt to discover or recreate the source code of the Solution and associated applications.
You shall use the Solution in accordance with Norwegian law, regulations and the terms applicable at any time, and provide us with such assistance as is necessary for us to deliver the Solution.
You shall indemnify us against any claims and disputes brought against us by third parties as a result of your use of the Solution in breach of these terms.
All rights in the Solution, adaptations made, associated applications, functions, content, material and data to which you gain access through the Solution, including but not limited to document packages, calculations, various tools, names, logos, trademarks, text and images, etc., belong to SmartCraft Norway AS and/or those from whom SmartCraft Norway AS derives its rights. Subject to the limitations under Norwegian law, you are not entitled to copy, download, use or make available content and material from the Solution without the prior written consent of SmartCraft Norway AS.
If you provide input on how the Solution may be further developed or otherwise changed or improved, all ownership rights, copyrights and other relevant tangible and intangible rights to such input and the results of such input shall accrue to SmartCraft Norway AS.
These rights also include the right to modify and further transfer, cf. Act of 15 June 2018 No. 40 relating to copyright in literary, scientific and artistic works, etc. (the Copyright Act) Section 68.
You retain ownership of data uploaded to the Solution and stored or processed using the Solution (“Customer Data”). The same applies to the result of such processing of Customer Data. We have access to Customer Data to the extent necessary for us to deliver the Solution and user support as agreed, and we have the right to use aggregated and anonymised Customer Data for any business purpose. Provisions in the data processing agreement shall not prevent this.
To use the Solution, you must create an account. You are responsible for keeping your account information confidential and for all activities that occur under your account. You shall notify us immediately if you discover unauthorised use of your account. We reserve the right to suspend or terminate accounts used in breach of these terms.
Payment for use of the Solution is made either monthly or annually, depending on the payment plan you choose. All payments are made in advance. The prices for the service are stated in your agreement or on our website and may be adjusted in accordance with section 7 (Changes).
If payment is not made or we do not receive sufficient payment information, we reserve the right to suspend your access to the Solution until outstanding payment has been received. You are responsible for any costs incurred in connection with late payment, including debt collection costs.
You may add or remove user licences at any time. Changes will take effect from the next payment period, unless otherwise explicitly agreed. Additional licences are charged from the purchase date until the end of the current payment period, and the costs will be invoiced immediately. Reductions in the number of licences will apply from the start of the next payment period.
If you wish to upgrade or downgrade your subscription, this can be done via your account. Changes in functionality or costs resulting from an upgrade or downgrade will take effect from the next payment period, unless otherwise agreed.
Price adjustments: Unless explicitly agreed otherwise with the customer, we reserve the right to adjust the prices for the service. Price changes will take effect in the next payment period, and we will notify you of such changes no later than 30 days before they take effect. If you do not accept the new prices, you may terminate the subscription in accordance with section 8 (Termination and suspension).
You may terminate your subscription at any time by giving us written notice through our stated communication channels. The subscription will end at the expiry of your current payment period, and no refunds will be given for paid but unused periods.
In the event of suspension, we will attempt to notify you in advance and give you a reasonable deadline to remedy the breach, unless suspension is necessary to prevent further misuse or damage.
We reserve the right to close your access to the Solution and/or take other reasonable measures to prevent further misuse if we suspect or discover a breach of these terms. In such cases, we will notify you as soon as possible before suspending the Solution.
To better understand how our service is used, we may analyse (i) the content on an aggregated and anonymised basis, and (ii) by using third-party analytics tools including, but not limited to, Google Tag Manager and Google Analytics.
We reserve the right for errors and inaccuracies in the content of the Solution, and for interruptions in the Solution as a result of maintenance and updates. All use of information from the Solution is at your own risk.
Compensation for indirect losses related to use of the Solution may not be claimed. Indirect losses include, but are not limited to, lost profits and gains of any kind, lost savings and claims from third parties, except awarded liability for infringement. Loss of data is considered an indirect loss, except for the Customer’s reasonable costs related to reconstruction of such data. This applies even if the parties have been informed of the possibility of such losses. Our total annual liability for damages under these terms is limited to the annual fee for the Solution. The limitation also applies to the data processing agreement.
We reserve the right to make changes to the Terms and the Solution, including but not limited to removing and adding functionality, without notifying the User. This also applies if the change is made to comply with a statutory order.
In the event of material changes to the disadvantage of the User, the User will be asked to approve the change at the next login. If the User continues to use the Solution after the change has entered into force, the changes shall be deemed accepted.
These terms are governed by Norwegian law, and any disputes shall be handled by Oslo District Court.
This agreement governs the Processor’s processing of personal data on behalf of the Controller, in accordance with the requirements of the GDPR and Norwegian data protection legislation. The agreement shall ensure that personal data is processed in a secure and lawful manner, and that the rights of the data subjects are safeguarded.
To access the Service, the Controller must provide certain information to the Processor, including the correct name, contact information and email address of each individual user. In addition, users of the Service must allow the Processor to store and retrieve information through the use of cookies, as this is necessary for the login/logout procedures used in the Service and to ensure that unauthorised persons do not gain access to the Service. Consent is voluntary, given through an active action, and may be withdrawn.
The agreement applies to all processing of personal data in connection with SmartCraft Norway’s solution SmartCraft Flow, hereinafter referred to as the Solution. The Controller uses the Solution for administration of access to the system, quotations, calculations, users, hours, projects, checklists, deviations, inspections, etc.
The personal data processed through the Solution is used for the following purposes:
– Administration of user data. – Analysis of user patterns for system optimisation. – User support communication and system maintenance. – Communication regarding operational messages and updates. – Access management to ensure that unauthorised persons do not gain access to the system.
The Controller is responsible for ensuring that the processing of personal data takes place in accordance with the Personal Data Act and the GDPR, see GDPR Article 24. The Controller is also responsible for ensuring that there is a legal basis for the personal data processing that the Processor is instructed to carry out under this agreement, see section 7.
The Processor undertakes to make available all information necessary to demonstrate compliance with the obligations under this agreement and under Article 28 of the GDPR.
Personal data that may be processed includes:
– Name, email address, telephone number and position. – User activity in the system, for example logging of logins, pages visited, buttons clicked, IP addresses and device type. – Information registered by users themselves, including quotation information. – Cookies for login and analytics.
The Processor processes personal data based on the following legal grounds:
– Consent: For the use of cookies and newsletter subscriptions. – Legitimate interest: For administration of business relationships, system optimisation and security. – Performance of contract: To deliver the Solution in accordance with the agreement with the Controller.
The Processor uses subcontractors to deliver the Solution. These include, but are not limited to:
– Microsoft Azure (storage and operations) – Atlas (storage) – MongoDB (storage) – Mixpanel, Hotjar Inc. (measurement and tracking) – Intercom.io (support communication and user storage) – Google, Meta, Schibsted (marketing)
All subcontractors are subject to data processing agreements ensuring that personal data is processed in accordance with the GDPR. The Processor shall notify the Controller of any plans to use processors other than those mentioned here, so that the Controller has the opportunity to object to such changes.
Personal data is stored on secure servers within the EU/EEA, mainly with Microsoft Azure in Norway. The Processor implements technical and organisational measures to protect personal data, including encryption using Transport Layer Security and access control.
Data subjects have the following rights under the GDPR:
– Access: The right to know what personal data is being processed. – Right to rectification: Request correction of inaccurate information. – Right to erasure: Request deletion of personal data (“the right to be forgotten”). – Right to restriction of processing. – Right to object to processing. – Right to data portability.
The Controller is responsible for handling requests from data subjects, but the Processor will assist with necessary information. In the event of a request for erasure from a data subject, the Processor shall inform the Controller without undue delay.
The Processor undertakes to implement necessary security measures to protect personal data. This includes protection against unauthorised access, destruction, alteration or disclosure of data. The Processor follows ISO 27001 guidelines for internal security processes.
Data encryption: All data transferred between users and the system is encrypted using Transport Layer Security (TLS) to prevent unauthorised access during transfer.
Storage on secure servers: Personal data is stored on servers in data centres that meet strict security standards.
Firewalls and network security: The Processor uses firewalls and security software to monitor and control traffic to and from the servers, and to protect against external attacks.
Regular security updates: Software and systems are updated regularly to ensure that the latest security updates and bug fixes are implemented.
Backup and data recovery: Regular backups of data are performed to ensure that information can be restored in the event of data loss or security breaches. These backups are stored in separate locations with the same security level as production data.
Access management: Access to personal data is restricted to authorised personnel who have a clear need to access the data. Access rights are reviewed regularly to ensure that they are aligned with roles and responsibilities.
Secure authentication: Users must use secure authentication methods such as two-factor authentication (2FA) to access the system.
The Processor shall, at the request of the Controller, be able to demonstrate that authorised persons are subject to confidentiality obligations or a duty of confidentiality. The duty of confidentiality also applies after completion of the data processing assignment.
Training in data security: All employees of the Processor who have access to personal data regularly undergo training in data security and privacy to ensure that they are up to date on applicable legal requirements and best practices.
Security policy: The Processor has implemented internal security policies that describe how personal data shall be processed securely and in accordance with the GDPR. The policies cover, among other things, information security management, securing workstations and how security breaches are handled.
Logging and monitoring: The Processor logs access to and use of the system. This makes it possible to detect and investigate unauthorised or suspicious activity in the system.
Incident reporting: All security breaches or suspected breaches of data security shall be reported immediately to the Processor, who will then notify the Controller in accordance with the GDPR. A plan for handling security breaches has been established, including procedures for reporting to relevant authorities, such as the Norwegian Data Protection Authority, if required.
Risk assessment: The Processor regularly carries out risk assessments of its technical and organisational measures to ensure that they are sufficient to protect personal data. Any weaknesses or deficiencies shall be handled proactively through updated security measures.
Security requirements for subcontractors: The Processor requires all subcontractors that process personal data on behalf of the Processor to implement equivalent security measures as described in this agreement.
Transfer of data outside the EU/EEA: Personal data is not transferred to a country outside the EU/EEA.
Personal data will be deleted or anonymised when it is no longer necessary for the purpose for which it was collected, or when the Controller requests deletion in accordance with the agreement.
In the event of an incident, the Processor shall notify the Controller without undue delay. The Controller is responsible for notifying the Norwegian Data Protection Authority if required, in accordance with GDPR Article 33. If a security breach entails a risk to the rights of data subjects, the notification to the Controller must contain the information required for the Controller to provide a detailed description of the breach to the Norwegian Data Protection Authority. In the event of such risk, the data subject must also be notified, and the notification must contain the information required for the Controller to fulfil the notification obligation in a clear manner.
Upon termination of the agreement, the Processor undertakes to delete all personal data within a reasonable period after the Controller has copied the necessary data. The Processor shall confirm in writing that deletion has been completed.
The agreement is governed by Norwegian law, and any disputes shall be handled by Oslo District Court.