1. Controller
INFODESK AS (org. no. 922 255 970), Langes gate 8, 3210 Sandefjord, Norway, is the controller of the personal data we process about customers, users of the customer portal and users of our apps. You can reach us at [email protected]. This policy supplements our Terms of Service.
2. What we process
- Account and contact: name, e-mail address, phone number, company, organisation number, address and language preference.
- Customer and payment records: orders, subscriptions, invoices, payment status, price group and discount codes used. Card details are processed by Stripe. We only see the card brand and last digits.
- Domain holders: the information required by the registries, see section 5.
- Support: the content of support tickets and e-mails you send us.
- Technical data: IP address, browser, sign-in times and event logs we need for security and troubleshooting.
3. Sign-in with Google or Microsoft
If you choose to sign in with Google or Microsoft, we receive from the provider:
- your name and e-mail address
- whether the e-mail address is verified by the provider
- a unique account ID at the provider
We use this information only to sign you in, to create an account the first time you sign in, and to link the sign-in to the right account. We never receive your password. We do not request access to your e-mail, files, calendar, contacts or any other data in your account. We do not sell the information, use it for advertising or share it with others unless the law requires it.
InfoDesk's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can remove InfoDesk's access at any time in your Google account or Microsoft account settings. Your InfoDesk account remains until you ask us to delete it.
4. Purposes and legal basis
- Delivering the services you ordered, including sign-in, domain registration, hosting, service agreements, billing and support. The legal basis is our contract with you (GDPR Article 6(1)(b)).
- Meeting legal obligations, such as bookkeeping, keeping accounting records and requirements from domain registries. The legal basis is legal obligation (Article 6(1)(c)).
- Security, abuse prevention and improving the services. The legal basis is our legitimate interest (Article 6(1)(f)).
- Newsletters and marketing are sent only with your consent, or where the law allows it towards existing customers. You can unsubscribe at any time.
5. Domain registration data
To register a domain we must send holder information to the registry. For .no that is Norid. For other extensions it is the registry for the extension, through our partner CentralNic. The information is name, address, e-mail, phone and organisation number or personal identifier (PID). Registries are independent controllers and may publish some information in their lookup service (whois) under their own rules. Norid's publication rules are available at norid.no.
6. Hosting and service agreements
We process content that you or your users store in hosting, e-mail or systems we operate on your behalf. You are then the controller and we are the processor, and our data processing agreement applies. We do not use such content for our own purposes.
7. Apps
Apps published by InfoDesk AS on Google Play and the Apple App Store have their own privacy information in the app and in the store's privacy details. It describes what data the app uses. Where an app has no separate notice, this policy applies. In-app purchases and subscriptions are handled by Google or Apple, which are independent controllers for the payment data.
8. Recipients and processors
We share information only where needed to deliver the service or where the law requires it:
- Stripe for card payments and subscriptions
- Norid and CentralNic and the domain registries for domain registration
- Google and Microsoft for sign-in when you choose it, and Microsoft for sending our e-mail
- providers of servers, operations and backup
- our accountant, auditor, debt collection agency and public authorities where the law requires it
If data is transferred to countries outside the EU/EEA, this happens only with a valid transfer mechanism, such as the European Commission's Standard Contractual Clauses or the EU–US Data Privacy Framework.
9. Retention
- Account and customer data is kept while you have an account or customer relationship with us, and then as long as needed to close the relationship.
- Invoices and other accounting records are kept for five years after the end of the financial year, as required by the Norwegian Bookkeeping Act.
- Domain data is kept while the domain is registered through us, and by the registry under its own rules.
- Technical logs are kept for a limited time, as long as they are needed for security and troubleshooting.
- Hosting content may be deleted from 30 days after the subscription has ended.
10. Security
We protect data with access control, encrypted transport (HTTPS), encrypted storage of keys and secrets, logging and backups. Only staff and suppliers who need it to deliver the service have access.
11. Your rights
You have the right to access the data we hold about you and to have incorrect data corrected. You can request erasure, restriction and data portability where the GDPR conditions are met. You can object to processing based on legitimate interest and withdraw consent. You can also complain to the Norwegian Data Protection Authority (Datatilsynet). We respond without undue delay and within one month at the latest.
12. Contact
INFODESK AS, Langes gate 8, 3210 Sandefjord, Norway · [email protected]