Privacy policyAvtalor

Privacy policy

Effective 1 September 2026 · version 1.0

This policy explains how personal data is processed in Avtalor, and also constitutes the data processing agreement between Avtalor AS as processor and the Company as controller.

Roles and responsibilities

The Company is the controller for data about its own employees and determines the purpose of the processing. Avtalor AS is the processor and processes data only on the Company's instructions and to deliver the Service.

For data about Avtalor's own contacts at customers and suppliers, and for marketing the Service, Avtalor is itself the controller.

Controller at Avtalor: Avtalor AS, company no. 916 048 092, Oslo. Privacy contact: support@avtalor.com

What data is processed

Account data: name, work email, phone number, job title, profile photo and role affiliation. Legal basis: necessary to perform the contract, GDPR Article 6(1)(b), and the controller's legitimate interest in administering employee access, Article 6(1)(f).

Usage data: which agreement cards are opened and used, time, category, device type and a pseudonymised user identifier. Legal basis: legitimate interest in operating, securing and improving the Service, Article 6(1)(f).

Content of documents uploaded for machine reading, including agreement text and contact details appearing in the document. Legal basis: performance of the contract, Article 6(1)(b).

Reported problems with an agreement, including free text written by the employee. Legal basis: legitimate interest in correcting errors, Article 6(1)(f). The identity is visible to the Company's administrator, but not to the Supplier.

Consents and notification preferences. Legal basis: consent, Article 6(1)(a), and the duty to document consent, Article 7(1).

We never store passwords. Sign-in uses a one-time link.

What the supplier can see

By default, a Supplier receives only aggregated figures and pseudonymised identifiers, without names or emails.

Names and contact details are shared with a Supplier only when two conditions are met at the same time: the Company has enabled sharing, and the employee has given separate, explicit consent.

Consent is voluntary, can be limited per supplier, and can be withdrawn at any time in the Service under Settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

If the Company chooses to share contact details without the employee's consent, the Company must itself have an independent legal basis and bears responsibility for it.

Automated decisions

Machine reading is used to suggest content in agreement cards and to provide tips and rankings for administrators and suppliers. The processing does not involve automated decisions with legal effect or similarly significant effect on individuals, cf. Article 22.

All suggestions require human review before publishing. Data is not used to train general-purpose models.

Sub-processors

Avtalor uses sub-processors for hosting, database storage, email delivery, notifications, error monitoring and machine reading of documents. All are bound by a data processing agreement with obligations at least equivalent to those in this policy.

Processing takes place within the EU/EEA where possible. For transfers to third countries, the European Commission's standard contractual clauses are used with supplementary measures.

An up-to-date list of sub-processors is available on request to support@avtalor.com. The Company is notified at least 30 days before new sub-processors are engaged and may object in writing.

Security

Data is transmitted encrypted with TLS and stored encrypted. Access to production data is limited to named personnel with a business need, is logged and requires two-factor authentication.

Access control is enforced in the database, so that a user can technically only read data they are entitled to. Actions performed by Avtalor personnel on behalf of a customer are logged.

In the event of a personal data breach, the Company is notified without undue delay and no later than 48 hours after the breach was discovered, with available information about scope, consequences and measures taken.

Retention

Usage data is retained for 24 months and then aggregated without the possibility of attribution to individuals.

Account data is deleted within 30 days after the portal is closed or access lapses. Data in accounting records is retained for five years after the end of the financial year, as required by the Norwegian Bookkeeping Act.

Uploaded documents are deleted once the agreement card is published, and at the latest after 12 months.

On the Company's instruction, Avtalor deletes or returns personal data on termination of the agreement.

Data subject rights

Employees have the right of access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interest.

Requests are directed to the Company as controller. Avtalor assists the Company in meeting the request within a reasonable time, normally within 14 days.

A data subject may lodge a complaint with the Norwegian Data Protection Authority, PO Box 458 Sentrum, 0105 Oslo.

Cookies

Necessary cookies are used for sign-in, session and security. These cannot be switched off without the Service ceasing to work.

Statistics and marketing require consent and can be switched off in the Service under Cookie preferences. Marketing cookies are used only on avtalor.com, never inside company portals.

Privacy | Avtalor