Privacy statement

What Berigo AS does with information about you when you use this website: what we collect, why, how long we keep it, and what you can ask us to do.

The short version

  • We collect what you type into a form, plus what it takes to run the site safely. Nothing else.
  • No tracking of you. We count page views and reading time anonymously on our own server — no cookies, no IP addresses, nothing that could recognise you or follow you from page to page. No third-party cookies, and the site loads nothing from anyone else's servers.
  • Whatever you send through a form is stripped of anything identifying after 12 months and deleted outright after 36. That happens automatically. If the enquiry turns into paid work, the invoice records have to be kept longer — see below.
  • We do not use what you write for newsletters or marketing. The one exception is the tick-box you can use yourself, to let us get in touch about a course you asked for the description of.
  • If you book a meeting, the booking itself happens at Proton — we store nothing about it on this site.
  • You can ask to see, correct or delete what we hold. Write to info@berigo.no.

Who is responsible

Berigo AS is the controller for everything described here. We decide what the information is used for, and we answer for it.

  • Berigo AS, Sinsenveien 51C, 0585 Oslo, Norway
  • Email: info@berigo.no
  • Phone: +47 9415 7716

We have not appointed a data protection officer. A data protection officer is someone whose job is to keep a business honest about privacy, and whom you can approach directly. Only certain organisations have to have one — public bodies, and businesses that carry out monitoring or handle sensitive data on a large scale (Art. 37). We are not one of them. Privacy questions go to Roger Ison-Haug, at info@berigo.no.

Three terms you will meet

  • The GDPR, the EU General Data Protection Regulation. Every article reference below — "Art. 6(1)(f)" and the like — points to it. In Norway it applies through the Personal Data Act.
  • Legitimate interest is one of the grounds the law allows for handling personal data. We can rely on it when we have a real need, the processing is necessary to meet that need, and the need outweighs the intrusion on you. We make that judgement ourselves — which is why you have the right to object to the result. See "Your rights".
  • Processor means someone who handles data on our behalf, on our instructions and not for their own purposes. The company that hosts the site is one.

What we process, why, and for how long

The table covers everything the site itself stores about you. It comes either from a form you filled in or from your visit.

What we use it forWhat we holdOur legal basisHow long
You write to us through the contact formName, email address, organisation (optional) and your message. Also the time you sent it and which language you wrote in.Our legitimate interest in being able to answer people who get in touch, Art. 6(1)(f).Anonymised after 12 months, deleted after 36
You register for an eventName, email address, organisation, phone and message — the last three are optional. Also which event, the time and the language.Necessary to carry out the registration you asked for, Art. 6(1)(b).Anonymised after 12 months, deleted after 36
You ask for a price for Dataset BuilderOrganisation, name, email address, phone (optional) and any message. Also your answers on the size of your organisation, the number of licences, how it would be rolled out and when.Necessary to answer your enquiry ahead of any contract, Art. 6(1)(b).Anonymised after 12 months, deleted after 36
You download a course descriptionName, email address and organisation (optional). Also which course, the time, whether you ticked the box letting us get in touch about it, and whether and how many times the file was fetched.Two things, on two different grounds. Sending you the description, and seeing which courses are being asked about: legitimate interest, Art. 6(1)(f). Getting in touch about the course afterwards: your consent in the tick-box, and nothing else, Art. 6(1)(a). Withdraw the consent and we stop contacting you — there is no other ground for us to fall back on.Anonymised after 12 months, deleted after 36
Security logIP address, what happened and when. Written when we sign in or make changes on our own pages, and when someone submits a price enquiry or asks for a course description. The log shows that it happened — not what the form said.Our legitimate interest in protecting the site against abuse and unauthorised access, Art. 6(1)(f).Deleted after 12 months
Block on repeated submissionsIP address and time, used as a counter. It stops the same machine from sending the same form over and over. The same block applies to sign-in on our own pages, and there it also stores the username that was typed in.Our legitimate interest in keeping out spam and automated submissions, Art. 6(1)(f).Deleted after 24 hours
You book a meetingName, email address and the time slot you pick. This is recorded at Proton, not with us — see the section below.Necessary to arrange the meeting you asked for, Art. 6(1)(b).We delete the calendar entry once the meeting has taken place
You download the executive guideThe email address you provide, and which language and page you came from. We note whether the follow-up email was sent, and whether the guide was fetched. No IP address.Legitimate interest in delivering what you asked for, and in seeing whether the guide is useful (Art. 6(1)(f)).The address is anonymised after 12 months and the row deleted after 36. The download link in the email stops working after 30 days.

Anonymising at 12 months is real deletion of the parts that point to you: name, email address, phone number, organisation and message text are emptied out. What stays behind is the time, the language and the choices that do not identify anyone — for registrations, which event it was; for price enquiries, which options were picked from the drop-down lists; and for course downloads, which course it was, whether the contact box was ticked, and whether and how many times the file was fetched. At 36 months the whole record goes.

The clean-up runs by itself rather than depending on anyone to remember it. It runs at most once a day, and it is triggered by someone visiting the site — so if a day passes with no visitors at all, the clean-up catches up the next time someone comes by.

When you ask for a course description you get a download link that stops working after 48 hours. That is a deadline for you, not a deletion deadline: the record of the download follows the periods in the table.

If the contact turns into paid work and we invoice you, the customer and invoice details become part of our accounts. Norwegian bookkeeping law requires accounting records to be kept, as a general rule, for five years after the end of the financial year. The basis for that is a legal obligation, Art. 6(1)(c), and those five years take precedence over the 12- and 36-month periods.

If we reply by email, the thread stays in our mailbox. It is not covered by the automatic clean-up — we go through it by hand and delete what we no longer need. If you would like an email thread deleted, tell us at info@berigo.no.

When you submit a form, we look up which country your IP address is registered in, and refuse the submission if that country is on a short block list. The lookup runs against data we have downloaded from the regional internet registries and stored on our own server — your address is not sent to anyone else to be looked up. The country is worked out on the spot, used to decide that one submission, and not stored. The basis is our legitimate interest in keeping out abuse, Art. 6(1)(f). If your submission is refused and you believe that is wrong, write to info@berigo.no — we answer email wherever you are.

The table covers what the site itself stores. On top of that, the company that hosts the site keeps ordinary server logs of traffic, as any web server does. We have not had confirmation of how long those are kept, and we would rather not quote a figure we do not know.

Do you have to fill in the fields?

No. No law requires you to tell us anything, and you can use the entire site without filling in a single form. But if you do send one, some fields have to be there for it to serve any purpose:

  • Contact form: name, email address and message. Without the email address we have no way to reply. Organisation is optional.
  • Event registration: name and email address. Without them we cannot record your place, and we have no address to confirm it to. We write and send that confirmation ourselves — the site sends no email at all. Organisation, phone and message are optional.
  • Price enquiry: organisation, name, email address, the size of your organisation and the number of licences. The last two are what set the price, so without them you get a round of questions instead of an answer. Phone, rollout, timeframe and message are optional.
  • Course description: name and email address. Organisation is optional. Ticking the box to let us get in touch about the course is entirely up to you — you get the description either way.

The security log and the block on repeated submissions are not things you can opt out of. They are part of running a website responsibly, and they are built to record as little as possible: what happened, when, and from which IP address.

Who receives the information

  • Us. What you send lands in the site's database and is available only to us, behind a sign-in. It is never searchable or visible on the public site. Course downloads have no screen of their own on our signed-in pages yet — they sit in the database, and we pull them out from there if we need them.
  • Our hosting provider. The site and its database run at a Norwegian provider with servers in Norway. The provider is a processor for us. We do not name it here, but we will tell you who it is if you ask at info@berigo.no.
  • Proton. If you book a meeting — see the section below.
  • Email providers. When we reply by email, the reply passes through our provider and on to yours.

There is no one else. This site has no third-party analytics tools, no tracking pixels, no share buttons, and no fonts or videos pulled in from anywhere else. We sell nothing on. And we do not use what you write for newsletters or any other marketing — with the single exception that you can tick a box yourself to let us get in touch about a course whose description you downloaded.

If we are legally required to hand information to a public authority, we will. The basis for that is a legal obligation, Art. 6(1)(c).

When you book a meeting

The booking page is not ours. Press the button to arrange a meeting and you arrive at our calendar at Proton; that is where you pick a time and give your name and email address. We store nothing about the booking on this website.

Berigo AS is the controller for this information as well. We decided to take meetings this way, and we decide what your name and address are used for. Proton AG supplies the service and acts as our processor.

All you give is a name, an email address and the time you want. The booking becomes an entry in our calendar at Proton, and we delete that entry once the meeting has taken place. Proton states that backups are kept for up to 30 days, so a residual copy may sit with them for a short while afterwards. We cannot promise more than that.

If you want to see a booking, or have it deleted, write to us at info@berigo.no. We answer for it, not Proton.

A confirmation goes to the address you give. From the moment it has been delivered to your own email provider, it is covered by whatever protection that provider gives it.

Proton states in its own privacy policy that it retains IP logs permanently only for activity that breaches its terms of service. That is written for people who hold a Proton account, and we have had no confirmation of what applies to a visitor on a booking page. This is Proton's account of its own practice, not something we have verified. Read it for yourself: Proton's privacy policy.

Cookies and storage in your browser

The site sets one cookie as soon as you arrive, and a second one only if you switch language yourself. Neither follows you to any other website.

  • berigo_sid — the session cookie. It does two things. It makes sure a form can only be submitted from the page it belongs to, so nobody can trick your browser into sending a form in your name from some other site. And it remembers that it was you who asked for a course description, so the download is tied to your browser rather than to a link that could be passed on. It is set on your first page view, holds nothing about you, and disappears when you close the browser.
  • berigo_lang — your language choice. It is set only if you click "EN" or "NO" yourself, and holds nothing but the language code. It lasts a year.

The session cookie is necessary for the site to work and for what you submit to arrive safely, so no consent is required for it under section 3-15 of the Norwegian Electronic Communications Act. The language cookie only remembers a choice you made yourself, and is used for nothing else. Our view is that it falls under the same exemption — but that is our assessment, not a settled point of law. There are no other cookies: our content statistics set none (see the separate section below), and nothing is set by anyone else.

One further value is stored locally in your browser: berigo-theme. It is written when you switch between the light and dark look, and holds the word "light" or "dark". It is not a cookie: a cookie is sent to us with every single request, whereas this value stays in the browser and is never sent anywhere. But it is still storage on your device, so you ought to know it is there. To get rid of it, clear site data for berigo.no in your browser settings — in most browsers the option sits under privacy, usually called something like "clear cookies and site data".

Content statistics on our own server

We want to know which pages are read, for how long, and which ones lead someone to get in touch. We measure this with a system we built ourselves, running exclusively on our own server. Your browser only ever talks to berigo.no; no measurement data goes anywhere else.

For each page view we record: which page, language, active reading time, how far down the page was scrolled, clicks on buttons such as "Book a meeting", e-mail and phone links, file downloads and links leaving the site (only which site the link points to), the site you arrived from (only the domain, never the full address), and campaign codes we created ourselves. That is all.

Just as important is what the system does not do: it never stores your IP address, sets no cookie, uses neither localStorage nor sessionStorage, reads no form values and builds no browser "fingerprint". Each page view gets a random one-time ID that is forgotten the moment you leave the page — two page views can never be linked to each other or to you. This also means we cannot count "unique visitors", and the statistics deliberately contain no geography: a country cannot be determined without an IP address, so we do not measure it.

As we assess it, this is anonymous statistics rather than personal data under the GDPR, and the measurement neither stores nor reads anything in your browser — so the consent requirement in section 3-15 of the Norwegian Electronic Communications Act is not triggered either. Raw data is deleted automatically after 13 months. If your browser asks not to be measured (Global Privacy Control), it is not measured.

When you buy a course or software

When you add something to the cart, we store only what you chose and how many seats — never the price, which is always recalculated on our side. The cart lives in its own cookie (berigo_cart) that lasts 30 days, so it is still there when you return. Abandoned carts are deleted after 90 days.

When you complete a purchase, we process what you enter at checkout: name, email address, phone (optional), and for business purchases the organisation name, organisation number, any PO number and the invoice address. The basis is performance of the contract with you, Art. 6(1)(b). We also record that you ticked the boxes accepting the terms of sale and acknowledging that the right of withdrawal lapses — this is our documentation that the duty to inform was met, Art. 6(1)(c).

The order, the order lines and the invoice are accounting records. Norwegian bookkeeping law requires us to keep them for five years after the end of the financial year, and the basis is then a legal obligation, Art. 6(1)(c). These records therefore fall outside the 12- and 36-month periods above — they are kept for as long as the law requires and then deleted.

Payment is currently by invoice. We do not accept card details, and no card data passes through our website. If we later add card or Vipps payment, the payment itself takes place at the payment provider, and we receive only a confirmation that it went through — never your card number.

An order confirmation is sent to the address you provide. If you register people other than yourself for a course, you provide a name and email address for each participant; these are used only to run the course and to issue certificates.

Transfers outside the EEA

Everything you send through the forms stays in Norway. The one piece of processing that happens outside the EEA is the booking.

Proton AG is based in Switzerland. The European Commission has found that Switzerland offers protection on a level with the EEA's. That decision was reviewed again in 2024 and stands. The transfer rests on it (Art. 45). For you it means your name and email address are covered by rules equivalent to the Norwegian ones, even after they cross the border.

Your rights

You exercise all of the rights below the same way: write to info@berigo.no and say what you want done. You do not have to give a reason, and it costs nothing.

  • access — a copy of what we hold about you, and what we use it for (Art. 15)
  • rectification — correction of anything that is wrong (Art. 16)
  • erasure — deletion of the information (Art. 17)
  • restriction — that we leave it untouched while something is being sorted out (Art. 18)
  • portability — what you gave us yourself, in a format you can take elsewhere (Art. 20)

Portability does not cover everything. The right applies only to information we handle because you have entered, or want to enter, into an agreement with us, or because you consented: event registrations, price enquiries, bookings, and the tick-box on a course download. The contact form, the security log and the block on repeated submissions fall outside it, because they rest on legitimate interest. Access and erasure you can ask for regardless.

The right to object. Where we handle information about you on the ground of legitimate interest — that covers the contact form, sending out the course description itself, the security log and the block on repeated submissions — you may object at any time, on grounds relating to your particular situation. Write to info@berigo.no and say briefly what the reason is. We then stop, unless we have compelling grounds that outweigh yours (Art. 21).

If you ticked the box letting us get in touch about a course, you can withdraw that consent whenever you like. One line to info@berigo.no is enough, and we stop contacting you. What we did while the consent stood remains lawful (Art. 7(3)).

We reply as quickly as we can, and within a month at the outside. If the matter is complicated we may take up to two months more, but you will hear from us inside the first month (Art. 12(3)).

If we are genuinely unsure who you are, we will ask you to confirm before handing anything over (Art. 12(6)). We never ask for a copy of a passport or other ID by email. Usually it is enough that you reply from the address the enquiry came from, or can point to something only you could know about it.

We make no automated decisions about you, and we do not carry out profiling (Art. 22).

Complaints

If you think we are handling information about you wrongly, we would rather hear it from you first — then we can put it right. But you are entitled to complain to Datatilsynet, the Norwegian Data Protection Authority, either way, and you do not have to come to us first (Art. 77).

  • Datatilsynet, Postboks 458 Sentrum, 0105 Oslo, Norway
  • Phone: +47 22 39 69 00
  • datatilsynet.no

Changes

If we change the site in a way that changes how we handle information, we update this statement. If we ever want to use information we already hold for something new, we will tell you before we do (Art. 13(3)).

Last updated 28.07.2026