Draft. This text is under legal review and is not final. Nothing here is binding until it is published as a numbered version.
Privacy policy
This policy explains what personal data Olav processes, why, and the rights you have. It covers this website.
The reviews are generated by AI, and they are not legal advice
The readiness review is produced by an AI system reading public sources and the law. It is information to help you act, not legal advice, and it does not create a lawyer-client relationship. For a binding legal opinion, speak to a qualified lawyer.
Scope and roles
This policy applies to Olav Engineering as the data controller for the personal data described here. A data controller is the party that decides why and how personal data is processed.
When we process personal data on behalf of a customer, for example the content a customer uploads to a review, we act as a data processor. That processing is governed by a separate data processing agreement, not by this policy.
You can reach us at Storåsveien 11A, 1169 Oslo, or at alf@01.inc.
Who we are
Olav Engineering is the company behind this website. We decide why and how your personal data is processed, which makes us the data controller.
You can reach us by email for any question about your data or this policy.
TODO (Alf / lawyer): Confirm the exact legal entity (name, organisation number, registered address) that is the data controller, and which entity form applies. Governing law and the controller identity both depend on this.
What data we process
We process the following personal data:
- Account details: the name, work email, and company you give us when you sign up.
- What you send us in a form on this website: your name, work email, company, and anything you write to us. A magazine request also takes the postal address we send it to. A sign-up also takes your role, how many people work with you, and how your IT is set up.
- Your company profile: public register data we look up from Brønnøysundregistrene (Brreg) and public information about your firm.
- Documents you choose to upload: any files you add to a review, and the text we read from them.
- The review itself: the report we generate for your company and the record of it.
- Usage and log data: basic technical data such as your device, browser, and the actions you take, used to run and secure the service.
- Website analytics: the pages you visit and your IP address. We only store analytics on your device if you accept. When you send us a form we also record that it happened, under a one-way pseudonym rather than your email address.
Why we process it, and our legal basis
We process your data to deliver the readiness review you asked for, to run and secure the service, and to reach you about it. We only process personal data when we have a valid basis for it under the GDPR.
Your account details and the review itself (the report we generate and the record of it) we process to perform our contract with you for the service. Your company profile (public register data from Brreg and public company information) and usage and log data (your device, browser, and the actions you take, used to run and secure the service) we process on the basis of our legitimate interest. Documents you upload and the text we read from them, and marketing email, we process only with your consent, and you can withdraw that consent at any time.
Reviews are AI-generated, not legal advice
The review is written by an AI system, grounded in public sources and the text of the law. It is built to cite what it can and to refuse what it cannot source, but it can still be incomplete or wrong.
Treat it as a starting point, not a legal opinion. It does not create a lawyer-client relationship. For a binding view on your obligations, consult a qualified lawyer.
Who else processes your data
We use a small set of service providers (sub-processors) to run the service. They process data only on our instructions and only for the purposes below. The full list is in the table further down.
Transfers outside the EU and EEA
Some of our providers are based in the United States or process data outside the EEA. Where that happens, personal data is transferred outside the EEA and needs a valid transfer safeguard under the GDPR.
For those transfers we rely on the EU Standard Contractual Clauses, and, where the provider is certified, the EU-US Data Privacy Framework. Anthropic, Exa, and Perplexity each transfer personal data to the United States under the EU Standard Contractual Clauses, with a data processing agreement in place. Anthropic, Cloudflare, Vercel, and Resend are additionally certified under the EU-US Data Privacy Framework. Files you upload stay in an EU-jurisdiction bucket at Cloudflare. The basis for each provider is shown in the sub-processor table below.
Our database is in the EU (Neon, Frankfurt), so your account and review data stays inside the EEA, and the functions that handle personal data run in the EU (Vercel, Frankfurt). Our transactional email provider (MailPace) hosts your email data in France, inside the EU.
How long we keep your data
We keep personal data only as long as we need it for the purposes above. When it is no longer necessary, we delete or anonymise it.
Some data we have to keep to meet a legal duty. As a business subject to the Norwegian bookkeeping rules, we keep accounting records in Norway for five years after the end of the accounting year, and some records for three years and six months. That duty overrides the right to erasure for as long as it lasts.
How uploaded documents are handled
Documents you upload are stored in a private, access-controlled bucket in EU jurisdiction (Cloudflare R2). We use them only to produce your review. You can ask us to delete them at any time, and we delete them on request.
To read the text from a document we use Mistral's OCR API, which runs in the EU (France). Mistral does not train on content sent to the paid API, and we run it with zero data retention, so an uploaded document is not kept on Mistral's side once the text has been returned.
Your rights and our response time
Under the GDPR you have the right to access your data, to correct it, to have it deleted, to restrict or object to processing, to data portability, and to withdraw consent where we rely on it.
To exercise any of these, email us at alf@01.inc. We help you use your rights and reply without undue delay, and within one month at the latest. Where a request is complex we may extend that by up to two months, and we tell you within the first month if we do.
How we keep data secure
We keep access to personal data limited to what is needed, store uploaded files in a private access-controlled bucket, and use reputable providers for hosting, storage, and email. Security is the core of what we do, and we hold our own systems to the standard we set for customers.
Cookies
Where we store information on your device or read information already stored there, for example through cookies or similar technology, we do so only after you have been informed and have given consent. That consent meets the consent standard in the GDPR, as the Norwegian Electronic Communications Act requires.
Storage or access that is strictly necessary to deliver a service you have expressly asked for does not need consent.
Everything we store on your device is listed in the table further down, with what it is for, which category it falls in, and how long it lasts.
We ask before we store anything that is not strictly necessary. If you decline, we count your visit without storing anything on your device. You can change your choice at any time, at the bottom of this page.
Disclosures
We may disclose personal data when we are legally required to, for example under a court order or other legal process. In that case the disclosure rests on the legal obligation we are under.
We may also disclose data to protect our rights or to prevent fraud, and in connection with a merger, acquisition, or other business transfer.
Complaints
If you think we have handled your data wrongly, please tell us first so we can put it right. You also have the right to complain to the Norwegian Data Protection Authority (Datatilsynet).
Changes to this policy
When we change this policy we update the version and effective date at the top. The current version is shown there.
Cookies and device storage
This is everything we store on your device. Strictly necessary items are needed to deliver what you asked for, so they are always present. Analytics is written only if you accept it.
| Name | Provider | Category | Purpose | Lifetime |
|---|---|---|---|---|
| lang | Olav | Strictly necessary | Remembers the language you chose, so the site does not switch back. | 1 year |
| __ph_opt_in_out_* | PostHog | Strictly necessary | Remembers whether you accepted or declined analytics, so we do not ask again. | Until you clear it |
| ph_* | PostHog | Analytics | Counts you as the same visitor across pages and visits, so we can see what works. Written only if you accept. | 1 year |
A name ending in a star is a prefix. PostHog names its storage after our project, so the full name is only visible in your own browser.
Sub-processors
These are the service providers that process data to run the service, with what they do and where they sit. This list is accurate as built on the effective date above.
| Provider | Purpose | Region |
|---|---|---|
| Anthropic (Claude) | The AI that generates the review. Does not train on our data. | United States · EU-US DPF and SCCs, DPA in place |
| Mistral | Reads text from uploaded documents (OCR). Does not train on the paid API, run with zero data retention. | France (EU) |
| Exa | Reads your company's public website | United States · EU Standard Contractual Clauses, DPA in place |
| Perplexity | Builds a public background summary of your company | United States · EU Standard Contractual Clauses, DPA in place |
| Cloudflare R2 | Private storage of uploaded files | EU-jurisdiction bucket · SCCs + EU-US DPF |
| Cloudflare Turnstile | Checks that you are not a bot when you submit a form. Receives your IP address. | United States · SCCs + EU-US DPF |
| Cloudflare DNS-over-HTTPS | Public DNS lookups | No personal data |
| PostHog | Website analytics. Receives the pages you visit and your IP address. When you submit a form we send a one-way pseudonym of your email address, never the address itself. | EU (PostHog Cloud EU) |
| MailPace (OhMySMTP Ltd) | Transactional email and report PDF delivery | France (EU) hosting · UK company, SCCs with sub-processors |
| Resend | Sends the email your form submission becomes, and holds marketing contacts if you opt in | United States · SCCs + EU-US DPF |
| Neon | Application database | EU · Frankfurt |
| Vercel | Application hosting and compute | EU · Frankfurt (fra1) |
| Brønnøysundregistrene (Brreg) | Public company register lookup | Norway, public data |
| Store norske leksikon / Wikipedia | Term and reference lookups | No personal data |
Providers marked with no personal data are used for public lookups only and do not receive your personal data.