Privacy Policy

At GapSolutions Norge AS and PersonvernPraktikerne.no (org. no. 996 848 639), we are committed to ensuring you know exactly how your personal data is processed. We want to make it as easy as possible for you to understand what data we collect, why we collect it, and how we protect it.

There's a philosophy embedded in our name: we are practitioners. We believe privacy is best when it's built into your existing routines – not as a separate compliance project on the side. That same thinking guides this statement.

Content


Who is responsible for your personal data?

GapSolutions Norge A/S is the data controller for the personal data we collect and use ourselves — typically in connection with marketing, sales, customer follow-up, and general business communication.

GapSolutions Norge A/S is wholly owned by the holding company Erik Net-Working Invest AS (hereinafter ENWIAS). ENWIAS also manages business collaborations with external partners. When we process your data—whether the contact was made through one of these collaborations or directly—GapSolutions Norge A/S is always the data controller.

What we are NOT responsible for

When you as a customer use a software solution that we facilitate or sell licenses for, the vendor of the solution and you as the customer are the parties in the GDPR-related role distribution concerning personal data processed within the solution itself. GapSolutions Norge A/S is then not a party to that processing.

Specifically, that means:

Operations and Contact Person

PersonvernPraktikerne is managed daily by Erik Horn. The company occasionally engages external consultants for selected assignments. Erik is your point of contact for all privacy-related inquiries. We have not appointed a dedicated Data Protection Officer (DPO) – as a small business, we are not obligated to do so – but you still have one clear contact person for all your requests.

For questions about how we process your information, you can contact us at:
Email: hei@personvernpraktikerne.no
Phone +47 922 92 400

We normally reply within three business days, and at the latest within 30 days — which is the deadline GDPR sets for access requests.

To the top


2. What information do we collect — and why?

2.1 Purpose of the Treatment

We use your information to:

2.2 What We Collect - Sorted by Legal Basis

Consent (GDPR Article 6(1)(a)):

Agreement (GDPR Article 6(1)(b)):

Legitimate interest (GDPR Article 6(1)(f)):

Legally required (GDPR Article 6(1)(c)):

2.3 We process the following types of personal data

2.4 In table form

Thead>Table header
PurposeLegal basisWhat we treatIn which systems
Send newsletters to those who have consentedConsent (Art. 6.1.a)Name, emailBrevo, Microsoft 365
Deliver the products and services you have purchasedAgreement (Art. 6.1.b)Name, phone, email, company, position, payment informationTripletex, Microsoft 365
Manage customer relationships or course participationLegitimate interest (Art. 6.1.f)Name, phone, email, company, titleGapPortalen, Twenty CRM, Tripletex, Microsoft 365
Follow-up questions and requestsLegitimate interest (Art. 6.1.f)Name, phone, email, companyTwenty CRM, Microsoft 365
Sales and meeting booking in the B2B target audienceLegitimate interest (Art. 6.1.f)Name, phone, email, company, titleTwenty CRM, Booking code, Microsoft 365, Cal.com
Accounting and invoicingLegally required (Art. 6.1.c)Billing details, payment dataTripletex

To the top


3. Use of systems and suppliers

To deliver our services, we use several systems and providers. We have consciously chosen EU-based solutions wherever possible and kept the number of providers low.

All suppliers are subject to a data processing agreement and have committed to complying with GDPR. A full list with short descriptions and links to the respective privacy policies can be found in the appendix at the bottom.

We do not use Google Analytics, and we do not use Cloudflare. These are conscious choices—we want to keep data flow simpler and closer to the EU than standard setups typically allow.

To the top


4. How do you withdraw consent?

If you have consented to receive newsletters from us, you can withdraw your consent at any time by clicking the «Unsubscribe» button at the bottom of the newsletter. You can also send us a short message:

Email: hei@personvernpraktikerne.no
Phone +47 922 92 400

You can similarly withdraw consent for marketing cookies by clicking on the cookie icon at the bottom of the website and changing your settings.

To the top


5. How do we protect your personal data?

We take information security seriously — it's half of our job, after all.

Specifically, that means:

We continuously review our security measures and update them as the threat landscape or practices change.

To the top


6. How long do we store your personal data?

We store your personal data for as long as it is necessary to fulfill the purposes we have described, or for as long as required by law.

When the storage period expires, we delete the data—or anonymize it if we need to retain aggregated statistics.

To the top


7. Your Rights

You have several rights regarding your personal data:

To exercise these rights, contact us at hei@personvernpraktikerne.no. We will respond within three business days, and no later than 30 days.

To the top


8. Transfer of data outside the EU/EEA

We generally do not transfer personal data outside the EU/EEA. All data is stored and processed primarily in Norway or within the EU/EEA.

In some cases, situations may arise where data is temporarily transferred outside the EU/EEA — for example, for technical support from vendors located outside the EU/EEA. In such cases, we ensure that the necessary safeguards are in place (typically the EU Commission's Standard Contractual Clauses, SCCs) that provide a level of protection equivalent to that required by GDPR.

Microsoft 365, Apple/iCloud, and Google may in some cases process data outside the EU/EEA. All have their own mechanisms for lawful transfer as described in their respective privacy policies (links in appendix).

To the top


9. Right of Appeal

If you believe we are not processing your information in accordance with the law, you can complain to the Norwegian Data Protection Authority:

The Norwegian Data Protection Authority
postkasse@datatilsynet.no
+47 22 39 69 00
datatilsynet.no

We appreciate you bringing any concerns to us first – that way, we can usually resolve them without them escalating.

To the top


Do you have questions?

If you have any questions about how we process your personal data, or wish to exercise your rights, please feel free to contact us. We are available to help.

GapSolutions Norway A/S
PrivacyPractitioners.no


Appendix — Supplier Overview

Thead>Table header
SupplierWhat they do for usPersonal data handlersPrivacy Policy
GAPSolutions A/S (DK)Delivers the GapPortal, which we market to Norwegian customers. Processes portal customers' own data directly with the customer. Uses Hetzner as a subcontractor for data center operations.Contact Information Between Our Companiesgapsolutions.dk/privacy-policy/
TwentySelf-hosted CRM system on our own server within the EU/EEAContact information, email, interaction datatwenty.com/legal/privacy
BrevoSending of newsletters and campaign emailsName, email, click databrevo.com/legal/privacypolicy/
Cal.comMeeting bookingName, email, meeting informationcal.com/privacy
Booking codeTelemarketing and appointment setting in the B2B segmentProspect Personal Data (CRM)bookingkoden.no/privacy
Microsoft 365Email, web meetings, document managementEmail, document content, calendar dataprivacy.microsoft.com
TripletexAccounting and InvoicingBilling details, contact informationtripletex.no/privacy-policy/
Domain shopDomain, email, and web hosting managementContact information, technical information (IP addresses)domene.shop/terms#privacy
ComplianzCookie Consent Management on WebsitesTechnical data, consent statuscomplianz.io/privacy-statement/
MatomoWebsite traffic analysis (self-hosted, scheduled 2026)Anonymized IP, page visits, click datamatomo.org/privacy-policy/
Apple/iCloudMac, iPhone, email, calendar, office support (BYOD)Email, calendar data, contact informationapple.com/legal/privacy/no/
GoogleAndroid phone, email, calendar, office support (BYOD)Email, calendar data, contact informationpolicies.google.com/privacy

To the top


Version log

Version 3.0 - effective from 2026-04-27

Changes from v2.5: updated vendor list (HubSpot → Twenty, Cookie Information → Complianz, WPMUDEV → Domeneshop, Cloudflare and Webberne removed, Brevo, Cal.com, Matomo added, Google mentioned as BYOD platform). LinkedIn removed from vendor overview — Erik's LinkedIn profile is a personal account, not part of the company's personal data processing. Contact address updated to hei@personvernpraktikerne.no, clarified ENWIA role, new visual presentation with table of contents. Wittario is not included in this version — will be added when the course platform is actively used.

Previous versions: v2.5 — effective as of 2024-10-29 | v1.21 — previous version

Newsletter

Stay updated

Sign up and get the latest articles, GDPR insights, and useful privacy perspectives.