Privacy
Privacy at Robvarde
This notice covers the public website, business follow-up and the customer portal. Customer and data processing agreements may contain more specific information for an individual delivery.
1. Controller and roles
Robvarde AS, Norwegian organisation number 937 717 016, is the controller for its website, enquiries, sales follow-up, account administration and security operations. Where Robvarde processes customer-controlled operational data solely on behalf of a customer, the roles are defined in the customer agreement and, where required, a data processing agreement.
2. Data and purposes
We process the information you choose to provide, such as contact details, organisation, building information, calculation inputs and your message, to answer, assess needs and prepare a demonstration, site assessment, proposal or agreement. The customer portal may process account, membership, permission, security, building, equipment, document, support and audit data.
3. Legal basis
We process data needed to take steps you request before a possible contract. For expected B2B dialogue and relevant follow-up, we rely on Robvarde's legitimate interest after a balancing assessment. Account, security and customer data are processed to deliver agreements, protect the service and comply with applicable obligations. The contact form is not consent to newsletters.
4. Providers and transfers
Access is limited to authorised Robvarde users and providers with a documented need. Vercel supports web hosting and security logging. Supabase supports database, authentication and technical storage in its Ireland EU/EEA region. Direct email is handled by Robvarde's email service. Any processing outside the EEA requires a documented transfer mechanism and necessary supplementary safeguards before activation.
5. Retention and security
New commercial enquiries are reviewed no later than after 12 months. Data is deleted or anonymised when no longer necessary, unless an active dialogue, agreement, legal claim or statutory duty requires further retention. Account and customer data follows the active agreement and documented retention rules. Pseudonymous abuse-prevention identifiers are automatically removed after short technical windows.
6. Cookies
The public website does not use marketing cookies or third-party analytics in this version, so it does not show an unnecessary consent banner. The customer portal uses strictly necessary first-party session cookies for secure access. Non-essential tracking will not be activated without prior valid consent and updated information.
7. AI and automated decisions
The public AI adviser is disabled. Robvarde does not use the website for solely automated decisions with legal or similarly significant effects. Calculator results are editable estimates and require human assessment before a proposal or recommendation.
8. Your rights
You may request information, access, correction or deletion and, where applicable, restriction, portability or object to processing. We normally respond within one month and may verify your identity. Contact hei@robvarde.no. You may also complain to the Norwegian Data Protection Authority.