Privacy Policy for 

PSA Solutions AS and its group companies

Version 2.0, July 2026

1. About this policy

1.1 PSA Solutions AS ("PSA", "we", "us") is committed to protecting your privacy and to processing your personal data lawfully, fairly and transparently.

1.2 This policy explains how we process personal data when we decide why and how it is processed — that is, when we act as a data controller. It covers personal data relating to:

  • visitors to our websites and users of our online services;
  • representatives of our clients, prospective clients, suppliers, partners and subcontractors;
  • individuals who contact our service desk or attend our events;
  • newsletter subscribers; and
  • applicants for employment with us.

1.3 This policy does not cover personal data that we process on behalf of our clients when we deliver, host or support their systems — for example data held in an iManage environment, a time-recording system or an ERP system that we operate for a client. In those cases the client is the controller and we act as a processor on their documented instructions. Section 3 explains this distinction. If you are a lawyer, employee or client of one of our clients and you want to know how your data is handled in a system we operate, please contact that organisation directly; they are responsible for answering you, and we will support them in doing so.

1.4 We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), which applies in Norway through the Personal Data Act (personopplysningsloven) and the EEA Agreement, together with the supplementary national data protection legislation of the other countries where we operate.

2. Who we are and how to contact us

2.1 PSA is a group of companies. Which of them is responsible for your personal data depends on what the data is being used for, not on which company you happen to have heard of. For some activities a single PSA company decides everything and is the sole controller. For a small number of group-wide activities, two or more PSA companies decide together and are joint controllers. Sections 2.2 to 2.4 set out which is which.

The PSA companies are:

Entity Registered address Organisation number
PSA Solutions AS (parent) Bryggegata 9, NO-0250 Oslo, Norway 919 276 835
PSA Sweden AB Luntmakargatan 26, SE-111 37 Stockholm, Sweden 559343-6685

 

2.2 Where a single PSA company is the controller. For your relationship with us as a client, supplier or partner — the contract, the project, the invoicing and the correspondence that goes with it — the controller is the PSA entity that contracts with you or with the organisation you represent. The same applies to our own employees and job applicants, where the employing or recruiting company is the controller. These companies decide these matters independently of each other.

2.3 Where PSA companies are joint controllers. For a small number of group-wide activities we decide the purposes and the essential means together, and we are therefore joint controllers under Article 26 GDPR. These activities are:

  • our group CRM system, in which we record and manage contacts across all our markets;
  • our marketing and newsletter distribution, and the analysis of how recipients interact with it; and
  • psasolutions.com and the forms, enquiries and cookie-based analytics on it.

For these activities the joint controllers are PSA Solutions AS and PSA Sweden AB.

2.3.1 For those activities we have entered into an arrangement under Article 26 GDPR allocating responsibility between us, in particular for providing this information, handling your requests, and notifying personal data breaches.

2.3.2 Your rights are not affected by how we have divided responsibility between ourselves. Where PSA companies are joint controllers, you may exercise your rights under Section 12 against any of them, and each of them must respond. To make it simple, we have designated a single contact point for all such requests: see Section 2.5.

2.4 Where one PSA company acts for another. Some group functions — IT operations, security monitoring, finance and administration — are run by one PSA company on behalf of the other. In those cases the company running the function acts as a processor on the other's instructions and does not use the data for its own purposes.

2.5 Contact us about privacy. This is also the designated contact point for the joint controllership described in Section 2.3.

  • Email: contact-se@psasolutions.com
  • Post: PSA Solutions AS, Att: Privacy, Bryggegata 9, NO-0250 Oslo, Norway
  • Phone: +47 22 12 04 01

3. When we act as a processor rather than a controller

3.1 A large part of what we do is operate, integrate and support software for our clients. When we do that, we handle personal data that belongs to our client's environment — documents, matters, time entries, mailboxes, user accounts, support tickets and system logs. Our client decides why and how that data is used. We do not.

3.2 For that data:

  • we act only on the client's documented instructions, under a written data processing agreement meeting Article 28(3) GDPR;
  • we do not use it for our own purposes, and we do not use it to develop, train or improve our own or any third party's products or artificial-intelligence models (unless the client has separately and specifically instructed us to);
  • we engage sub-processors only under a written contract imposing equivalent obligations, and we maintain an up-to-date sub-processor list, disclosed in Client DPAs;
  • we notify the client without undue delay after becoming aware of a personal data breach affecting their data, and we assist them with data subject requests, impact assessments and consultations;
  • we impose confidentiality obligations on all personnel with access, and we recognise that data belonging to legal-sector clients may be subject to legal professional privilege or a duty of confidentiality; and
  • on termination we delete or return the data at the client's choice, subject to any retention required by law.

3.3 If we receive a request under Section 12 (Your rights) that relates to data we hold as a processor, we will not action it ourselves. We will tell you promptly and, where we can identify the controller, refer the request to them.

4. Why we process personal data, on what legal basis, and for how long

We process personal data for the purposes set out below. Section 2 explains which PSA company is the controller for each — in short, the contracting company for the relationship-based purposes in 4.2, 4.4 and 4.7, the employing company for 4.6, and the joint controllers named in Section 2.3 for the website and marketing purposes in 4.1 and 4.3.

4.1 Operating and improving our websites

Controller: The joint controllers named in Section 2.3.

What we process: usage data (pages viewed, referring page, session behaviour, cookie and similar identifiers), device and connection data (IP address, browser and operating system type, approximate location derived from IP), and information you submit through web forms.

Legal basis: cookies and similar technologies that are strictly necessary to deliver the service you asked for are exempt from the consent requirement under the Norwegian Electronic Communications Act (ekomloven, LOV-2024-12-13-76) § 3-15 and Article 5(3) of the ePrivacy Directive; for the personal data they involve we rely on our legitimate interest (Art. 6(1)(f)) in operating a functioning and secure website. For all other cookies and similar technologies — including analytics, personalisation and marketing — we rely on your consent (Art. 6(1)(a)), collected through our cookie banner to the GDPR consent standard. The equivalent national rules are: Norway, ekomloven (LOV-2024-12-13-76) § 3-15; Sweden, lagen om elektronisk kommunikation (2022:482) 9 kap. 28 §; Denmark, cookiebekendtgørelsen (BEK nr. 1148 af 9. december 2011); and Finland, laki sähköisen viestinnän palveluista (917/2014) § 205. See Section 11 for how consent is obtained and withdrawn, and Section 11.7 for the authorities that supervise these rules.

Withdrawal: you can change or withdraw your cookie consent at any time, as easily as you gave it, using the cookie settings control in the site footer (Section 11.4). Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew.

Retention: cookie lifetimes are listed in Section 11 / our cookie notice. Aggregated analytics records are kept for 14 months and server security logs for 6 months.

4.2 Providing, supporting and administering our services and our client relationships

Controller: the PSA company that contracts with you or your organisation (Section 2.2).

What we process: contact details (name, business address, email, phone), work-related data (employer, job title, role in the project), the content of your correspondence with us, service desk and support ticket data, records of meetings and calls, administrative account data for the systems we operate, and contract and project documentation.

Legal basis: where our contract is with you personally, performance of that contract (Art. 6(1)(b)). Where our contract is with the organisation you represent — the usual case — our legitimate interest (Art. 6(1)(f)) in delivering the contracted services, managing the relationship and keeping proper project records; and the corresponding legitimate interest of your organisation in receiving the service.

Retention: for the duration of the relationship and then suggested: 3 years from the end of the contract, extended where a longer period is required by Section 4.7 or where a claim is pending or reasonably foreseeable (see 4.8).

4.3 Sales, marketing and events

Controller: The joint controllers named in Section 2.3 for the group CRM and for marketing distribution and analytics; the local PSA company for events it organises itself.

What we process: contact details, work-related data, marketing preferences and interaction data (whether you opened an email or clicked a link, event attendance, content downloads), and information you share in connection with a meeting or event (including dietary and accessibility requirements you choose to tell us — see Section 6).

Legal basis:

  • Email and SMS marketing to a named individual: your consent, or the narrow "soft opt-in" — available only where you are an existing customer, we obtained your electronic address in connection with a sale, we are marketing our own similar goods or services, and we gave you an easy and free opportunity to opt out both at the point of collection and in every message since.
  • Marketing to a generic organisational address, postal marketing, and running events: our legitimate interest (Art. 6(1)(f)) in promoting our services.
  • Analytics on how you interact with our marketing, and any profiling to tailor content: your consent.

Withdrawal: every marketing message contains an unsubscribe link, and you can opt out at any time at contact-se@psasolutions.com. Withdrawing consent does not affect the lawfulness of processing before withdrawal.

Retention: 24 months from the later of collection and your last interaction with us, after which we delete the marketing record in full. If you have opted out, the only element we retain is a hashed copy of your email address on our suppression list, kept indefinitely for the sole purpose of making sure we do not contact you again. It is not used for any other purpose.

4.4 Client and supplier onboarding, contracting and due diligence

What we process: identity and contact details of signatories and authorised representatives, company and credit information, sanctions and adverse-media screening results where applicable, and billing and payment information.

Legal basis: taking steps at your request prior to entering a contract, and performance of the contract (Art. 6(1)(b)); compliance with a legal obligation (Art. 6(1)(c)) where screening is required of us; and our legitimate interest (Art. 6(1)(f)) in verifying who we are dealing with and managing credit and counterparty risk.

Retention: Duration of the relationship plus 5 years, or longer where accounting or anti-money-laundering law requires.

4.5 Security, IT operations and fraud prevention

Controller: the PSA company that contracts with you or your organisation (Section 2.2).

What we process: access logs, authentication records, endpoint and network telemetry, and records of security incidents.

Legal basis: our legitimate interest (Art. 6(1)(f)) in keeping our systems, our clients' systems and our people secure; and compliance with legal obligations (Art. 6(1)(c)).

Retention: 12 months, longer for records relating to an investigated incident.

4.6 Recruitment

Controller: the PSA company recruiting for the role (Section 2.2).

What we process: your CV and application, contact details, employment and education history, interview notes, assessment and test results, and references. We do not carry out background checks.

Legal basis: our legitimate interest (Art. 6(1)(f)) in assessing candidates and keeping a record of recruitment decisions; and, once we are agreeing terms with you, steps taken at your request prior to entering a contract (Art. 6(1)(b)). (Most supervisory authorities treat Art. 6(1)(b) as unavailable for pre-offer candidate assessment, so legitimate interests is the primary basis.) Our recruitment is also subject to the limits in the Norwegian Working Environment Act (arbeidsmiljøloven) chapter 9, including § 9-3, which restricts the information we may ask applicants for — in particular about health.

Retention: 6 months after the recruitment process ends, or longer with your consent if we keep your details for future roles.

4.7 Complying with legal obligations

What we process: contact and identity data, payment and transaction data, accounting records, and correspondence relevant to a legal obligation.

Legal basis: compliance with a legal obligation to which we are subject (Art. 6(1)(c)) — for example accounting, audit, tax and, where applicable, employment and corporate law.

Retention: as required by the applicable law — for example five years after the end of the financial year for primary accounting documentation (and three years and six months for secondary documentation) under the Norwegian Bookkeeping Act (bokføringsloven § 13); and seven years from the end of the calendar year in which the financial year ended under the Swedish Accounting Act (bokföringslagen 7 kap. 2 §).

4.8 Establishing, exercising or defending legal claims

Controller: the PSA company involved in the legal claim.

What we process: any of the above categories, to the extent relevant to a claim.

Legal basis: our legitimate interest (Art. 6(1)(f)) in protecting our legal position, and Art. 9(2)(f) where special category data is involved.

Retention: until the claim is resolved and the applicable limitation period has expired.

5. Where we get your personal data

5.1 Most of the personal data we hold comes from you or from the organisation you represent — when we start a business relationship, while we deliver a project, through our website and online forms, through email and our service desk, and at meetings and events.

5.2 We also obtain personal data from the sources below. From these sources we typically obtain your name, job title, employer, business contact details and publicly available company and credit information — not the content of your correspondence with us, which comes only from you.

  • your employer or the organisation you represent;
  • other PSA group companies;
  • public registers, including Brønnøysundregistrene (Norway), Bolagsverket (Sweden) and the equivalent registers in other countries;
  • business information providers;
  • publicly available professional sources such as your organisation's website and your public professional profiles, where we use these for business development; and
  • our partners, resellers and technology vendors where they refer you to us.

5.3 Where we obtain your data from a source other than you, we will tell you within one month of obtaining it — or, if sooner, at our first communication with you, or at the latest when we first disclose the data to another recipient — unless an exception in Article 14(5) GDPR applies. This policy also serves that purpose.

6. Special categories of personal data and criminal offence data

6.1 We do not seek out special category data (Article 9 GDPR — for example health, religious belief or trade union membership) in the course of our controller activities. We may nonetheless receive some, for example when you tell us about a dietary requirement or an accessibility need for an event, or health information relevant to a recruitment adjustment. Where we do, we rely on your explicit consent (Art. 9(2)(a)); on Art. 9(2)(b) in an employment context, to the extent authorised by Union or national law or by a collective agreement providing appropriate safeguards; or on Art. 9(2)(f) where it is needed to establish, exercise or defend a legal claim.

6.2 We do not process criminal conviction or offence data (Article 10 GDPR) as a controller, with the exception of the adverse-media screening specified in Section 4.4.

6.3 Systems we operate for clients may contain special category or criminal offence data belonging to our client's own matters. We process that only as a processor under Section 3, and we do not access it except as necessary to deliver, secure or support the service.

7. Automated decision-making, profiling and artificial intelligence

7.1 We do not make decisions about you that produce legal effects, or similarly significantly affect you, based solely on automated processing.

7.2 We carry out limited profiling for marketing purposes — for example scoring how engaged a contact is, or segmenting our mailing lists — where you have consented. You may withdraw that consent at any time (Section 12.9), and you may object to profiling for direct marketing at any time and without giving a reason (Section 12.8). Where we ever rely on legitimate interests for profiling, you may object under Section 12.7.

7.3 Our products and services include features that use artificial intelligence. Where those features process personal data for which we are the controller, we describe the processing in this policy. Where they process our clients' data, we do so only as a processor on the client's instructions and we do not use client data to train models — see Section 3.2.

8. Whether you have to give us your personal data

8.1 Whether you have to provide personal data, and what happens if you do not, depends on why we are asking:

  • Contractual requirement. The contact, identity and contractual data needed to enter into or perform an agreement must be provided. If you do not provide it, we cannot conclude or perform the contract and cannot deliver the service.
  • Statutory requirement. Some data we are obliged to collect and keep by law — in particular the identity, transaction and invoicing data required by the Norwegian Bookkeeping Act (bokføringsloven) and equivalent accounting, tax and audit legislation in the other countries where we operate, and any anti-money-laundering or sanctions-screening obligations that apply to us. If you do not provide it, we cannot invoice or transact with you.
  • Voluntary. Everything else — marketing preferences, event and dietary information, optional form fields, and non-necessary cookies — is entirely up to you. If you decline non-necessary cookies, parts of our website may be less useful to you, but the site will still work, and declining has no effect on any service you receive from us.

9. Who we share personal data with

9.1 We share personal data only where there is a lawful basis and a need to do so. Recipients fall into these categories:

  • Other PSA group companies. Depending on the activity, another PSA company may receive your data as a joint controller (Section 2.3), as a separate controller managing its own client or supplier relationship (Section 2.2), or as a processor running a shared group function on our instructions (Section 2.4). Group companies that access client environments as sub-processors are identified on the sub-processor list referred to in Section 3.2.
  • Processors acting on our instructions, including providers of cloud infrastructure and hosting, CRM and marketing automation, service desk and ticketing, accounting and invoicing, HR and recruitment, and IT security. Each is bound by a written agreement under Article 28 GDPR.
  • Technology vendors and partners whose products we resell, implement or support, where the sharing is necessary to license, provision or support your solution.
  • Professional advisers — auditors, accountants, lawyers and insurers — who act as independent controllers or as processors depending on the engagement.
  • Event suppliers, such as venues, hotels, caterers and speakers.
  • Subcontractors engaged in delivering a project, under equivalent confidentiality and data protection obligations.
  • Public authorities and courts, where we are legally required to disclose or where disclosure is necessary for a legal claim.
  • Counterparties and their advisers in a corporate transaction, such as a merger, acquisition, financing or reorganisation, under confidentiality obligations. If our business is transferred, personal data may transfer with it; we will inform you if this materially changes how your data is handled.

9.2 Social media platforms. We advertise and publish content on platforms including LinkedIn. When we use audience, insights or advertising tools on those platforms, we and the platform act as joint controllers for the collection and transmission of the data underlying those tools, in line with Court of Justice case law (Wirtschaftsakademie, C-210/16; Fashion ID, C-40/17). The platform is solely responsible for its own subsequent processing.

9.3 We do not sell your personal data. We do not disclose your personal data to third parties for their own independent marketing purposes.

10. International transfers

10.1 We process personal data primarily within the EU/EEA. Some of our processors, technology vendors and group functions are located in, or access data from, countries outside the EU/EEA.

10.2 Where we transfer personal data outside the EU/EEA, we rely on one of the following:

  • an adequacy decision of the European Commission, as incorporated into the EEA Agreement, covering the destination country — including, for transfers to organisations self-certified under the EU–U.S. Data Privacy Framework, Commission Implementing Decision (EU) 2023/1795;
  • the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914; or
  • a derogation under Article 49 GDPR, in the limited cases where it applies.

10.3 Your rights where standard contractual clauses apply. Where a transfer of your personal data is made under the standard contractual clauses:

  • you are entitled, on request, to a copy of the clauses (with commercial terms redacted) and to be informed of the categories of personal data transferred and of any onward transfer;
  • you may invoke and, where necessary, enforce the clauses against the data exporter and the data importer as a third-party beneficiary; and
  • the data importer is required to notify the data exporter and, where practicable, the data subject if it receives a legally binding request from a public authority in the destination country for disclosure of the transferred data, or if it becomes aware of any direct access by public authorities to that data, unless prohibited from doing so.

11. Cookies and similar technologies

11.1 We use cookies, pixels, tags, local storage and similar technologies on our websites. Some read or write information on your device.

11.2 We place only strictly necessary cookies by default. All other categories — statistics/analytics, preferences and marketing — are set only after you give consent through our cookie banner. The banner offers "Accept all" and "Reject all" with equal prominence, and does not use pre-ticked boxes.

11.3 The categories we use are:

Category Purpose Consent needed? Typical lifetime
Strictly necessary Session management, load balancing, security, remembering your cookie choice No Session – 12 months
Preferences Remembering language and display settings Yes 12 months
Statistics / analytics Understanding how the site is used so we can improve it Yes up to 14 months
Marketing Measuring campaign performance Yes up to 13 months

 

11.3.1 How long your choice lasts. We ask you to renew your cookie choice at most once every 12 months. If you have declined, we will not ask you again for at least 12 months, and we will not re-prompt you during a visit or repeat the request from page to page. We will ask again sooner only if we materially change what we use cookies for.

11.4 You can change or withdraw your consent at any time by clicking "Cookie settings" in the footer of any page. Withdrawing consent is as easy as giving it. You can also block or delete cookies in your browser settings, though this may affect how the site works.

11.5 We do not treat continued scrolling or browsing as consent, and we do not use a cookie wall. We do not set any non-necessary cookie or similar technology before you have consented, and we do not make access to our website conditional on your consent.

11.6 Tracking technologies other than cookies. The consent requirement is not limited to cookies. It applies to anything that stores information on, or reads information from, your device — and, following the European Data Protection Board's Guidelines 2/2023 on the technical scope of Article 5(3) of the ePrivacy Directive (version 2.0, adopted 16 October 2024), also to techniques such as tracking pixels, tracking URLs and link decoration, browser or device fingerprinting, local and session storage, mobile advertising identifiers, and tracking based on IP address alone. Moving a tracking technique to our own servers does not remove the need for consent. Wherever this policy refers to cookies, it means all of these.

11.7 Who supervises these rules. Cookie and tracking rules are supervised separately from the GDPR, and by different bodies in each country:

Country Cookie / tracking supervision GDPR supervision
Norway Nkom and Datatilsynet jointly, under ekomloven § 3-15 Datatilsynet
Sweden Post- och telestyrelsen (PTS), under LEK 9 kap. 28 § Integritetsskyddsmyndigheten (IMY)

 

You may raise a cookie or tracking concern with the relevant authority above, in addition to the rights in Section 12.

12. Your rights

12.1 Our responsibility. As a controller we are responsible for enabling you to exercise the rights below. Contact us using the details in Section 2.5. Where the processing you are asking about is jointly controlled by more than one PSA company (Section 2.3), you may address your request to any of them, or simply use the contact point in Section 2.5 and we will route it. We may need to verify your identity before we act, and we will only ask for what is necessary to do so.

12.2 Timescales and cost. We will respond within one month of receiving your request. If your request is complex, or if you have made a number of requests, we may extend this by up to two further months and will tell you within the first month, with our reasons. Our response is free of charge. If a request is manifestly unfounded or excessive — in particular because it is repetitive — we may charge a reasonable fee based on the administrative cost of responding, or refuse to act; in either case we will explain why and tell you how to complain.

12.3 Access. You can ask whether we process personal data about you and, if so, receive a copy together with information about the processing. If you ask electronically, we will respond in a commonly used electronic format unless you ask otherwise. We may charge a reasonable administrative fee for further copies.

12.4 Rectification and completion. You can ask us to correct inaccurate personal data and to complete incomplete data, including by providing a supplementary statement. We may also correct data on our own initiative when we become aware it is wrong.

12.5 Erasure. You can ask us to erase your personal data where: it is no longer needed for the purpose we collected it for; you withdraw the consent we relied on and there is no other basis; you object under 12.7 and we have no overriding legitimate grounds; you object to direct marketing; we have processed it unlawfully; or we are legally required to erase it. We may not be able to erase data we are required to keep by law or that we need for a legal claim; if so, we will tell you and will restrict our other use of it.

12.6 Restriction. You can ask us to temporarily stop using your personal data where: you contest its accuracy, while we verify it; the processing is unlawful but you prefer restriction to erasure; we no longer need it but you need it for a legal claim; or you have objected under 12.7 and we are still assessing whether our grounds override yours.

12.7 Objection. Where we rely on legitimate interests, you can object at any time on grounds relating to your particular situation. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or we need the data for a legal claim.

12.8 Objection to direct marketing.You may object at any time, free of charge, without giving a reason, and PSA will stop direct marketing immediately. To object, use the unsubscribe link in any message or write to us at contact-se@psasolutions.com.

12.9 Withdrawal of consent. Where we rely on your consent — for non-necessary cookies, for some marketing, and for special category data — you can withdraw it at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.

12.10 Portability. Where we process your data by automated means on the basis of your consent or a contract with you, you can ask to receive it in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.

12.11 Notification to recipients. Where we rectify, erase or restrict your personal data, we will notify each recipient we disclosed it to, unless this proves impossible or involves disproportionate effort. On request, we will tell you who those recipients are.

12.12 Complaints. We would like the chance to resolve your concern first, so please contact us. You also have the right to lodge a complaint with a supervisory authority — in particular in the EU/EEA country where you live or work, or where you believe the infringement occurred. We consider our lead supervisory authority to be the Norwegian Data Protection Authority (Datatilsynet), P.O. Box 458 Sentrum, 0105 Oslo, Norway (visiting address Trelastgata 3, 0191 Oslo), telephone +47 22 39 69 00. Datatilsynet asks that complaints be submitted through the complaint form on its website rather than by email, so that your personal data is not sent unencrypted. Other authorities relevant to our operations include the Swedish Authority for Privacy Protection (IMY), the Danish Data Protection Agency (Datatilsynet, Denmark), and the Office of the Data Protection Ombudsman (Finland). You also have the right to an effective judicial remedy against a supervisory authority or against us.

13. Children

13.1 Our services and our website are directed at businesses and business professionals. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

14. How we protect your personal data

14.1 We maintain appropriate technical and organisational measures to protect personal data against unauthorised or unlawful access, alteration, disclosure, loss and destruction, taking account of the state of the art, the cost of implementation and the risks involved. These include access control on a least-privilege basis, multi-factor authentication, encryption in transit and at rest, network segregation, logging and monitoring, secure development practices, supplier assurance, personnel confidentiality undertakings and training, and tested backup and recovery.

14.2 Breach notification. If a personal data breach occurs for which we are the controller, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to your rights and freedoms. Where the breach is likely to result in a high risk to you, we will also inform you without undue delay and explain what happened, its likely consequences, the measures we are taking and what you can do to protect yourself. Where we act as a processor, we notify our client without undue delay and support their notifications.

15. Changes to this policy

15.1 We may update this policy from time to time — for example when we change our services, our suppliers or our systems, or when the law changes.

15.2 The version number and effective date appear at the top of this policy. Where a change is more than editorial and materially affects you, we will give you notice — by email where we hold your address for that purpose, and by a prominent notice on our website — a reasonable period before it takes effect. Where a change requires your consent, we will ask for it before relying on the change.

15.3 New purposes. If we intend to use your personal data for a purpose other than the one we collected it for, we will tell you about that new purpose, and give you the information in this policy that relates to it, before we start — and where the new purpose is not compatible with the original one, we will identify a fresh legal basis and, where that basis is consent, ask you for it.

16. Contact us

PSA Solutions AS Bryggegata 9, NO-0250 Oslo, Norway Org. no. 919 276 835

Privacy enquiries: contact-se@psasolutions.com