Legal

Privacy Policy

Helkrypt AI AS

Last updated: 25 September 2026


1. Who we are

Helkrypt AI AS (“Helkrypt AI”, “we”, “us” or “our”) is a Norwegian company that provides AI-driven automation solutions for Norwegian businesses.

We are the controller for personal data processed through our services and website.

Contact: marius@helkrypt.no

2. What information we collect

Payment data

  • Billing name, address and payment details
  • Transaction history
  • We never store full card numbers — these are processed by Stripe

Technical data

  • IP address, browser type, operating system
  • Device identifiers
  • Log data (access times, pages visited, errors)

Communication data

  • Enquiries via the contact form (name, email, optionally phone and message)
  • Messages sent to our support
  • Responses to surveys or feedback forms

Enquiries via the contact form are not stored in a database. They are sent to us as email via Resend, and we keep them for up to 12 months, with the legal basis in GDPR art. 6(1)(b) (steps prior to entering into a contract). We do not log IP address or browser information together with the enquiry.

3. How we use your information

PurposeExamples
Providing our servicesOperating our services
Processing paymentsInvoicing, subscription management
Improving our productsAggregated usage analysis, bug fixing
Communicating with youProduct updates, support replies
Security and fraud preventionDetecting unauthorised access
Regulatory complianceMeeting GDPR, tax and regulatory requirements

We do not sell your personal data to third parties.

4. Legal basis for processing (GDPR)

Processing activityLegal basis
Providing the services we have agreed with youContract (art. 6(1)(b))
Answering enquiries via the contact formSteps prior to a contract (art. 6(1)(b))
Processing paymentsContract (art. 6(1)(b))
Security monitoring and fraud preventionLegitimate interest (art. 6(1)(f))
Product improvement (aggregated analysis)Legitimate interest (art. 6(1)(f))
Sending marketing communicationsConsent (art. 6(1)(a))
Compliance with legal obligationsLegal obligation (art. 6(1)(c))

5. Data sharing and sub-processors

All sub-processors are bound by data processing agreements (DPAs) requiring GDPR-compliant data handling.

Sub-processorPurposeLocationBasis
Supabase (AWS)Database, authentication, storageEU (Frankfurt)GDPR DPA, SCCs
VercelWeb hosting, edge functionsEU (Frankfurt)GDPR DPA
StripePayment processingEU (Stripe Payments Europe, IE)GDPR DPA — EU entity, SCCs not required
AnthropicAI inference (Claude API)EU (DPA active via Ireland)GDPR DPA — EU entity, SCCs not required
Resend (Plus Five Five, Inc.)Email notifications from the contact formEU (Ireland), US companyGDPR DPA, SCCs (module 2), EU–US Data Privacy Framework
Domene.noWeb hosting and emailNorwayGDPR DPA

We do not share your data with advertising networks or data brokers without your consent.

6. International data transfers

Except for Resend, all our sub-processors are located in the EU/EEA (Vercel Frankfurt, Supabase Frankfurt, Stripe Ireland, Anthropic Ireland, Domene.no Norway).

Resend (USA) sends email notifications from the contact form. This transfer is based on the European Commission's standard contractual clauses (SCCs, decision 2021/914, module 2) and Resend's certification under the EU–US Data Privacy Framework (Resend's data processing agreement).

If further transfers outside the EU/EEA become relevant, we will use the European Commission's standard contractual clauses (SCCs, decision 2021/914) or adequacy decisions, and update this page.

Questions about data location: marius@helkrypt.no

7. How long we keep data

Data categoryRetention period
Contact form enquiries12 months
Payment information5 years (Norwegian Bookkeeping Act)
Support communication2 years from closure
Log/technical data90 days
Consent records (marketing)Duration of consent + 3 years

8. Cookies and tracking

This website does not use cookies, analytics tools or tracking technology. We do not collect usage statistics about visitors.

9. Your rights — EU/EEA users (GDPR)

Under GDPR articles 15–22 and the Norwegian Personal Data Act:

RightDescription
Right of access (art. 15)Request a copy of your personal data
Right to rectification (art. 16)Correct inaccurate or incomplete data
Right to erasure (art. 17)Request deletion of your data
Right to restriction of processing (art. 18)Pause the processing of your data
Right to data portability (art. 20)Receive your data in a machine-readable format
Right to object (art. 21)Object to processing based on legitimate interest
Rights related to automated decisions (art. 22)Request human review of automated decisions
Withdraw consent (art. 7(3))Withdraw consent at any time

Submit a request: marius@helkrypt.no — we respond within 30 days.

Supervisory authorities:
Norway: Datatilsynet (Norwegian Data Protection Authority) — www.datatilsynet.no
EU: Your local data protection authority

10. Children's privacy

Our services are not intended for users under 18. We do not knowingly collect data from children. Contact marius@helkrypt.no if you believe a child has submitted data.

11. Security

  • In transit: TLS 1.2+ encryption
  • At rest: AES-256 encryption
  • Access controls: Role-based, least-privilege access
  • Breach notification: Datatilsynet is notified within 72 hours of a qualifying breach (GDPR art. 33); affected users are notified without undue delay (art. 34)

Suspected unauthorised access: contact marius@helkrypt.no immediately.

12. Changes to this policy

Material changes will:

  • Be published with an updated “Last updated” date
  • Require new consent where required by law

13. Atlassian Marketplace apps

Our apps for Atlassian cloud products and our customer support are covered by a separate privacy policy: https://www.helkrypt.no/privacy/apps.

14. Contact us

Helkrypt AI AS
marius@helkrypt.no
Norway

Complaints (Norway): Datatilsynet — www.datatilsynet.no


This privacy policy applies to Helkrypt AI AS and our services.