Privacy Policy
Last updated: 1 September 2026
This policy describes how Risan Solutions handles personal data on risansolutions.com, risansolutions.no and risansolutions.store. It is written to meet the requirements of Articles 13 and 14 of the General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (personopplysningsloven).
1. Data Controller
Risan Solutions (Org.nr 937 137 273), a Norwegian sole proprietorship (enkeltpersonforetak), is the data controller for personal data processed through this website and associated services.
- Address: Valenvegen 49, 3802 Bø i Telemark, Norway
- Email: contact@risansolutions.com
We have not appointed a Data Protection Officer; we are not required to do so under Article 37. Privacy enquiries go to the address above.
2. What Data We Collect
If you create an account
- Email address and display name, which you provide
- A cryptographic hash of your password — we never store the password itself and cannot recover it
- Account state: whether your email is verified, the time of your last sign-in, and the times your account was created and last changed
While you are signed in
- A session record holding your account ID, a truncated-and-hashed form of your IP address, and a hashed form of your browser’s user-agent string. The truncation removes the final part of the address before hashing, so the original IP cannot be recovered from it. Sessions are held in memory and expire after 7 days.
If you use the contact form
- Your name, email address, subject and message
- A truncated-and-hashed IP address, used only to rate-limit spam submissions
Security and administration logs
- Security events — failed sign-in attempts, account lockouts, password changes and resets, and rate-limit triggers. These records contain your full IP address and full user-agent string, because a truncated address is not sufficient to investigate an attack.
- Administrative audit records of actions taken by our administrators on accounts, including the administrator’s IP address.
- If you submit a bug report, abuse report or feedback: the subject, message, the page you were on, and your account ID if you were signed in.
What we do not collect
We do not use analytics, advertising or tracking services. We do not build profiles, and we do not make any decision about you by automated means, including profiling, within the meaning of Article 22. We do not knowingly collect data from children under 13, and accounts are not intended for them.
3. Why We Process It, and On What Legal Basis
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and running your account | Account data, session data | Art. 6(1)(b) — performance of a contract |
| Verifying your email address | Email address | Art. 6(1)(b) — performance of a contract |
| Answering your enquiry | Contact form submission | Art. 6(1)(b) / 6(1)(f) — steps prior to a contract, or our legitimate interest in responding |
| Protecting accounts against attack and abuse | Security events, rate-limit data | Art. 6(1)(f) — our legitimate interest in securing the service, balanced against your interests |
| Recording administrator actions | Audit records | Art. 6(1)(f) and Art. 5(2) — accountability |
| Service notifications about your account | Email address, display name | Art. 6(1)(b) — performance of a contract |
We do not currently send marketing email. If we ever do, it will be on the basis of your consent under Art. 6(1)(a), asked for separately, and you will be able to withdraw that consent at any time without affecting the lawfulness of what came before.
4. Whether You Have to Provide It
Providing an email address, display name and password is necessary to create an account — without them we cannot provide one. You are not otherwise required to give us personal data, and you can browse the public parts of these websites without an account.
5. Who Else Sees Your Data
We do not sell personal data, and we do not share it for anyone else’s marketing. We use the following processors, each acting only on our instructions:
| Processor | Role | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting — all databases and application servers run here | Germany (EU) |
| Google Ireland Ltd. / Google LLC (Gmail) | Delivery of transactional email — verification, password reset, and contact confirmations | EU and United States |
Transfers outside the EEA. Sending you an email means your email address and the content of that message are handled by Google’s mail infrastructure, which includes servers in the United States. Google LLC is certified under the EU–US Data Privacy Framework, which the European Commission has found to provide an adequate level of protection under Art. 45. No other personal data leaves the EEA.
We may also disclose personal data where we are legally required to — for example in response to a valid order from a Norwegian court or authority.
6. How Long We Keep It
| Data | Retained for |
|---|---|
| Account data | As long as your account exists. When you delete it, the account is deactivated immediately and permanently erased 30 days later. |
| Session data | 7 days from last activity, then automatically discarded |
| Contact form submissions | 12 months |
| Security event logs | 12 months |
| Administrator audit records | 3 years, as our accountability record under Art. 5(2) |
These limits are enforced automatically by a scheduled job that runs monthly and deletes anything past its window. The 30-day period after account deletion exists so that an accidental deletion can be reversed — write to us within that time if you need it undone. After it passes, recovery is not possible.
7. Your Rights
Under the GDPR you have the right to:
- Access your personal data and receive a copy of it (Art. 15)
- Rectify data that is inaccurate or incomplete (Art. 16)
- Erase your data (Art. 17)
- Restrict our processing of it (Art. 18)
- Data portability — receive your data in a structured, commonly used, machine-readable format (Art. 20)
- Object to processing based on our legitimate interests, including the security logging described above (Art. 21)
- Withdraw consent at any time, where processing is based on consent (Art. 7(3))
Several of these are built into the site and need no request:
- Access and portability: download everything we hold about you as a JSON file from your account settings.
- Rectification: change your display name and email address from the same page.
- Erasure: delete your account from the same page.
For anything else, email contact@risansolutions.com. We will respond within one month, as required by Art. 12(3). If your request is complex we may extend that by up to two further months and will tell you why within the first month. Exercising these rights is free of charge.
8. Complaints
If you believe we have handled your personal data unlawfully, you can complain to the Norwegian Data Protection Authority:
- Datatilsynet, Postboks 458 Sentrum, 0105 Oslo, Norway
- www.datatilsynet.no
You may also complain to the supervisory authority in the EEA country where you live or work. We would appreciate the chance to address it first, but you are not required to come to us before going to a regulator.
9. Security
We protect personal data with measures appropriate to the risk, as required by Art. 32:
- All traffic is encrypted in transit with HTTPS, enforced by HSTS
- Passwords are stored as bcrypt hashes, never in a recoverable form
- Session cookies are HttpOnly, Secure and SameSite=Lax, and cannot be read by JavaScript
- Sign-in, registration, password reset and the contact form are rate-limited, and accounts lock after repeated failed sign-in attempts
- Databases are not reachable from the public internet
- Administrative access is restricted and every administrative action on an account is recorded
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify Datatilsynet within 72 hours under Art. 33, and notify you directly where Art. 34 requires it.
10. Changes to This Policy
We may update this policy as the service changes. The date at the top always reflects the current version. If a change materially affects how we handle your data, we will tell account holders by email before it takes effect.
11. Contact
For any privacy question or to exercise a right: contact@risansolutions.com