Hopp til hovedinnhold
Privacy

Privacy Policy

Echo Algori Data – Last updated: December 8, 2025 (v2.0)

This privacy policy describes how Echo Algori Data collects, uses, stores and protects your personal data when you visit our websites (echoalgoridata.no and echoalgoridata.com) or use our services.

We take privacy seriously and comply with GDPR and Norwegian privacy legislation. See also:

1. Who We Are (Data Controller)

Echoalgoridata av Kisuule

St. Olavs gate 32

0166 Oslo, Norge

Org.nr.: 928 592 405

E-post: privacy@echoalgoridata.no

Echo Algori Data is the data controller for personal data we collect through our websites and in connection with our services, unless otherwise agreed (e.g. in a data processing agreement where we act as a data processor on your behalf).

2. What This Policy Covers

This privacy policy applies to:

  • Visits to our websites (echoalgoridata.no / .com)
  • Use of contact forms, newsletters and other features
  • Communication with us via email or other channels
  • Delivery of our consulting, development and automation services
  • Participation in our startup accelerator program

When we process personal data on behalf of our customers (as data processor), this is regulated by a separate data processing agreement (DPA) between us and the customer.

3. What Information We Collect

3.1. Information You Provide Directly

  • Contact information: Name, email address, company name, position
  • Project information: Descriptions of needs, system access, business data
  • Communication: Content of emails, messages and meeting notes
  • Payment information: Billing address, payment references (not card numbers)

3.2. Information We Collect Automatically

  • Technical information: IP address, browser type, operating system, device information
  • Usage data: Pages visited, clicks, time on page, referral sources
  • Location data: Approximate geographic location based on IP address

3.3. Information from Third Parties

We may receive information from business partners, public registers or social media when you choose to link your account or share information through these platforms.

4. How We Use the Information

We use personal data for the following purposes:

Service Delivery

To deliver, administer and improve our consulting, development and automation services.

Communication

To respond to inquiries, send project updates, invoice information and relevant service information.

Service Improvement

To analyze usage patterns, identify errors and improve the user experience on our websites.

Marketing

To send newsletters and service information, only with your consent. You can unsubscribe at any time.

Security and Compliance

To protect our systems, prevent fraud and comply with legal obligations.

5. Legal Basis for Processing

We process personal data based on the following legal grounds under GDPR:

Contract (Art. 6(1)(b))

When processing is necessary to fulfill a contract with you or at your request before entering into a contract.

Consent (Art. 6(1)(a))

For newsletters, marketing and non-essential cookies. You can withdraw consent at any time.

Legitimate Interest (Art. 6(1)(f))

For website operation, security, fraud prevention and service improvement.

Legal Obligation (Art. 6(1)(c))

For accounting requirements, tax purposes and other legal obligations.

6. Storage and Retention

We store personal data only as long as necessary for the purpose for which it was collected:

  • Customer data: Throughout the customer relationship plus 5 years after termination (accounting requirements)
  • Marketing data: Until you unsubscribe or withdraw consent
  • Website analytics: Max 26 months
  • Inquiries: 2 years unless they lead to a customer relationship

After the retention period expires, the data will be deleted or anonymized. Upon specific deletion request from you, we will delete data within 30 days, unless we have a legal basis to retain it.

7. Security

We take the security of your personal data seriously and have implemented appropriate technical and organizational measures:

  • Encryption of data in transit (HTTPS/TLS) and at rest where relevant
  • Access control and principle of least privilege
  • Regular backups and recovery testing
  • Updated systems and continuous security monitoring
  • Employee training in privacy and security

In Case of Security Breach

If a personal data breach occurs that poses a risk to your rights, we will notify relevant supervisory authorities within 72 hours and you directly if the risk is high.

8. Sharing of Information

We never sell your personal data. We may share information with the following categories of recipients:

Service Providers

Hosting (Vercel), email (Mailtrap), analytics (Vercel Analytics), and others who help us deliver our services. All are subject to data processing agreements.

Group Companies

ALG Dynamics (USA) and other group partners for project delivery, always subject to the same privacy standards.

Legal Requirements

Public authorities when required by law, or to protect our rights and security.

When transferring data to countries outside the EU/EEA, we use the EU Commission's Standard Contractual Clauses (SCC) or equivalent approved mechanisms to ensure adequate protection.

9. Cookies

In accordance with the Norwegian E-Com Act (effective January 1, 2025) and GDPR, we use cookies with your consent where required:

Strictly Necessary Cookies

Required for basic functions. Does not require consent under E-Com Act.

NamePurposeDurationType
localeLanguage selection (no/en)1 yearFirst-party
__next_*Next.js session managementSessionFirst-party

Analytics Cookies (require consent)

Used for anonymized traffic analysis and performance measurement.

ServicePurposeProviderPrivacy
Vercel AnalyticsAnonymized traffic analysisVercel Inc. (USA)No PII
Vercel Speed InsightsCore Web Vitals measurementVercel Inc. (USA)No PII

E-Com Act 2025 Compliance

We follow Datatilsynet's guidelines from April 2025. Consent for non-essential cookies is: freely given, specific, informed, and unambiguous. "Accept" and "Reject" are presented with equal visual weight.

You can manage and withdraw consent at any time via browser settings or by contacting us. Note that blocking necessary cookies may affect website functionality.

10. Your Rights

Under GDPR, you have the following rights regarding your personal data:

Right of Access

Request a copy of the information we have about you.

Right to Rectification

Ask us to correct inaccurate or incomplete information.

Right to Erasure

Request that we delete your data ("right to be forgotten").

Right to Restriction

Request that we restrict processing in certain situations.

Right to Data Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interest.

To exercise your rights, contact us at privacy@echoalgoridata.no. We will respond within 30 days.

11. Automated Decision-Making and AI

We use AI technology in our services and on our websites:

  • AI-supported customer service and chatbot functions
  • Automated validation of startup ideas (Echo Startup Accelerator)
  • Content recommendations and personalization

AI Service Providers We Use:

ProviderPurposeLocation
Anthropic (Claude)Text generation, analysis, agentsUSA (SCC)
OpenAI (GPT)Text generation, embeddingsUSA (SCC)
Google (Gemini)Multimodal AI, researchUSA/EU (SCC)
DeepSeekCode assistance, analysisCN (SCC)

SCC = EU Standard Contractual Clauses for international transfers

EU AI Act Compliance

We are preparing for the EU AI Act (effective August 2025-2027). Our AI systems are classified as minimal or limited risk. We implement AI literacy, documentation, and transparency requirements as per the regulation.

Human Oversight (GDPR Art. 22)

We do not make legally binding decisions solely based on automated processing. You always have the right to human review of decisions that significantly affect you.

12. Right to Complain

If you believe we are not processing personal data in accordance with regulations, you have the right to complain to the Data Protection Authority:

Datatilsynet

Postboks 458 Sentrum

0105 Oslo

Website: www.datatilsynet.no

We appreciate if you contact us first so we can try to resolve the matter directly.

13. Changes to Privacy Policy

We may update this privacy policy as needed. Changes take effect when published on this page with an updated date.

For material changes, we will notify you via email or a prominent notice on the website.

14. Contact Us

Do you have questions about this privacy policy or how we process your personal data?

Email (privacy): privacy@echoalgoridata.no

Email (general): info@echoalgoridata.no

15. Version History

VersionDateChanges
2.008.12.2025Added detailed cookie table, E-Com Act 2025 compliance, AI provider list, EU AI Act references
1.007.12.2025Initial version with 14 sections

Privacy | Terms | GDPR Compliant