Nesdal Advisory AS – Privacy Policy

    1. Data controller

    Nesdal Advisory AS (organisation number 829499452), represented by Leonard Nesdal, is the data controller for our processing of personal data. Contact: contact@nesdal.no

    2. Purpose of processing

    We process personal data in order to:

    • provide our services
    • fulfil our obligations under law (anti-money laundering legislation, bookkeeping requirements)
    • administer customer relationships and engagements
    • ensure correct archiving and documentation
    • operate the website and respond to enquiries

    3. Categories of data processed

    Typical categories include:

    • contact information
    • case information and documents, which may contain sensitive data
    • identity information (AML requirements)
    • billing and payment information
    • technical logs (IP address, timestamps)

    We only process information that is necessary to carry out the engagement.

    4. Legal basis for processing

    Processing is carried out pursuant to:

    • GDPR Article 6(1)(b) – performance of a contract
    • GDPR Article 6(1)(c) – legal obligation (AML requirements, archiving obligations)
    • GDPR Article 6(1)(f) – legitimate interests

    5. Sharing of information

    Personal data is only shared when necessary:

    • with courts, counterparties, or public authorities
    • with data processors (IT providers, cloud storage) that have a data processing agreement in place

    Data processors only handle information in accordance with our instructions, and we do not share information for marketing or commercial purposes.

    6. Retention periods

    Customer files are retained for 10 years after the engagement has concluded. Information subject to the Anti-Money Laundering Act is retained for 5 years, pursuant to section 30. Information included in accounting records is retained for 5 years in accordance with the Bookkeeping Act.

    7. Your rights

    You have the right to:

    • access (Art. 15)
    • rectification (Art. 16)
    • limited erasure (Art. 17), insofar as statutory retention duties do not prevent this

    Requests must be submitted in writing.

    8. Information security

    We use:

    • encrypted storage (Microsoft 365)
    • two-factor authentication
    • backup routines
    • strict access control
    • no use of AI with customer data

    9. Data processors

    Our service providers include:

    • Microsoft 365
    • Uniweb
    • OpenAI (ChatGPT Business – without customer data)
    • Lovable Labs Inc.

    All have data processing agreements where required.

    10. Contact and right to complain

    Questions or requests concerning privacy should be sent to: contact@nesdal.no You may lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) if you believe your rights have not been respected.