Privacy Policy

    STÖ GROUP AS — stogroup.no

    Version 1.0 · Effective: 12 March 2026 · Last revised: 12 March 2026

    1. Data Controller

    The data controller for personal data collected and processed through this website is:

    STÖ GROUP AS

    Registration number: 935 699 819

    Johan Berentsens vei 109

    5163 Laksevåg, Bergen

    Email: personvern@stogroup.no

    Website: stogroup.no

    STÖ GROUP AS is a Norwegian limited company registered in the Register of Business Enterprises. The company is the parent company of a group that includes SYDERA.io Technologies AS. This privacy policy applies exclusively to the processing of personal data in connection with the website stogroup.no and enquiries received through this website. Other group companies have their own privacy policies.

    If you have questions about our processing of personal data, you may contact us at the email address above. We respond to all enquiries within 30 days, cf. GDPR Article 12(3).

    2. What personal data we process, and why

    We only process personal data that is necessary to fulfil the purposes described below. We do not collect more information than necessary, and we never process personal data for purposes other than those stated here, cf. GDPR Article 5(1)(b) (purpose limitation) and (c) (data minimisation).

    2.1 Contact form

    When you fill out the contact form on stogroup.no, we process the following data:

    DataPurposeLegal basis
    NameIdentify sender and address reply correctlyGDPR Art. 6(1)(b) (necessary to respond to the enquiry)
    Email addressRespond to the enquiryGDPR art. 6(1)(b)
    Organisation / companyUnderstand the context of the enquiryGDPR Art. 6(1)(f) (legitimate interest)
    Enquiry typeRoute the enquiry to the correct contact personGDPR art. 6(1)(b)
    Message contentRespond to the enquiryGDPR art. 6(1)(b)

    We do not process special categories of personal data (sensitive data) via the contact form, cf. GDPR Article 9. If you voluntarily provide information in the message field that may be classified as special categories — for example health data — we will process it solely to respond to your enquiry, and we will not retain such data beyond what is necessary for that purpose.

    2.2 Technical logs and website operations

    When you visit stogroup.no, technical data necessary for secure and stable operation of the website is processed. This includes IP address, browser type, operating system, time of visit and pages visited. This data is processed on the basis of GDPR Article 6(1)(f) (legitimate interest), as we have a legitimate interest in ensuring the technical function of the website and protecting it against misuse.

    IP addresses are anonymised or deleted in accordance with the retention period stated in section 4.

    2.3 Cookies

    The website stogroup.no uses a limited number of cookies. We distinguish between necessary cookies and optional cookies:

    Necessary cookies are technically required for the website to function correctly. These are stored without consent, cf. the Norwegian Electronic Communications Act § 2-7b and the Norwegian Data Protection Authority's guidance on cookies. They do not contain any personally identifiable information.

    We use Plausible Analytics to understand how visitors use the website. Plausible Analytics is EU-hosted, uses no cookies and does not require GDPR consent for basic visitor statistics.

    A complete overview of the cookies we use, their purposes and retention periods, is available in our separate cookie policy, accessible via the link at the bottom of the page.

    3. Who we share data with

    We do not sell personal data to third parties. We do not share personal data with anyone other than what is necessary to fulfil the purposes described in section 2.

    We use the following categories of data processors who process personal data on our behalf:

    CategoryServicePurposeTransfer outside EEA
    Website hostingVercel Inc. (USA)Operation and hosting of the websiteYes — see section 3.1
    Form handlingFormspree (USA)Receipt and forwarding of contact form submissionsYes — see section 3.1
    AnalyticsPlausible Analytics (EU)Anonymised visitor statisticsNo

    We have entered into data processing agreements with all data processors in accordance with GDPR Article 28. The agreements ensure that the data processors only process the data in accordance with our instructions and in compliance with the GDPR.

    3.1 Transfers to third countries

    Some of our data processors are established in the USA, which is a third country outside the EEA. Such transfers are carried out pursuant to the European Commission's Standard Contractual Clauses (SCC), cf. GDPR Article 46(2)(c), and/or pursuant to the EU-U.S. Data Privacy Framework where applicable.

    We carry out ongoing Transfer Impact Assessments of transfers to third countries to ensure that the level of protection is adequate.

    4. Retention periods

    We retain personal data only for as long as is necessary for the purposes for which it was collected, and no longer than required by law.

    Processing activityRetention periodJustification
    Contact form — enquiries2 years from date of receiptNecessary to document and follow up business relationships
    Technical logs (IP addresses etc.)90 daysNecessary for security and troubleshooting
    Analytics data13 months (rolling)Standard for web analytics
    Email correspondence5 yearsNorwegian Bookkeeping Act § 13 and general business practice

    Upon expiry of the retention period, the data is deleted or anonymised in a secure and irreversible manner.

    5. Your rights

    As a data subject, you have the following rights under GDPR Chapter III. We process all rights requests free of charge and within 30 days, cf. GDPR Article 12(3). If a request is particularly complex or we receive a large number of requests, the deadline may be extended by a further two months, and we will inform you accordingly.

    Right of access (GDPR Art. 15)

    You have the right to obtain confirmation as to whether we process personal data about you, and if so, to access that data and information about the processing.

    Right to rectification (GDPR Art. 16)

    You have the right to have inaccurate personal data about you corrected without undue delay. You also have the right to have incomplete personal data supplemented.

    Right to erasure ("right to be forgotten", GDPR Art. 17)

    You have the right to have personal data about you erased without undue delay if one of the specified conditions is met, including if the data is no longer necessary for the purposes for which it was collected, or if you withdraw consent on which the processing is based.

    Right to restriction of processing (GDPR Art. 18)

    You have the right to request restriction of processing in certain situations, for example if you contest the accuracy of the data or have objected to the processing.

    Right to data portability (GDPR Art. 20)

    Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used and machine-readable format, and to transmit it to another data controller.

    Right to object (GDPR Art. 21)

    You have the right to object to the processing of personal data about you that is based on GDPR Article 6(1)(e) or (f) (public interest or legitimate interest), including profiling. If you object, we will no longer process the personal data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms.

    Right to withdraw consent (GDPR Art. 7(3))

    Where processing is based on your consent, you have the right to withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.

    To exercise your rights, send a written request to personvern@stogroup.no. We may ask you to verify your identity to ensure that we do not disclose data to the wrong person.

    6. Right to lodge a complaint with the Data Protection Authority

    If you believe that our processing of personal data is in breach of data protection regulations, you have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).

    Datatilsynet

    Postboks 458 Sentrum, 0105 Oslo

    Phone: 22 39 69 00

    Email: postkasse@datatilsynet.no

    Website: datatilsynet.no

    We nevertheless encourage you to contact us directly first, so that we can attempt to resolve any issues.

    7. Information security

    We process personal data with a high degree of confidentiality and have implemented technical and organisational security measures designed to protect personal data against unauthorised access, alteration, disclosure, destruction or loss, cf. GDPR Article 32.

    The measures include encryption of data in transit (TLS/HTTPS), access control based on the principle of least privilege, regular review of security procedures and data processing agreements with all suppliers who process personal data on our behalf.

    In the event of a personal data breach that poses a high risk to the rights and freedoms of data subjects, we will notify the affected data subjects without undue delay, cf. GDPR Article 34.

    8. STÖ GROUP's approach to privacy

    STÖ GROUP AS operates at the intersection of health, occupational information and technology. We are mindful that this is an area where privacy is particularly important, and where trust in us as an operator depends on our processing personal data with integrity and care.

    Our approach is based on Privacy by Design, cf. GDPR Article 25. This means that privacy is built into our systems and processes from the ground up — not added as an afterthought. We do not process special categories of personal data (including health data) via stogroup.no, and we have no systems for profiling or automated decisions with legal or similarly significant effects.

    The group's technology company SYDERA.io Technologies AS is built around an architectural principle that the platform shall not process personal data falling under GDPR Article 9. This is a deliberate design decision, not a compliance exercise. SYDERA.io Technologies AS has its own privacy policy available at sydera.no.

    9. Automated decisions and profiling

    STÖ GROUP AS does not make automated decisions that have legal or similarly significant effects for you, cf. GDPR Article 22. We do not engage in profiling of visitors to stogroup.no.

    10. Changes to this policy

    We may update this privacy policy if there are changes to our processing of personal data, to applicable regulations, or if we receive guidance from the Data Protection Authority or other supervisory authorities that warrant changes.

    Material changes will be clearly communicated on the website. The date of the last revision is stated at the top of this document. We recommend that you regularly review the policy.

    11. Contact

    All questions, requests to exercise rights, or concerns related to our processing of personal data should be directed to:

    STÖ GROUP AS — Data Protection Contact

    Email: personvern@stogroup.no

    Postal address: Johan Berentsens vei 109, 5163 Laksevåg, Bergen

    We respond to all enquiries within 30 days.

    This privacy policy has been prepared in accordance with the GDPR (EU) 2016/679, the Norwegian Personal Data Act of 15 June 2018 No. 38, and the Norwegian Data Protection Authority's guidance on the duty to inform. The policy covers the requirements of GDPR Articles 12, 13 and 14.