Privacy Policy
STÖ GROUP AS — stogroup.no
Version 1.0 · Effective: 12 March 2026 · Last revised: 12 March 2026
1. Data Controller
The data controller for personal data collected and processed through this website is:
STÖ GROUP AS
Registration number: 935 699 819
Johan Berentsens vei 109
5163 Laksevåg, Bergen
Email: personvern@stogroup.no
Website: stogroup.no
STÖ GROUP AS is a Norwegian limited company registered in the Register of Business Enterprises. The company is the parent company of a group that includes SYDERA.io Technologies AS. This privacy policy applies exclusively to the processing of personal data in connection with the website stogroup.no and enquiries received through this website. Other group companies have their own privacy policies.
If you have questions about our processing of personal data, you may contact us at the email address above. We respond to all enquiries within 30 days, cf. GDPR Article 12(3).
2. What personal data we process, and why
We only process personal data that is necessary to fulfil the purposes described below. We do not collect more information than necessary, and we never process personal data for purposes other than those stated here, cf. GDPR Article 5(1)(b) (purpose limitation) and (c) (data minimisation).
2.1 Contact form
When you fill out the contact form on stogroup.no, we process the following data:
| Data | Purpose | Legal basis |
|---|---|---|
| Name | Identify sender and address reply correctly | GDPR Art. 6(1)(b) (necessary to respond to the enquiry) |
| Email address | Respond to the enquiry | GDPR art. 6(1)(b) |
| Organisation / company | Understand the context of the enquiry | GDPR Art. 6(1)(f) (legitimate interest) |
| Enquiry type | Route the enquiry to the correct contact person | GDPR art. 6(1)(b) |
| Message content | Respond to the enquiry | GDPR art. 6(1)(b) |
We do not process special categories of personal data (sensitive data) via the contact form, cf. GDPR Article 9. If you voluntarily provide information in the message field that may be classified as special categories — for example health data — we will process it solely to respond to your enquiry, and we will not retain such data beyond what is necessary for that purpose.
2.2 Technical logs and website operations
When you visit stogroup.no, technical data necessary for secure and stable operation of the website is processed. This includes IP address, browser type, operating system, time of visit and pages visited. This data is processed on the basis of GDPR Article 6(1)(f) (legitimate interest), as we have a legitimate interest in ensuring the technical function of the website and protecting it against misuse.
IP addresses are anonymised or deleted in accordance with the retention period stated in section 4.
2.3 Cookies
The website stogroup.no uses a limited number of cookies. We distinguish between necessary cookies and optional cookies:
Necessary cookies are technically required for the website to function correctly. These are stored without consent, cf. the Norwegian Electronic Communications Act § 2-7b and the Norwegian Data Protection Authority's guidance on cookies. They do not contain any personally identifiable information.
We use Plausible Analytics to understand how visitors use the website. Plausible Analytics is EU-hosted, uses no cookies and does not require GDPR consent for basic visitor statistics.
A complete overview of the cookies we use, their purposes and retention periods, is available in our separate cookie policy, accessible via the link at the bottom of the page.
3. Who we share data with
We do not sell personal data to third parties. We do not share personal data with anyone other than what is necessary to fulfil the purposes described in section 2.
We use the following categories of data processors who process personal data on our behalf:
| Category | Service | Purpose | Transfer outside EEA |
|---|---|---|---|
| Website hosting | Vercel Inc. (USA) | Operation and hosting of the website | Yes — see section 3.1 |
| Form handling | Formspree (USA) | Receipt and forwarding of contact form submissions | Yes — see section 3.1 |
| Analytics | Plausible Analytics (EU) | Anonymised visitor statistics | No |
We have entered into data processing agreements with all data processors in accordance with GDPR Article 28. The agreements ensure that the data processors only process the data in accordance with our instructions and in compliance with the GDPR.
3.1 Transfers to third countries
Some of our data processors are established in the USA, which is a third country outside the EEA. Such transfers are carried out pursuant to the European Commission's Standard Contractual Clauses (SCC), cf. GDPR Article 46(2)(c), and/or pursuant to the EU-U.S. Data Privacy Framework where applicable.
We carry out ongoing Transfer Impact Assessments of transfers to third countries to ensure that the level of protection is adequate.
4. Retention periods
We retain personal data only for as long as is necessary for the purposes for which it was collected, and no longer than required by law.
| Processing activity | Retention period | Justification |
|---|---|---|
| Contact form — enquiries | 2 years from date of receipt | Necessary to document and follow up business relationships |
| Technical logs (IP addresses etc.) | 90 days | Necessary for security and troubleshooting |
| Analytics data | 13 months (rolling) | Standard for web analytics |
| Email correspondence | 5 years | Norwegian Bookkeeping Act § 13 and general business practice |
Upon expiry of the retention period, the data is deleted or anonymised in a secure and irreversible manner.
5. Your rights
As a data subject, you have the following rights under GDPR Chapter III. We process all rights requests free of charge and within 30 days, cf. GDPR Article 12(3). If a request is particularly complex or we receive a large number of requests, the deadline may be extended by a further two months, and we will inform you accordingly.
Right of access (GDPR Art. 15)
You have the right to obtain confirmation as to whether we process personal data about you, and if so, to access that data and information about the processing.
Right to rectification (GDPR Art. 16)
You have the right to have inaccurate personal data about you corrected without undue delay. You also have the right to have incomplete personal data supplemented.
Right to erasure ("right to be forgotten", GDPR Art. 17)
You have the right to have personal data about you erased without undue delay if one of the specified conditions is met, including if the data is no longer necessary for the purposes for which it was collected, or if you withdraw consent on which the processing is based.
Right to restriction of processing (GDPR Art. 18)
You have the right to request restriction of processing in certain situations, for example if you contest the accuracy of the data or have objected to the processing.
Right to data portability (GDPR Art. 20)
Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used and machine-readable format, and to transmit it to another data controller.
Right to object (GDPR Art. 21)
You have the right to object to the processing of personal data about you that is based on GDPR Article 6(1)(e) or (f) (public interest or legitimate interest), including profiling. If you object, we will no longer process the personal data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms.
Right to withdraw consent (GDPR Art. 7(3))
Where processing is based on your consent, you have the right to withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.
To exercise your rights, send a written request to personvern@stogroup.no. We may ask you to verify your identity to ensure that we do not disclose data to the wrong person.
6. Right to lodge a complaint with the Data Protection Authority
If you believe that our processing of personal data is in breach of data protection regulations, you have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).
Datatilsynet
Postboks 458 Sentrum, 0105 Oslo
Phone: 22 39 69 00
Email: postkasse@datatilsynet.no
Website: datatilsynet.no
We nevertheless encourage you to contact us directly first, so that we can attempt to resolve any issues.
7. Information security
We process personal data with a high degree of confidentiality and have implemented technical and organisational security measures designed to protect personal data against unauthorised access, alteration, disclosure, destruction or loss, cf. GDPR Article 32.
The measures include encryption of data in transit (TLS/HTTPS), access control based on the principle of least privilege, regular review of security procedures and data processing agreements with all suppliers who process personal data on our behalf.
In the event of a personal data breach that poses a high risk to the rights and freedoms of data subjects, we will notify the affected data subjects without undue delay, cf. GDPR Article 34.
8. STÖ GROUP's approach to privacy
STÖ GROUP AS operates at the intersection of health, occupational information and technology. We are mindful that this is an area where privacy is particularly important, and where trust in us as an operator depends on our processing personal data with integrity and care.
Our approach is based on Privacy by Design, cf. GDPR Article 25. This means that privacy is built into our systems and processes from the ground up — not added as an afterthought. We do not process special categories of personal data (including health data) via stogroup.no, and we have no systems for profiling or automated decisions with legal or similarly significant effects.
The group's technology company SYDERA.io Technologies AS is built around an architectural principle that the platform shall not process personal data falling under GDPR Article 9. This is a deliberate design decision, not a compliance exercise. SYDERA.io Technologies AS has its own privacy policy available at sydera.no.
9. Automated decisions and profiling
STÖ GROUP AS does not make automated decisions that have legal or similarly significant effects for you, cf. GDPR Article 22. We do not engage in profiling of visitors to stogroup.no.
10. Changes to this policy
We may update this privacy policy if there are changes to our processing of personal data, to applicable regulations, or if we receive guidance from the Data Protection Authority or other supervisory authorities that warrant changes.
Material changes will be clearly communicated on the website. The date of the last revision is stated at the top of this document. We recommend that you regularly review the policy.
11. Contact
All questions, requests to exercise rights, or concerns related to our processing of personal data should be directed to:
STÖ GROUP AS — Data Protection Contact
Email: personvern@stogroup.no
Postal address: Johan Berentsens vei 109, 5163 Laksevåg, Bergen
We respond to all enquiries within 30 days.
This privacy policy has been prepared in accordance with the GDPR (EU) 2016/679, the Norwegian Personal Data Act of 15 June 2018 No. 38, and the Norwegian Data Protection Authority's guidance on the duty to inform. The policy covers the requirements of GDPR Articles 12, 13 and 14.