Privacy Policy

Last updated: 2026-08-24

PrivyLedger is operated by Vassbrekke AS, organisation number 835 834 212, Norway. The service helps organizations inventory the vendors and processors that hold their company and customer data.

For personal data in your workspace, your organization is the controller and Vassbrekke AS acts as processor under our Data Processing Agreement (GDPR Art. 28) which applies from first use. For your own account data (this section), Vassbrekke AS is the controller.

What we store

  • Account email, name, password hash (scrypt), role
  • Optional two-factor authentication secret (for TOTP login)
  • Workspace profile, vendor roster, DSAR cases, site notes
  • Documents you attach to vendors (e.g. signed DPAs)
  • Billing identifiers from Stripe (customer / subscription ids) — never card numbers
  • Session cookies and security logs (e.g. password resets)

We do not run third-party analytics, advertising, or telemetry in the product, and your data is never used to train machine-learning models.

Lawful bases (GDPR Art. 6)

  • Contract (Art. 6(1)(b)) — creating and securing your account, providing the register, scoring, exports, and support you request.
  • Legitimate interests (Art. 6(1)(f)) — securing the service (rate limiting, abuse prevention, security logging) and product improvement that does not compromise your rights. You may object under Art. 21.
  • Legal obligation (Art. 6(1)(c)) — retaining accounting records as required by Norwegian law.

Where data lives & international transfers

Application, database, and backups run on infrastructure operated by Vassbrekke AS in Norway/EEA. Register data is not transferred outside the EEA by us. Two account-level processors operate outside the EEA: Stripe (United States — billing identifiers only) and Resend (transactional email). Where these transfers occur, we rely on the EU–US Data Privacy Framework certification and/or European Commission Standard Contractual Clauses, as applicable. Details: Trust & jurisdiction.

Processors

We keep the list deliberately short; the current version with change log lives at /subprocessors. Summary:

  • Hosting — Vassbrekke AS infrastructure (Norway/EEA)
  • Stripe — payments, when enabled (billing identifiers only)
  • Resend — transactional email (password reset, verification, digests), when enabled

Retention & deletion

Workspace data is kept while the account is active. You can export everything at any time via the built-in export tools before closing an account. After your account ends:

  • Workspace register data (vendors, DSARs, documents, activity) — deleted within 30 days of termination.
  • Account records (email, name, billing identifiers) — kept up to 90 days, then deleted.
  • Invoices and transaction records — retained as required by Norwegian accounting law (bokføringsloven, 5 years), independent of account deletion.
  • Backups — encrypted, rolling; a deleted workspace is excluded from new backups and ages out within 35 days.

We may keep data longer only where EEA/Norwegian law requires it (e.g. accounting rules) or to resolve a dispute.

Cookies

PrivyLedger sets no advertising or analytics cookies. The only cookie set is a strictly-necessary session cookie (pr_session) created when you sign in — no consent banner is needed because nothing else tracks you. Public pages set no cookies at all. Full details in our cookie policy.

Automated decision-making

Risk scores and exposure bands in PrivyLedger are produced by deterministic rules from data you enter — not by machine-learning profiling — and they carry no legal effect on any individual. No automated decision-making under GDPR Art. 22 takes place.

Children

PrivyLedger is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.

Your rights

You may access, correct, export, or delete your account data at any time — most of this is self-service in the product (Account settings, Export). You also have the rights to restrict or object to processing, to withdraw consent where processing is consent-based, and to lodge a complaint with your local supervisory authority — in Norway: Datatilsynet (datatilsynet.no). For anything else, contact us as below and we will respond within GDPR timelines. If you are a data subject whose data appears in a customer's register, please contact that organization directly; we forward any requests we receive to them.

Changes to this policy

We update this policy when the service or our processing changes. Material changes are announced on the site (and by email for account changes) before they take effect. The “last updated” date above reflects the current version.

Contact

Vassbrekke AS · contact@vassbrekke.no · Security reports: /.well-known/security.txt. Canonical version of this policy: https://privyledger.com/privacy.