Privacy Policy
Last updated: 29 May 2025
1. Who We Are
This website is operated by Kermit Tech AS("Kermittech", "we", "us", or "our"). We are a data and AI engineering consultancy based in Norway.
For any privacy-related queries, contact us at: speaktous@kermittech.no
2. What Data We Collect and Why
We collect personal data only when you interact with us directly. Here is what we process and why:
Newsletter Sign-up
- Data collected: Email address, IP address, timestamp, consent record
- Legal basis: Consent (GDPR Art. 6(1)(a))
- Purpose: To send you our monthly briefing on AI and data engineering
- Retention: Until you unsubscribe or request deletion
Contact Form
- Data collected: Name, email address, company name (optional), message
- Legal basis: Legitimate interest / pre-contractual measures (GDPR Art. 6(1)(b) and (f))
- Purpose: To respond to your enquiry
- Retention: Up to 2 years from last contact
Website Usage (Server Logs)
- Data collected: IP address (in server logs only)
- Legal basis: Legitimate interest (GDPR Art. 6(1)(f))
- Purpose: Security monitoring and abuse prevention
- Retention: Standard server log rotation (typically 30 days)
3. How We Protect Your Data
We take data security seriously and apply the following technical measures:
- Newsletter email addresses are encrypted at rest using AES-256-GCM
- All data is transmitted over HTTPS/TLS
- Access to personal data is restricted to authorised personnel only
- Database backups are stored in encrypted, access-controlled storage
4. Data Processors (Third Parties)
We use the following third-party services to process data on our behalf. Each is bound by a data processing agreement and is GDPR-compliant:
| Processor | Purpose | Location |
|---|---|---|
| Resend | Transactional email delivery | USA (SCCs) |
| Amazon Web Services (S3) | Encrypted database backups | EU region |
We do not sell, rent, or share your personal data with any third party for marketing purposes.
5. Your Rights Under GDPR
As a data subject under GDPR, you have the following rights:
- Right of access — request a copy of the data we hold about you
- Right to rectification — ask us to correct inaccurate data
- Right to erasure ("right to be forgotten") — ask us to delete your data
- Right to restrict processing — ask us to limit how we use your data
- Right to data portability — receive your data in a machine-readable format
- Right to object — object to processing based on legitimate interest
- Right to withdraw consent — unsubscribe from the newsletter at any time
To exercise any of these rights, email us at speaktous@kermittech.no. We will respond within 30 days.
6. Right to Lodge a Complaint
If you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the Norwegian Data Protection Authority:
7. Cookies
We use only essential cookies required for website functionality. We do not use tracking, analytics, or marketing cookies. See our Cookie Policy for details.
8. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. We encourage you to review this page periodically.