Legal

Privacy Policy

Last updated: 29 May 2025

1. Who We Are

This website is operated by Kermit Tech AS("Kermittech", "we", "us", or "our"). We are a data and AI engineering consultancy based in Norway.

For any privacy-related queries, contact us at: speaktous@kermittech.no

2. What Data We Collect and Why

We collect personal data only when you interact with us directly. Here is what we process and why:

Newsletter Sign-up

  • Data collected: Email address, IP address, timestamp, consent record
  • Legal basis: Consent (GDPR Art. 6(1)(a))
  • Purpose: To send you our monthly briefing on AI and data engineering
  • Retention: Until you unsubscribe or request deletion

Contact Form

  • Data collected: Name, email address, company name (optional), message
  • Legal basis: Legitimate interest / pre-contractual measures (GDPR Art. 6(1)(b) and (f))
  • Purpose: To respond to your enquiry
  • Retention: Up to 2 years from last contact

Website Usage (Server Logs)

  • Data collected: IP address (in server logs only)
  • Legal basis: Legitimate interest (GDPR Art. 6(1)(f))
  • Purpose: Security monitoring and abuse prevention
  • Retention: Standard server log rotation (typically 30 days)

3. How We Protect Your Data

We take data security seriously and apply the following technical measures:

  • Newsletter email addresses are encrypted at rest using AES-256-GCM
  • All data is transmitted over HTTPS/TLS
  • Access to personal data is restricted to authorised personnel only
  • Database backups are stored in encrypted, access-controlled storage

4. Data Processors (Third Parties)

We use the following third-party services to process data on our behalf. Each is bound by a data processing agreement and is GDPR-compliant:

ProcessorPurposeLocation
ResendTransactional email deliveryUSA (SCCs)
Amazon Web Services (S3)Encrypted database backupsEU region

We do not sell, rent, or share your personal data with any third party for marketing purposes.

5. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

  • Right of access — request a copy of the data we hold about you
  • Right to rectification — ask us to correct inaccurate data
  • Right to erasure ("right to be forgotten") — ask us to delete your data
  • Right to restrict processing — ask us to limit how we use your data
  • Right to data portability — receive your data in a machine-readable format
  • Right to object — object to processing based on legitimate interest
  • Right to withdraw consent — unsubscribe from the newsletter at any time

To exercise any of these rights, email us at speaktous@kermittech.no. We will respond within 30 days.

6. Right to Lodge a Complaint

If you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the Norwegian Data Protection Authority:

Datatilsynet

Postboks 458 Sentrum, 0105 Oslo, Norway

www.datatilsynet.no

7. Cookies

We use only essential cookies required for website functionality. We do not use tracking, analytics, or marketing cookies. See our Cookie Policy for details.

8. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. We encourage you to review this page periodically.