ColLabNordic is committed to protecting your data and operating in full compliance with Norwegian and European regulations.
General Data Protection Regulation (EU 2016/679)
ColLabNordic fully complies with the General Data Protection Regulation (GDPR), incorporated into Norwegian law via Personopplysningsloven. We implement comprehensive data protection measures to safeguard your personal information.
Request a copy of your personal data
Correct inaccurate personal data
Request deletion of your data
Export your data in a standard format
Object to processing of your data
Limit how we use your data
Operating under Norwegian law
ColLabNordic is a registered Norwegian company (Aksjeselskap/AS) operating in full compliance with Norwegian business and data protection laws.
The Norwegian Personal Data Act implements GDPR into Norwegian law. We comply with all requirements for processing personal data of Norwegian residents.
Financial records, contracts, and transaction data are retained for a minimum of 5 years as required by Norwegian accounting law. This includes invoices, payment records, and contractual documentation.
Contract and claim-related documentation may be retained for up to 10 years to establish, exercise, or defend legal claims as permitted under the statute of limitations.
All influencer marketing content facilitated through our platform must comply with Norwegian marketing regulations, including proper disclosure of sponsored content.
How long we keep your data
We retain data only as long as necessary for the purposes for which it was collected, or as required by law. Here's an overview of our retention periods:
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Profile Data | Until account deletion | Consent / Contract |
| Messages | Until account deletion | Contract performance |
| Contracts | 5-10 years | Legal obligation |
| Payment Records | 5 years minimum | Bokføringsloven |
| Invoices | 5 years minimum | Bokføringsloven |
| Login Sessions | 90 days | Legitimate interest (security) |
Right to erasure (GDPR Article 17)
You can request deletion of your account at any time through your account settings. When you delete your account, we process your data as follows:
Account deletion is not available while you have active contracts or open disputes. Please complete or cancel all active work before requesting deletion.
Right to access & data portability (GDPR Articles 15 & 20)
How we protect your data
All data encrypted via TLS 1.3
Database and storage encryption
OAuth 2.0, password hashing (bcrypt)
OTP verification for unknown devices
All data stored in European data centers
Continuous monitoring and updates
If you have questions about our compliance practices or want to exercise your data protection rights, please contact us:
Contact: Use our contact form
Response Time: Within 30 days (as required by GDPR)
You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) at www.datatilsynet.no
Last updated: January 2026