Privacy
Last updated 6 October 2026.
This is an English translation. If the two versions differ, the Norwegian version applies: Personvern.
Here we explain what personal data HolmestrandIT processes, what we use it for and how you can contact us about your data.
HOLMESTRANDIT AS, org. no. 938 342 121, is responsible for the processing described here. Questions about privacy can be sent to [email protected] or asked by phone on 995 60 122.
Who is responsible
| Controller | HOLMESTRANDIT AS, org. no. 938 342 121 |
|---|---|
| Address | Gladengveien 5F, 0661 Oslo |
| [email protected] | |
| Privacy and erasure | [email protected] |
| Phone | 995 60 122 |
The contact form
If you write to us through the form on the website, what you wrote is sent as an e-mail to our mailbox. The server that receives the form does not store its content, and the log there contains no name, phone number, e-mail address or message.
Our mailbox is with Domeneshop. Our case management tool, which runs on our own server, fetches the e-mail from there and stores it together with the case, so that we can keep track of what has been said. The same applies to e-mail you send directly to us.
A new enquiry may be read by Claude from Anthropic, which suggests what it is about and proposes a draft reply.
| What | Why | Legal basis |
|---|---|---|
| Name | So that we know who we are replying to | Legitimate interest |
| Phone number or e-mail address | So that we can reply to you | Legitimate interest |
| Business and location, if you provide them | So that we know where the job is | Legitimate interest |
| The topic you chose and your message | To understand what you need help with | Legitimate interest |
The message stays in our inbox for as long as the case is ongoing, and for 12 months after that. If you ask us to delete it before then, we delete it both in the inbox and in the case management tool.
When we help you through remote support
During a remote support session, we see your screen. This means that we may end up seeing personal files, e-mails or websites you have open. We do not go looking; we only look at what is needed to solve the problem.
What makes our remote support different
The tool we use connects to our own server, not to a service abroad. No third party relays the session, and no one but us sees it.
We make no recordings. When you close the tool, the session is over, and we have no access to your computer afterwards. The tool may stay where it is, but it does nothing until you start it yourself and press Accept. Delete it whenever you like.
The server logs the time of connections, not their content. These logs are kept for 30 days.
When we import content from your Facebook page
Importing posts from Facebook is not in use yet. We will update this section when it comes into use.
If your business has a website with us, we import posts and images from your Facebook page and show them on your own website. That way you do not have to maintain the website separately, because you post as before, and the site keeps up.
This only happens when you have given us a role on the page yourselves, and only for the page you have chosen. We only use the role to import the content, and we do not publish anything on your page. If an Instagram account is linked to the page, we import posts and images from there in the same way. We see nothing on private profiles.
| What | Why | How long |
|---|---|---|
| The text of the post | So that it can be shown on your website | Until you delete the post or end the agreement |
| The images in the post | As above | As above |
| The time of the post and a link to it | So that we can show the newest first and link back | As above |
| The access token | So that we can import without asking each time | Until you revoke the access |
We do not embed Facebook, we download the content
The images and the text are stored on your website, not in a window from Facebook. This means that no one who visits the site is tracked by Facebook. The site also becomes faster, and it works even if Facebook is down.
We only import what is already public on your page. We do not import comments or messages from others.
If you want to stop it, the page about deleting data explains how to revoke the access and have the copy deleted.
Businesses we contact
We contact businesses in Holmestrand and the surrounding area to tell them what we can help with, through a visit, a phone call or a letter. That is why we keep a record of the businesses we are considering and have spoken to.
| What | Where we got it from | Why |
|---|---|---|
| Name, address, phone number, organisation number and industry | The Central Coordinating Register for Legal Entities (Enhetsregisteret) at the Brønnøysund Register Centre (Brønnøysundregistrene), and Google | So that we know who we are contacting |
| Whether the business has a website, and how it works | What is public online, assessed by us | So that we have something relevant to say |
| What was said, and when | The conversation with you | So that we remember what has been agreed, and do not contact you again when you have said no |
The legal basis is legitimate interest: offering our services to businesses in the area. The data is deleted or anonymised twelve months after the last contact, if you do not become a customer.
If the business is run by a sole trader, the data about the owner is personal data. We do not send e-mail about our services to an owner who has not said yes to it.
You can say no
If you do not want us to contact you, just let us know: reply to the e-mail, call us, or write to [email protected]. We will then note that you do not want to be contacted, and delete the rest of what we have about you. You do not need to give a reason.
Who else is involved
We use a few services to make the website and e-mail work. They process data on our behalf, and are not allowed to use it for anything else.
| Service | What they do | Where |
|---|---|---|
| Domeneshop | Our mailbox, where e-mail and messages from the form end up | Norway |
| Resend | Sends the e-mail from the contact form | EU and USA |
| Anthropic (Claude) | Reads new enquiries in our case management tool and suggests what they are about | USA |
| Cloudflare | Delivers the website and protects it against attacks | Worldwide |
| Meta (Facebook) | Delivers the posts and images from your page, for customers who have a website with us | EU and USA |
When data is transferred to the USA. Resend, Cloudflare, Inc. and Meta Platforms, Inc. are certified under the EU-US Data Privacy Framework, and that is the basis when data is transferred to the USA. We checked this against the public list on 6 October 2026. Anthropic is not on that list. For Anthropic, the basis is the EU standard contractual clauses (modules 2 and 3), which form part of Anthropic's data processing agreement, effective from 24 February 2025.
Remote support and the case management tool run on our own servers. We do not sell data on, and we do not use it for marketing.
Cookies
We do not set any cookies on the website, and we have no tracking or visitor statistics. Whether Cloudflare, which delivers the site, sets its own cookies to protect it has not been checked.
The websites we make for customers do not set any cookies either, and have no analytics or tracking from us. The fonts are stored on the same server as the site, so no one else finds out who visits it. Each customer site has its own privacy policy. When importing posts from Facebook comes into use, we download the content instead of embedding Facebook's own window, because the window would set tracking cookies for everyone who visits the site.
What you are entitled to
- Access. You can ask to be told what we hold about you.
- Rectification. If anything is wrong, we correct it.
- Erasure. You can ask us to delete what we hold.
- Objection. You can object to our processing of your data.
Send an e-mail to [email protected], and we will reply within 30 days. That address goes straight to the person who handles such requests.
If you want something deleted, the page about deleting data sets out the procedure step by step.
If you are not satisfied with how we handle it, you can complain to the Norwegian Data Protection Authority (Datatilsynet).
If something goes wrong
Should personal data go astray, we notify the Norwegian Data Protection Authority within 72 hours, and you directly if it is likely to involve a risk to you.