Skip to content
HolmestrandIT Call 995 60 122 Call

Privacy

Last updated 6 October 2026.

This is an English translation. If the two versions differ, the Norwegian version applies: Personvern.

Here we explain what personal data HolmestrandIT processes, what we use it for and how you can contact us about your data.

HOLMESTRANDIT AS, org. no. 938 342 121, is responsible for the processing described here. Questions about privacy can be sent to [email protected] or asked by phone on 995 60 122.

Who is responsible

ControllerHOLMESTRANDIT AS, org. no. 938 342 121
AddressGladengveien 5F, 0661 Oslo
E-mail[email protected]
Privacy and erasure[email protected]
Phone995 60 122

The contact form

If you write to us through the form on the website, what you wrote is sent as an e-mail to our mailbox. The server that receives the form does not store its content, and the log there contains no name, phone number, e-mail address or message.

Our mailbox is with Domeneshop. Our case management tool, which runs on our own server, fetches the e-mail from there and stores it together with the case, so that we can keep track of what has been said. The same applies to e-mail you send directly to us.

A new enquiry may be read by Claude from Anthropic, which suggests what it is about and proposes a draft reply.

WhatWhyLegal basis
NameSo that we know who we are replying toLegitimate interest
Phone number or e-mail addressSo that we can reply to youLegitimate interest
Business and location, if you provide themSo that we know where the job isLegitimate interest
The topic you chose and your messageTo understand what you need help withLegitimate interest

The message stays in our inbox for as long as the case is ongoing, and for 12 months after that. If you ask us to delete it before then, we delete it both in the inbox and in the case management tool.

When we help you through remote support

During a remote support session, we see your screen. This means that we may end up seeing personal files, e-mails or websites you have open. We do not go looking; we only look at what is needed to solve the problem.

What makes our remote support different

The tool we use connects to our own server, not to a service abroad. No third party relays the session, and no one but us sees it.

We make no recordings. When you close the tool, the session is over, and we have no access to your computer afterwards. The tool may stay where it is, but it does nothing until you start it yourself and press Accept. Delete it whenever you like.

The server logs the time of connections, not their content. These logs are kept for 30 days.

When we import content from your Facebook page

Importing posts from Facebook is not in use yet. We will update this section when it comes into use.

If your business has a website with us, we import posts and images from your Facebook page and show them on your own website. That way you do not have to maintain the website separately, because you post as before, and the site keeps up.

This only happens when you have given us a role on the page yourselves, and only for the page you have chosen. We only use the role to import the content, and we do not publish anything on your page. If an Instagram account is linked to the page, we import posts and images from there in the same way. We see nothing on private profiles.

WhatWhyHow long
The text of the postSo that it can be shown on your websiteUntil you delete the post or end the agreement
The images in the postAs aboveAs above
The time of the post and a link to itSo that we can show the newest first and link backAs above
The access tokenSo that we can import without asking each timeUntil you revoke the access

We do not embed Facebook, we download the content

The images and the text are stored on your website, not in a window from Facebook. This means that no one who visits the site is tracked by Facebook. The site also becomes faster, and it works even if Facebook is down.

We only import what is already public on your page. We do not import comments or messages from others.

If you want to stop it, the page about deleting data explains how to revoke the access and have the copy deleted.

Businesses we contact

We contact businesses in Holmestrand and the surrounding area to tell them what we can help with, through a visit, a phone call or a letter. That is why we keep a record of the businesses we are considering and have spoken to.

WhatWhere we got it fromWhy
Name, address, phone number, organisation number and industryThe Central Coordinating Register for Legal Entities (Enhetsregisteret) at the Brønnøysund Register Centre (Brønnøysundregistrene), and GoogleSo that we know who we are contacting
Whether the business has a website, and how it worksWhat is public online, assessed by usSo that we have something relevant to say
What was said, and whenThe conversation with youSo that we remember what has been agreed, and do not contact you again when you have said no

The legal basis is legitimate interest: offering our services to businesses in the area. The data is deleted or anonymised twelve months after the last contact, if you do not become a customer.

If the business is run by a sole trader, the data about the owner is personal data. We do not send e-mail about our services to an owner who has not said yes to it.

You can say no

If you do not want us to contact you, just let us know: reply to the e-mail, call us, or write to [email protected]. We will then note that you do not want to be contacted, and delete the rest of what we have about you. You do not need to give a reason.

Who else is involved

We use a few services to make the website and e-mail work. They process data on our behalf, and are not allowed to use it for anything else.

ServiceWhat they doWhere
DomeneshopOur mailbox, where e-mail and messages from the form end upNorway
ResendSends the e-mail from the contact formEU and USA
Anthropic (Claude)Reads new enquiries in our case management tool and suggests what they are aboutUSA
CloudflareDelivers the website and protects it against attacksWorldwide
Meta (Facebook)Delivers the posts and images from your page, for customers who have a website with usEU and USA

When data is transferred to the USA. Resend, Cloudflare, Inc. and Meta Platforms, Inc. are certified under the EU-US Data Privacy Framework, and that is the basis when data is transferred to the USA. We checked this against the public list on 6 October 2026. Anthropic is not on that list. For Anthropic, the basis is the EU standard contractual clauses (modules 2 and 3), which form part of Anthropic's data processing agreement, effective from 24 February 2025.

Remote support and the case management tool run on our own servers. We do not sell data on, and we do not use it for marketing.

Cookies

We do not set any cookies on the website, and we have no tracking or visitor statistics. Whether Cloudflare, which delivers the site, sets its own cookies to protect it has not been checked.

The websites we make for customers do not set any cookies either, and have no analytics or tracking from us. The fonts are stored on the same server as the site, so no one else finds out who visits it. Each customer site has its own privacy policy. When importing posts from Facebook comes into use, we download the content instead of embedding Facebook's own window, because the window would set tracking cookies for everyone who visits the site.

What you are entitled to

  • Access. You can ask to be told what we hold about you.
  • Rectification. If anything is wrong, we correct it.
  • Erasure. You can ask us to delete what we hold.
  • Objection. You can object to our processing of your data.

Send an e-mail to [email protected], and we will reply within 30 days. That address goes straight to the person who handles such requests.

If you want something deleted, the page about deleting data sets out the procedure step by step.

If you are not satisfied with how we handle it, you can complain to the Norwegian Data Protection Authority (Datatilsynet).

If something goes wrong

Should personal data go astray, we notify the Norwegian Data Protection Authority within 72 hours, and you directly if it is likely to involve a risk to you.