Legal

Privacy Policy

Last updated: 10 June 2026

This Privacy Policy explains how Heimdall Charge AS ("Heimdall", "we", "us") collects, uses, shares and protects personal data when you visit our website, contact us, or use our EV charging services. We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Norwegian Personal Data Act (personopplysningsloven).

1. Data controller

The data controller responsible for your personal data is:

Heimdall Charge AS
Stavanger, Norway

2. Personal data we collect

  • Contact form data: name, company, site location, number of parking spaces, email address.
  • Communications: emails you send us and our replies.
  • Charging service data (if you are a driver or operator): account details, charging session metadata (timestamps, kWh delivered, pole ID), and payment data processed by our payment provider.
  • Technical data: IP address, browser type, device and approximate location, pages visited, and similar log data. We keep this to a minimum and do not use analytics or advertising cookies without your consent.

3. Purposes and legal bases

We process personal data only for specified, legitimate purposes:

  • Responding to enquiries submitted via the contact form — legal basis: Art. 6(1)(b) GDPR (steps prior to entering a contract) and Art. 6(1)(f) (our legitimate interest in answering you).
  • Providing charging services to operators and drivers — legal basis: Art. 6(1)(b) GDPR (performance of a contract).
  • Compliance with legal obligations (e.g. accounting, tax) — legal basis: Art. 6(1)(c) GDPR.
  • Securing our website and preventing abuse — legal basis: Art. 6(1)(f) GDPR (legitimate interest).
  • Optional analytics or marketing, if ever introduced — legal basis: Art. 6(1)(a) GDPR (your consent), which you can withdraw at any time.

4. Cookies and similar technologies

We use only strictly necessary cookies and local storage required to make the site work (e.g. remembering your cookie preference). These do not require consent under the ePrivacy Directive. We do not use advertising or cross-site tracking cookies. If we ever add non-essential analytics, we will ask for your prior consent through a cookie banner and you will be able to refuse or withdraw at any time.

5. Recipients and processors

We share personal data only with carefully selected processors acting on our instructions under a Data Processing Agreement compliant with Art. 28 GDPR. Typical categories:

  • Cloud hosting and infrastructure providers (EU/EEA region where available).
  • Email and customer-communication tools.
  • Payment processors (for charging transactions).
  • Accounting and legal advisors, where strictly necessary.

We do not sell personal data.

6. International transfers

Personal data is primarily processed within the EU/EEA. Where a processor is located outside the EEA, we rely on appropriate safeguards under Chapter V GDPR, in particular the European Commission's Standard Contractual Clauses, and we perform a transfer impact assessment where required.

7. Retention

  • Contact-form enquiries: up to 24 months after the last interaction, then deleted or anonymised.
  • Customer and charging records: for the duration of the contract and up to 5 years thereafter, to comply with Norwegian bookkeeping law.
  • Server logs: typically up to 90 days, unless needed longer for security investigations.

8. Your rights

Under the GDPR you have the right to:

  • Access your personal data (Art. 15).
  • Rectify inaccurate data (Art. 16).
  • Erase your data ("right to be forgotten", Art. 17).
  • Restrict processing (Art. 18).
  • Data portability (Art. 20).
  • Object to processing based on legitimate interest (Art. 21).
  • Withdraw consent at any time, without affecting prior lawful processing (Art. 7(3)).

To exercise any of these rights, contact us at privacy@heimdall-charge.com. We respond within one month.

9. Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority. In Norway this is the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no). If you reside elsewhere in the EU/EEA, you may also contact your local authority.

10. Security

We implement appropriate technical and organisational measures (encryption in transit, access controls, least-privilege principles, monitoring) to protect personal data against unauthorised access, loss or alteration, as required by Art. 32 GDPR.

11. Automated decision-making

We do not use automated decision-making, including profiling, that produces legal or similarly significant effects on you within the meaning of Art. 22 GDPR.

12. Changes to this policy

We may update this policy from time to time. Material changes will be highlighted on this page and, where appropriate, communicated to you directly. The "Last updated" date above always reflects the current version.