Legal

Privacy policy

Calmocean AS is responsible for the personal data you give us through this website. This policy sets out what we collect, why we collect it, who we share it with and what you can require of us.

In short

  • This site sets no advertising or cross-site tracking cookies, and loads nothing from a third-party server — not even its typefaces.
  • Visitor measurement is anonymous and aggregated. We cannot tell who you are from it, and it stores nothing on your device.
  • The only personal data we collect here is what you type into the contact form, or send us by email or phone.
  • We never sell personal data, and we do not use it to build profiles or to advertise to you.

Who we are

Calmocean AS, organisation number 929 932 951, registered in Norway, is the data controller for the personal data described in this policy. Our registered office address and the offices we work from are listed on our contact page.

For any question about this policy, or to exercise the rights described below, write to privacy@calmocean.no or to info@calmocean.no. We answer data requests ourselves; there is no ticket queue.

What we collect, and why

We collect as little as we can. Everything this website gathers falls into one of four groups.

We do not ask for, and would rather you did not send us, sensitive personal data — health information, political or religious views, trade union membership or anything similar. If a project genuinely requires it, we will agree in writing how it is handled before you send it.

How we measure visits

We use Vercel Web Analytics, which runs on the same domain as this site. It was chosen because it is anonymous by design and because it works everywhere our clients are, including mainland China, where the common alternatives are blocked.

  • No cookie is set and nothing is written to your browser's storage.
  • Visitors are counted using a hash derived from the incoming request. It is discarded after 24 hours and cannot be reversed to an IP address.
  • Your location is recorded at country level only — never a city, street or coordinate.
  • The data cannot be joined to any other site, service or advertising network, because there is no shared identifier to join it on.

The result is a count of page views and visitors by page, country, referring site and device type. There is no way for us to look at it and learn that a particular person visited, and no way for anyone else to.

We do not ask permission for this, and the reason is not that we are cutting a corner. Norway's Electronic Communications Act governs storing or reading data on your device, and this stores and reads nothing; the GDPR governs personal data, and an aggregate count is not personal data. Both tests are about what is actually done, not about what a banner says. If we ever add something that does track you, we will ask first — properly, with declining as easy as accepting.

Cookies and local storage

This website uses no advertising, marketing or cross-site tracking cookies. The only thing it stores on your device is a record of the choice you made in the consent banner, so that we do not ask again on every page.

Our cookie policy lists each item, what it is for and how to remove it, and lets you change your choice at any time.

Who else handles it

We do not sell personal data and we do not share it for anyone else's marketing. A small number of suppliers process data on our behalf, under written data processing agreements that bind them to our instructions:

Where a supplier is outside the EEA, the transfer is covered by the European Commission's Standard Contractual Clauses together with the supplier's own technical safeguards. We will tell you which mechanism applies to a specific transfer if you ask.

We also disclose personal data where we are legally obliged to — to a court, a regulator, or an auditor acting under a statutory mandate.

How long we keep it

When a retention period ends the data is deleted or irreversibly anonymised.

Your rights

Under the GDPR and the Norwegian Personal Data Act you may ask us to:

Where we rely on your consent — the contact form and the visit measurement — you may withdraw it at any time. Withdrawing consent does not undo processing that already, lawfully, took place.

Write to privacy@calmocean.no. We reply without undue delay and within one month at the latest. There is no charge unless a request is excessive or repetitive, and we will say so before charging anything.

If you think we have handled your data badly, please tell us first — it is usually quicker to fix. You are entitled either way to complain to the Norwegian Data Protection Authority, Datatilsynet, Postboks 458 Sentrum, 0105 Oslo (datatilsynet.no).

How we protect it

The site is served over HTTPS only. Access to our email and project systems requires multi-factor authentication and is limited to the colleagues who need it. Our quality management system is certified to ISO 9001 by DNV, which covers how we handle client information.

No system is perfect. If a breach ever affects your personal data and puts you at risk, we will notify Datatilsynet within 72 hours and tell you directly.

Children

This is a business-to-business website. We do not direct it at children and we do not knowingly collect personal data from anyone under 16.

Changes

If we change how we use personal data we will update this page and move the date below. Where a change matters to you, we will do more than change the page quietly.