Privacy policy.
How we collect and use personal data in our business, and the rights you have.
In short
- We only collect what you give us yourself: through the contact form, newsletter signup, course registration, or when we work together.
- The website does not use cookies for marketing or tracking, and our visitor statistics are anonymous.
- We never sell personal data, and we only share it with the vendors needed to run the business. They are listed by name in section 6.
- You can request access, rectification, or erasure at any time, and you can lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).
01Data controller
This privacy policy explains how we collect and use personal data in our business. STARSHINE AI AS is the data controller for the processing.
We take privacy seriously and want it to be easy to understand what we do with your data. If anything is unclear, get in touch.
02What we process, why, and for how long
When you contact us
When you use the contact form on our website, email us, or reach out via LinkedIn or phone, we process your name, contact details, and the content of your message. The contact form is delivered to us as email via the provider Resend.
Purpose: to answer your inquiry, follow up the dialogue, and keep documentation in case of later questions, complaints, or legal claims.
Legal basis: legitimate interest (GDPR Article 6(1)(f)), or contract if the inquiry concerns an engagement (point (b)).
Retention: we review and delete inquiries that are no longer relevant, at least once a year.
When you sign up for the newsletter
On signup we process your first name and email address. Signing up requires actively ticking a consent box, and is confirmed with double opt-in: you receive an email where you must confirm your subscription before being added to the list. The newsletter is sent via Kit (formerly ConvertKit).
The tool shows us statistics on opens and clicks, which we use to make the content better and more relevant. The statistics are not used for decisions with legal effect for you.
Purpose: to send you the newsletter you asked for, normally at most one email per week.
Legal basis: consent (GDPR Article 6(1)(a)). You can withdraw consent at any time via the unsubscribe link included in every email.
Retention: until you unsubscribe. On unsubscribing you are removed from the mailing list.
When you register for a course or event
For open courses, registration and payment happen through Checkin.no, a Norwegian registration service. It processes name, contact details, and payment information. If you register interest via the form on our website, we process your name, email, and the contents of your message.
After an event we may send you an evaluation request and invite you to similar events.
Purpose: to run the event you registered for, and to improve what we offer.
Legal basis: contract (registration and delivery), legitimate interest (evaluation and follow-up).
Retention: participant lists are normally deleted no later than 12 months after the event. Payment information is retained under the Norwegian Bookkeeping Act, see the section on purchases.
When you buy services from us
When you buy courses, advisory, or development services, we process name, contact details, contract and invoicing information, and correspondence related to the engagement.
Purpose: to deliver the service, manage the client relationship, and meet legal obligations.
Legal basis: contract (GDPR Article 6(1)(b)) and legal obligation (point (c)), including under Norwegian bookkeeping and tax legislation.
Retention: accounting records are kept for 5 years under the Norwegian Bookkeeping Act. Other engagement documentation is deleted when no longer needed.
In existing client relationships we may send you relevant information about our services by email, in line with section 15 of the Norwegian Marketing Control Act. You can easily opt out.
When you answer a survey
We always state the purpose of a survey and whether it is anonymous. In anonymous surveys we do not collect personal data. Otherwise the basis is consent, and answers are not used for any purpose other than the one stated.
When you are a supplier or partner
We process name, contact details, and correspondence to enter into and follow up the agreement. The basis is contract and legal obligations under bookkeeping and tax legislation. Data is kept for as long as the relationship lasts, and accounting-related material for 5 years.
03Automation
We use simple automation in our marketing: the newsletter tool segments recipients (for example by language) and shows statistics on opens and clicks. No decisions with legal or similarly significant effect for you are made automatically. You can always contact us to learn more about how this works, or object to the processing.
04Cookies and visitor statistics
Our website does not set cookies or similar technologies that require consent under section 3-15 of the Norwegian Electronic Communications Act. We use Vercel Web Analytics for visitor statistics. The tool does not use cookies and does not store data that can identify you; the statistics are aggregated and anonymous.
If we later adopt tools that require consent, we will implement a consent solution meeting the requirements of the Electronic Communications Act section 3-15 and the GDPR before the tool is activated.
05Your rights
Contact us if you have questions about, or wish to exercise, your rights. You are entitled to a response within 30 days.
- Access and rectification: you can request a copy of all data we process about you, and have inaccuracies corrected.
- Erasure or restriction: you can ask us to delete or restrict processing, but we cannot delete data we are legally required to retain.
- Objection: where we process data based on legitimate interest, you can object.
- Data portability: for processing based on consent or contract, you can request your data delivered to you or transferred to another controller.
- Withdraw consent: consent can be withdrawn at any time, with effect going forward.
- Complaint: you can lodge a complaint with Datatilsynet (the Norwegian Data Protection Authority), but we would appreciate you telling us first so we can try to resolve the matter directly.
06Who we share personal data with
We only share personal data when necessary to run the business, and we enter into data processing agreements with everyone who processes data on our behalf. Our main data processors and service providers are:
| Provider | Used for | Where |
|---|---|---|
| Kit (ConvertKit LLC) | Newsletter and email lists | USA |
| Resend | Delivery of contact form emails | USA |
| Vercel | Website hosting and anonymous visitor statistics | USA (EU servers for content) |
| Google Workspace | Email, calendar, documents, and video meetings | EU/USA |
| Checkin.no | Course registration and payment | Norway |
| DNB Regnskap | Accounting and invoicing | Norway |
In addition, we may share data with professional advisers (legal, accounting, audit) and public authorities where we are required to.
07Transfers outside the EU/EEA
Several of the providers above operate in the USA. Transfers there only take place with a valid transfer mechanism under GDPR Chapter V: the EU Commission's adequacy decision on the EU-U.S. Data Privacy Framework for certified providers, or the EU Standard Contractual Clauses (SCCs) with necessary supplementary measures. Contact us if you want to know more about the transfer basis for a specific provider.
08Security
We protect your data with encrypted data transfer (HTTPS/TLS), access control, two-factor authentication, strong passwords, and backups, among other measures. We use reputable providers, grant access to data only where necessary, and review our privacy work regularly.
09Changes to this policy
We update this policy as needed, for example when we adopt new tools or regulations change. Material changes will be announced on the website. The date below shows when the policy was last updated.
Last updated: 7 August 2026
