Skip to content
PreferiumJoin the waitlist
Menu
Platform
White labelPricing
Compare
Resources
Company
Join the waitlist

Legal

Privacy Notice

Which personal data we process when you use preferium.com and our services, why we do it, how long we keep it, and the rights you have, including your US state privacy rights.

For a concluded agreement, the document versions recorded in the accepted Order or signature apply. A new version on this website does not change the agreement by itself.

Preferium AS · contact and company details

Company
Preferium AS
Org. no.
999 323 286
Registers
Central Coordinating Register for Legal Entities (Enhetsregisteret, since 5 January 2013), Register of Business Enterprises (Foretaksregisteret) and VAT Register (Merverdiavgiftsregisteret)
Office address
Produksjonsveien 18, 2nd floor, 1618 Fredrikstad
Postal address
Sponheimveien 19, 1613 Fredrikstad
Contact
post@preferium.no · +47 977 91 286

1. Who and what this Notice covers

This Notice explains how Preferium AS, Norwegian organization no. 999 323 286, processes personal data as an independent controller when people visit preferium.com, join the waitlist, contact us, submit a privacy request, represent a customer, agency or supplier, or receive service messages from us.

The Notice is information, not an agreement and not consent. Where Preferium only processes data on behalf of a customer or an agency, that customer is the controller and the [Data Processing Agreement](/dpa) governs Preferium's role. Processing inside Preferium AI Edge (the Dashboard, branded client panels and connected websites) is described in the product's own documentation and in the Data Processing Agreement; a description of a function or provider on this page does not mean that it is used on every visit to preferium.com.

Contact: post@preferium.no · +47 977 91 286 · Sponheimveien 19, 1613 Fredrikstad, Norway. Preferium has not appointed a Data Protection Officer under Article 37 GDPR. Robert André Johansen is the operational privacy contact, not an independent Data Protection Officer.

The retired domain preferium.no only redirects to preferium.com. Requests and records created while the Norwegian site was live are handled under this Notice.

2. Processing on preferium.com

ActivityData and sourcePurpose and legal basisNormal retention
Website delivery and securityIP address, user agent, URL, time and security signals from the browser and Cloudflare, which serves the siteDeliver and protect the pages; legitimate interest in secure and available operation, Art. 6(1)(f)Short provider-controlled security and operations periods
Contact and waitlist formsName, work email, agency name or website, an optional phone number, the subject you choose and the message that you enter; a Cloudflare Turnstile token that proves the form was submitted by a personAnswer the enquiry and prepare an agreement, Art. 6(1)(b) where you may become a contracting party, otherwise legitimate interest in business dialogue, Art. 6(1)(f)Reviewed and cleared by purpose; normally up to 24 months after the last relevant dialogue, longer where an agreement or a dispute follows
Privacy requestsName, email address, your relationship to us, an optional organization, website and reference, the request type, your description, the verification token sent to your email address, our investigation and our replyFulfil data-protection obligations, Art. 6(1)(c)Three years after the case is closed, with earlier minimisation of direct identifiers where possible
Privacy choices and consent evidenceYour purpose choices, the document and policy versions shown, time, a random receipt reference and any withdrawal. The consent record contains no name, email address or raw IP addressRespect and document your choices as the relevant documentation duties require, Art. 6(1)(c), and legitimate interest in proving compliance, Art. 6(1)(f)A choice is valid for 180 days without automatic renewal; the evidence is kept for three years after expiry or withdrawal
Administrative security and incidentsThe authorized administrator, the reason for access, the case, the measures taken, risk assessments and notificationsData-protection obligations, Art. 6(1)(c), and, where relevant, legitimate interest in security and legal claims, Art. 6(1)(f)Administrator audit trail for three years; incident cases for five years after closure

The network address of a request is used as a keyed digest for rate limiting of the contact, consent and privacy endpoints. That digest cannot be reversed into the address and is not stored with your choices or your request.

We do not use these data for decisions that have legal or similarly significant effects on people. Required fields in a form must be provided for the enquiry or request to be handled; without them we cannot answer.

3. Processing in the customer relationship

When an agency or another business becomes a customer, Preferium processes the following as controller for its own purposes:

ActivityData and sourcePurpose and legal basisNormal retention
Account and agreement recordsName, work email, organization, role, accepted document versions, login and configuration activityPerform the agreement, administer users and document security, Art. 6(1)(b)/(f)The term of the agreement and thereafter according to deletion and limitation periods
Billing and accountingCustomer, contact, invoice, subscription and payment references from the customer or the payment providerPerform the agreement, collect payment and keep statutory accounts, Art. 6(1)(b)/(c)Accounting records for the statutory retention period under Norwegian bookkeeping law; other payment data no longer than necessary
Support and incidentsDialogue, attachments, technical logs and measures from the customer, the system and supportPerform the agreement, troubleshoot, secure the Service and defend legal claims, Art. 6(1)(b)/(f)According to the risk and need of the case; sensitive content is minimised
Service messages and marketingWork contact details, preferences and delivery statusNecessary service messages, Art. 6(1)(b)/(f); marketing only with consent or within a lawful existing customer relationshipUntil you object or the purpose ends; suppression data may be kept to respect an objection

For data about a business's representatives, the person is not automatically a contracting party. Agreement administration and relevant follow-up then rest on an assessed legitimate interest, Art. 6(1)(f); Art. 6(1)(b) applies where the person is a contracting party. Statutory processing has its own basis.

4. Processing on behalf of customers

When Preferium AI Edge serves a customer's or an End Customer's website, technical request data and public website content may pass through the infrastructure. The customer determines the purpose and the content and must inform its visitors. Preferium follows the documented instructions in the Data Processing Agreement.

In white-label relationships the End Customer may be the controller, the agency a processor and Preferium a subprocessor. For Preferium's own account, security, billing and supplier administration, Preferium remains an independent controller.

5. Cookies and tracking

The [Cookie Notice](/cookies) and the privacy choices control in the page footer show which technologies are present and which optional purposes are available on preferium.com. Analytics, ad measurement and ad personalization each require their own consent choice. Consent to one purpose is not consent to the others. Rejection or withdrawal does not prevent use of the website's necessary functions.

No Google tag is loaded until a purpose-specific consent exists. Google Analytics 4 is the only optional purpose configured in this version. It loads only after you choose "Analytics" in the consent manager, sends page views only (no custom events, user ID, Google signals, advertising features or cross-domain measurement), and is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acting as our processor under Google's data processing terms. Ad measurement and ad personalization are not configured. When you consent, the processing covers page address and referring address, network IP address, browser and device, consent signals and the _ga and _ga_* identifiers, with the storage period stated in the Cookie Notice. Data retention in our Google Analytics property is set to 2 months and is not reset by new activity. Those are not anonymous data.

Read Google's Business Data Responsibility, how Google uses information from sites or apps that use its services and Google's Privacy Policy.

On customers' domains the customer is responsible for its own purposes, categorisation, legal basis and consent management platform. This does not limit Preferium's own duties for technology we determine.

6. Recipients and international transfers

We share data only with employees and contractors who need access, providers that deliver the Service, professional advisers under a duty of confidence, authorities where the law requires it, and a party to a business transaction with appropriate protection.

Recipients, services, processing locations and documented transfer bases are listed in the [Subprocessor Register](/subprocessors). The providers for preferium.com are:

  • Cloudflare, Inc. serves the website from its global edge network, provides Turnstile form protection, rate limiting and the Access login for our administration, and hosts the compliance database (Cloudflare D1) created in the EU jurisdiction. Storage in the EU does not mean that requests are processed only in the EU: the edge network processes each request close to the visitor. Cloudflare's Customer DPA (version 6.4, 3 April 2026) relies on the EU Standard Contractual Clauses and the Data Privacy Framework for restricted transfers.
  • Resend (Plus Five Five, Inc.) delivers our email: contact-form notifications, waitlist confirmations, privacy request verification and case messages. Emails are sent from a preferium.com sender address to and from our mailbox post@preferium.no. Resend's DPA (27 August 2026) states that its primary processing takes place in the United States and provides for the EU Standard Contractual Clauses and the Data Privacy Framework.
  • Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) receives page-view data for Google Analytics 4 only after you consent to analytics, as described in Section 5. Nothing is sent to Google before that. Google may transfer data to Google LLC in the United States under the EU Standard Contractual Clauses and the Data Privacy Framework as set out in Google's data processing terms.

A transfer outside the EEA requires a valid transfer basis for the actual recipient and processing. An adequacy decision is used only within its scope. Where standard contractual clauses are required, the relevant instrument must be bindingly concluded and accompanied by the necessary assessments and measures. You may ask for information about the safeguards that apply to your data, with the necessary security redactions.

For a restricted transfer covered by UK data-protection law, a valid UK basis is used. The EU standard contractual clauses alone are not UK standard clauses; the current UK Addendum or the IDTA may be used where necessary and the conditions are met.

7. Security and data minimisation

We limit processing and access to what is necessary for the purpose. The technical controls that apply to preferium.com, and the matters that depend on other systems or providers, are described in the [Trust and Security](/trust) page. A public description is not a security certification and not a guarantee against incidents.

Do not send special categories of personal data, criminal-conviction data, children's data, raw card data or passwords in free-text fields unless this is expressly agreed and legally assessed.

8. Retention and deletion

We do not keep data longer than the purpose, the agreement, security, legal requirements or legal claims make necessary. The retention periods for our case and evidence records are Preferium's policy (version 1 of 8 September 2026), not general statutory minimum periods:

Data classPeriodCounted from
Privacy choice180 days, no automatic renewalThe choice is recorded
Consent evidence3 yearsExpiry or withdrawal of the choice
Administrator audit3 yearsThe event is recorded
Privacy request3 yearsThe case is closed
Incident5 yearsThe case is closed

A scheduled nightly job deletes what has outlived the policy for its data class, skips anything under an active legal hold and records one evidence entry per class for what was deleted. A legal hold is limited to the data and the reason that make continued retention necessary and is reviewed.

The backup of the compliance database is the provider's built-in point-in-time history of 30 days (Cloudflare D1 Time Travel). We keep no separate recovery copies. Data deleted from the active database may therefore remain recoverable within that window, and the provider's physical removal may occur later than the end of the window. A restore is documented for the point in time that was actually restored and must not make previously deleted data available again without handling the deletion and any valid retention requirement.

At the end of a customer relationship the export and deletion process in the Service Terms and the Data Processing Agreement applies. Active serving, Frozen Delivery, account access, production data, export copies, backups and statutory records are different categories with different deadlines. If a deletion cannot be completed within the deadline, we explain the reason, the temporary restriction and the further processing.

9. Your rights

Where the legal conditions are met, you may request access, rectification, erasure, restriction and data portability, and object to processing based on legitimate interest. You may withdraw consent without earlier processing becoming unlawful. You may also ask for information about transfer safeguards.

You can use the [privacy request form](/privacy/request) or write to post@preferium.no. You do not need to use a particular form or give a reason for an access request. If the form cannot be used, you can still contact us directly.

We handle the request without undue delay and normally within one calendar month of receipt (Article 12(3) GDPR). Where the complexity or the number of requests makes it necessary, the period may be extended by up to two further months. We then inform you of the extension and the reason within the first month. An internal processing target is a working goal and does not change the statutory deadline.

We may ask for necessary additional information where there is reasonable doubt about your identity or your authority to act for someone else. Verification is proportionate. The form sends a one-time verification link to the email address you give; confirming it proves control of the reply address, not identity or authority on its own. We record the original receipt and do not restart the deadline because the address is confirmed. Any effect of a necessary identity check on the deadline is assessed separately under the applicable rules.

If we do not comply with a request, we state the reason and the possibility of complaining or seeking judicial review.

You may complain to the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no) or to the supervisory authority of the EU or EEA country where you live or work. People in the United Kingdom may complain to the Information Commissioner's Office (ico.org.uk). Whether a UK representative is required is assessed before regular UK-targeted processing; none is represented as appointed in this version.

10. Your US state privacy rights

This section applies to residents of US states with comprehensive privacy laws, including California (CCPA as amended by the CPRA). Preferium may fall below the revenue and volume thresholds at which these laws apply to a business; we extend the rights below to all US residents regardless, on the terms stated here.

What we do not do. We do not sell personal information and we do not share it for cross-context behavioral advertising. No targeted advertising technology is active on preferium.com at the time of this version. Google Analytics 4 (analytics, page views only) loads only after you choose analytics in the consent manager; no optional technology is loaded without a purpose-specific choice. We do not collect sensitive personal information for the purpose of inferring characteristics, and we do not knowingly collect personal information from anyone under 16.

Your rights. You have the right to know what personal information we have collected about you, the categories of sources and recipients and the purposes; to access it in a portable format; to have inaccurate personal information corrected; to have personal information deleted, subject to the exceptions the law allows; to opt out of the sale or sharing of personal information; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights. The categories we collect and their purposes are listed in Sections 2 and 3.

Global Privacy Control. We honor the Global Privacy Control signal (the Sec-GPC: 1 request header) as a valid request to opt out of sale and sharing for that browser. Because we neither sell nor share personal information, honoring the signal means that no optional technology is activated for that browser: the consent manager treats the signal as a standing denial of every optional purpose, even if an earlier choice on the same browser granted one. Because the signal is honored and nothing is sold or shared, we do not display a separate "Do Not Sell or Share My Personal Information" link (Cal. Civ. Code § 1798.135(b)(1)).

How to submit a request. Use the [privacy request form](/privacy/request) and choose the request type "Do not sell or share my personal information (CCPA)", or write to post@preferium.no. You may use an authorized agent; we may ask the agent for proof of authorization and ask you to confirm the request directly. We verify requests through the one-time link sent to the email address you provide and, where necessary for a request to know, delete or correct, through information that matches what we already hold. We will not ask for more information than is necessary to verify and fulfil the request.

Deadlines. We respond within 45 days of receiving a request to know, delete or correct. Where reasonably necessary we may extend once by a further 45 days, in which case we notify you of the extension and the reason within the first 45-day period (Cal. Civ. Code § 1798.130(a)(2)(A)). Requests to opt out are given effect as soon as feasible and no later than 15 business days after receipt. If we deny a request in whole or in part, we explain why and you may ask us to reconsider by replying to that decision. California residents may also contact the California Privacy Protection Agency or the California Attorney General.

We do not use personal information for decisions that produce legal or similarly significant effects.

11. Changes and contact

We update this Notice when processing or legal requirements change. Material changes that affect existing people are actively notified where reasonable and required; it is not the individual's responsibility to discover them alone. Earlier versions are available on request; the version, effective time and document hash are shown above the text.

Preferium AS · Sponheimveien 19, 1613 Fredrikstad, Norway · post@preferium.no · +47 977 91 286

Build your agency on Preferium

Partner registration opens to founding partners first. Join the waitlist, or talk to us about Enterprise — both reach the same people.

Privacy choices

Optional analytics and advertising technologies are not activated on this site. Here you find information about the necessary technologies.

See the cookie notice, the privacy notice and theterms.

Necessary technologies Always necessary

Preferium AS and Cloudflare deliver the site, protect forms against abuse and remember documented privacy choices. These purposes have no optional switch.

Cloudflare Turnstile
Provider: Cloudflare. Abuse protection that loads only on forms where Turnstile is necessary. Storage period: Short-lived control value tied to a form submission.