Documents
Preferium AS · 999 323 286
post@preferium.no
Legal
Privacy Notice
Which personal data we process when you use preferium.com and our services, why we do it, how long we keep it, and the rights you have, including your US state privacy rights.
For a concluded agreement, the document versions recorded in the accepted Order or signature apply. A new version on this website does not change the agreement by itself.
Preferium AS · contact and company details
- Company
- Preferium AS
- Org. no.
- 999 323 286
- Registers
- Central Coordinating Register for Legal Entities (Enhetsregisteret, since 5 January 2013), Register of Business Enterprises (Foretaksregisteret) and VAT Register (Merverdiavgiftsregisteret)
- Office address
- Produksjonsveien 18, 2nd floor, 1618 Fredrikstad
- Postal address
- Sponheimveien 19, 1613 Fredrikstad
- Contact
- post@preferium.no · +47 977 91 286
1. Who and what this Notice covers
This Notice explains how Preferium AS, Norwegian organization no. 999 323 286, processes personal data as an independent controller when people visit preferium.com, join the waitlist, contact us, submit a privacy request, represent a customer, agency or supplier, or receive service messages from us.
The Notice is information, not an agreement and not consent. Where Preferium only processes data on behalf of a customer or an agency, that customer is the controller and the [Data Processing Agreement](/dpa) governs Preferium's role. Processing inside Preferium AI Edge (the Dashboard, branded client panels and connected websites) is described in the product's own documentation and in the Data Processing Agreement; a description of a function or provider on this page does not mean that it is used on every visit to preferium.com.
Contact: post@preferium.no · +47 977 91 286 · Sponheimveien 19, 1613 Fredrikstad, Norway. Preferium has not appointed a Data Protection Officer under Article 37 GDPR. Robert André Johansen is the operational privacy contact, not an independent Data Protection Officer.
The retired domain preferium.no only redirects to preferium.com. Requests and records created while the Norwegian site was live are handled under this Notice.
2. Processing on preferium.com
| Activity | Data and source | Purpose and legal basis | Normal retention |
|---|---|---|---|
| Website delivery and security | IP address, user agent, URL, time and security signals from the browser and Cloudflare, which serves the site | Deliver and protect the pages; legitimate interest in secure and available operation, Art. 6(1)(f) | Short provider-controlled security and operations periods |
| Contact and waitlist forms | Name, work email, agency name or website, an optional phone number, the subject you choose and the message that you enter; a Cloudflare Turnstile token that proves the form was submitted by a person | Answer the enquiry and prepare an agreement, Art. 6(1)(b) where you may become a contracting party, otherwise legitimate interest in business dialogue, Art. 6(1)(f) | Reviewed and cleared by purpose; normally up to 24 months after the last relevant dialogue, longer where an agreement or a dispute follows |
| Privacy requests | Name, email address, your relationship to us, an optional organization, website and reference, the request type, your description, the verification token sent to your email address, our investigation and our reply | Fulfil data-protection obligations, Art. 6(1)(c) | Three years after the case is closed, with earlier minimisation of direct identifiers where possible |
| Privacy choices and consent evidence | Your purpose choices, the document and policy versions shown, time, a random receipt reference and any withdrawal. The consent record contains no name, email address or raw IP address | Respect and document your choices as the relevant documentation duties require, Art. 6(1)(c), and legitimate interest in proving compliance, Art. 6(1)(f) | A choice is valid for 180 days without automatic renewal; the evidence is kept for three years after expiry or withdrawal |
| Administrative security and incidents | The authorized administrator, the reason for access, the case, the measures taken, risk assessments and notifications | Data-protection obligations, Art. 6(1)(c), and, where relevant, legitimate interest in security and legal claims, Art. 6(1)(f) | Administrator audit trail for three years; incident cases for five years after closure |
The network address of a request is used as a keyed digest for rate limiting of the contact, consent and privacy endpoints. That digest cannot be reversed into the address and is not stored with your choices or your request.
We do not use these data for decisions that have legal or similarly significant effects on people. Required fields in a form must be provided for the enquiry or request to be handled; without them we cannot answer.
3. Processing in the customer relationship
When an agency or another business becomes a customer, Preferium processes the following as controller for its own purposes:
| Activity | Data and source | Purpose and legal basis | Normal retention |
|---|---|---|---|
| Account and agreement records | Name, work email, organization, role, accepted document versions, login and configuration activity | Perform the agreement, administer users and document security, Art. 6(1)(b)/(f) | The term of the agreement and thereafter according to deletion and limitation periods |
| Billing and accounting | Customer, contact, invoice, subscription and payment references from the customer or the payment provider | Perform the agreement, collect payment and keep statutory accounts, Art. 6(1)(b)/(c) | Accounting records for the statutory retention period under Norwegian bookkeeping law; other payment data no longer than necessary |
| Support and incidents | Dialogue, attachments, technical logs and measures from the customer, the system and support | Perform the agreement, troubleshoot, secure the Service and defend legal claims, Art. 6(1)(b)/(f) | According to the risk and need of the case; sensitive content is minimised |
| Service messages and marketing | Work contact details, preferences and delivery status | Necessary service messages, Art. 6(1)(b)/(f); marketing only with consent or within a lawful existing customer relationship | Until you object or the purpose ends; suppression data may be kept to respect an objection |
For data about a business's representatives, the person is not automatically a contracting party. Agreement administration and relevant follow-up then rest on an assessed legitimate interest, Art. 6(1)(f); Art. 6(1)(b) applies where the person is a contracting party. Statutory processing has its own basis.
4. Processing on behalf of customers
When Preferium AI Edge serves a customer's or an End Customer's website, technical request data and public website content may pass through the infrastructure. The customer determines the purpose and the content and must inform its visitors. Preferium follows the documented instructions in the Data Processing Agreement.
In white-label relationships the End Customer may be the controller, the agency a processor and Preferium a subprocessor. For Preferium's own account, security, billing and supplier administration, Preferium remains an independent controller.
5. Cookies and tracking
The [Cookie Notice](/cookies) and the privacy choices control in the page footer show which technologies are present and which optional purposes are available on preferium.com. Analytics, ad measurement and ad personalization each require their own consent choice. Consent to one purpose is not consent to the others. Rejection or withdrawal does not prevent use of the website's necessary functions.
No Google tag is loaded until a purpose-specific consent exists. Google Analytics 4 is the only optional purpose configured in this version. It loads only after you choose "Analytics" in the consent manager, sends page views only (no custom events, user ID, Google signals, advertising features or cross-domain measurement), and is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acting as our processor under Google's data processing terms. Ad measurement and ad personalization are not configured. When you consent, the processing covers page address and referring address, network IP address, browser and device, consent signals and the _ga and _ga_* identifiers, with the storage period stated in the Cookie Notice. Data retention in our Google Analytics property is set to 2 months and is not reset by new activity. Those are not anonymous data.
Read Google's Business Data Responsibility, how Google uses information from sites or apps that use its services and Google's Privacy Policy.
On customers' domains the customer is responsible for its own purposes, categorisation, legal basis and consent management platform. This does not limit Preferium's own duties for technology we determine.
6. Recipients and international transfers
We share data only with employees and contractors who need access, providers that deliver the Service, professional advisers under a duty of confidence, authorities where the law requires it, and a party to a business transaction with appropriate protection.
Recipients, services, processing locations and documented transfer bases are listed in the [Subprocessor Register](/subprocessors). The providers for preferium.com are:
- Cloudflare, Inc. serves the website from its global edge network, provides Turnstile form protection, rate limiting and the Access login for our administration, and hosts the compliance database (Cloudflare D1) created in the EU jurisdiction. Storage in the EU does not mean that requests are processed only in the EU: the edge network processes each request close to the visitor. Cloudflare's Customer DPA (version 6.4, 3 April 2026) relies on the EU Standard Contractual Clauses and the Data Privacy Framework for restricted transfers.
- Resend (Plus Five Five, Inc.) delivers our email: contact-form notifications, waitlist confirmations, privacy request verification and case messages. Emails are sent from a preferium.com sender address to and from our mailbox post@preferium.no. Resend's DPA (27 August 2026) states that its primary processing takes place in the United States and provides for the EU Standard Contractual Clauses and the Data Privacy Framework.
- Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) receives page-view data for Google Analytics 4 only after you consent to analytics, as described in Section 5. Nothing is sent to Google before that. Google may transfer data to Google LLC in the United States under the EU Standard Contractual Clauses and the Data Privacy Framework as set out in Google's data processing terms.
A transfer outside the EEA requires a valid transfer basis for the actual recipient and processing. An adequacy decision is used only within its scope. Where standard contractual clauses are required, the relevant instrument must be bindingly concluded and accompanied by the necessary assessments and measures. You may ask for information about the safeguards that apply to your data, with the necessary security redactions.
For a restricted transfer covered by UK data-protection law, a valid UK basis is used. The EU standard contractual clauses alone are not UK standard clauses; the current UK Addendum or the IDTA may be used where necessary and the conditions are met.
7. Security and data minimisation
We limit processing and access to what is necessary for the purpose. The technical controls that apply to preferium.com, and the matters that depend on other systems or providers, are described in the [Trust and Security](/trust) page. A public description is not a security certification and not a guarantee against incidents.
Do not send special categories of personal data, criminal-conviction data, children's data, raw card data or passwords in free-text fields unless this is expressly agreed and legally assessed.
8. Retention and deletion
We do not keep data longer than the purpose, the agreement, security, legal requirements or legal claims make necessary. The retention periods for our case and evidence records are Preferium's policy (version 1 of 8 September 2026), not general statutory minimum periods:
| Data class | Period | Counted from |
|---|---|---|
| Privacy choice | 180 days, no automatic renewal | The choice is recorded |
| Consent evidence | 3 years | Expiry or withdrawal of the choice |
| Administrator audit | 3 years | The event is recorded |
| Privacy request | 3 years | The case is closed |
| Incident | 5 years | The case is closed |
A scheduled nightly job deletes what has outlived the policy for its data class, skips anything under an active legal hold and records one evidence entry per class for what was deleted. A legal hold is limited to the data and the reason that make continued retention necessary and is reviewed.
The backup of the compliance database is the provider's built-in point-in-time history of 30 days (Cloudflare D1 Time Travel). We keep no separate recovery copies. Data deleted from the active database may therefore remain recoverable within that window, and the provider's physical removal may occur later than the end of the window. A restore is documented for the point in time that was actually restored and must not make previously deleted data available again without handling the deletion and any valid retention requirement.
At the end of a customer relationship the export and deletion process in the Service Terms and the Data Processing Agreement applies. Active serving, Frozen Delivery, account access, production data, export copies, backups and statutory records are different categories with different deadlines. If a deletion cannot be completed within the deadline, we explain the reason, the temporary restriction and the further processing.
9. Your rights
Where the legal conditions are met, you may request access, rectification, erasure, restriction and data portability, and object to processing based on legitimate interest. You may withdraw consent without earlier processing becoming unlawful. You may also ask for information about transfer safeguards.
You can use the [privacy request form](/privacy/request) or write to post@preferium.no. You do not need to use a particular form or give a reason for an access request. If the form cannot be used, you can still contact us directly.
We handle the request without undue delay and normally within one calendar month of receipt (Article 12(3) GDPR). Where the complexity or the number of requests makes it necessary, the period may be extended by up to two further months. We then inform you of the extension and the reason within the first month. An internal processing target is a working goal and does not change the statutory deadline.
We may ask for necessary additional information where there is reasonable doubt about your identity or your authority to act for someone else. Verification is proportionate. The form sends a one-time verification link to the email address you give; confirming it proves control of the reply address, not identity or authority on its own. We record the original receipt and do not restart the deadline because the address is confirmed. Any effect of a necessary identity check on the deadline is assessed separately under the applicable rules.
If we do not comply with a request, we state the reason and the possibility of complaining or seeking judicial review.
You may complain to the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no) or to the supervisory authority of the EU or EEA country where you live or work. People in the United Kingdom may complain to the Information Commissioner's Office (ico.org.uk). Whether a UK representative is required is assessed before regular UK-targeted processing; none is represented as appointed in this version.
10. Your US state privacy rights
This section applies to residents of US states with comprehensive privacy laws, including California (CCPA as amended by the CPRA). Preferium may fall below the revenue and volume thresholds at which these laws apply to a business; we extend the rights below to all US residents regardless, on the terms stated here.
What we do not do. We do not sell personal information and we do not share it for cross-context behavioral advertising. No targeted advertising technology is active on preferium.com at the time of this version. Google Analytics 4 (analytics, page views only) loads only after you choose analytics in the consent manager; no optional technology is loaded without a purpose-specific choice. We do not collect sensitive personal information for the purpose of inferring characteristics, and we do not knowingly collect personal information from anyone under 16.
Your rights. You have the right to know what personal information we have collected about you, the categories of sources and recipients and the purposes; to access it in a portable format; to have inaccurate personal information corrected; to have personal information deleted, subject to the exceptions the law allows; to opt out of the sale or sharing of personal information; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights. The categories we collect and their purposes are listed in Sections 2 and 3.
Global Privacy Control. We honor the Global Privacy Control signal (the Sec-GPC: 1 request header) as a valid request to opt out of sale and sharing for that browser. Because we neither sell nor share personal information, honoring the signal means that no optional technology is activated for that browser: the consent manager treats the signal as a standing denial of every optional purpose, even if an earlier choice on the same browser granted one. Because the signal is honored and nothing is sold or shared, we do not display a separate "Do Not Sell or Share My Personal Information" link (Cal. Civ. Code § 1798.135(b)(1)).
How to submit a request. Use the [privacy request form](/privacy/request) and choose the request type "Do not sell or share my personal information (CCPA)", or write to post@preferium.no. You may use an authorized agent; we may ask the agent for proof of authorization and ask you to confirm the request directly. We verify requests through the one-time link sent to the email address you provide and, where necessary for a request to know, delete or correct, through information that matches what we already hold. We will not ask for more information than is necessary to verify and fulfil the request.
Deadlines. We respond within 45 days of receiving a request to know, delete or correct. Where reasonably necessary we may extend once by a further 45 days, in which case we notify you of the extension and the reason within the first 45-day period (Cal. Civ. Code § 1798.130(a)(2)(A)). Requests to opt out are given effect as soon as feasible and no later than 15 business days after receipt. If we deny a request in whole or in part, we explain why and you may ask us to reconsider by replying to that decision. California residents may also contact the California Privacy Protection Agency or the California Attorney General.
We do not use personal information for decisions that produce legal or similarly significant effects.
11. Changes and contact
We update this Notice when processing or legal requirements change. Material changes that affect existing people are actively notified where reasonable and required; it is not the individual's responsibility to discover them alone. Earlier versions are available on request; the version, effective time and document hash are shown above the text.
Preferium AS · Sponheimveien 19, 1613 Fredrikstad, Norway · post@preferium.no · +47 977 91 286