TechVikingAS
Oslo --:-- Operational

Personverngjelder fra 19.04.2026

Privacy

TechViking AS is the controller for the data described here. For the objects you store with us we are the processor, and your own privacy policy governs them.

What we hold

Account and billing data

Company name, organisation number, billing address, the names and email addresses of the people you nominate as contacts, and the invoices themselves. Legal basis is performance of the contract, article 6(1)(b), and for the invoices the Norwegian Bookkeeping Act, which requires us to keep them for five years after the end of the financial year.

Request logs

Every API request writes a line: timestamp, source IP address, HTTP method, bucket, key, response code, bytes transferred, and the access key used. These are kept for 30 days for abuse handling, billing disputes and incident investigation, then deleted. Legal basis is legitimate interest, article 6(1)(f). We do not log request or response bodies, and we do not log query strings that carry signatures.

Object contents

We do not read them, index them, scan them, or train anything on them. Objects are encrypted at rest with AES-256. If you use SSE-C we never hold the key, which means that if you lose it the object is gone and there is nothing we can do.

This website

The web server keeps access logs for 14 days, containing IP address, path, status code and response size. There is no analytics package, no tag manager, no advertising pixel, no A/B testing tool, and no fonts or scripts loaded from a third party. The page you are reading makes requests to exactly one hostname, which is the one in your address bar.

Informasjonskapsler

Cookies

This site sets none. That is why there is no consent banner: under ekomloven section 3-15 a banner is required for storage that is not strictly necessary, and we do not store anything at all.

The console at console.techviking.cc sets one session cookie named tv_session, marked HttpOnly, Secure and SameSite=Strict, which expires after eight hours or when you sign out. It is strictly necessary for authentication and carries no identifier that survives the session.

Databehandleravtale

Data processing agreement

Our standard DPA follows GDPR article 28 and is part of the contract, signed before the first byte is written rather than bolted on afterwards. It is available in Norwegian and English, and we will sign yours instead if it does not conflict with ours. Ask personvern@techviking.cc.

The DPA covers: the subject matter and duration, the categories of data subject, our obligation to process only on documented instruction, the confidentiality undertaking from every employee with production access, the security measures in annex 2, the sub-processor list and the 30 day notice period, assistance with data subject requests, breach notification within 24 hours of our becoming aware, and deletion or return on termination.

No personal data is transferred outside the EEA, so there is no transfer mechanism to argue about and no transfer impact assessment to write. Every sub-processor is listed on the company page and all of them are Norwegian.

Your rights

What you can require of us

Access to the data we hold about you, correction of anything wrong, deletion where we have no legal obligation to keep it, restriction of processing while a dispute is open, portability of what you gave us, and objection to processing based on legitimate interest. Write to personvern@techviking.cc and we answer within 30 days, which is the deadline the regulation sets rather than a target we invented.

If you are not satisfied with our answer you may complain to Datatilsynet, Postboks 458 Sentrum, 0105 Oslo. You do not have to go through us first.

Changes to this page

Material changes are announced by email to account contacts 30 days before they take effect. The current version is dated 19 April 2026. Earlier versions are kept and will be sent on request.