Privacy

    Privacy policy

    Last updated: September 23, 2026

    This document exists in Norwegian and English. The Norwegian version prevails if the two versions differ.

    1. Data controller

    Brødrene Gåsdal AS (org. no. 935 519 640) is the data controller for personal data processed in connection with use of the Justera service. Written enquiries go to post@justera.no. The service is automated; we state no response deadline and no named contact person.

    2. What data we process

    • Account data: name, email, organisation.
    • Content: questions, documents and contracts you upload or enter.
    • Usage data: timestamps, IP address, browser, and features used.
    • Payment data: handled by our payment provider — we store only customer ID and subscription status.

    3. Purpose and legal basis

    The legal basis is the General Data Protection Regulation (GDPR) Article 6(1), implemented in Norwegian law by the Personal Data Act. Each processing activity has one basis:

    • Account, sign-in and delivery of analyses: Art. 6(1)(b) (contract).
    • Organisation number check at checkout and operational account messages: Art. 6(1)(b) (contract).
    • Receipts and accounting records: Art. 6(1)(c) (legal obligation), cf. Bookkeeping Act section 13.
    • Security logs, audit trails and improving analysis quality: Art. 6(1)(f) (legitimate interest).
    • Marketing by email: Art. 6(1)(a) (consent), cf. Art. 7. Consent can be withdrawn at any time.

    4. Sub-processors and transfers

    We use sub-processors within the following categories: cloud provider for database and file storage (eea), error reporting provider (eea), providers of ai model inference, transactional email provider, web analytics provider, payment provider, norwegian public registries.

    We do not name sub-processors publicly. The named list is Annex B to the data processing agreement and is provided to customers on request. Changes are notified by email at least 30 days in advance, and the customer may object and terminate without cost.

    Data processing agreements are in place with all of them. Customer data is stored in the EU/EEA. Some sub-processors may process data outside the EEA, and such transfers take place under the EU Commission's Standard Contractual Clauses (SCC 2021/914) with supplementary measures.

    5. Retention

    Analyses and documents are stored as long as the account is active. You can delete content at any time in the app. Aggregated usage data is retained for 24 months. Deleted data is removed from backups within 30 days.

    6. Cookies and browser storage

    Justera uses no cookies for analytics or marketing, and therefore shows no consent banner. Our traffic measurement (Plausible) and visit counting store nothing in your browser. Unique visits are counted with a salted hash that is rotated and deleted every night.

    The following is stored in your browser because the service needs it, or because you chose it (Norwegian Electronic Communications Act section 3-15(2)):

    • sb-…-auth-token (local storage): keeps you signed in. Removed when you sign out.
    • klarsynt_theme, klarsynt-lang: your choice of light/dark theme and language.
    • klarsynt_workspace_id: the workspace you last used.
    • Dismissed notices and drafts (e.g. klarsynt-draft-* in session storage): so that what you wrote or closed stays that way.
    • ks_did (cookie, 1 year) and klarsynt_device_id: set only on /try and at purchase, to prevent abuse of the free analyses. Sent to us only as a hash.
    • klarsynt_henvisning_kode and justera_ref_code (session storage): set only when you open a referral link, and kept only through sign-up or until the tab is closed, so the person who referred you gets the credit.
    • sidebar:state (cookie): whether the side menu is open or closed.

    7. Your rights

    Under the GDPR you have the right to:

    • access (Art. 15)
    • rectification (Art. 16)
    • erasure (Art. 17)
    • restriction of processing (Art. 18)
    • notification of recipients on rectification, erasure or restriction (Art. 19)
    • data portability (Art. 20)
    • object to processing based on legitimate interest and to direct marketing (Art. 21)
    • not be subject to a decision based solely on automated processing with legal effects for you (Art. 22). Justera makes no such decisions about you.

    Written enquiries go to post@justera.no. The service is automated; we state no response deadline and no named contact person. You can also lodge a complaint with the Norwegian Data Protection Authority (Art. 77). Source: Personal Data Act including the Regulation.

    8. Security

    All traffic is encrypted (TLS 1.3). Access control is role-based and workspace-isolated via row-level security. Logs and audit trails are immutable. Details at /sikkerhet.

    9. Legal sources

    Statutory text and section references in the analyses are taken from Lovdata's open dataset of Norwegian acts and central regulations. Source: Lovdata, NLOD 2.0. Contains data under the Norwegian Licence for Open Government Data (NLOD) made available by Lovdata.

    10. Changes

    Material changes are notified by email at least 30 days before taking effect. Minor editorial adjustments are published directly on this page.