Privacy Policy
Improbus is committed to protecting your privacy. This page explains what we collect, why, how long we keep it, and what your rights are under the GDPR.
Last updated: . This is a working draft — see the note at the end.
1 · Controller identity
Improbus AS, Org. No. NO 911 688 689 MVA, Bergen, Norway. Email contact@improbus.com, phone +47 94 10 20 30.
Data Protection Officer: dpo@improbus.com — for privacy questions, GDPR matters, and data-subject requests.
2 · Cookies
This site uses zero cookies. We do not set localStorage, sessionStorage, or IndexedDB entries. We do not load third-party trackers, analytics, advertising scripts, or social media embeds.
3 · Server logs
Our web server records standard access metadata for security and operational purposes:
- WhatTimestamp · request path · status code · response size · user-agent · referer
- IPTruncated (/24 IPv4, /48 IPv6) at log-rotation time
- Retention30 days, then deleted
- Lawful basisLegitimate interest (security, abuse prevention)
4 · Communications you initiate
If you email, call, or message us, we process the contents of your message to respond. Lawful basis: Pre-contractual measures (Art. 6(1)(b)) or legitimate interest (Art. 6(1)(f)). Retention: As long as the relationship is active, then 5 years for accounting per Norwegian law, then deleted.
5 · Recipients and transfers
We self-host this site on FreeBSD servers. We do not transfer your data to third-country processors. We may engage Norwegian or EU/EEA sub-processors for telecommunications, accounting, and legal services on a need-to-know basis under written DPAs.
6 · Your rights
You have the right to: Access, rectification, erasure, restriction, data portability, and to object to processing. To exercise these rights, contact us. You may complain to Datatilsynet (the Norwegian DPA).
7 · Security
We follow industry-standard practices (TLS in transit, access controls, principle of least privilege, regular review). For security-relevant disclosures, see /.well-known/security.txt.