Norwegian law, European protections
The Norwegian Personal Data Act incorporates the GDPR into Norwegian law. Norway is part of the EEA. This page explains the proposed allocation of data protection responsibilities for Bytops; it is not a GDPR certificate, security audit or signed processing agreement. Sector-specific requirements still need separate assessment.
Who decides, who processes
The customer determines why personal data belongs in its entities, records and portals, who may access it and how long it should remain. Bytops processes workspace data on documented instructions. Bytops has separate controller responsibilities for its own customer relationship and website activities, as described in the privacy policy.
A separate processing agreement
Before production personal data is processed, the parties must agree an Article 28 data processing agreement. Its annexes should identify the service, duration, data subjects and data types, instructions, security measures, approved subprocessors, international transfers, assistance, audits and return/deletion arrangements. This public overview does not execute that agreement.
Controls inside your workspace
Entity and record permissions, fields, relationship rules, workflow configuration and audit history help administrators organise access and accountability. These features do not choose a legal basis or make a deployment compliant automatically. Apply least privilege, review portal audiences and exports, remove departed users and document administrative changes.
Security and EU hosting
Bytops AS confirms encrypted service data and hosting in EU regions. The security annex must validate protection in transit and at rest, key custody, privileged access, incident monitoring, recovery tests and backup deletion. Do not infer end-to-end encryption, a certification or a guarantee that no provider personnel can access any data from this page.
Subprocessors and international access
A verified register must identify each subprocessor, its role and countries of processing/access, including AI services. Customers need the authorisation and change-notification arrangements agreed in the processing agreement. EU data residency and the legal assessment of an international transfer are different questions; any non-EEA transfer must have the required safeguards.
Rights, incidents and cooperation
Requests about workspace data normally go to the customer as controller. Bytops should assist under the processing agreement rather than independently changing the customer’s records. Report suspected exposure to contact@bytops.com with minimal necessary detail; never include credentials or a full data export.
A processor must inform the controller of a personal data breach without undue delay. The controller assesses notification to the authority, normally within 72 hours of awareness unless the breach is unlikely to risk individuals’ rights and freedoms. High-risk breaches can also require notice to affected people. These rules are not a promise that every incident is reportable or that 72 hours is an acceptable processor response target.
Before you put data into production
Identify your purposes and lawful basis, minimise fields, publish an appropriate notice and set retention rules. Assess high-risk processing, special-category data, employee monitoring and AI-assisted decisions before enabling them. Complete a DPIA where required. Verify offline-device controls and exports, agree the DPA and security annex, and test rights handling and deletion. Contact Bytops to obtain the actual documentation; do not treat this overview as evidence of a completed assessment.
Before publication
- Add the organisation number, registered business address and VAT status. The Ålesund address is currently a contact location.
- Confirm subprocessors, AI providers, remote-access locations, encryption/key ownership and the security annex.
- Approve the purpose-by-purpose legal bases and retention/deletion schedule, including backups and offline copies.
- Approve business terms, the Article 28 data processing agreement and any consumer-specific terms.
Legal framework & guidance
- Personopplysningsloven (Norway)
- GDPR — Regulation (EU) 2016/679
- Datatilsynet — individual rights
- Datatilsynet — processing agreements
- Datatilsynet — international transfers
- Datatilsynet — cookies and similar technologies
- Ehandelsloven § 8 — business information
- Digitalytelsesloven — consumer digital services