Who is responsible?
Bytops AS is the provider described in this notice. Contact: contact@bytops.com. Contact address: Fargerivegen 2, 6002 Ålesund, Norway. The organisation number and registered business address must be added or verified before this notice takes effect.
Bytops determines the purposes of its own business enquiries, customer administration and website operations. For personal data placed in a workspace by a customer, that customer normally acts as controller and Bytops acts as processor under a separate data processing agreement. Contact the workspace organisation first for requests about its records.
Information and its sources
Information may include your name, work email, organisation, messages, account identifiers, invitations, roles, subscription and usage records, and technical connection or security logs. It comes from you, your workspace administrator, your use of the service and integrations your organisation enables. Do not include passwords or unnecessary sensitive information in enquiries.
Workspace content can include entity fields and records, files, relationships, queries, workflow events, portals, AI prompts and selected context, permissions and audit activity. The customer decides what to collect and must inform the people concerned. Product examples do not mean that patient records, children’s data or other regulated data are approved for use.
Purposes and legal bases
The proposed basis for answering enquiries and administering business contacts is legitimate interests in communicating with customers and providing the service (Article 6(1)(f)), subject to a documented balancing assessment. Article 6(1)(b) applies only where processing is necessary for a contract with the individual or steps they request before that contract. A company’s contract is not automatically a contract with every employee.
Security and abuse prevention require a documented legitimate-interest assessment. Statutory accounting obligations may require processing under Article 6(1)(c). Optional marketing or non-essential tracking requires an appropriate separate basis and consent where applicable. Workspace processing follows the customer’s documented instructions; the customer establishes its own legal basis. These purpose-to-basis mappings must be approved before launch.
Retention and deletion
The following is a proposed schedule for approval, not a statement of verified current operation: unsuccessful business enquiries—12 months after closure; routine technical/security logs—90 days; active account administration—for the account lifetime and a limited closure period. Confirm exceptions for investigations and legal claims, and restrict access to retained material.
Workspace retention follows the customer’s instructions and the signed processing agreement. A proposed exit schedule is a 30-day export window, followed by deletion from active systems and expiry of remaining backups within 90 days. These periods, legal-retention exceptions, accounting record categories and restoration safeguards must be approved and implemented before they become commitments. Customers must also remove exported and offline copies from their devices.
Website preferences and external content
This website uses local storage for the selected appearance and motion preference. These choices remain until you clear site data or replace the preference. The reviewed website code contains no advertising or audience-analytics scripts. Hosting may still produce request/security logs; provider settings and retention need confirmation.
The contact form opens your email application; it does not transmit the form to a website form service. Sending the draft shares it with Bytops and your email provider. The embedded Google map is loaded only after you choose to load it; Google then receives connection information such as your IP address. Ordinary external links connect you to those services when followed. Non-essential device storage or tracking must not be introduced without the information and valid consent required by Norwegian electronic communications rules.
AI, automation and offline work
AI features can process prompts and the workspace context selected for a task. Before enabling them for personal data, verify the provider, retention, transfer arrangements and any training use. No provider-wide “never used for training” promise is made in this draft. Review outputs before relying on them; do not configure solely automated decisions with legal or similarly significant effects without assessing the applicable safeguards.
Offline mode places supported data on the device you choose. Use a private, secured device, protect the browser profile and synchronise before removing local data. Clearing browser storage can destroy unsynchronised work. Server deletion does not necessarily erase a disconnected device immediately. Administrators must manage device access and local-copy removal.
Your rights and how to ask
Depending on the conditions in the law, you may request access, correction, deletion, restriction or portability, object to processing, and withdraw consent without affecting earlier lawful processing. You may object to direct marketing at any time. Write to contact@bytops.com, identify the relevant service and explain your request; avoid sending identity documents unless reasonably needed for verification.
The normal response deadline is one month. A justified extension of up to two further months may apply to complex or numerous requests, with notice within the first month. Rights are not absolute: legal retention and other lawful exceptions may apply. You can complain to Datatilsynet in Norway or the competent EEA supervisory authority, without first contacting us.
Changes to this notice
The revision date identifies this draft, not an effective date. Material changes to purposes, recipients or legal bases must be assessed and communicated before the changed processing where required. This notice is information about data handling, not consent to optional processing and not a replacement for a customer data processing agreement.
Before publication
- Add the organisation number, registered business address and VAT status. The Ålesund address is currently a contact location.
- Confirm subprocessors, AI providers, remote-access locations, encryption/key ownership and the security annex.
- Approve the purpose-by-purpose legal bases and retention/deletion schedule, including backups and offline copies.
- Approve business terms, the Article 28 data processing agreement and any consumer-specific terms.
Legal framework & guidance
- Personopplysningsloven (Norway)
- GDPR — Regulation (EU) 2016/679
- Datatilsynet — individual rights
- Datatilsynet — processing agreements
- Datatilsynet — international transfers
- Datatilsynet — cookies and similar technologies
- Ehandelsloven § 8 — business information
- Digitalytelsesloven — consumer digital services