Privacy Policy
Last updated: Jul 28, 2026
Data controller
This privacy policy explains how we collect and use (process) personal data in our business. COBRIEF AS, represented by its CEO, is the data controller for the processing.
Our contact information is:
COBRIEF AS
Business address: Tordenskiolds gate 2, 0160, Oslo, Norway
Organization number: 931645544
E-mail address: contact@cobrief.com
In addition to what is described in this document, Cobrief also has a Cookie policy, Terms of Service with an accompanying data processing agreement and a list of our sub-processors. The Terms of Service with the data processing agreement govern Cobrief's role as a data processor for Customer Content, that is, data our customers themselves upload or register in the System at https://cobrief.com/en/ and https://app.cobrief.com/. For operational data related to the System, such as user accounts, usage statistics, and error logs, Cobrief is itself the data controller. This processing is described in the section "You use our System" below.
We take your privacy seriously, and we have taken several steps to ensure that we give you clear information about how we process your data and what rights you have. If you feel that anything is unclear or missing, do not hesitate to contact us.
Your rights
Contact us if you have questions about, or wish to exercise, any of your rights. You are entitled to a response within 30 days at the latest. Read more at the Norwegian Data Protection Authority's website.
- Access to and rectification of your own data: You can request a copy of all data we process about you, and ask us to correct data that is not accurate.
- Erasure or restriction: In some situations you can ask us to delete and/or restrict the processing of data about yourself, but we cannot delete data we are required to process.
- Object to processing: If we process data about you on the basis of legitimate interest, you have the right to object.
- Data portability: If we process data about you on the basis of consent or a contract, you can ask us to transfer data about you to you or to another data controller.
- You also have the right to withdraw your consent at any time.
- If you are not satisfied with how your data is processed, you can complain to the Norwegian Data Protection Authority (Datatilsynet), but we hope you will let us know directly first, so we can try to resolve the matter for you in a good way.
Who we process personal data about
We process personal data about:
- Customers
- Potential customers
- Contact persons at suppliers and partners
- Website visitors
- Employees
- Former employees
How we collect personal data
Providing personal data to us is voluntary, but in order to complete a transaction we do need certain information from you.
We process personal data when you:
- buy our products/services
- contact us by phone, SMS, our website, e-mail, or social media
- sign up for our newsletter
- sign up for events we organize
- respond to a survey
- use our website
- apply for a job with us or work for us
- are a supplier or partner of ours
Purposes, legal basis, and storage
Under Article 6(1) of the GDPR, personal data may be processed on the basis of:
- Your consent
- A contract we have entered into
- A legal obligation we have
- To protect the vital interests of the data subject or another natural person
- To perform a task in the public interest or exercise official authority
- A legitimate interest we believe we have
As a general rule, personal data shall not be processed and stored longer than necessary to fulfill the purpose of the processing. If we process your personal data on the basis of a legitimate interest we believe we have, you can object to the processing by contacting us. We will then assess your objection and give you prompt feedback.
To comply with this, we conduct annual GDPR audits where we formally assess and review our privacy work. The purpose is to change, update, and if necessary delete personal data.
We retain data for as long as we are required to under applicable legal obligations, for example related to accounting, tax, or employment legislation, and/or other relevant rules and regulations. You can contact us at any time if you want us to stop processing or to delete your personal data, but note that we cannot delete personal data we are legally obliged to process.
We have procedures in place to ensure that personal data is deleted from all relevant systems when we no longer have a purpose and/or a legal basis for continuing to process it.
Accounting records are kept for up to 5 years, in accordance with the Norwegian Bookkeeping Act.
How we process personal data
Here we describe in detail when and how we process your personal data, for what purposes, on what legal basis, and for how long.
We process personal data when:
You communicate with us
When you give us your business card or contact us via the website (contact form, comment field, chat, or similar), by e-mail, by phone (calls, text messages), or on social media, we process personal data. Depending on where and how you send us a message, this may include name, contact information, IP address, and any other information you choose to send us.
We use a CRM (Customer Relationship Management) system and/or a customer support system to process personal data about potential and existing customers.
The purpose is to be able to respond to inquiries from you, to keep a history, and to have documentation in case we receive complaints, claims, or legal claims.
The legal basis may be:
- Your consent.
- A legitimate interest we believe we have, where the legitimate interest is to be able to respond to inquiries from you, to keep a history, and to have documentation in case we receive complaints, claims, or legal claims.
We review, archive, and delete inquiries as needed, but no less often than once a year.
You buy our products and services
When you buy products and services from us, we process personal data such as name, contact information, order and payment information, and purchase history.
The purpose is to deliver products and services to you upon order/purchase, to keep a history of sold products and services, and otherwise to administer and follow up on our customer relationship with you.
The legal basis may be:
- Your consent.
- A contract we have entered into.
- A legitimate interest we believe we have, where the legitimate interest is to be able to respond to inquiries from you, to keep a history, and to have documentation in case we receive complaints, claims, or legal claims.
You use our System
When you use the System as a user at one of our customers (your employer or another organization you represent), we process certain personal data for which Cobrief itself determines the purpose and is the data controller:
- Account data: name, e-mail address, role, and authentication information for your user account. The purpose is to create and administer the account, give you access to the System, and communicate with you about the service. Account data is stored for as long as your user account exists, and is deleted on request and at the latest 120 days after the customer relationship ends.
- Usage data (telemetry): information about how the System is used, such as which features are used, and technical performance data. The purpose is to improve and further develop the System. We use internal user IDs rather than name and e-mail address where possible. Usage data is stored for as long as it is relevant for this purpose, and is deleted on request.
- Error and log data: security logs, IP address, and technical error reports. The purpose is to operate the System securely, detect and fix errors, and prevent misuse. We automatically scrub customer content from error reports before they are processed in our tools. Error reports are deleted automatically after 90 days, and security logs are stored for up to one year.
The legal basis is a legitimate interest we believe we have, where the legitimate interest is to deliver, secure, operate, and improve the System.
The content you and your organization enter into the System (Customer Content, such as tender documents and proposal texts) is processed by us solely as a data processor on behalf of the organization, under the data processing agreement. If you have questions about this data, your organization (the data controller) is the right point of contact, but we assist them as needed.
Marketing in existing customer relationships
When you become a customer of ours, we process personal data as mentioned above. If you have an existing customer relationship with us, we may send you marketing by e-mail and SMS, in accordance with section 15 of the Norwegian Marketing Control Act. The legal basis will then be legitimate interest, but may also be consent.
The purpose of the marketing is to provide good customer service.
You can unsubscribe from marketing by e-mail and SMS at any time. Information about how to unsubscribe is provided in all marketing-related e-mails and text messages we send.
The data is processed for as long as the customer relationship exists, or until you unsubscribe from the marketing list.
You apply for a job or work for us
When you apply for a job with us, we process personal data such as name, contact information, CV, and other information we need to assess your application.
The legal basis may be:
- Your consent.
- A contract we have entered into.
- A legitimate interest we believe we have.
The legal basis may vary depending on where we are in the recruitment process and what kind of position it concerns.
The data is deleted after a person has been selected for the job, unless you have consented to us storing your information longer in case you want to apply for a job at a later occasion. In that case, the consent is renewed annually.
For employees, we process personal data as mentioned above, in addition to information necessary to pay salaries and otherwise administer the employment relationship.
The legal basis may be:
- A contract we have entered into.
- A legal obligation we have.
Most information about employees is processed in accordance with the employment agreement and is, as a general rule, deleted when the employment relationship ends, unless special circumstances (such as a dispute about termination or dismissal) make it necessary to keep it longer.
You sign up for an event
When you attend free events with us, we process personal data such as name and contact information. For paid events, we also collect order and payment information. The purpose is to offer relevant courses, talks, and workshops, or to fulfill the agreement for the booked event.
The legal basis may be:
- Your consent.
- A legitimate interest we believe we have.
We may also use your personal data to send you a request to evaluate the event you attended, and possibly invite you to other similar events. The legal basis is then legitimate interest, where the legitimate interest is to continuously improve our products and services and to offer you good customer follow-up.
How long we store the data depends on the type of event, but it is usually deleted within 12 months at the latest.
You respond to a survey
We always inform you about the purpose of the surveys we conduct, and whether they are anonymous or not. We do not share the information with others, or use it for purposes other than those stated. For anonymous surveys, we do not collect personal data.
The legal basis for surveys that are not anonymous may be:
- Your consent.
- A legitimate interest we believe we have.
You are a supplier or collaborate with us
When you enter into an agreement with us, either as a supplier, partner, or data processor, we process personal data such as name, contact information, and correspondence.
The purpose is to be able to enter into an agreement with you, and the legal basis may be:
- Your consent.
- A contract we have entered into.
- A legal obligation we have, under, among others, the Norwegian Bookkeeping Act and Tax Act.
- A legitimate interest we believe we have.
The data is stored for as long as we have an ongoing relationship. We process personal data related to general correspondence and communication as described above.
You use our website
When you use our website, we process personal data in accordance with our cookie policy. The purpose is to administer our website, promote the company, and respond to inquiries from visitors. The legal basis for cookies that store or process data covered by section 2-7b of the Norwegian Electronic Communications Act is consent through a preset in your browser, in line with the recommendations of the Norwegian Communications Authority (Nkom) as described here.
Ad measurement and tailored marketing
To measure the effectiveness of our marketing and show relevant ads, we in some cases share certain personal data with advertising partners such as Google and Meta (Facebook/Instagram).
When you sign up for a trial period or become a paying customer, we may share your contact information (for example your e-mail address) in a strongly encrypted (hashed) format with these partners. The partners use this information solely to see whether you have previously interacted with one of our ads (conversion tracking), and to help us reach similar companies (lookalike audiences).
The legal basis for this processing is consent (which you give via our cookie solution on the website) and/or our legitimate interest in measuring the effectiveness of our marketing campaigns.
Who we share personal data with
To run our business efficiently and securely, we sometimes need to share your personal data with parties such as:
- Data processors: providers of various services who process your personal data on our behalf*
- Professional advisers from sectors such as legal, finance, accounting, auditing, and insurance
- User support for IT and administration systems
- Public authorities we are required to report to
- Platforms for advertising and marketing measurement (e.g., Google and Meta)
We require that everyone we share your personal data with secures your data in accordance with good information security practice and the requirements of the GDPR. We enter into data processing agreements with everyone who processes data on our behalf, and confidentiality agreements as needed.
*We use data processors for:
- e-mail, calendar, and digital meetings
- bookkeeping, accounting, and invoicing
- cloud storage
- newsletters
- electronic signing
- surveys
For security reasons, we have not specified these by name, but feel free to contact us if you would like to know more.
Transfer of personal data outside the EU/EEA
In some cases, personal data for which we are the data controller is transferred to countries outside the EU/EEA, primarily the USA. For example, outside the EU/EEA we have:
- a CRM system for processing customer information
- AI assistants and language models used in our internal work
- an e-mail client for company e-mail
- tools for error monitoring and technical logging
- metadata from the support chat in the application
and otherwise to run our business in a safe and efficient manner. Such transfers only take place to countries approved by the European Commission, or with the necessary safeguards under Chapter V of the GDPR. We use the EU Standard Contractual Clauses (SCC), where relevant combined with the recipient's certification under the EU-U.S. Data Privacy Framework, and we assess the level of protection for each transfer (Transfer Impact Assessment) with supplementary measures where necessary.
Feel free to contact us if you would like to know more about the suppliers we use as a data controller, and about the safeguards and security measures that apply to such transfers.
Security
We take information security seriously, and we will always do our utmost to protect your personal data in the best possible way.
Among other things, we use:
- strong passwords
- encryption of data
- access control
- backups
- two-factor authentication
to secure our data and prevent unauthorized persons from viewing, changing, deleting, or in any way affecting the data we store, including your personal data.
We only use recognized providers of IT and administration services such as web hosting, website and PC security, antivirus software, e-mail providers, backups, and more. We only allow others to access and/or process your personal data in accordance with our instructions, and only where strictly necessary (e.g., for IT support).
We have established procedures for handling data security breaches. In cases where we are the data controller, we will, in the event of a breach, notify the Norwegian Data Protection Authority within 72 hours of discovering the breach. If the breach entails a high privacy risk, we will also notify the affected data subjects.