Privacy Policy for Kimaa AS

Version 1.0 — effective from 12.08.2026

This is an English translation. The Norwegian version is the governing one — see section 13.

This privacy policy explains how Kimaa AS processes personal data when you use Kimaa, our service for sustainability (ESG) reporting (the "Service"). It applies both to you as the holder of a user account and to you if you are in contact with us in other ways.

1. Data controller

Kimaa AS is the data controller for the personal data described in section 3.

CompanyKimaa AS
Organisation number931 985 019
AddressMøllergata 6, 0179 Oslo, Norway
Emailmail@kimaa.no

Questions about privacy, and requests concerning your rights under section 8, can be directed to the email address above.

2. When is Kimaa the controller, and when are we a processor?

This distinction determines which rules apply and who you should contact.

Kimaa is the data controller for information about you as a user of the Service: your contact details, your user account, login history and correspondence with us. This policy applies to that information.

Kimaa is a data processor for personal data the company you are affiliated with itself enters into the Service — for example information included in ESG data or in uploaded documents. There, the company is the controller, and the processing is governed by the Data Processing Agreement in Appendix 1 to the Terms of Service. Requests concerning such information must be directed to the company.

3. What personal data we process

  • Contact and account data: name, username, email address, telephone number, job title — including any job title you enter yourself under "Other" — language preference, which company you are affiliated with and what role you hold there.
  • Change history: previous versions of the data above, and who made the change. This is an audit trail, and is covered by the retention periods in section 7.
  • Authentication data: user identifier and login metadata. We do not store passwords in plain text.
  • Data from electronic ID: if you sign in with BankID, we receive your name and email address from the eID broker in order to link the sign-in to your user account. We do not receive your national identity number from this sign-in, and we do not store it.
  • Data about a person asked to approve the agreement: if you are named as the person who may enter into an agreement on a company's behalf, we process the name, email address and role stated for you, so that we can send you the request and document the conclusion of the agreement. That information is provided by the person who placed the order.
  • Usage data: technical logs of use of the Service, primarily for operations, troubleshooting and security. Usage statistics are aggregated and anonymised.
  • Customer correspondence: enquiries to support and our replies.
  • Subscription and invoicing data: which subscription the company holds, who approved the agreement on the company's behalf, the role they stated, the time of approval and which version of the terms was approved. This is retained as documentation of the formation of the agreement.

We do not process special categories of personal data (sensitive personal data) about you as a user.

4. Purposes and legal bases

PurposeLegal basis
Creating and administering a user account, and providing access to the ServiceContract, GDPR Art. 6(1)(b)
Entering into and performing the subscription agreement, and documenting who approved itContract, GDPR Art. 6(1)(b), and legal obligation, (c)
Invoicing and accountingLegal obligation, GDPR Art. 6(1)(c), cf. the Norwegian Bookkeeping Act
Customer service and supportContract, GDPR Art. 6(1)(b)
Operations, security, troubleshooting and prevention of misuseLegitimate interest, GDPR Art. 6(1)(f)
Improving the Service based on aggregated and anonymised statisticsLegitimate interest, GDPR Art. 6(1)(f)
Marketing by emailConsent, GDPR Art. 6(1)(a), cf. the Norwegian Marketing Control Act § 15

Where processing is based on legitimate interest, we have assessed that our interest in operating and securing the Service is not outweighed by your privacy interests. You may object to such processing under section 8.

Consent to marketing may be withdrawn at any time, and every marketing email contains an unsubscribe link.

5. Processors and sub-processors

We use the following suppliers, which process personal data on our behalf. A data processing agreement is in place with each of them.

SupplierPurposePlace of processingBasis for transfer
UpCloud LtdOperation of the Service, and storage of databases and filesFinland (within the EEA)Within the EEA
HubSpot Ireland LtdCustomer records (CRM), sending email from the Service and customer correspondenceWithin the EEA, with support from the United StatesEU Standard Contractual Clauses (SCC)
Idura (eID broker for BankID sign-in)Authentication at sign-inWithin the EEAWithin the EEA
Anthropic PBCThe AI assistant in the Service: guidance, text generation and analysis of uploaded documentsUnited StatesEU Standard Contractual Clauses (SCC)

About the AI assistant. When you use the AI assistant in Kimaa, or upload a document that is analysed automatically, the content of the question or document is sent to Anthropic PBC for processing. This may include text you have entered into the Service yourself. Content sent to Anthropic is not used to train models. Companies that do not want this processing may request that the AI assistant be disabled for their account.

An up-to-date list of sub-processors is made available to customers, and we give at least 30 days' notice before a sub-processor is added or replaced.

Other recipients and sources. These are not our processors — they are independent controllers — but information is exchanged with them:

PartyWhat is exchanged
Brønnøysundregistrene (the Norwegian Register of Business Enterprises)We retrieve information about companies, including the names of individuals registered as general manager, chair of the board, signatory or holder of a power of procuration. This is publicly available information, and we use it to show who may enter into an agreement on a company's behalf
Statens vegvesen (the Norwegian Public Roads Administration)Where a vehicle is to be registered in the Service, we send the registration number and receive information about the vehicle. The request is sent from our servers, not from your browser
Google Ireland Ltd (Google Maps)Where a location is to be geocoded, your browser sends the address to Google's geocoding service to obtain coordinates. Google thereby also receives your IP address. If you wish to avoid this, you can enter the coordinates manually instead

The fonts used in the Service are served from our own domain. No request is made to Google in order to load them, and Google receives no information about you as a result.

6. Transfers of personal data outside the EEA

The majority of processing takes place within the EEA: the Service is operated and the data stored with UpCloud in Finland, and sign-in takes place through an eID broker within the EEA.

Data may be transferred outside the EEA in two cases: to Anthropic PBC in the United States when the AI assistant is used, and to HubSpot to the extent that the company's support functions in the United States have access to the customer records. Both transfers are made on the basis of the European Commission's Standard Contractual Clauses, supplemented by technical and organisational measures. You may request access to the basis for the transfer by contacting us.

If you use the map function to geocode an address, Google also receives your IP address, cf. section 5.

7. How long we retain the data

Erasure at your request. If you ask us to erase personal data about you, we carry out the erasure without undue delay and no later than thirty (30) days. It covers your user account, its change history, sign-in data and content you have sent to the AI assistant — including where that data is held in more than one of our systems.

We retain only what we are legally required to keep, or what is necessary to establish, exercise or defend a legal claim. In practice that means accounting records and documentation of who entered into the agreement on a company's behalf. We tell you what, if anything, remains and why, and we erase it once that basis falls away.

If you do not ask for erasure, the following periods apply:

  • Active user account: for as long as the account is active.
  • Closed account: the user account and its change history are deleted or anonymised within ninety (90) days after the account is closed.
  • Inactive account: if an account has not been used for five years, the data is deleted or anonymised.
  • Accounting records, including invoicing documentation: retained for five years after the end of the financial year, as required by the Norwegian Bookkeeping Act.
  • Documentation of the formation of the agreement (who approved which version of the terms, and when): retained for as long as the contractual relationship lasts and for three years after it ends, in order to be able to document the agreement in the event of a dispute.

8. Your rights

You have the right to:

  • obtain access to the personal data we process about you, and receive a copy
  • have inaccurate or incomplete data corrected
  • have data erased, subject to the limitations following from statutory retention or a court order
  • require that processing be restricted
  • receive the data you have provided to us in a machine-readable format (data portability)
  • object to processing based on legitimate interest
  • withdraw a consent you have given

Requests are sent to mail@kimaa.no. We respond within one month. Where the request is complex or extensive, we may extend that period by up to two further months; we will tell you within the first month if we do. We may ask you to confirm your identity before we disclose or erase information.

If the request concerns data we process on behalf of a customer company — see section 2 — we will refer you to that company, which is the controller for that data.

9. Cookies

Kimaa uses cookies that are necessary for the Service to function: login and session, language preference, and security. In addition we use anonymised usage statistics to improve the Service.

We do not use cookies for advertising or profiling, and we do not share data with advertising networks.

10. Security

We have implemented technical and organisational measures to protect personal data, including encryption in transit and at rest, role-based access control, logging and routines for restoration. In the event of a personal data breach we notify the Norwegian Data Protection Authority within 72 hours where the regulations require it, and affected individuals where the breach entails a high risk.

11. Children

The Service is intended for businesses and is not directed at persons under the age of 18. We do not knowingly collect personal data about children. If we become aware that we have received such data, we delete it.

12. Changes to this privacy policy

We may update this policy. Each version has a version number and a date from which it applies, and previous versions are archived. In the event of material changes we notify users in the Service or by email.

13. Language

This policy exists in Norwegian and English. In the event of conflict or doubt as to interpretation, the Norwegian version is the governing one.

14. Complaints to the Norwegian Data Protection Authority

If you believe we are processing personal data in breach of the regulations, we encourage you to contact us first. You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).

Datatilsynet, Postboks 458 Sentrum, 0105 Oslo — www.datatilsynet.no

Kimaa AS
Møllergata 6
0179 Oslo
Norway

About Kimaa

Contact

Privacy Policy

Kimaa logo

Easy VSME reporting