Oppdrett.info
Privacy Policy
How Oppdrett.info collects, uses and protects personal data about you as a visitor, account holder or subscriber.
This privacy policy explains which personal data Oppdrett.info (https://oppdrett.info) processes, why we do so, and which rights you have. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable national law.
1. Data controller
Oppdrett.info
For any privacy question, contact us at kontakt@oppdrett.info.
2. What data we process
Visiting the site. When you use Oppdrett.info, our server and our analytics tool record your IP address, browser type, pages visited, timestamps and the referring site. See section 5 on cookies.
User account. Sign-in is handled by our identity provider Auth0. We store your e-mail address, your name (as registered with the provider you sign in with), a technical user ID, the time of your last sign-in and the access plan of your account.
Subscription and payment. Payments are processed by Stripe. We store only Stripe's customer ID and subscription ID linked to your account. Card numbers and other payment details go directly to Stripe and are never stored by us.
Alerts and newsletter. If you subscribe to the newsletter or create price or sea-lice alerts, we store your e-mail address, the alerts you chose and when alerts were sent. For the newsletter we also record whether and when the e-mail is opened and which links are clicked (through a tracking image and tracked links from Postmark), as well as bounces and spam complaints. We use this to measure interest and keep the list clean. If you do not want to be tracked, unsubscribe from the newsletter or block images in your e-mail client.
B2B enquiries. If you submit the business contact form, we store your name, company, e-mail, phone, message, timestamp and IP address (to prevent abuse of the form).
API usage. If you hold an API key, we store the key and the number of calls per day to enforce the usage limits of your plan.
3. Purposes and legal basis
- Providing the service (account, subscription, API, alerts you requested): necessary to perform our contract with you (GDPR art. 6(1)(b)).
- Newsletter: your consent (art. 6(1)(a)). You can unsubscribe at any time using the link in every e-mail.
- Analytics and personalised advertising: your consent where the law requires it, otherwise our legitimate interest in understanding how the site is used and in funding free content (art. 6(1)(f)).
- Security, abuse prevention and troubleshooting: our legitimate interest in a stable and secure site (art. 6(1)(f)).
- Accounting and bookkeeping: legal obligation (art. 6(1)(c)).
- Auth0 (Okta) – sign-in and account security.
- Stripe – payments, subscription management and receipts. Stripe is an independent controller for payment data.
- Postmark – delivery of alerts, newsletters and system e-mails.
- Google Analytics and Google AdSense – traffic analytics and advertising.
- Our hosting provider – server operations and backups.
- Necessary: a session cookie that keeps you signed in and remembers your language. Cannot be disabled.
- Analytics: Google Analytics uses cookies to measure traffic. IP anonymisation is enabled where available.
- Advertising: Google AdSense may set cookies to serve and measure ads, and to personalise ads where you have consented.
- Account: for as long as the account is active. If you delete your account, your profile is removed within 30 days.
- Subscription and payment history: as long as accounting law requires (normally five years after the end of the financial year).
- Newsletter and alerts: until you unsubscribe or delete the alert.
- B2B enquiries: up to 24 months after the last contact.
- Server logs and analytics data: deleted or anonymised through routine rotation, normally within 14 months.
4. Who we share data with
We never sell personal data. We rely on the following processors and independent services to run the site:
Some providers process data outside the EEA. Transfers rely on the EU Commission's Standard Contractual Clauses (SCC) or equivalent safeguards. We may also disclose data where required by law.
5. Cookies
You can delete or block cookies in your browser and manage personalised ads at adssettings.google.com. Read how Google uses data at policies.google.com.
6. How long we keep data
7. Your rights
You have the right to access, rectify and erase your data, to restrict or object to processing, and to data portability. Where processing is based on consent, you may withdraw it at any time. E-mail kontakt@oppdrett.info and we will respond within 30 days.
You may also lodge a complaint with the Norwegian Data Protection Authority (datatilsynet.no) or the supervisory authority in your country of residence.
8. Public data about businesses
Oppdrett.info publishes information about fish farms, vessels and companies from public sources such as the Norwegian Directorate of Fisheries, BarentsWatch, the Norwegian Food Safety Authority and Statistics Norway. This is business data, not personal data. If you are an individual named in a public register and wish to limit how it is displayed, please contact us.
9. Security
All traffic to the site is encrypted (HTTPS). Access to personal data is limited to those who need it to operate the service, and administrative access requires separate authentication. We never store passwords; sign-in is handled by Auth0.
10. Changes
We may update this policy when the service or the law changes. The date at the top shows when it was last changed. Material changes are announced on the site or by e-mail to registered users.