LAST UPDATED 14 SEPTEMBER 2026
Privacy notice
This notice explains how TEAM NORSO AS handles personal information in connection with this international website and enquiries about our services.
Who is responsible?
TEAM NORSO AS, organisation number 928 127 591, is the controller. Our address is Martin Barstads veg 31, 7056 Ranheim, Norway. Svein Erik Haugan is responsible for privacy matters within the company. Contact privacy@teamnorso.com.
Enquiries and business relationships
If you email us, we receive the information you choose to provide, such as your name, email address, organisation and message. We use it to answer your enquiry, arrange a conversation and follow up on services you request.
Where an enquiry concerns a contract with you, the basis is taking steps at your request before entering a contract or performing that contract. For professional contacts acting on behalf of an organisation, we rely on our legitimate interest in responding to enquiries and managing business relationships. Where required, legal obligations also provide a basis for processing.
We do not add you to marketing lists simply because you contact us.
Website visits
The website does not include advertising pixels, Google Analytics, behavioural profiling or a ChatGPT tracking script. Images are served from the website rather than embedded from social media. Contact links open your own email application; no contact form data is stored by this website.
Hosting and security infrastructure necessarily processes technical information such as IP addresses, requested URLs and request times to deliver the website and protect it from abuse. This is separate from marketing analytics. We rely on our legitimate interest in secure, reliable operation.
Resilience Check
You can complete the Resilience Check without an account, name or email address. We store the selected perspective, assessment length, dimension scores, overall score and any optional context you provide, such as role, country, industry and organisation size. We use these anonymous results to produce the report and understand aggregate patterns. Do not enter names or information about health or identifiable colleagues.
When you choose to share an individual result, the website creates an unguessable private link that displays the scores without optional context information. Anyone who receives that link can view the result, and the link expires after twelve months. When someone creates a team check, we store the team name, an unguessable sharing code and anonymous responses for 30 days. A combined team result is shown only after at least five responses. The organiser cannot see who responded or view individual responses through the team link. Technical security logs may still process IP addresses separately to prevent abuse.
Administration accounts
For authorised editors, we store their name, email address, role, account status, securely hashed password and login-session information. This supports secure access and publication. Password setup links expire after 48 hours. Login sessions expire after eight hours. Disabling an account revokes its sessions.
Temporary login-attempt counters support abuse prevention. These expire after 15 minutes and are removed on subsequent login attempts. Their keys are hashed; they are not used for audience measurement.
Cookies
The application sets an essential authentication cookie only when an administrator signs in. See our cookie notice for details. We do not use optional tracking cookies.
Service providers and transfers
We use service providers for website operation, storage, security and email. Access is limited to the services they provide, and processor agreements are required where applicable. We do not sell personal information.
Before this website is launched, the final hosting providers, processing locations and retention arrangements must be confirmed. If personal information is transferred outside the EEA, the transfer must have a valid legal basis, such as an adequacy decision or the European Commission’s standard contractual clauses with any necessary supplementary measures.
Retention
We keep enquiries only for as long as they are relevant to the enquiry or business relationship. We review correspondence and delete or anonymise information when it is no longer needed. Contract, accounting or legal records may need to be retained to meet applicable legal requirements or establish, exercise or defend legal claims.
Disabled administrator accounts remain restricted records until they are removed through the operator’s retention process. Public author names and published content remain visible until edited or removed. Technical infrastructure retention depends on the final hosting configuration.
Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting the lawfulness of earlier processing.
Email privacy@teamnorso.com to exercise your rights. We may need proportionate information to verify your identity. You can complain to the Norwegian Data Protection Authority or your competent local supervisory authority.
Candidate portal and other websites
Our candidate portal has its own privacy policy. ROBUST360, ASASO and AnchorView are separate websites with their own applicable notices. Following a link takes you to that service; its content is not automatically loaded into this website.
Changes
We update this notice when our services, providers or practices change. The date above identifies this version.
Book a conversation ↗