Privacy Notice

1. Introduction

This privacy notice applies to Visense AS (company registration no. 933 913 406), hereinafter “Visense”, "we" or "us", a wholly owned subsidiary of VIS Forsikring Gjensidig (company registration no. 954 662 764).

The privacy notice describes how Visense processes personal data in connection with our digital services, portal solutions, websites, customer follow-up and other business activities. It primarily applies where Visense processes personal data as data controller, but also addresses instances where Visense processes personal data as a data processor on behalf of our customers.

Visense provides digital platform services to housing associations, tradesmen's firms, insurance companies, damage restoration companies, businesses and private individuals. Our role under data protection law varies depending on which service is provided, to whom the service is provided, and for what purpose the personal data is processed.

1.1 Visense as data controller

Visense is the data controller when we determine the purpose and means of the processing of personal data. This applies, among other things, when we process personal data for our own purposes, for example in connection with customer relationship administration, sales and contract follow-up, support, operations and product development, system security, marketing where relevant, website operation, recruitment, and where we provide services directly to private individuals.

1.2 Visense as data processor

Visense is the data processor when we process personal data on behalf of a customer who is the data controller. This may, for example, be businesses, housing cooperatives/associations, tradesmen's firms or other data controller customers. In such cases, it is the customer who determines the purpose of the processing, and we process personal data in accordance with instructions from the customer and in accordance with the data processing agreement entered into with the customer.

When Visense is the data processor, it is the customer who determines the purpose of the processing, the legal basis and how long the data will be stored. If you have questions about processing that takes place in a service provided on behalf of a customer, or wish to exercise your rights under data protection law, you should as a starting point contact the relevant customer. Visense will assist the customer in handling such requests where relevant.

This privacy notice is structured so that sections 2–8 describe Visense's general processing of personal data as data controller. Section 9 contains service-specific descriptions for the various portal solutions, including information on the allocation of roles, categories of personal data and who the data subjects are.

Contact information for privacy-related questions:

Visense AS, P.O. Box 416 Sentrum, 0103 Oslo, Norway

E-mail: kontakt@visense.no

2. What do we use personal data for?

Visense only processes personal data to the extent necessary for the relevant purpose. Below we describe the most important instances where Visense processes personal data as data controller.

2.1 Administration of customer relationships, agreements and user profiles

We process personal data to administer customer relationships, manage agreements, follow up customers and partners, identify users, and administer user profiles and access rights.

The personal data processed for this purpose may include name, address, e-mail address, telephone number, company affiliation, role or position, login information, role and access levels, technical logs, invoicing information, building number or other building/property information where this can be linked to you or your customer relationship, as well as information appearing from communications with us.

The processing takes place on the basis of our legitimate interest in administering user profiles, following up customer relationships and administering our services, cf. GDPR Article 6(1)(f). Where the processing is necessary to perform an agreement directly with you, the processing may also take place on the basis of GDPR Article 6(1)(b).

2.2 Operation, maintenance and security of our services

We process personal data in order to provide, operate, maintain and secure our digital services and portal solutions. This includes, among other things, processing necessary for the services to function technically, to fix errors, ensure stable operation, administer functionality and protect the services against misuse, unauthorised access and security incidents.

The personal data processed for this purpose may include contact information, user and access information, technical logs, IP address, device information, information on use of the services, event logs and other information appearing from communications or activity within the services.

The processing takes place on the basis of our legitimate interest in providing, operating, maintaining and securing our services, cf. GDPR Article 6(1)(f).

2.3 Customer service, support and incident handling

We process personal data in order to respond to enquiries, provide customer service and support, handle errors, follow up users and prevent misuse or unauthorised use of the services.

The personal data processed for this purpose may include contact information, user and access information, information on your use of the service, technical logs and information appearing from enquiries or other communications with us.

The processing takes place on the basis of our legitimate interest in providing support, securing the services, preventing misuse and handling enquiries from users, cf. GDPR Article 6(1)(f).

2.4 Analysis, statistics and product development

We process personal data when we carry out analyses and prepare statistics and reports in order to improve our digital services, system platforms and user experience.

The personal data processed for this purpose may include technical logs, usage data, information on activity in the portals, access data, building/property information where this can be linked to an identifiable person, and other information showing how the services are used. Where possible, analyses, statistics and reports will be based on aggregated and anonymised data.

We use Plausible Analytics to understand how our websites and portal solutions are used, so that we can improve the services. Plausible is a privacy-friendly analytics tool that does not use cookies, and which is designed to provide statistics without identifying individuals. The data we receive is aggregated and may include, among other things, the number of page views, referral sources, approximate geographic location based on IP address without the IP address being stored, and the type of device used. All data is stored within the EU. You can read more about how Plausible handles data in their data policy: plausible.io/data-policy.

The processing takes place on the basis of our legitimate interest in developing and improving our products and offering good and functional services, cf. GDPR Article 6(1)(f). If we use analytics tools that involve the use of cookies or similar technology that is not strictly necessary, this will be handled in accordance with applicable requirements for information and consent. See further under section 6.

2.5 Marketing

Visense may send marketing communications to existing customers about similar services, or based on obtained consent. Where marketing is sent on the basis of an existing customer relationship, you will always be given the opportunity to opt out of further marketing. Marketing communications do not include practical or necessary information directly related to your use of our services.

Where marketing takes place on the basis of consent, the consent will be voluntary, informed and active. You can withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing that took place before the consent was withdrawn.

The legal basis is legitimate interest where the marketing is directed at existing customers regarding similar services, cf. GDPR Article 6(1)(f), or consent where this is required or has been obtained, cf. GDPR Article 6(1)(a) and Section 15 of the Norwegian Marketing Control Act.

2.6 Recruitment

We process personal data if you apply for a job at Visense, or otherwise participate in a recruitment process with us. The purpose is to assess your application, carry out the recruitment process and, where relevant, enter into an employment contract.

The personal data processed for this purpose may include name, contact information, CV, application, diplomas, certificates, information from interviews, references and other information you provide to us or which is necessary to assess your application.

The processing generally takes place because it is necessary to take steps prior to entering into a possible employment contract, cf. GDPR Article 6(1)(b). Where we carry out our own investigations, for example obtaining references or verifying information, the processing takes place on the basis of our legitimate interest in finding the right candidate for the position, cf. GDPR Article 6(1)(f).

To the extent special categories of personal data, such as health information or other information referred to in GDPR Article 9(1), appear from the application or documentation you send us, we will only process such data where and to the extent this is necessary and lawful under data protection law.

3. Categories of personal data

Personal data may be obtained directly from you, from the business or customer you are affiliated with, from representatives of a customer, from use of our services, or generated technically through use of websites and portal solutions.

Depending on the purpose, the following categories of personal data may be processed where Visense is the data controller:

  • Identification data: name, e-mail address and telephone number
  • Professional information: position, company affiliation and role
  • User and access information: login history, role and access levels, system events and error logs
  • Communications: e-mail correspondence relating to support, customer relationships and other dialogue with us.
  • Payment and invoicing information: invoice address and references (not payment card data)
  • Technical information: IP address, device information, technical logs and information on use of our websites and services.
  • Building/property information, where such information can be linked to you or your customer relationship.
  • Free text, images, attachments or other documentation entered into the services, where such functionality is used and the information can be linked to an identifiable person.

As a general rule, Visense does not process special categories of personal data (sensitive data), cf. GDPR Article 9. If such data is nonetheless processed, this only takes place where and to the extent the processing is necessary and has a valid legal basis under data protection law.

4. Disclosure of personal data

4.1 Disclosure to sub-suppliers (data processors)

When Visense is the data controller, we use sub-suppliers and service providers who process personal data on our behalf.

This may, for example, be providers of operations, hosting, support, security, analytics, e-mail dispatch, payment solutions or other technical services. A data processing agreement in accordance with GDPR Article 28 has been entered into with all such providers.

We only share personal data where this is necessary for the purposes described in this privacy notice. If you would like an overview of our data processors, you can contact us at kontakt@visense.no

4.2 Disclosure to third-party data controllers

If Visense shares personal data with third parties who are themselves data controllers, this only takes place where there is a valid legal basis, for example agreement, legal obligation, consent or legitimate interest.

This may, for example, be disclosure to VIS Forsikring, agents, partners or other third parties where they process personal data for their own purposes.

In the case of systematic sharing of personal data between independent data controllers, the sharing will be regulated in a data transfer agreement or corresponding contractual arrangement.

4.3 Disclosure where Visense is the data processor

When Visense processes personal data as a data processor for a customer, we share information in accordance with the instructions and data processing agreement with the customer. This may, for example, include sharing with the customer's representatives, sub-processors or other relevant parties that the customer has instructed us to share information with.

Visense may also use sub-processors to provide and operate the services. Such sharing takes place in accordance with the data processing agreement with the customer and the overview of approved sub-processors.

4.4 Transfer to third countries

If personal data is transferred to countries outside the EU/EEA, Visense will ensure that the transfer takes place in accordance with GDPR Chapter V, including through the use of the European Commission's standard contractual clauses (SCC), an adequacy decision or another lawful transfer mechanism.

5. Storage and deletion

Visense does not store personal data for longer than necessary for the purpose of the processing or to comply with statutory requirements.

  • Personal data processed on the basis of consent is deleted when the consent is withdrawn, unless we have another lawful basis for further processing.
  • Personal data related to contractual relationships is deleted when the agreement has ended and all statutory obligations have been fulfilled, including any retention requirements under accounting legislation.
  • Technical log data is deleted after 3 months, unless it is necessary to store the data for longer in order to handle security incidents, errors or legal claims.
  • Data processed by Visense as data processor is deleted or returned to the data controller in accordance with instructions and the applicable data processing agreement.
  • Applications and other information from recruitment processes are normally stored for up to 6 months after the recruitment process has ended. Further storage may take place on the basis of our legitimate interest where necessary to establish, exercise or defend a legal claim, cf. GDPR Article 6(1)(f), or where you have consented to further storage, cf. GDPR Article 6(1)(a).

6. Cookies

Visense may use cookies in our portal solutions and at www.visense.no. The use of cookies may vary between the different services.

Cookies are small text files that are placed on your device when you open a website or application. Some cookies are necessary for the services to function, for example for login, session management and language settings.

Necessary cookies are used on the basis of our legitimate interest in providing a functional and secure service, cf. GDPR Article 6(1)(f). This may include cookies required for the services to function, including login sessions and language settings. Storage of, or access to, information on the user's device is additionally subject to the requirements of the Electronic Communications Act.

If we use cookies or similar technology that is not strictly necessary, for example for marketing purposes, this will be based on consent where required. You can withdraw your consent at any time.

You can read more about which cookies we use, why they are used, and how you can manage them in our cookie policy here.

7. Security

Visense implements technical and organisational measures to ensure a level of security appropriate to the risk, including access control, encryption in transit and at rest, and procedures for handling security breaches. We limit access to personal data to personnel and third parties who need access to perform their tasks. These are subject to a duty of confidentiality.

If a personal data breach occurs that entails a risk to data subjects, Visense will notify the Norwegian Data Protection Authority without undue delay and no later than 72 hours after becoming aware of the breach, cf. GDPR Article 33. If the breach entails a high risk to data subjects, they will also be notified directly.

When Visense processes personal data as a data processor, we safeguard security in accordance with the data processing agreement and instructions from the data controller. All sub-suppliers that process personal data on behalf of Visense are bound by a duty of confidentiality and a data processing agreement. In the event of a personal data breach, Visense, as data processor, will notify the data controller without undue delay after becoming aware of the breach, so that the data controller can assess whether to notify the Norwegian Data Protection Authority and the data subjects.

8. Your rights

As a data subject, you have rights under the GDPR. Below we describe how these can be exercised vis-à-vis Visense where Visense is the data controller for the processing. The rights may be subject to limitations or exceptions under applicable data protection law or other legislation.

8.1 Access

You have the right to obtain confirmation as to whether Visense processes personal data about you, and if so, access to that data, cf. GDPR Article 15.

8.2 Rectification

You have the right to have inaccurate data corrected, cf. GDPR Article 16.

8.3 Erasure

In certain cases, you can request that data about you be deleted, cf. GDPR Article 17. This right does not apply if Visense has a lawful basis for continuing the processing.

8.4 Restriction of processing

In certain cases, you can request that the processing of your personal data be restricted, cf. GDPR Article 18.

8.5 Data portability

For data you have provided to us, which is processed automatically on the basis of an agreement or consent, you can request that it be provided to you or transferred to another provider in a structured, commonly used and machine-readable format, cf. GDPR Article 20.

8.6 Right to object

You have the right to object to processing based on legitimate interest, cf. GDPR Article 21.

8.7 Withdrawal of consent

Where processing is based on your consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing that took place before the withdrawal.

8.8 Right to lodge a complaint

If you believe Visense is processing personal data in breach of applicable law, you have the right to lodge a complaint with the Norwegian Data Protection Authority (datatilsynet.no).

Requests regarding rights should be directed to kontakt@visense.no. We will respond to requests free of charge and within 30 days. In the case of complex or numerous requests, the deadline may be extended by a further two months, cf. GDPR Article 12(3). In that case, you will receive notice of the extension within the initial deadline.

Please note: If you are a user of a service where a housing association, a business or another data controller is the data controller, you should first contact them to exercise rights relating to that processing. Visense will assist the customer in handling the request where relevant.

9. Service descriptions

Visense is generally the data processor for the processing activities in connection with the delivery of our services. VIS Forsikring and any agents may also act as sub-processors where they actually process personal data on behalf of Visense in connection with the service.

Where Visense processes personal data for its own purposes, Visense may act as an independent data controller for such processing. Analysis for Visense's own purposes shall, as far as possible, be based on anonymised or aggregated data. See further under section 2.

Below is a description of the privacy-related aspects of each individual service provided by Visense.

9.1 "Bygårdsportalen" and related services

"Bygårdsportalen" is a portal for board members and residents in housing cooperatives and associations, with functionality for, among other things, health and safety (HSE), maintenance tasks, resident follow-up, and the distribution and completion of the Home Check.

The Home Check is a digital tool that helps fulfil the shared responsibility for health and safety in the building, by having residents in housing cooperatives/associations answer questions about their flat relating to fire safety, electrical installations, heating appliances, kitchens and wet rooms, with the aim of identifying and preventing damage.

The Inspection Portal is a service linked to "Bygårdsportalen" and is used by tradesmen and electricians to carry out inspections in buildings and residential blocks. The Inspection Portal is also used by the board/users of the "Bygårdsportalen" to carry out self-inspections, in which questions relating to the building are answered.

9.1.1 Visense's role in the processing

Visense acts as data processor and processes personal data on behalf of the housing association in accordance with the data processing agreement.

The housing cooperative/association, represented by the board, is normally the data controller for the processing of personal data about board members and residents in the portal, and for the completion of "Bosjekken" and the use of the results of residents' answers in "Bosjekken". The specific purpose of the processing, the legal basis and how long the data is stored when Visense acts as data processor are determined by the housing association as data controller.

The board does not have access to the individual resident's answers in "Bosjekken", but only receives access to an aggregated and anonymised risk overview for the building. Visense nonetheless processes information at the flat level to the extent necessary to collect answers, operate the service, generate the aggregated risk overview and handle technical operations and troubleshooting.

The tradesman's/electrician's firm is the data controller for its own employees and partners, and for processing carried out for its own purposes.

9.1.2 Who, and which personal data, Visense processes

When Visense acts as data processor for the housing association, Visense may process personal data about board members, the chair of the board, the property manager, tradesmen/electricians engaged for the assignment, residents and any other persons affiliated with the housing association. This may include:

  • Contact information about users: name, address, e-mail address, telephone number, role/position (for board members), affiliated company (for electricians/tradesmen), building and flat affiliation (building number/flat number and other building/property information where this can be linked to an identifiable person), and any electrical certification information (for electricians).
  • User data, login information, technical logs, timestamps and access logs.
  • Communications and activity in the portal.
  • Information entered by the board or other users in the portal.
  • Any free text fields, images, attachments or other information entered by the resident in “Bosjekken”, where such functionality is used.
  • Inspection reports, images and observations from the assignment
  • Contact information for the assignment and the association: name, telephone number and role
  • Building address, building number, cadastral data, the association's name, company registration number, property manager, registered title holder and property information.

9.2 Visense Skade

Visense Skade is a sensor-based monitoring service for moisture control in wood and concrete, with wireless IoT sensors, a real-time dashboard and automated documentation supporting damage restoration processes.

9.2.1 Visense's role in the processing

Visense is the data processor when Visense provides and operates the solution on behalf of businesses. The business subscribing to Visense Skade (e.g. the damage restoration company) is the data controller for the processing of personal data in connection with use of the portal.

9.2.2 Who, and which personal data, Visense processes

When Visense acts as data processor for businesses, Visense may process personal data about employees and users of the subscribing business, the business's customers, and any other persons involved in the damage follow-up (e.g. affected owners or tenants). This may include:

  • User profile for portal access: name, e-mail address and role
  • Damage address and property information
  • Sensor and measurement data related to specific damage cases
  • Reports and documentation from the drying process
  • Technical information, logs and activity data in the portal
  • Any free text fields, images, attachments, reports or other documentation entered in connection with the damage case, where the information can be linked to an identifiable person.

10. Updates to the privacy notice

Visense will update this privacy notice in the event of changes to our services, our use of sub-suppliers, or applicable law. If we make material changes to how we process personal data, we will notify you in an appropriate manner. Minor changes, linguistic clarifications or clarifications of existing processing activities will normally not be separately notified.

The updated version is always available at www.visense.no and upon login to the relevant portal.

This privacy notice was last updated: September 2026.