Legal

Privacy Policy

How Arpuro Labs collects and processes personal data on arpuro.io, through sales and marketing, and in our B2B CRM.

Arpuro Labs AS

1. About this policy

This Privacy Policy explains how Arpuro Labs AS ("Arpuro", "we", "us", "our") collects and processes personal data in connection with:

  • our website at arpuro.io and any subdomains;
  • our sales, marketing, and communication activities; and
  • our records of business contacts at current, prospective, and partner organisations.

Important scope notice. This policy does not govern personal data that Arpuro processes on behalf of a customer when delivering the Arpuro platform — for example user accounts, login credentials, sensor-linked data, or any other personal data uploaded to or generated within the platform. That processing is governed by a separate Data Processing Agreement (databehandleravtale) under Article 28 GDPR, together with the applicable Service Level Agreement (SLA), entered into between Arpuro and the customer. See section 10.

2. Controller

Arpuro Labs AS
Org. nr: to be inserted on completion of Brønnøysund registration
Tingsakerveien 2, 4790 Lillesand
Norway
Privacy contact: post@arpuro.io

3. What we collect from website visitors

When you visit arpuro.io we may process:

  • Technical data such as IP address (truncated where feasible), browser type and version, device type, operating system, referring URL, language, and timestamps.
  • Usage data such as pages viewed, time spent, clicks, scroll depth, downloads, search queries on the site, and session identifiers.
  • Information you submit through forms, including your name, business email, phone number, employer, job title, country, and the content of your message.

Legal basis: consent for cookies and similar technologies that are not strictly necessary (Norwegian ekomloven § 2-7b and Article 6(1)(a) GDPR), and legitimate interest in operating, securing, and improving the website (Article 6(1)(f) GDPR).

4. What we collect about business contacts (B2B CRM)

Arpuro is a business-to-business company. We maintain a customer-relationship-management ("CRM") system in which we record professional contact information about individuals at:

  • existing customers and partners;
  • prospective customers (leads); and
  • public and private organisations that we have reason to believe have a legitimate professional interest in our products and services (for example HSE managers, plant managers, technical buyers, and procurement contacts at industrial sites).

Typical data: name, employer, job title, business email, business phone, business address, public professional profile (e.g. LinkedIn), notes from meetings, demos, and calls, email and message correspondence, quotes and offers, opportunity and pipeline status, and engagement metadata (e.g. opens, clicks).

Sources: information you provide directly (business card, demo request, signup form, conversation); publicly available business sources (company websites, LinkedIn, Brønnøysundregistrene, the trade press, conference attendee lists); information disclosed by third parties acting on behalf of you or your employer (for example a colleague making an introduction); and our own meeting and communication records.

Legal basis: legitimate interest under Article 6(1)(f) GDPR. Our legitimate interest is to identify, contact, and maintain relationships with relevant professionals on matters reasonably relevant to their work role, to manage our pipeline and accounts, and to keep records necessary for our business.

We have performed a balancing test (interesseavveining) and concluded that the processing does not override the rights and freedoms of the data subjects, because:

  • the data is limited to professional contact information and a person's professional role;
  • the processing takes place in the context of a person's employment, not their private life;
  • such processing is foreseeable in a B2B sales and account-management context;
  • you may object to the processing and unsubscribe from marketing at any time and we will respect such requests promptly.

Direct marketing communications by email and phone to business contacts about products and services reasonably relevant to your work role are made on the basis of legitimate interest and in accordance with the Norwegian Marketing Control Act (markedsføringsloven) § 15, which permits such communications in the context of an existing or prospective business relationship subject to a clear opt-out mechanism.

5. Why we process personal data

We process personal data to:

  • operate, secure, analyse, and improve our website and digital channels;
  • respond to enquiries and requests for demos, quotes, or information;
  • manage and develop B2B relationships, including outreach, follow-up, account management, and after-sales communications;
  • run marketing and engagement activities, including newsletters, events, webinars, and targeted campaigns to business audiences;
  • prepare and manage contracts, orders, deliveries, support, and invoicing;
  • comply with legal obligations (e.g. bookkeeping, tax, sanctions, and product compliance);
  • defend and exercise legal rights.

6. Tools and recipients

We use third-party tools and service providers in the following categories. A current, detailed list of subprocessors is available on request.

  • Website and product analytics, including Google Analytics (Google Ireland Ltd.), Woopra (Woopra Inc.), and similar analytics or product-analytics services. See the Cookie Policy for details.
  • Marketing and engagement, including newsletter and email platforms, form builders, webinar and event tools, ad networks, retargeting pixels (e.g. LinkedIn, Google, Meta), and content-management plugins.
  • CRM and sales operations, including the CRM platform itself, sales-engagement tools, contact-enrichment providers, calendar and scheduling tools, e-signature tools, and meeting recording/transcription services.
  • Business operations, including office productivity, cloud storage and email (e.g. Google Workspace), accounting and invoicing, payment processors, and identity providers.
  • Infrastructure and security, including website and platform hosting, content-delivery networks, monitoring and observability, security tooling, and IT support.

All processors are bound by a written data processing agreement under Article 28 GDPR. Where data is transferred outside the EU/EEA, we rely on adequacy decisions or the EU Commission's Standard Contractual Clauses (SCCs), supplemented by additional safeguards (technical, contractual, or organisational) where required by the transfer impact assessment.

We may also disclose personal data to public authorities, courts, or counterparties where we are required to do so by law or where it is necessary to establish, exercise, or defend legal claims.

We do not sell personal data.

7. Retention

We keep personal data only as long as necessary for the purpose for which it was collected:

  • Website analytics data: typically up to 14 months, after which it is deleted or fully aggregated.
  • Form submissions and one-off enquiries: up to 24 months after the last contact, unless a longer period is justified by an ongoing relationship.
  • CRM records of business contacts: as long as the contact remains professionally relevant, with periodic reviews. Inactive contacts are deleted or anonymised. We may retain a minimal record (name, employer, and opt-out flag) for as long as necessary to honour an objection or unsubscribe request.
  • Contractual, accounting, and tax records: as required by Norwegian law (typically five years under bokføringsloven, longer for certain documents).
  • Security logs and backups: retained according to our security and IT policies, generally no longer than necessary.

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • request correction of inaccurate or incomplete data;
  • request deletion in certain cases;
  • request restriction of processing;
  • object to processing based on legitimate interest, including direct marketing, at any time;
  • receive your data in a portable format where applicable; and
  • lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet, www.datatilsynet.no).

To exercise your rights — including asking us to remove you from our CRM or marketing lists — write to post@arpuro.io. We will respond within one month and may extend that period by two further months for complex requests, in which case we will notify you.

Every marketing email we send contains a one-click unsubscribe link.

9. Security

We apply administrative, technical, and physical safeguards appropriate to the risk, including access controls, least-privilege principles, encryption in transit, audit logging, secure software development practices, and vendor due diligence. We will notify affected parties and Datatilsynet of personal data breaches in accordance with Articles 33 and 34 GDPR.

10. Customer personal data (separate agreement)

When Arpuro processes personal data on behalf of a customer as part of providing the Arpuro platform or related services, Arpuro acts as a data processor and the customer is the controller. Such processing is governed by:

  • a separate Data Processing Agreement (databehandleravtale) under Article 28 GDPR; and
  • the applicable Service Level Agreement (SLA).

These agreements set out the purposes, instructions, subprocessors, security measures, audit rights, breach notification, retention, deletion, and assistance obligations that apply to customer personal data. This Privacy Policy does not extend or modify those agreements.

If you are an end-user of the Arpuro platform and want to exercise your rights regarding data in the platform, please contact your employer (the controller) or your employer's privacy contact in the first instance. We will assist the controller in responding.

11. Children

Our website and services are directed at businesses and professionals. We do not knowingly collect personal data from children.

12. Changes to this policy

We may update this Privacy Policy from time to time. The current version is always available at arpuro.io. Material changes will be communicated via the website or by direct notice where appropriate. The "Last updated" date at the top reflects the most recent revision.

13. Contact

Arpuro Labs AS
post@arpuro.io

See also: Cookie Policy.

Last updated 15 May 2026.