How Arpuro Labs collects and processes personal data on arpuro.io, through sales and marketing, and in our B2B CRM.
Arpuro Labs AS
This Privacy Policy explains how Arpuro Labs AS ("Arpuro", "we", "us", "our") collects and processes personal data in connection with:
Important scope notice. This policy does not govern personal data that Arpuro processes on behalf of a customer when delivering the Arpuro platform — for example user accounts, login credentials, sensor-linked data, or any other personal data uploaded to or generated within the platform. That processing is governed by a separate Data Processing Agreement (databehandleravtale) under Article 28 GDPR, together with the applicable Service Level Agreement (SLA), entered into between Arpuro and the customer. See section 10.
Arpuro Labs AS
Org. nr: to be inserted on completion of Brønnøysund registration
Tingsakerveien 2, 4790 Lillesand
Norway
Privacy contact: post@arpuro.io
When you visit arpuro.io we may process:
Legal basis: consent for cookies and similar technologies that are not strictly necessary (Norwegian ekomloven § 2-7b and Article 6(1)(a) GDPR), and legitimate interest in operating, securing, and improving the website (Article 6(1)(f) GDPR).
Arpuro is a business-to-business company. We maintain a customer-relationship-management ("CRM") system in which we record professional contact information about individuals at:
Typical data: name, employer, job title, business email, business phone, business address, public professional profile (e.g. LinkedIn), notes from meetings, demos, and calls, email and message correspondence, quotes and offers, opportunity and pipeline status, and engagement metadata (e.g. opens, clicks).
Sources: information you provide directly (business card, demo request, signup form, conversation); publicly available business sources (company websites, LinkedIn, Brønnøysundregistrene, the trade press, conference attendee lists); information disclosed by third parties acting on behalf of you or your employer (for example a colleague making an introduction); and our own meeting and communication records.
Legal basis: legitimate interest under Article 6(1)(f) GDPR. Our legitimate interest is to identify, contact, and maintain relationships with relevant professionals on matters reasonably relevant to their work role, to manage our pipeline and accounts, and to keep records necessary for our business.
We have performed a balancing test (interesseavveining) and concluded that the processing does not override the rights and freedoms of the data subjects, because:
Direct marketing communications by email and phone to business contacts about products and services reasonably relevant to your work role are made on the basis of legitimate interest and in accordance with the Norwegian Marketing Control Act (markedsføringsloven) § 15, which permits such communications in the context of an existing or prospective business relationship subject to a clear opt-out mechanism.
We process personal data to:
We use third-party tools and service providers in the following categories. A current, detailed list of subprocessors is available on request.
All processors are bound by a written data processing agreement under Article 28 GDPR. Where data is transferred outside the EU/EEA, we rely on adequacy decisions or the EU Commission's Standard Contractual Clauses (SCCs), supplemented by additional safeguards (technical, contractual, or organisational) where required by the transfer impact assessment.
We may also disclose personal data to public authorities, courts, or counterparties where we are required to do so by law or where it is necessary to establish, exercise, or defend legal claims.
We do not sell personal data.
We keep personal data only as long as necessary for the purpose for which it was collected:
Under the GDPR you have the right to:
To exercise your rights — including asking us to remove you from our CRM or marketing lists — write to post@arpuro.io. We will respond within one month and may extend that period by two further months for complex requests, in which case we will notify you.
Every marketing email we send contains a one-click unsubscribe link.
We apply administrative, technical, and physical safeguards appropriate to the risk, including access controls, least-privilege principles, encryption in transit, audit logging, secure software development practices, and vendor due diligence. We will notify affected parties and Datatilsynet of personal data breaches in accordance with Articles 33 and 34 GDPR.
When Arpuro processes personal data on behalf of a customer as part of providing the Arpuro platform or related services, Arpuro acts as a data processor and the customer is the controller. Such processing is governed by:
These agreements set out the purposes, instructions, subprocessors, security measures, audit rights, breach notification, retention, deletion, and assistance obligations that apply to customer personal data. This Privacy Policy does not extend or modify those agreements.
If you are an end-user of the Arpuro platform and want to exercise your rights regarding data in the platform, please contact your employer (the controller) or your employer's privacy contact in the first instance. We will assist the controller in responding.
Our website and services are directed at businesses and professionals. We do not knowingly collect personal data from children.
We may update this Privacy Policy from time to time. The current version is always available at arpuro.io. Material changes will be communicated via the website or by direct notice where appropriate. The "Last updated" date at the top reflects the most recent revision.
Arpuro Labs AS
post@arpuro.io
See also: Cookie Policy.
Last updated 15 May 2026.