Privacy policy
This policy explains how Point-IT AS processes personal data in connection with point-it.no and Penny assessment services.
Last updated: 5 September 2026
Controller
Point-IT AS, organisation number 937 051 379, Norway, is controller for personal data submitted through the website and for its own customer administration.
Data we process
We may process contact and company details, order information, authorised domains and IP addresses, correspondence, billing information, technical server logs and assessment-related metadata. Assessment evidence may contain technical identifiers and, incidentally, personal data visible on authorised public services.
Purposes and legal basis
We process data to answer enquiries, take pre-contractual steps, perform and administer contracts, document authorisation and scope, protect our systems, prevent abuse, comply with legal obligations and establish or defend legal claims. Depending on the processing, the basis is contract/pre-contractual measures, legal obligation or legitimate interests.
Assessment data and roles
Where Point-IT processes personal data solely on a customer's documented instructions as part of an assessment, a data-processing agreement may be required. The parties will determine the appropriate GDPR roles based on the actual service and data involved.
Hosting and recipients
The website, mail environment and Penny infrastructure are hosted in Germany. Data may be disclosed to hosting, mail, accounting or professional advisers only where needed and under appropriate contractual and confidentiality safeguards.
Retention
We retain data only as long as necessary for the relevant purpose. Order, contract and accounting records may be retained for statutory periods. Assessment reports and technical evidence may be retained for service continuity, dispute handling and security documentation, then deleted or minimised when no longer needed.
Security
We use access controls, encrypted transport, separation of public and assessment systems and data minimisation. No internet-connected service can be guaranteed completely secure.
Your rights
Subject to applicable law, individuals may request access, correction, deletion, restriction or portability and may object to certain processing. Complaints may be made to the Norwegian Data Protection Authority or another competent EEA supervisory authority.
Cookies
The current website does not use marketing cookies or third-party behavioural analytics. Essential technical processing may be used to deliver and secure the service.
