Privacy Policy
Last updated: July 30, 2026
This policy explains what personal data Gadder processes, why we process it, who we may share it with, and what rights you have. It applies to gadder.no and the Privat and Proff services unless a separate customer agreement provides more specific terms.
We use personal data only for clear, stated purposes.
You control whether a plan is shared with suppliers or banks.
You may request access, rectification, erasure, or restriction.
1. Who is the data controller?
Gadder AS is the data controller for the processing described here. This means that we determine the purposes and means of the processing. Our contact details appear at the bottom of this page.
If a business customer uses Proff under a separate agreement, the agreement and any applicable data processing agreement may define how the roles are divided between the customer and Gadder.
2. Personal data we may process
The personal data we process depends on how you use Gadder. For standard registration in Privat, first name, last name, email address, phone number, password, and acceptance of the Terms of Use are required. We cannot create a standard account without this information. Signing in with Vipps or Google is optional. In the contact form, your name, email address, and message are required so that we can respond; company and phone number are optional. Marketing preferences are optional wherever they appear.
You must provide an address and the building information marked as required in the analysis flow so that we can calculate an energy plan. Connecting Elhub, uploading documents, using AI chat, sharing a plan, and selecting a supplier or bank are optional features. If you choose not to use one of these features, you lose only that specific additional feature.
Do not enter health data, political or religious beliefs, trade union membership, biometric or genetic data, data concerning your sex life, or other special categories of personal data in free-text fields, AI chat, drawings, or documents. Gadder does not need this information to provide its services.
- Account and contact data, such as your name, email address, phone number, company, and login information.
- Home and building data, such as address, year of construction, floor area, construction, heating, energy use, coordinates, and selected upgrades.
- Project and proposal data, such as your budget, requested upgrades, messages, and the partners from whom you request proposals.
- Payment and contract information. Payment card details are normally processed by the payment provider and are not stored by Gadder.
- Technical data, such as IP address, browser, device, security logs, and usage events.
- Content you send us through the contact form, support, a demo request, or other communications.
3. Where the data comes from
We receive most data directly from you. When you ask us to build an energy or building model, we may also retrieve data from public registers and external data sources, such as Kartverket/Geonorge, Norkart, Elhub, Hjemla, or Google Solar, depending on the feature you select.
Address searches on the Privat page are sent directly from your browser to the Norwegian Mapping Authority's address service. The Proff address search and 3D demo send requests through Gadder's servers to services that provide address data and building geometry. These providers may receive your IP address and technical request data.
4. Purposes and legal bases
We associate each processing activity with a specific purpose and a valid legal basis under the General Data Protection Regulation (GDPR).
- Creating an account and providing energy calculations, models, plans, and agreed features: necessary to enter into or perform our contract with you (Article 6(1)(b)).
- Responding to contact forms, support requests, and demo requests: performance of a contract or our legitimate interest in following up on inquiries (Article 6(1)(b) or (f)).
- Sharing a plan with suppliers, energy advisors, or banks: your freely given consent (Article 6(1)(a)). You may withdraw your consent.
- Payments, accounting, and documentation: performance of a contract and compliance with legal obligations (Article 6(1)(b) and (c)).
- Security, troubleshooting, and abuse prevention: our legitimate interest in secure and stable operations (Article 6(1)(f)).
- Newsletters or other electronic marketing: consent where required (Article 6(1)(a)).
- Counting visits to gadder.no without storing anything on your device: our legitimate interest in knowing how many people use the site (Article 6(1)(f)). The identifier is derived by PostHog as an irreversible hash of a daily salt, your IP address, your browser string and the hostname. The salt is deleted each day, after which the figures cannot be linked back to you, not even by us.
- Recognising you between visits to gadder.no, so we can see how many people return: your freely given consent (Article 6(1)(a)). This is only set if you choose “Accept analytics”, and can be withdrawn from “Privacy choices” in the footer.
5. AI features and uploaded documents
When you use AI chat, document analysis, floor plan analysis, or image generation, the content you choose to use is sent to the configured AI and workflow service together with the necessary home or building context. Privat uses n8n for AI chat, among other services. Privat and Proff may use Microsoft Azure OpenAI/Azure AI Foundry, and, depending on its configuration, Proff may use an Anthropic model through Azure AI Foundry or Google Gemini.
The purpose is to provide the analysis or response you request. The legal basis is performance of a contract under Article 6(1)(b), or Gadder's legitimate interest in providing a feature to a business customer under Article 6(1)(f). AI outputs are suggestions and decision support; they are not used on their own to make decisions that produce legal effects or similarly significantly affect you.
We do not allow Gadder's own data to be used to train a provider's general-purpose models without a separate assessment and notice to the affected data subjects. Only upload documents that you have the right to use, and remove names, contact details, and other personal data that is not necessary for the analysis.
6. Sharing with others
We do not sell personal data. We may give limited access to service providers that support our operations, email, customer support, payments, data storage, analytics, and security. They may process personal data only on our instructions and under a data processing agreement where required.
Potential recipients include Microsoft Azure (hosting, storage, and AI), Twilio SendGrid and Resend (email and contact forms), n8n (AI chat and workflows), PostHog (consent-based website and product analytics), Vipps MobilePay (payments and optional login), and Google (optional login, Solar data, and Gemini where configured). Address and building features may use Kartverket/Geonorge, Norkart, Hjemla/Boligmappa, Elhub, Metria, and Gadder's Proff service. Data is shared only with the providers required for the feature you select.
We share information about you and your home with energy advisors, suppliers, or banks only when you actively request it or when sharing is necessary to perform a contract you have entered into. We may also disclose data when required by law or a valid order from a public authority.
7. Transfers outside the EU/EEA
Some technology providers may process data outside the EU/EEA. For these transfers, we use a valid transfer mechanism, such as the EU Standard Contractual Clauses, an adequacy decision, or the EU–U.S. Data Privacy Framework where the recipient is certified. Contact us for more information about the safeguards that apply.
8. How long we retain data
We retain data for as long as necessary for its purpose and then delete or anonymize it. A deletion request in Privat is processed automatically unless handled manually. Identifying home and account data is anonymized or deleted, while certain non-identifying statistical data may be retained. Backups are overwritten according to the normal rotation schedule and are not used for other purposes in the meantime.
Legal requirements, disputes, security needs, and documentation of contracts and consent may require us to retain certain data longer. The periods below apply to production data; provider backups may have a short, separate overwrite period.
- Account and project data: while the account or customer agreement remains active. In Privat, identifying production data is deleted or anonymized when a deletion request is completed. Proff projects are deleted on the customer's instructions or according to the agreed termination procedure.
- AI and abuse logs in Privat: token and usage logs for 90 days and abuse logs for 180 days. Human-to-human chat and message requests in Privat are deleted after 365 days. AI chat is also processed in n8n; its specific retention period follows Gadder's active n8n configuration.
- Proff logs under the configured cleanup schedule: usage and audit logs for 90 days, AI usage logs for 365 days, abuse logs for 180 days, and login sessions for 90 days. These periods assume that the cleanup job runs as scheduled.
- Contact forms and sales correspondence: while we follow up on the inquiry, and normally no longer than 24 months after the last contact.
- Contact form abuse protection: a process-local, keyed hash of the network address is used only for short-term rate limiting. The counter normally expires after ten minutes, and this solution does not log the raw network address.
- Security and operational logs in Privat: activity logs for 90 days and audit logs for 365 days. Raw logs on the hosting platform follow the operational logging configuration and may be retained longer in response to a specific security incident.
- Accounting, transaction, and documentation data: for as long as required by bookkeeping rules, statutes of limitation, and other applicable laws. When this data must be retained after account deletion, payment history is anonymized in relation to the account.
9. Analytics, cookies, and automation
The gadder.no marketing website, default without consent: Your visit is counted, including when you choose “Necessary only”. The counting stores nothing in your browser: no cookies, no local storage, no session storage. Instead PostHog derives an identifier on its own server as an irreversible hash of a daily salt, your IP address, your browser string and the hostname. The salt is deleted each day, after which the figures cannot be linked back to you. The price of that anonymity is that the same visitor is counted again the next day. Before transmission a page view is limited to the site address without query parameters or fragment, the path, the host and the referring domain. GeoIP enrichment, person profiles, session recording, automatic click events and custom events for forms, address selection or demos are all disabled. The IP address is used only in the hash computation and is not stored as an event property.
The gadder.no marketing website, if you choose “Accept analytics”: PostHog additionally sets a cookie that recognises your browser between visits, so we can see how many people return rather than only how many came by each day. You can return to the storage-free counting at any time by choosing “Necessary only” under “Privacy choices” in the footer. The cookie is then removed.
The product applications (Privat and Proff) are a separate setup, distinct from the marketing website. The product applications may use necessary storage for login and security. If analytics tools use cookies or similar technology, they are activated only after valid consent. See the separate Cookie Policy.
Energy calculations and recommendations are generated automatically from available data and technical models. They provide decision support and do not constitute a solely automated decision that produces legal effects or similarly significantly affects you. Banks, suppliers, and advisors make their own assessments.
10. Your rights
Contact us to exercise your rights. We may request information needed to verify your identity. Statutory exceptions may apply.
- Access to the personal data we hold about you and information about how we use it.
- Rectification of inaccurate or incomplete personal data.
- Erasure or restriction of processing when the applicable conditions are met.
- Data portability for personal data processed automatically on the basis of consent or a contract.
- Objection to processing based on legitimate interests.
- Withdrawal of consent, without affecting the lawfulness of processing carried out before withdrawal.
- The right to lodge a complaint with the Norwegian Data Protection Authority if you believe that the processing violates data protection law.
11. Security and children
We use technical and organizational measures to protect personal data against unauthorized access, alteration, loss, and misuse. Access is limited to people and service providers that need it.
The services are not intended for children under 16. Contact us if you believe that a child has provided personal data without a valid legal basis.
12. Changes
We update this policy when our processing activities or applicable rules change. The date at the top shows the latest update. If material changes affect you, we will provide appropriate notice before they take effect.
Questions or a privacy request?
Contact us to exercise your rights or ask questions about our processing. We respond without undue delay and normally within one month.