Legal
Privacy Policy
Last updated 21 August 2026
This Privacy Policy explains how Newcode.ai AS (“we”, “us” or “our”) collects and uses personal data when you visit newcode.ai or contact us through our website.
We are headquartered in Norway and have offices in Sweden, Ireland and the United States. We process personal data in accordance with the EU General Data Protection Regulation (“GDPR”), as incorporated into the European Economic Area, the Norwegian Personal Data Act and, where applicable, Norwegian rules on cookies and electronic communications.
1. Who is responsible for your personal data?
The data controller for the processing described in this Privacy Policy is:
Newcode.ai AS; Organisation number: 933 866 513; Registered address: Dokkveien 1, 0250 Oslo, Norway; Email: support@newcode.ai
Our offices and affiliated companies may assist us in responding to enquiries. If a different group company is responsible for a particular interaction, we will inform you where appropriate.
2. What personal data do we collect?
Information you provide
When you use our contact form or contact us by email, we may collect:
- your name;
- your email address and phone number contact details;
- your company and job title, if provided;
- the contents of your message; and
- any other information you choose to provide.
Please do not submit sensitive personal data, special category data or confidential information through the contact form unless it is necessary and we have asked you to provide it. If you do provide such information, we will process it only where we have a lawful basis under GDPR Article 6 and, where required, an applicable condition under GDPR Article 9.
Information collected when you visit the website
Our website and its hosting or security providers may automatically process limited technical information, such as:
- your IP address;
- browser and device type;
- date and time of access;
- pages requested;
- referring website; and
- security and diagnostic logs.
We use this information to deliver the website, maintain its security and reliability, diagnose technical problems and prevent misuse.
3. Why do we use your personal data?
Where we rely on Article 6(1)(f) GDPR, we consider whether the processing is necessary for our legitimate interests and whether your rights and interests override those interests.
We do not use information submitted through the contact form to send marketing communications unless you have requested them or we otherwise have a lawful basis and any required consent to do so. You can withdraw marketing consent or unsubscribe at any time.
The following table summarises the purposes of processing and the corresponding legal bases:
| Purpose | Legal basis |
|---|---|
| To receive, review and respond to your enquiry | Article 6(1)(f) GDPR – our legitimate interest in communicating with people who contact us |
| To take steps you request before entering into a contract | Article 6(1)(b) GDPR – taking steps at your request before entering into a contract; or Article 6(1)(f) GDPR where the enquiry is made in a business capacity |
| To operate, secure and troubleshoot our website | Article 6(1)(f) GDPR – our legitimate interest in providing a secure and reliable website |
| To maintain appropriate business and compliance records | Article 6(1)(c) GDPR – compliance with legal obligations; and Article 6(1)(f) GDPR – our legitimate interest in maintaining appropriate business records |
| To establish, exercise or defend legal claims | Article 6(1)(f) GDPR – our legitimate interest in protecting our legal rights |
| To send marketing communications, where permitted and if we offer them | Article 6(1)(a) GDPR – consent; or Article 6(1)(f) GDPR – our legitimate interest in direct marketing where permitted without consent under applicable law |
4. Who receives your personal data?
We may share personal data, where necessary, with:
- our personnel and offices in Norway, Sweden, Ireland and the United States;
- security and support providers;
- professional advisers, such as lawyers, accountants and auditors, if you become a customer of Newcode; and
- public authorities, courts or regulators where required by law
Service providers may process personal data only for the agreed purposes and under appropriate contractual and confidentiality obligations.
We do not sell personal data.
5. International transfers
Some recipients or service providers may be located outside the European Economic Area (“EEA”), including in the United States.
When personal data is transferred outside the EEA, we use a legally recognised transfer mechanism where required. This may include:
- a European Commission adequacy decision;
- the EU Standard Contractual Clauses, together with any necessary supplementary safeguards; or
- another transfer mechanism permitted under applicable data protection law.
You may contact us at support@newcode.ai for further information about the safeguards used for international transfers under Articles 45 and 46 of the GDPR, including how to obtain a copy of the relevant safeguards. We may redact commercially confidential information from any copy provided.
6. How long do we keep personal data?
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including to meet legal obligations, resolve disputes, enforce agreements and maintain appropriate business records.
As a general rule:
- contact-form submissions and related correspondence are ordinarily retained for up to 12 months after the enquiry is closed;
- information relating to an actual or potential contractual relationship may be retained for the duration of that relationship and for the period required by applicable limitation, accounting and record-keeping rules; and
- technical and security logs are ordinarily retained for up to 90 days, unless they are needed for investigating a security incident or complying with a legal obligation.
We may retain information for longer where required by law or where necessary to establish, exercise or defend legal claims. Personal data will then be deleted or anonymised when it is no longer required.
7. Your rights
Subject to the conditions and exceptions in applicable law, you may have the right to:
- request access to your personal data (Article 15 GDPR);
- ask us to correct inaccurate or incomplete personal data (Article 16 GDPR);
- ask us to delete your personal data (Article 17 GDPR);
- ask us to restrict how we use your personal data (Article 18 GDPR);
- object to processing based on our legitimate interests (Article 21 GDPR);
- receive certain personal data in a portable format (Article 20 GDPR);
- withdraw your consent at any time, where processing is based on consent (Article 7(3) GDPR); and
- complain to a data protection authority (Article 77 GDPR).
Withdrawing consent does not affect processing carried out before the withdrawal.
To exercise your rights, contact us through the contact form on our website, via email at support@newcode.ai or by post at Newcode.ai AS, Dokkveien 1, 0250 Oslo, Norway. We may ask for information reasonably necessary to confirm your identity and to process your request. We will respond within the period required by applicable law.
You may lodge a complaint with the data protection authority in the country where you live or work, or where you believe a violation occurred. Our Norwegian supervisory authority is:
Datatilsynet (Norwegian Data Protection Authority) — https://www.datatilsynet.no/
We encourage you to contact us first so that we can try to address your concern directly.
9. Security
We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction.
No website or method of electronic communication is completely secure. You should therefore avoid sending sensitive or confidential information through the contact form unless necessary.
10. Children
Our website is intended for business and general informational purposes and is not directed at children. We do not knowingly collect personal data from children through the website.
If you believe that a child has provided us with personal data, please contact us so that we can take appropriate action.
11. Automated decision-making
We do not use personal data collected through this website to make decisions based solely on automated processing that produce legal or similarly significant effects under the GDPR.
12. External websites
Our website may contain links to websites operated by third parties. We are not responsible for their privacy practices. You should review the privacy policy of any third-party website you visit.
13. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to our website, business practices or legal obligations. The current version will be published on this page, with the “Last updated” date shown below.
If a change materially affects how we use personal data, we will provide additional notice where required by law.
14. Contact us
For questions about this Privacy Policy or our use of personal data, contact:
Newcode.ai AS; Dokkveien 1, 0250 Oslo, Norway; Email: support@newcode.ai