Privacy statement
Last updated
This statement explains how Laminar AS processes personal data in the Objektor service (objektor.io, app.objektor.io and the accompanying API) and when you contact us. It follows the structure recommended by the Norwegian Data Protection Authority (Datatilsynet): the essentials first, then the details. The Norwegian version prevails if the two differ.
1. Who is responsible
Laminar AS, company registration no. 934 010 779, Storgaten 60 D, 4876 Grimstad, Norway, is the controller for the processing described in sections 3.1 and 3.5 to 3.8, and the processor for the content customers register in Objektor (sections 3.2 to 3.4).
Privacy questions can be sent to hei@laminar.no. We do not have a data protection officer, as the company is not required to appoint one.
2. Controller or processor?
Objektor is sold to organisations (the customer), who give their employees, contractors and partners access. That creates two distinct roles:
- The customer is the controller for everything registered in Objektor: assets, issues, checklists, notes, photos, locations, who did what, and who is a member of a project. The customer decides the purpose and is responsible for the registration being lawful, for example when photos show people. Laminar AS processes this data only on the customer's instructions, governed by a data processing agreement.
- Laminar AS is the controller for your user account, for enquiries to us, for operating and securing the service, and for visits to objektor.io.
If you have questions about how your organisation uses Objektor, or want access to something the organisation has registered about you, contact the organisation. We assist them in responding.
3. What data we process, and why
3.1 User account and sign-in
- Data
- Name, email address, password (stored only in hashed form by the sign-in provider Clerk; we never see the password), which organisations and projects you belong to and your role there, sign-in times, and IP address and device information in Clerk's security log.
- Source
- From you when you create an account, or from the person in the organisation who invited you.
- Purpose
- To identify you, give you access to the right organisations and projects, show who did what in the service, and protect the account against misuse.
- Legal basis
- Necessary to perform the agreement on the use of Objektor (GDPR Article 6(1)(b)). The security logs rest on our legitimate interest in securing the service (Article 6(1)(f)).
- Retention
- As long as the account is active. To delete your account, email hei@laminar.no and we delete the profile at Clerk within 30 days. The Objektor database holds only a technical user ID on history entries (for example who created an asset). Once the account is deleted, that ID can no longer be linked to you.
3.2 Content registered in Objektor
Here Laminar AS acts as processor for the customer.
- Data
- Assets with location, issues, checklists, notes, files and photos, timestamps and who created or changed something, project members with roles, assignments and notifications. Photos may show people, vehicles or private property if the customer chooses to take such photos.
- Purpose and legal basis
- Determined by the customer. Typically the purpose is to document and follow up assets and issues the customer is responsible for, based on the customer's contracts, statutory duties or legitimate interests.
- Retention
- For as long as the customer agreement runs, or until the customer deletes the content. After the agreement ends, all content is deleted within 90 days unless the customer requests earlier deletion. The customer can export its data before deletion.
3.3 Photos and location data
When you take a photo directly in Objektor, the device's GPS position, accuracy and time are stored with the photo. Position, time and project name are also stamped visibly into the image itself, so the documentation can be verified. Other hidden metadata (EXIF) is removed, the original file is not kept, and the image is re-encoded at a reduced size.
Location is read only when you grant the browser or app permission, and only at the moment you register something or ask to be shown on the map. Objektor does not track your location in the background.
3.4 Email notifications
- Data
- Your email address, the name of the issue and project, what happened and the name of the person who did it. We store the notification, whether the email was delivered, and the provider's message ID.
- Purpose
- To notify you when you are assigned an issue, when its status changes, or when someone adds a note to something you follow.
- Legal basis
- Necessary to provide the service (Article 6(1)(b)), on behalf of the customer.
- Retention
- Notifications follow your account and are deleted together with the customer's data. Emails are sent through Resend, which keeps delivery logs for a limited period under its own terms. The sender address is varsler@objektor.io.
3.5 Maps and lookups against public registers
The map in Objektor is provided by Mapbox. Your browser fetches map tiles directly from Mapbox, which therefore sees your IP address, browser information and the map area you view. Mapbox does not use this to identify you for us, and we do not have access to it. The basis is that the map is necessary to provide the service (Article 6(1)(b)).
To suggest a road reference and the nearest address for an asset, our server queries the Norwegian National Road Database (Statens vegvesen) and the Norwegian Mapping Authority's address service (Kartverket). Only the asset's coordinates are sent, no information about you.
3.6 Operations, security and logs
- Data
- IP address, time, the request made, browser type and any error messages, in the server logs of the API and websites.
- Purpose
- To operate the service, find and fix errors, and detect misuse or attacks.
- Legal basis
- Our legitimate interest in a stable and secure service (Article 6(1)(f)).
- Retention
- Logs are deleted automatically after 30 days. Database backups are taken daily and overwritten after 7 days.
3.7 Enquiries to us
- Data
- Name, email address, phone number and organisation where given, and the content of the enquiry.
- Purpose
- To respond to you, provide support, and enter into or manage customer agreements.
- Legal basis
- Contract or steps prior to a contract (Article 6(1)(b)), otherwise our legitimate interest in answering enquiries (Article 6(1)(f)).
- Retention
- Deleted when the matter is closed, at the latest after two years. Data in contracts and invoices is kept for five years under the Norwegian Bookkeeping Act.
3.8 Visits to objektor.io
The objektor.io website is static and uses no cookies, analytics or embedded third-party content. It is served through Firebase Hosting (Google), which keeps ordinary server logs with IP addresses for operations and security, see section 3.6.
4. Cookies and local storage
We only use cookies and local storage that are necessary for the service to work. These do not require consent. We use no cookies for analytics, marketing or cross-site tracking.
| Where | Name | Purpose | Duration |
|---|---|---|---|
| objektor.io | None | The website sets no cookies. | – |
| app.objektor.io | Clerk session (__session, __client_uat and similar) | Keeps you signed in and protects the session against misuse. | Until you sign out or the session expires. |
| app.objektor.io | sidebar_state | Remembers whether the side menu is open or closed. | 7 days |
| app.objektor.io | objektor.activeProjectId, objektor.language (local storage) | Remembers your last selected project and language. | Until you clear browser data. |
5. Who we share data with
We never sell or rent personal data. The following providers process data on our behalf (processors), governed by data processing agreements:
| Provider | Used for | Where data is processed |
|---|---|---|
| Google Cloud (Google Cloud EMEA Ltd., Ireland / Google LLC, USA) | Server (Cloud Run), database (Cloud SQL), file and photo storage (Cloud Storage), notification queue (Cloud Tasks), logs (Cloud Logging) and website hosting (Firebase Hosting). | Database, files and server in Finland (europe-north1). Queue in Belgium. Websites are served from Google's global network. |
| Clerk, Inc. (USA) | Sign-in, user profiles, organisations and roles. | USA |
| Resend, Inc. (USA) | Sending email notifications. | USA |
| Mapbox, Inc. (USA) | Map tiles and map rendering in the app. | USA (fetched directly by your browser) |
Statens vegvesen (National Road Database) and Kartverket receive only coordinates for lookups, not personal data, and are not processors for us.
Beyond the processors, data may be shared with:
- The organisation you belong to and other members of the projects you take part in. They see your name, your email address and what you register.
- Public authorities when we are legally required to.
- Advisers such as auditors or lawyers, bound by confidentiality, when necessary to meet our legal obligations.
6. Transfers outside the EEA
Customer content, the database and files are stored in the EU. Clerk, Resend and Mapbox are US companies, so the data described in sections 3.1, 3.4 and 3.5 is transferred to the USA. Google may additionally access data from the USA for support and operations.
The transfers rely on the European Commission's standard contractual clauses (Article 46(2)(c)) and, for providers that are certified, the EU–US Data Privacy Framework adequacy decision (Article 45). We assess the providers and apply supplementary measures where needed, including encryption in transit and at rest. You can ask for a copy of the safeguards by writing to hei@laminar.no.
7. How we protect the data
- All traffic is encrypted (TLS), and data is encrypted at rest.
- Access is controlled per organisation and project, and every API request is checked against the signed-in user and their role.
- Files and photos are not publicly accessible. Downloads use time-limited links that expire after 15 minutes.
- Hidden metadata is stripped from photos, and the original file is discarded after processing.
- Secrets and keys are kept in Google Secret Manager, with access limited to what is necessary.
- Backups are taken daily, and logs are reviewed when misuse is suspected.
If we discover a personal data breach, we notify affected customers without undue delay and Datatilsynet within 72 hours where the law requires it.
8. Your rights
You have the right to:
- access the data we hold about you, and receive a copy,
- rectification of data that is wrong or incomplete,
- erasure of data we no longer have grounds to keep, including deletion of your user account,
- restriction of processing while an objection or correction is being considered,
- data portability: receive data you have given us in a machine-readable format,
- object to processing based on legitimate interest, and
- withdraw any consent you have given, without affecting the lawfulness of processing before withdrawal.
Send your request to hei@laminar.no. We respond within one month and may ask you to confirm your identity. If the request concerns data your organisation has registered in Objektor, we forward it to the organisation, which is responsible for responding.
If you believe we process your data in breach of the rules, we hope you will contact us first. You always have the right to lodge a complaint with Datatilsynet, the Norwegian Data Protection Authority.
9. Automated decisions and profiling
Objektor makes no automated decisions with legal effect on you, and we do not profile users.
10. Changes to this statement
We update this statement when the service or its providers change. The date of the last change is shown at the top. For material changes we notify you by email or in the app before they take effect, and highlight what is new.