Legal
How Enigma.i collects, uses and protects personal data — and the rights you have under the GDPR.
Enigma.i builds AI modules for the offshore, maritime and energy industries — including RTP — TenderEdge, the FEED Intelligent Platform, Barrier Management, DockFinder, CrewPool and DocExtract. This policy explains what personal data we collect, why we collect it, the legal basis we rely on, and the rights you have under the EU General Data Protection Regulation (GDPR) as implemented in Norway by the Personal Data Act (personopplysningsloven).
Privacy by design is one of our build principles: we collect the minimum data needed, keep it inside the EU/EEA, and give you straightforward ways to exercise your rights.
The data controller responsible for the personal data described in this policy is:
For any question about this policy or to exercise your rights, contact us at contact@enigmai.no.
It matters in which role we handle your data, because our responsibilities differ.
This Privacy Policy applies where Enigma.i AS acts as data controller — that is, where we decide why and how personal data is processed. This covers our website, enquiries, sales communications, demo requests, newsletters and customer relationship management.
Where Enigma.i AS processes customer-uploaded data inside our modules — such as the FEED Intelligent Platform or RTP — TenderEdge — on behalf of a customer, we normally act as data processor. The customer determines the purpose and means of that processing. It is governed by the applicable customer agreement, Data Processing Agreement (DPA) and product-specific security documentation — not by this policy.
During demos and unsecured evaluations, please do not upload real personal or operational data; use sample or anonymised material unless a DPA is already in place.
We collect only what we need to respond to you and to run our services.
| Category | Examples | How we get it |
|---|---|---|
| Contact & enquiry data | Name, work email, company name, role, module of interest, and the content of your message | You provide it via our contact form or by email |
| Demo & pilot data | Information shared during a demo, scoping call or pilot | You provide it during the engagement |
| Technical & usage data | IP address, browser and device type, pages viewed, referring page, timestamps | Collected automatically by our web server and any analytics |
| Cookie data | Identifiers and preferences stored by strictly necessary and, with consent, analytics cookies | Set by your browser — see section 9 |
We do not ask for special categories of personal data, and we ask that you do not include them in free-text fields. We do not knowingly collect data from anyone under 18.
We process personal data only where the GDPR gives us a lawful basis to do so.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Respond to enquiries and demo/pilot requests | Pre-contract steps at your request, and our legitimate interest in answering you — Art. 6(1)(b) and (f) |
| Deliver and support a pilot or service you have engaged us for | Performance of a contract — Art. 6(1)(b) |
| Operate, secure and improve the website | Legitimate interest in a safe, working site — Art. 6(1)(f) |
| Analytics and any marketing communications | Your consent — Art. 6(1)(a) — which you may withdraw at any time |
| Meet legal, accounting and compliance obligations | Legal obligation — Art. 6(1)(c) |
If we send you marketing about our modules or pilots, we do so in line with the Norwegian Marketing Control Act (markedsføringsloven § 15): we rely on your prior consent, or on an existing customer relationship for closely related products. Every marketing message includes a simple way to opt out, and you can withdraw consent at any time by emailing contact@enigmai.no. Withdrawing consent does not stop service or transactional messages you need, such as a reply to your enquiry.
Our modules use AI to help structure, extract and analyse engineering and tender data. Two commitments matter for your privacy:
We do not sell your personal data. We share it only with:
We use service providers (subprocessors) to host our infrastructure, handle email and customer communication, and operate our website. All subprocessors are bound by a data processing agreement and host personal data within the EU/EEA. A current list of our subprocessors is available on request from contact@enigmai.no.
Our website uses cookies and similar technologies. Non-essential cookies — including analytics — may be set only after you give consent; strictly necessary cookies that make the site work are exempt.
Today this website uses only strictly necessary cookies. We do not use analytics, advertising or marketing cookies.
| Cookie | Provider | Purpose | Duration | Category |
|---|---|---|---|---|
| enigmai_session | Enigma.i | Maintains your session and site security | Session | Strictly necessary |
We store and process personal data within the European Union / European Economic Area (EU/EEA). If a provider needs to transfer data outside the EU/EEA, we only allow it under a valid GDPR transfer mechanism — an adequacy decision or the European Commission's Standard Contractual Clauses with appropriate safeguards.
We keep personal data only as long as we need it, then delete or anonymise it.
| Data | Retention |
|---|---|
| Enquiries that do not become a customer relationship | Deleted or anonymised within 12 months |
| Demo & sales dialogue | 24 months after last contact, unless dialogue is ongoing |
| Customer & contract data | For the duration of the relationship, plus up to 5 years afterwards |
| Accounting records | 5 years, as required by the Norwegian Bookkeeping Act (bokføringsloven) |
| Product / pilot data | Per the applicable DPA or pilot agreement — typically deleted or exported when the pilot ends |
We apply technical and organisational measures appropriate to the risk, including access controls, encryption in transit, logging and least-privilege access. Security is part of our roadmap: we are working toward ISO/IEC 27001 alignment. No method of transmission or storage is completely secure, but we work to protect your data and will notify you and Datatilsynet of a personal data breach where the law requires it.
Under the GDPR you have the right to:
To exercise any right, email contact@enigmai.no. We respond within one month.
If you believe we have handled your data unlawfully, we would like the chance to put it right — please contact us first. You also have the right to complain to the Norwegian Data Protection Authority:
We may update this policy as our services, technology or the law change. When we make material changes we will update the date at the top of this page and, where appropriate, notify you.
Last updated: 18 June 2026.