Legal

Privacy Policy

How Enigma.i collects, uses and protects personal data — and the rights you have under the GDPR.

Last updated 18 June 2026Enigma.i AS · Tønsberg, Norway

01 Overview

Enigma.i builds AI modules for the offshore, maritime and energy industries — including RTP — TenderEdge, the FEED Intelligent Platform, Barrier Management, DockFinder, CrewPool and DocExtract. This policy explains what personal data we collect, why we collect it, the legal basis we rely on, and the rights you have under the EU General Data Protection Regulation (GDPR) as implemented in Norway by the Personal Data Act (personopplysningsloven).

Privacy by design is one of our build principles: we collect the minimum data needed, keep it inside the EU/EEA, and give you straightforward ways to exercise your rights.

02 Who we are (data controller)

The data controller responsible for the personal data described in this policy is:

EntityEnigma.i AS
Org. no.937 495 714
AddressPostboks 24, 3119 Tønsberg, Norway
Emailcontact@enigmai.no
Webenigmai.no

For any question about this policy or to exercise your rights, contact us at contact@enigmai.no.

03 When this policy applies — controller vs. processor

It matters in which role we handle your data, because our responsibilities differ.

Where we are the data controller

This Privacy Policy applies where Enigma.i AS acts as data controller — that is, where we decide why and how personal data is processed. This covers our website, enquiries, sales communications, demo requests, newsletters and customer relationship management.

Where we are a data processor

Where Enigma.i AS processes customer-uploaded data inside our modules — such as the FEED Intelligent Platform or RTP — TenderEdge — on behalf of a customer, we normally act as data processor. The customer determines the purpose and means of that processing. It is governed by the applicable customer agreement, Data Processing Agreement (DPA) and product-specific security documentation — not by this policy.

During demos and unsecured evaluations, please do not upload real personal or operational data; use sample or anonymised material unless a DPA is already in place.

04 What data we collect

We collect only what we need to respond to you and to run our services.

CategoryExamplesHow we get it
Contact & enquiry dataName, work email, company name, role, module of interest, and the content of your messageYou provide it via our contact form or by email
Demo & pilot dataInformation shared during a demo, scoping call or pilotYou provide it during the engagement
Technical & usage dataIP address, browser and device type, pages viewed, referring page, timestampsCollected automatically by our web server and any analytics
Cookie dataIdentifiers and preferences stored by strictly necessary and, with consent, analytics cookiesSet by your browser — see section 9

We do not ask for special categories of personal data, and we ask that you do not include them in free-text fields. We do not knowingly collect data from anyone under 18.

05 Why we use it and our legal basis

We process personal data only where the GDPR gives us a lawful basis to do so.

PurposeLegal basis (GDPR Art. 6)
Respond to enquiries and demo/pilot requestsPre-contract steps at your request, and our legitimate interest in answering you — Art. 6(1)(b) and (f)
Deliver and support a pilot or service you have engaged us forPerformance of a contract — Art. 6(1)(b)
Operate, secure and improve the websiteLegitimate interest in a safe, working site — Art. 6(1)(f)
Analytics and any marketing communicationsYour consent — Art. 6(1)(a) — which you may withdraw at any time
Meet legal, accounting and compliance obligationsLegal obligation — Art. 6(1)(c)

06 Marketing communications

If we send you marketing about our modules or pilots, we do so in line with the Norwegian Marketing Control Act (markedsføringsloven § 15): we rely on your prior consent, or on an existing customer relationship for closely related products. Every marketing message includes a simple way to opt out, and you can withdraw consent at any time by emailing contact@enigmai.no. Withdrawing consent does not stop service or transactional messages you need, such as a reply to your enquiry.

07 AI, your data and automated decisions

Our modules use AI to help structure, extract and analyse engineering and tender data. Two commitments matter for your privacy:

  • Decision support only. Our modules support human decisions; they do not make decisions with legal or similarly significant effect automatically. A person reviews and approves outcomes at critical points, consistent with GDPR Article 22.
  • We do not train models on your data without your agreement. We do not use customer-uploaded documents to train AI models, except where specifically agreed with you in a contract.

08 How we share data

We do not sell your personal data. We share it only with:

  • Service providers (processors) who host our infrastructure, run analytics or help us deliver pilots — bound by data processing agreements and acting only on our instructions.
  • Professional advisers such as auditors or lawyers, where needed.
  • Authorities where we are legally required to disclose, or to protect our rights and the security of our systems.

Our subprocessors

We use service providers (subprocessors) to host our infrastructure, handle email and customer communication, and operate our website. All subprocessors are bound by a data processing agreement and host personal data within the EU/EEA. A current list of our subprocessors is available on request from contact@enigmai.no.

09 Cookies and analytics

Our website uses cookies and similar technologies. Non-essential cookies — including analytics — may be set only after you give consent; strictly necessary cookies that make the site work are exempt.

Today this website uses only strictly necessary cookies. We do not use analytics, advertising or marketing cookies.

CookieProviderPurposeDurationCategory
enigmai_sessionEnigma.iMaintains your session and site securitySessionStrictly necessary

10 Where your data is stored

We store and process personal data within the European Union / European Economic Area (EU/EEA). If a provider needs to transfer data outside the EU/EEA, we only allow it under a valid GDPR transfer mechanism — an adequacy decision or the European Commission's Standard Contractual Clauses with appropriate safeguards.

11 How long we keep it

We keep personal data only as long as we need it, then delete or anonymise it.

DataRetention
Enquiries that do not become a customer relationshipDeleted or anonymised within 12 months
Demo & sales dialogue24 months after last contact, unless dialogue is ongoing
Customer & contract dataFor the duration of the relationship, plus up to 5 years afterwards
Accounting records5 years, as required by the Norwegian Bookkeeping Act (bokføringsloven)
Product / pilot dataPer the applicable DPA or pilot agreement — typically deleted or exported when the pilot ends

12 How we protect data

We apply technical and organisational measures appropriate to the risk, including access controls, encryption in transit, logging and least-privilege access. Security is part of our roadmap: we are working toward ISO/IEC 27001 alignment. No method of transmission or storage is completely secure, but we work to protect your data and will notify you and Datatilsynet of a personal data breach where the law requires it.

13 Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Have inaccurate data corrected, and incomplete data completed.
  • Have your data erased where there is no lawful reason to keep it.
  • Restrict or object to how we process your data.
  • Receive your data in a portable format and have it transmitted to another controller.
  • Withdraw consent at any time, without affecting processing already carried out.

To exercise any right, email contact@enigmai.no. We respond within one month.

14 Complaints

If you believe we have handled your data unlawfully, we would like the chance to put it right — please contact us first. You also have the right to complain to the Norwegian Data Protection Authority:

AuthorityDatatilsynet (Norwegian Data Protection Authority)
Webdatatilsynet.no
PostPostboks 458 Sentrum, 0105 Oslo, Norway

15 Changes to this policy

We may update this policy as our services, technology or the law change. When we make material changes we will update the date at the top of this page and, where appropriate, notify you.

Last updated: 18 June 2026.