Privacy policy
Draft for approval. The controller completes the [brackets]. The list of processors must match the "Overview of sub-processors" (data processing agreement 6.2) before publication.
Last updated: [date]
Who is responsible
EVVA AUTO AS, organisation number 931 027 204, Roald Amundsens vei 148, 1658 Torp, Norway, is the controller of personal data collected on this website and in the web shop. Contact: [post@evvaauto.no], [telephone].
The web shop is operated technically by NordicSync AS on behalf of EVVA AUTO AS (processor).
What we process, why and on what basis
| What | Why | Legal basis | How long |
|---|---|---|---|
| Name, e-mail, telephone, delivery and billing address | Fulfil the purchase, deliver the goods, send order confirmation and notifications | Contract (GDPR art. 6(1)(b)) | Order data is kept for 5 years after the financial year (Bookkeeping Act) |
| Order history, payment method and status (not card number) | Customer service, returns, complaints, accounting | Contract and legal obligation (art. 6(1)(b) and (c)) | 5 years |
| Organisation number, company name, reference (business customers) | Receipt/invoice to the business | Contract | 5 years |
| Name, e-mail, telephone, requested time, service, optional registration number and note (appointment booking) | Handle and confirm the appointment request, prepare the work | Contract / pre-contractual steps (art. 6(1)(b)) | Registration number and note deleted [30 days] after the appointment; the rest [12 months] |
| Content of messages via the contact form | Answer your enquiry | Legitimate interest (art. 6(1)(f)) | [90 days] in the solution |
| IP address, browser type, time (technical logs) | Security, troubleshooting, preventing abuse | Legitimate interest (art. 6(1)(f)) | 30 days |
| Cookie choice | Remember what you consented to | Legal obligation (Electronic Communications Act § 3-15) | 12 months |
We do not process card numbers – the payment provider does (Stripe, Vipps MobilePay, Klarna). We do not use your data for marketing without separate consent, and we do not sell it.
Who we share data with
Processors acting on our behalf:
- NordicSync AS (Norway) – development, operation and support of the web shop
- Supabase Pte. Ltd – database, images and backups, stored in Stockholm (EU)
- [Railway Corp] – hosting of the shop's server in Amsterdam (EU)
- Vercel Inc. – hosting of the website; server functions in Stockholm (EU)
- [Resend – Plus Five Five, Inc.] – sending e-mail from the web shop; e-mail is sent from Ireland (EU), but the provider stores logs and content in the USA for up to 30 days
Independent controllers receiving data to deliver their service:
- Stripe Payments Europe Ltd (Ireland) – card payments and Klarna; Klarna Bank AB (Sweden) – "pay later"; Vipps MobilePay AS (Norway) – Vipps payments. They process your payment data under their own privacy policies.
- The Brønnøysund Register Centre – organisation number lookup (public register) when you buy as a business.
Our tyre supplier does not receive your name, address or registration number – only our order number and which tyres to deliver to the workshop.
Your data is stored in the EU/EEA. Some of our processors are US companies; transfers to the USA happen only where stated above and are safeguarded by the EU–US Data Privacy Framework and the EU Commission's standard contractual clauses (SCC). Payment providers may use sub-processors outside the EEA under their own safeguards; see their policies.
Your rights
You have the right to access the data we hold about you, to have errors corrected, to erasure (where we are not legally required to keep the data), to restriction, to object to processing based on legitimate interest, and to data portability. Send requests to [post@evvaauto.no]; we reply within 30 days. You may complain to the Norwegian Data Protection Authority (datatilsynet.no) if you believe we process your data unlawfully.
Security
All communication with the web shop is encrypted (HTTPS). The database is not reachable from the internet, the admin requires two-factor authentication, and backups are encrypted. In the event of a personal data breach we notify the Data Protection Authority and affected persons as required by the GDPR.
Cookies
See the separate cookie overview.
Changes
Changes to this policy are published on this page with a new date.
v. 2026-09-16