Privacy Policy

1. Who we are (Data Controller)

This website, https://eix.me, is operated by:

[eix.me / eix.me]
[Organisation number, if registered in Brønnøysundregistrene]
[Postal address]
Email: [privacy@eix.me]

We are the data controller (“behandlingsansvarlig”) for personal data processed through this website. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act of 2018 (personopplysningsloven).

We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. All privacy enquiries can be sent to the email address above. (If you later appoint a DPO, list their name and contact details here.)

2. What personal data we collect, why, and on what legal basis
2.1 User accounts

If you register an account, we collect:

  • Username and password (passwords are stored hashed, never in plain text)
  • Name
  • Email address
  • Phone number (if provided)
  • Address (if provided)

Purpose: To create and administer your user account, authenticate you, and communicate with you about your account.
Legal basis: Article 6(1)(b) GDPR — processing is necessary to perform our agreement with you (providing the account). Optional profile fields (such as phone number and address, where not required for a service) are processed based on your consent, Article 6(1)(a).

You can view and edit your profile information at any time by logging in. Providing the required fields is necessary to hold an account; if you do not provide them, we cannot register you.

2.2 Comments

When visitors leave comments, we collect the data shown in the comment form, plus the visitor’s IP address and browser user agent string to help spam detection.

An anonymised string (hash) created from your email address may be provided to the Gravatar service to check whether you use it. Gravatar’s privacy policy: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

Legal basis: Article 6(1)(f) GDPR — our legitimate interest in enabling discussion and preventing spam and abuse.

2.3 Media uploads

If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS). Visitors can download and extract location data from images on the website. Uploaded files are publicly accessible.

2.4 Analytics and usage data

We collect information about how visitors use the site, such as pages visited, links and buttons clicked, referring website, approximate time of visit, and technical information such as browser type and device type. Where possible this data is anonymised or aggregated.

We use Google Analytics. Its privacy policy: https://policies.google.com/privacy?hl=en-US.

Purpose: To understand how the site is used and improve content and functionality.
Legal basis: Your consent, Article 6(1)(a) GDPR. Analytics cookies and similar tracking are only set after you accept them in our cookie banner, as required by § 3-15 of the Norwegian Electronic Communications Act (ekomloven). You can withdraw consent at any time via [link to cookie settings], and you can browse the site fully without accepting analytics.

2.5 Contact forms (delete if you have none)

If you contact us through a form, we process the details you submit (name, email, message) to answer your enquiry. Submissions are retained for [e.g. 6 months] for customer-service purposes and are not used for marketing.
Legal basis: Article 6(1)(f) GDPR — our legitimate interest in responding to enquiries.

We do not knowingly collect special categories of personal data (e.g. health data), and we ask that you do not submit such data through the site. The site is not directed at children under 13.

3. Cookies

Cookies are small text files stored on your device. Under the Norwegian Electronic Communications Act and GDPR, we only set non-essential cookies with your prior consent, which you give or refuse in our cookie banner. Strictly necessary cookies are set without consent.

CookiePurposeCategoryLifetime
wordpress_[hash], wordpress_logged_in_[hash]Keeps you logged inStrictly necessarySession / 2 days (2 weeks with “Remember Me”)
wordpress_test_cookieChecks whether your browser accepts cookies (login page)Strictly necessarySession
wp-settings-*Saves your screen/display preferencesStrictly necessary1 year
comment_author_*Remembers your name/email/website for future comments (opt-in)Functional (consent)1 year
[Analytics cookies — list name, purpose, lifetime]Usage statisticsAnalytics (consent)[lifetime]

You can change or withdraw your cookie consent at any time via [link to cookie settings] or by deleting cookies in your browser.

4. Embedded content from other websites

Pages on this site may include embedded content (e.g. videos, images, articles). Embedded content from other websites behaves exactly as if you had visited the other website. Those websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with the embedded content — including if you have an account and are logged in to that website. Where such embeds involve tracking, they are only loaded after you consent.

5. Who we share your data with

We do not sell personal data. We share data only with service providers (“data processors”) who help us run the site, under data processing agreements pursuant to Article 28 GDPR:

— Web hosting: Namecheap, EU — stores all site data. Privacy policy: Namecheap Privacy Policy
— Email delivery: Namecheap (if you use Namecheap’s email hosting) — sends account and notification emails. Privacy policy: Namecheap Privacy Policy
— Spam detection: Visitor comments may be checked through an automated spam-detection service such as Akismet. (If you don’t use Akismet or another anti-spam service, you can remove this line.)
— Analytics: Google Analytics. Privacy information: How Google uses information from sites or apps that use its services
— Gravatar (Automattic) — as described in section 2.2.

If you request a password reset, your IP address will be included in the reset email.

We may also disclose data where required by law or to establish, exercise, or defend legal claims.

6. Where your data is sent (transfers outside the EEA)

We aim to keep personal data within the EU/EEA. Where a provider processes data outside the EEA (e.g. [provider, country]), the transfer is safeguarded by an adequacy decision under Article 45 GDPR (including, for US providers, certification under the EU–US Data Privacy Framework) or by the European Commission’s Standard Contractual Clauses with supplementary measures where needed. You may contact us for a copy of the relevant safeguards.

7. How long we retain your data

  • Account data: for as long as your account exists. If you delete your account (or ask us to), personal data is deleted or anonymised within [e.g. 30 days], unless we must keep it longer by law.
  • Comments: the comment and its metadata are retained indefinitely so we can recognise and approve follow-up comments automatically.
  • Contact form submissions: [e.g. 6 months].
  • Analytics data: [e.g. 14/26 months], then deleted or anonymised.
  • Server logs (including IP addresses): [e.g. 30 days], for security and troubleshooting.
8. Your rights

Under GDPR Chapter III you have the right to:

  • Access the personal data we hold about you (Art. 15), including an exported file of it
  • Rectify inaccurate or incomplete data (Art. 16)
  • Erasure — have your data deleted (Art. 17), except data we must keep for administrative, legal, or security purposes
  • Restrict processing (Art. 18)
  • Data portability — receive your data in a machine-readable format (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal

To exercise your rights, email privacy@eix.me. We respond within one month. Registered users can also view, edit, or delete most of their personal information directly from their profile page (usernames cannot be changed).

Complaints: If you believe our processing violates data protection law, you can complain to the Norwegian Data Protection Authority:
Datatilsynet, P.O. Box 458 Sentrum, 0105 Oslo — www.datatilsynet.no

9. How we protect your data

We use appropriate technical and organisational measures, including HTTPS/TLS encryption for all traffic, hashed passwords, access controls limiting administrative access, and regular software updates and backups. [Add anything else you actually do: 2FA for admins, firewall/WAF, etc.]

10. Data breaches

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify Datatilsynet within 72 hours as required by Article 33 GDPR, and notify affected users without undue delay where the risk is high (Article 34).

11. Automated decision-making and profiling

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

12. Changes to this policy

We may update this policy from time to time. The current version is always available on this page, with the “last updated” date above. Significant changes will be announced on the site or by email to registered users.