Privacy
Privacy policy
RoboConnect AS is the data controller for the personal data processed on this platform. We comply with the Norwegian Personal Data Act and the GDPR. This policy explains what data we collect, why, how long we store it and what rights you have.
Last updated: 19 September 2026
1. Data controller
RoboConnect AS, company reg. no. 935 121 159, is the data controller. Privacy enquiries can be sent to hei@roboconnect.no.
2. What personal data we process
We process the following categories of data, depending on your role:
All signed-in users
- Email address and password (stored hashed by Supabase Auth)
- Session cookies for signing in
- IP address and user agent for sensitive actions (audit log)
- Any consents you give (terms, newsletter, visibility)
Industrial companies (customers)
- Contact person: position/title, mobile, phone
- Company information: company name, company registration number, email, website, visiting address, postcode, town, county
- Company size: number of employees, year founded, annual revenue, industry
- Project descriptions (goals, budget, ROI, space, working environment, start date)
Actors (system integrators, suppliers, R&D actors)
- Company information: company name, company registration number, county, postcode, year founded, annual revenue, number of employees
- Professional profile: “about us” text, areas of expertise, solutions, partnerships, tags
- Any showroom, test lab or demonstration facilities (suppliers)
Payment (match fee)
- Stripe transaction ID, amount and status
- We do not store card data. Stripe processes card information directly and is subject to PCI DSS.
Chat
If you use the RoboConnect assistant, we store your messages in pseudonymised form. The content may be used for troubleshooting and further development of the service. Do not share customer PII or sensitive information in the chat.
3. Purposes and legal bases
We process personal data for the following purposes:
- Providing the service (contract, GDPR art. 6(1)(b)): Signing in, profile handling, project creation, manual matching, contact requests, payment of the match fee, release of contact information (unlock) and reporting of contracts and quotes.
- Legitimate interest (art. 6(1)(f)): Security, abuse prevention, audit logging, operations and troubleshooting on the platform.
- Consent (art. 6(1)(a)): Newsletter, non-essential cookies (analytics, marketing) and voluntary visibility in search on the platform. Consent can be withdrawn at any time.
- Legal obligation (art. 6(1)(c)): Bookkeeping obligations for issued invoices (match fee, success fee).
4. Anonymisation and visibility
Projects are published in the public list in anonymised form: actors see the title, region, industry and a short summary — but not the customer’s name, company registration number or contact information. Contact information is only released once RoboConnect has approved the actor, the customer has approved the contact and the match fee has been paid.
Actor profiles are shown in anonymised form (role, county, competence, short “about us”) in the customer and admin interfaces until the corresponding conditions are met.
5. Who we share data with
We use third-party services (sub-processors) to operate the platform. These services process personal data on behalf of RoboConnect under written data processing agreements.
| Service | Purpose | Storage location / transfer basis |
|---|---|---|
| Vercel | Hosting of the frontend and serverless functions | Preferably EU region. Transfer to the USA on the basis of the EU-US Data Privacy Framework (DPF). |
| Supabase | Database (Postgres), authentication, Row-Level Security | EU/EEA (Ireland). Transfer to the USA on the basis of the EU Standard Contractual Clauses (SCC) with a Transfer Impact Assessment. |
| Stripe | Payment processing for the match fee, handling of card data | EU/EEA for European transactions. Intra-group transfers to the USA on the basis of the DPF. |
| Resend | Sending transactional emails and email logging | EU region where available. Transfer to the USA on the basis of the DPF. |
| GitHub | Source code storage, code maintenance, CI/CD | USA. Transfer basis: DPF. |
The RoboConnect assistant uses a third-party AI provider (Anthropic or OpenAI). RoboConnect is the account holder with the AI provider and has its own data processing relationship with them. Do not send customer PII or sensitive information into the chat.
We do not sell personal data and do not share it with third parties for marketing without your consent.
6. Transfers to third countries
Personal data is stored within the EU/EEA as a general rule. Some sub-processors are established in the USA or have group companies in the USA that may access the data in connection with operations, support or administrative tasks. Such transfers take place on the basis of the EU-US Data Privacy Framework (DPF) where the provider is certified, or the EU Standard Contractual Clauses (SCC) combined with a completed Transfer Impact Assessment.
7. Retention periods
We store personal data for as long as it is necessary for the purpose:
- Active user and company profiles are stored for as long as the account is active. You can request deletion at any time (see section 9).
- Audit logs (actions, IP, user agent) are stored for up to 24 months for security and abuse follow-up.
- Transaction data (match fee, invoicing basis) is stored for five years in accordance with the Norwegian Bookkeeping Act.
- Anonymised chat messages and usage statistics may be stored for longer for service improvement.
- Deleted accounts are removed from the database and backups within 90 days.
8. Cookies
We use necessary cookies for signing in and security. With your consent we may additionally collect anonymised analytics and use marketing pixels. You can adjust your cookie choices at any time via the Cookies link in the footer, and you can also delete or block cookies in your browser.
9. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Rectification of inaccurate data
- Erasure of data (“the right to be forgotten”)
- Restriction of processing
- Data portability — receiving your data in a machine-readable format
- Withdraw consent without affecting processing carried out beforehand
- Object to processing based on legitimate interest
Send requests to hei@roboconnect.no. We respond within one month.
If you believe our processing breaches data protection rules, you have the right to lodge a complaint with Datatilsynet, the Norwegian Data Protection Authority: datatilsynet.no.
10. Security
We have implemented technical and organisational measures appropriate to the risk, including pseudonymisation where possible, encryption in transit (TLS), access control (Row-Level Security in the database), audit logging of sensitive actions and rate limiting on sign-in and payment flows. Sub-processors are required to apply equivalent security measures through their own agreements.
11. Changes
This policy may be updated following changes to the service, to legislation or to the use of sub-processors. Material changes are notified by email to registered users at least 30 days before they take effect. The last updated date at the top of the page reflects the most recent revision.
12. Contact
Questions about privacy? Send an email to hei@roboconnect.no. You can also read our terms of use.