Privacy Policy
Bifrost Analytics
Last updated: 9 September 2026
This policy explains how we handle personal data when you use Bifrost Analytics at bifrostanalytics.no (the "Service"). It applies to you as a user of the Service.
1. Who is responsible
Bifrost Analytics is the data controller for the personal data described here. Enquiries about privacy: bmb150905@gmail.com.
2. What we collect
Account data. Your name, email address, phone number and a cryptographically hashed version of your password. We never store your password in readable form. Payment card details are handled by our payment provider and are not stored by us.
Data you create in the Service. The companies you add to a watchlist (identified by ISIN, LEI or ticker), any filters or display preferences you save, and items you mark as read or saved.
Technical data. Each time you use the Service our servers record your IP address, browser and operating system, the pages and data you requested, and the date and time. Sign-in events, including failed attempts, are logged.
We do not collect special category data, and we ask you not to enter any into the Service.
3. Why we process it, and on what legal basis
| Purpose | Legal basis (GDPR Article 6) |
|---|---|
| Giving you access to the Service and keeping your account working | Performance of a contract, Art. 6(1)(b) |
| Showing you news relevant to the companies you have chosen to follow | Performance of a contract, Art. 6(1)(b) |
| Protecting the Service against unauthorised access and abuse | Legitimate interests, Art. 6(1)(f) |
| Diagnosing faults and maintaining service quality | Legitimate interests, Art. 6(1)(f) |
| Meeting record-keeping obligations that apply to us | Legal obligation, Art. 6(1)(c) |
| Sending optional email alerts, where offered | Consent, Art. 6(1)(a) |
Where we rely on legitimate interests, we have considered your rights and limited the processing to what is necessary. Where we rely on consent, you may withdraw it at any time without affecting anything done before you withdrew it.
4. A note on the news itself
The Service displays regulatory and corporate press releases published by listed companies. These are public documents about companies, not about you. They may name individuals, typically company officers and directors, because those names appear in the releases as the companies published them. We display those documents as issued and do not alter, enrich or index them by individual.
Press releases reach us from our news sources. Those sources receive no information about you, and we send them nothing about your account or your watchlist.
5. Who else processes your data
- Our hosting and database provider for the application and its database. Your data is stored in the Central EU region (Frankfurt, Germany).
- Our email provider for delivery of news and trigger alert emails.
- Analytics: we use none.
Each processor works under a data processing agreement. We do not sell your personal data, and we do not disclose it to third parties for their own purposes. We may disclose data where we are legally required to, for example to a regulator, a court, or a tax or supervisory authority.
6. Where your data is stored
Your data is stored within the EU. We do not currently transfer personal data outside the EEA. If that changes, we will update this policy and rely on an appropriate safeguard such as the European Commission's standard contractual clauses.
7. How long we keep it
| Data | Retention |
|---|---|
| Account data | For as long as your account is active, then 12 months |
| Watchlists and preferences | Deleted with your account |
| Server and sign-in logs | 90 days |
| Records we must keep by law | For the statutory period that applies |
Press releases and analyses are retained indefinitely as a research archive. They contain no personal data about you.
8. Your rights
Under the GDPR and the Norwegian Personal Data Act you may ask us to:
- confirm what personal data we hold about you, and give you a copy
- correct data that is inaccurate or incomplete
- delete your data, where we have no continuing basis to keep it
- restrict how we process it, or object to processing based on legitimate interests
- provide your data in a portable, machine-readable form
- withdraw any consent you have given
Write to bmb150905@gmail.com and we will respond within one month. If you are not satisfied with how we have handled your request, you may complain to the Norwegian Data Protection Authority, Datatilsynet (postkasse@datatilsynet.no, www.datatilsynet.no).
9. Security
Access to your account requires a personal login. Passwords are stored only as salted hashes. All traffic runs over encrypted connections. Access to the underlying database is restricted to named administrators.
No system is perfectly secure. If a breach occurs that is likely to present a risk to you, we will notify you and Datatilsynet as the GDPR requires.
10. Cookies and similar technologies
The Service stores on your device only what it needs in order to work: the sign-in token that keeps you logged in, held in your browser's local storage, and a security token that protects sign-in forms against misuse. These are strictly necessary to deliver the service you have asked for, so under the Norwegian Electronic Communications Act we do not need your consent for them, and you will not see a cookie banner. We use no analytics, advertising or tracking technologies.
Our Cookie Policy lists each item, its purpose and how long it lasts.
11. Changes
We may update this policy. If a change materially affects how we handle your data we will tell you by email or by a notice in the Service before it takes effect. The date at the top shows when this version was issued.
12. Contact
Bifrost Analytics
bmb150905@gmail.com
ulrik.vaage@gmail.com