Privacy Policy
Last updated: 4th August 2026
This Privacy Policy explains how id3as-company Ltd ("Norsk", "we", "us" or "our") collects, uses, shares and protects your personal data when you visit norsk.video, use our products and services, or otherwise interact with us. It also explains your rights and how to exercise them.
We are committed to protecting your privacy and handling your data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the EU GDPR for individuals in the European Economic Area (EEA), and equivalent data protection standards for users elsewhere in the world.
Please read this policy carefully. If you do not agree with it, please do not use our website or services.
1. Who we are
id3as-company Ltd is the data controller responsible for your personal data.
- Company: id3as-company Ltd, trading as Norsk
- Registered office: 2 Forest Farm Business Park, Fulford, York, YO19 4RH, United Kingdom
- Company number: 07510535
- Contact for privacy matters: privacy@norsk.video, or write to us at the registered office above, marked "Data Protection".
We have not appointed a statutory Data Protection Officer, as we are not required to. Dom Robinson (Director) is responsible for data protection within the business and is your point of contact for any questions.
2. Who this policy applies to
This policy applies to everyone whose personal data we handle in connection with our website and services, including:
- Website visitors — people who browse norsk.video.
- Customers and users — individuals at organisations that use, trial, or subscribe to our products.
- Prospects and contacts — people who have asked us for information, signed up to hear from us, or otherwise given us their details directly.
It does not cover our handling of employee, worker, or job-applicant data, which is dealt with in our separate staff and recruitment privacy notices.
3. The personal data we collect
We collect personal data directly from you. We do not buy contact lists or obtain your details from third-party data brokers. The information we hold comes from you giving it to us — when you contact us, request information, sign up, trial or buy our services, or interact with us — or is generated automatically when you use our website.
Depending on how you interact with us, we may collect:
- Identity and contact data — your name, job title, employer or organisation, email address, telephone number, and postal or business address.
- Account and service data — login credentials, the products or plans you use, configuration and usage of the service, and support requests.
- Billing and transaction data — billing contact details and records of purchases. Card payments are handled by our payment providers; we do not store full card details.
- Marketing and communications data — your marketing preferences and consents, and records of the communications we have had with you.
- Technical and usage data — IP address, device and browser information, and information about how you use our website and software, collected through cookies and similar technologies (see section 6).
You do not have to provide the data we ask for, but if you don't, we may not be able to provide the service or respond to your request.
4. How and why we use your data, and our lawful bases
We only use your personal data where the law allows us to. The table below sets out what we use it for and the lawful basis we rely on under UK and EU GDPR.
| What we use it for | Lawful basis |
|---|---|
| Providing, maintaining and supporting our products and services to you or your organisation | Performance of a contract; our legitimate interests in running the service |
| Setting up and administering accounts, billing and payments | Performance of a contract; compliance with a legal obligation (e.g. tax and accounting) |
| Responding to your enquiries and providing customer support | Performance of a contract; our legitimate interests in helping our users |
| Sending marketing and product updates you have asked for | Your consent; or our legitimate interests in marketing to existing customers about similar products (with an easy opt-out) |
| Understanding how our website and services are used, and improving and securing them | Our legitimate interests in improving, developing and protecting our services |
| Keeping records and meeting legal, regulatory and tax obligations | Compliance with a legal obligation |
| Establishing, exercising or defending legal claims | Our legitimate interests in protecting our business |
Where we rely on legitimate interests, we have considered the impact on you and do not use your data where your rights override our interests. You can ask us for more detail about this assessment at any time.
Where we rely on consent — for example for certain marketing — you can withdraw it at any time without affecting anything we did before you withdrew it (see section 5).
5. Marketing and your choices
We contact you with marketing only where we are allowed to — either because you have opted in, or because you are an existing customer and the message is about similar products or services and you were given a clear chance to opt out.
You are in control. You can change your marketing preferences or opt out at any time, either by using the unsubscribe link in any marketing email or by contacting us using the details in section 1. We act on opt-outs promptly and keep a minimal suppression record so that we do not contact you again by mistake. Opting out of marketing does not stop essential service messages, such as billing or security notices.
You have an absolute right to object to direct marketing — if you tell us to stop, we will.
6. Cookies and similar technologies
Our website uses cookies and similar technologies to make the site work, to remember your preferences, and to understand how the site is used. Non-essential cookies are only used with your consent, which you can manage or withdraw at any time through our cookie banner or your browser settings.
7. Who we share your data with
We do not sell your personal data. We share it only where necessary, with:
- Service providers (processors) who help us run our business, including our CRM provider, and providers of email, analytics, payment and support tools. These providers act only on our instructions under written data processing agreements.
- Professional advisers such as accountants, auditors and lawyers, where needed.
- Authorities, regulators or law enforcement, where we are legally required to disclose information.
- A buyer or successor, if we sell or reorganise our business, in which case your data may be transferred subject to this policy.
A current list of our main processors is available on request.
8. International data transfers
We are based in the UK, and some of our service providers store or process data outside the UK and EEA — including in the United States (for example, our hosting and CRM providers use infrastructure in the US).
Whenever we transfer your personal data outside the UK or EEA, we make sure it is protected by appropriate safeguards, which will be one or more of: an adequacy decision by the UK government or European Commission; the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses; or the EU Standard Contractual Clauses. You can ask us for a copy of the safeguards we use.
9. How long we keep your data
We keep your personal data only for as long as we need it for the purposes set out in this policy, and then delete or anonymise it.
- Customer data is kept for the duration of our relationship and then for a further period to meet legal, tax and accounting requirements — generally 7 years after the relationship ends.
- Prospect and marketing data is kept while you remain interested in hearing from us. We review it periodically and remove contacts who have been inactive or unengaged for extended periods, or sooner if you ask us to or withdraw consent.
We may keep certain information for longer where we need it to establish, exercise or defend legal claims.
10. How we protect your data
We use appropriate technical and organisational measures to protect your personal data, including access controls, encryption where appropriate, and limiting access to those who need it. We keep these measures under review and require our service providers to do the same.
11. Your rights
Under the UK and EU GDPR you have the following rights over your personal data:
- Access — to be told whether we hold data about you and to receive a copy.
- Rectification — to have inaccurate or incomplete data corrected.
- Erasure — to have your data deleted in certain circumstances.
- Restriction — to limit how we use your data in certain circumstances.
- Portability — to receive certain data in a portable format, or have it sent to another provider.
- Objection — to object to processing based on legitimate interests, and to object to direct marketing at any time (which we will always honour).
- Withdraw consent — where we rely on consent, to withdraw it at any time.
- Automated decisions — we do not make decisions with legal or similarly significant effects about you by automated means only; if this changes, you will have the right to human review.
To exercise any of these rights, contact us using the details in section 1. We will respond within one month, though we may extend this by up to two further months for complex requests, and we will tell you if so. Exercising your rights is normally free.
12. Users outside the UK
Our services are available internationally, and this policy applies wherever you are. We apply UK and EU GDPR-standard protections to personal data globally.
If you are in California or another US state with privacy laws, you may have additional rights, such as the right to know what personal information we hold, to request deletion, and not to be discriminated against for exercising your rights. We do not sell personal information. Contact us to exercise these rights.
If you are elsewhere in the world, you may contact us using the details in section 1 to exercise the rights available to you under your local law.
13. How to complain
If you have a concern about how we handle your personal data, please contact us first using the details in section 1. We will acknowledge your complaint within 30 days and respond as quickly as we can.
You also have the right to complain to a data protection regulator:
- In the UK — the Information Commissioner's Office (ICO), at ico.org.uk, or 0303 123 1113.
- In the EEA — your local data protection supervisory authority.
We would appreciate the chance to address your concerns before you approach the regulator, but you are entitled to contact them at any time.
14. Children
Our website and services are intended for businesses and are not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
15. Changes to this policy
We may update this policy from time to time. When we make significant changes, we will update the "last updated" date above and, where appropriate, notify you. Please check back periodically.
16. How to contact us
For any questions about this policy or your personal data, contact:
id3as-company Ltd (Norsk)2 Forest Farm Business Park, Fulford, York, YO19 4RH, United Kingdom
Email: privacy@norsk.video