This Privacy Policy complies with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws. As a compliance platform, we practice what we preach.
Embodier AS ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our AI-powered compliance platform.
We process documents you upload for compliance analysis. These documents are encrypted, processed by our AI engines, and automatically deleted after analysis completion unless you choose to store them.
Under GDPR, we process your personal data based on the following legal grounds:
Processing necessary to provide our compliance services as outlined in our Terms of Service.
Improving our services, preventing fraud, and ensuring platform security.
Marketing communications and optional data processing activities.
Compliance with tax, accounting, and other legal requirements.
We do not sell, trade, or rent your personal information. We may share your data with:
We may disclose your information if required by law, court order, or to protect our rights, property, or safety, or that of our users or the public.
We implement industry-standard security measures to protect your personal information:
Retained while your account is active and for 12 months after closure for legal and business purposes.
Scan results stored for 24 months. Uploaded documents deleted after processing unless explicitly saved.
Anonymized usage data retained for 36 months to improve our services and AI algorithms.
As a data subject under GDPR, you have the following rights:
Request a copy of your personal data
Correct inaccurate or incomplete data
Request deletion of your personal data
Limit how we use your data
Export your data in a machine-readable format
Object to processing for certain purposes
Withdraw consent for data processing
File complaint with supervisory authority
Contact us at privacy@embodier.com or use the privacy controls in your account settings. We will respond within 30 days as required by GDPR.
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA) where our service providers are located.
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
For any questions about this Privacy Policy or to exercise your rights, please contact:
Norwegian Data Protection Authority: If you are not satisfied with our response, you may lodge a complaint with Datatilsynet (datatilsynet.no).