Machine-translated draft
This English version is a non-binding preview. The Norwegian version is the authoritative, legally binding text. Human translation is pending.
Privacy statement
How we process personal data — GDPR art. 13 and 14.
Sist oppdatert: 12. juni 2026
1. Data controller
The data controller is Gevity AS, business reg. no. 937 274 122, Svanholmen 2, 4033 Stavanger, Norway. Privacy enquiries: personvern@gevity.no.
2. Overview
This statement describes what personal data we collect, why, the legal basis, retention periods, and your rights under the GDPR (art. 13/14).
3. What we collect
- Account information: name, email, phone, and date of birth (collected at sign-up to verify the 18+ age requirement)
- Health data (GDPR art. 9): self-reported health information and Visbody measurements. Visbody data is manually entered by our operator and stored only in Gevity's own database — we do not use a third-party cloud and have no DPA with SpiroFit.
- Booking and transaction data
- Technical data: IP address, user agent, event logs
4. Purpose and legal basis
Processing relies on GDPR art. 6(1)(b) (contract), art. 6(1)(c) (legal obligation), art. 6(1)(f) (legitimate interest) and art. 9(2)(a) (explicit consent) for health data.
5. Retention
Health data: 5 years after last treatment. Accounting data: 5 years. Inactive accounts: we notify after 22 months and delete after 24 months of inactivity.
6. Security
Data is stored in Azure PostgreSQL (Norway East) with transparent data encryption (TDE) at rest and TLS 1.2+ in transit.
7. Observability
Operational logs are retained for approximately 90 days in Azure Application Insights / Log Analytics for troubleshooting and security monitoring. They are never used for marketing.
8. Sharing
We share data with Vipps / Stripe (payments), Twilio (SMS), Microsoft Azure (hosting) and lock providers (Nuki / TTLock) under data processing agreements. We do not sell personal data.
9. Your rights
You may request access, rectification, erasure, restriction, portability, and object to processing. You may also lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).