Privacy Policy
Last updated: 22 June 2026
This Privacy Policy explains how [Company name] AS collects, uses, and protects personal data when you use our website and Telegram Mini App (the "Service"). We process personal data in accordance with the General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (personopplysningsloven).
1. Data controller
The controller of your personal data is [Company name] AS, organisation number [NO 000 000 000], registered at [Registered address, Norway].
For any data-protection questions, contact us at [privacy@example.com].
2. What we collect and why
An account identifier and its creation date — to give you access to the guide you purchased.
An identity reference: either your Telegram ID (if you sign in with Telegram) or your email address (if you sign in via email link). We do not ask for a password.
Your entitlements and purchases — to determine which content you may access.
Hashed one-time sign-in tokens — to securely send and verify email sign-in links. We do not store the links themselves.
A strictly-necessary session cookie (sid) — to keep you signed in after logging in on the website.
We do NOT use analytics, advertising cookies, trackers, or tracking pixels.
3. Legal bases for processing
Performance of a contract (Art. 6(1)(b) GDPR) — to provide access to the digital guide you purchased.
Legitimate interests (Art. 6(1)(f) GDPR) — to keep the Service secure and prevent abuse.
Legal obligation (Art. 6(1)(c) GDPR) — to comply with accounting and tax law.
4. Cookies
We use a single strictly-necessary cookie, sid. It holds a signed session so you stay logged in. It lasts 30 days and is HttpOnly, Secure, and SameSite=Lax.
We also store one technical flag in your browser’s local storage (cookie-notice-dismissed) to remember that you closed the cookie notice.
Because these are strictly necessary for the Service to function, no consent is required under ePrivacy rules. We do not use cookies for analytics, advertising, or tracking.
5. Sharing with third parties (processors)
Cloudflare — hosting, database (D1), file storage (R2), and compute infrastructure (Workers).
Resend — sending transactional sign-in emails.
Telegram — verifying authentication when you sign in with Telegram (Mini App and Login Widget).
These processors may process data outside the EEA. Where they do, transfers are covered by Standard Contractual Clauses (SCCs) or another lawful mechanism. We do not sell your personal data.
6. Retention
Account and entitlement data are kept while your account is active.
Purchase records are retained for the period required by Norwegian bookkeeping law (typically up to 5 years).
Sign-in tokens are short-lived and removed after use or expiry.
7. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, objection to processing, and to withdraw consent where processing is based on consent.
To exercise these rights, contact us at [privacy@example.com].
You may also lodge a complaint with the Norwegian supervisory authority, Datatilsynet (www.datatilsynet.no), or the data-protection authority in your country of residence.
8. Children
The Service is not directed to anyone under 16, and we do not knowingly collect their data.
9. Changes and contact
We may update this Policy from time to time. The current date is shown at the top of this page.
For privacy questions, contact [privacy@example.com].