Legal — 01
Privacy Policy
This policy explains what personal data SAMMES AS collects through Connect, Intel, Social and the website, why we collect it, the legal basis for each purpose, who we share it with, how long we keep it, and the rights you can exercise.
1. Who is responsible for your data
SAMMES AS (referred to in this policy as "Sammes", "we", "us" or "our") is the data controller for the personal data described in this policy. A controller is the organisation that decides why and how personal data is processed.
Our details are:
- Legal entity: SAMMES AS
- Organisation number: 938 141 657
- Registered address: Øvrehusvegen 37E, 4054 Tjelta, Norway
- Data-protection contact: [email protected]
- General contact: [email protected]
We are established in Norway and our business is software development (Norwegian NACE code 62.100). We operate the Connect, Intel and Social mobile applications and the website at sammes.no. In this policy, "the Services" means those applications and the website together, and "the User" means any individual who uses them.
This policy should be read together with our Cookie Policy, our App Privacy page and our Terms of Service.
2. Personal data we collect
Personal data is any information that can be linked to an identifiable individual, and it is defined broadly under the GDPR. We group what we collect into the categories below. The App Privacy page sets out which app collects which category.
Account data
When you create an account we collect your name, email address, a hashed password or third-party sign-in identifier, your display name, profile image, preferred language and country, and the date the account was created. We also store your notification and marketing preferences and a record of the consents you have given.
Device and connected-hardware data
Connect links your account to hardware you choose to pair, such as sensors, controllers and other connected devices. We collect the device model, serial number, firmware version, connection status and configuration settings, together with the readings, events and state changes that those devices report. Where a connected device reports a position, that position is treated as device data.
Usage and diagnostics data
We collect how the Services are used: features accessed, screens viewed, session start times and duration, in-app actions, crash reports, performance measurements, error logs, operating-system version, app version, device model and a device identifier. Diagnostics are used to keep the Services stable, secure and performant.
Content you create
This is the material you upload or publish, including text, images, video and audio, together with metadata such as the time of creation and any caption or tag. For Social this also includes posts, comments, direct messages, group memberships, and your interactions such as likes, follows and reactions.
Location data
Some features need your position, for example to show nearby devices or to attach a place to a post. We collect location only after the operating system has asked your permission and you have allowed it. You may grant approximate (coarse) location or precise (fine) location, and you can revoke either at any time in your device settings. We do not collect location in the background unless a feature you have enabled requires it, and we explain the reason at the point of asking.
Purchase and subscription data
If you buy a subscription or a paid feature, the payment is processed by Apple or Google. We receive a transaction identifier, the product purchased, the purchase date and the subscription status. We do not receive or store your full payment-card number.
3. How we use personal data
We process personal data only for the purposes below, and we do not use it for a new purpose without telling you first.
- To create your account, authenticate you and keep your settings in sync across devices.
- To provide the core Services: pairing, monitoring and controlling connected devices through Connect.
- To generate insights, alerts and recommendations through Intel, based on the devices and data you have connected.
- To operate the social features of Social, including publishing content, following other users, messaging and moderation.
- To provide customer support and respond to your requests.
- To send service messages, such as security notices, downtime notifications and changes to our terms or this policy.
- To keep the Services safe and secure, including detecting fraud, abuse and attempts to compromise accounts.
- To measure and improve the Services, using first-party, aggregated metrics wherever possible.
- To send marketing about our own products, but only where you have opted in or where we are otherwise permitted to contact you, and always with a way to opt out.
- To meet legal, tax and accounting obligations.
Automated decision-making
Intel generates automated insights, such as a suggested action or a warning based on readings from a connected device. These outputs are decision support; they do not by themselves produce legal effects for you or similarly significantly affect you as described in Article 22 GDPR. A human can review any recommendation, and you can object to how an insight was produced by contacting [email protected]. If we ever introduce solely automated decision-making with legal or similarly significant effects, we will inform you in advance, explain the logic involved and the expected consequences, and give you a way to request human intervention and to contest the decision.
4. Legal bases for processing
Under the GDPR (the EU General Data Protection Regulation, as incorporated in Norway through the Personal Data Act) we must have a legal basis from Article 6 for every purpose. The table below shows the basis we rely on for each purpose. Where we rely on legitimate interests, we name the interest and confirm that we have balanced it against your rights and expectations.
| Purpose | Legal basis (Article 6 GDPR) |
|---|---|
| Create and manage your account; authenticate you | Performance of a contract (Article 6(1)(b)) |
| Provide Connect device pairing, monitoring and control | Performance of a contract (Article 6(1)(b)) |
| Generate Intel insights personalised to your connected data | Performance of a contract (Article 6(1)(b)) |
| Operate Social features, content publishing and messaging | Performance of a contract (Article 6(1)(b)) |
| Customer support | Performance of a contract (Article 6(1)(b)); legitimate interests (Article 6(1)(f)) in resolving issues efficiently |
| Security, fraud and abuse prevention | Legitimate interests (Article 6(1)(f)) in protecting users and the platform from harm and misuse |
| Product analytics and service improvement | Legitimate interests (Article 6(1)(f)) in understanding feature usage so we can prioritise development and fix problems, using first-party and aggregated data |
| Service messages about security, downtime and changes | Performance of a contract (Article 6(1)(b)); legitimate interests (Article 6(1)(f)) in keeping users informed |
| Marketing about our own products | Consent (Article 6(1)(a)); or legitimate interests (Article 6(1)(f)) in promoting similar products to existing customers, with an easy opt-out |
| Precise location features | Consent (Article 6(1)(a)), collected through the operating-system permission prompt |
| Non-essential cookies and similar technologies | Consent (Article 6(1)(a)) |
| Accounting, tax and other statutory records | Legal obligation (Article 6(1)(c)) |
Where we rely on consent you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal. Where we rely on legitimate interests you have the right to object, as explained in section 9.
5. Who we share personal data with
We do not sell personal data, and we do not share it for third-party advertising. We disclose personal data only in the circumstances below.
- Processors. We use service providers that process data on our behalf under a written data-processing agreement. They fall into these categories: cloud hosting and databases; content delivery; email and push-notification delivery; error monitoring and crash reporting; customer-support tooling; and analytics. Each processor may act only on our instructions.
- App stores and payment providers. Apple and Google process payments and manage subscriptions as independent controllers under their own privacy policies.
- Connected-device manufacturers. Where a device you pair is made by a third party, that manufacturer may receive device status and telemetry needed to operate the device. The manufacturer is an independent controller for its own processing.
- Other users. Content you publish through Social is visible to the audience you choose. Treat anything you post as public and do not include personal data about others without their permission.
- Authorities and advisers. We may disclose data to public authorities where the law requires it, and to professional advisers such as auditors and lawyers under confidentiality obligations.
- Corporate transactions. If we merge, are acquired or transfer assets, data may be transferred to the successor, subject to this policy.
6. International transfers
We are based in Norway and we keep personal data in the European Economic Area (EEA) by default. Where a processor processes data outside the EEA, we make sure a lawful transfer mechanism is in place. We rely on an adequacy decision from the European Commission where one exists, and otherwise on the EU Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914. Where the Clauses are used, we carry out a transfer-impact assessment and add technical and organisational measures such as encryption in transit and at rest, access controls and minimisation. You can request a copy of the safeguards we rely on by writing to [email protected].
7. How long we keep personal data
We keep personal data only as long as we need it for the purpose it was collected, or as long as the law requires. The table below gives the standard retention period for each category. Where a legal obligation sets a longer period, that period applies.
| Data category | Retention period |
|---|---|
| Account data (name, email, credentials, profile) | While the account is active, then 12 months after closure |
| Connected-device records, readings and events | 24 months from collection, or 30 days after you unlink the device, whichever is sooner |
| Usage data (feature and session analytics) | 14 months |
| Crash reports and error logs | 90 days |
| Content you publish (posts, uploads) | Until you delete it or close your account; removed within 30 days of deletion |
| Direct messages | While both accounts exist, then 12 months |
| Location data | 30 days for live features; a place attached to a post is kept with the post until the post is deleted |
| Purchase and subscription records | 5 years, to meet Norwegian bookkeeping law, then deleted |
| Support correspondence | 24 months from the last exchange |
| Cookie consent records | 12 months |
| Security and server logs | 90 days |
| Marketing consent records | Until withdrawn, then 24 months as evidence of the withdrawal |
When a retention period ends we delete the data or render it permanently anonymous. Residual copies may remain in encrypted backups for a further period of no more than 35 days before they are overwritten, and we do not use backup data for any other purpose.
8. How we protect your data
We use technical and organisational measures designed to protect personal data against loss, misuse and unauthorised access. These include:
- encryption of data in transit using TLS 1.2 or later, and encryption of data at rest;
- storage of passwords only as salted hashes produced by a modern key-derivation function;
- role-based access control on a least-privilege basis, with multi-factor authentication required for staff accounts;
- logging and monitoring of access to production systems;
- regular review of processors and security testing of the Services;
- a documented incident-response procedure.
No system can be guaranteed to be completely secure. If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify Datatilsynet without undue delay and within 72 hours of becoming aware of it, and we will notify you directly where the breach is likely to result in a high risk to you.
9. Your rights
Subject to the conditions in the GDPR, you have the following rights:
- Access. You can ask for a copy of the personal data we hold about you and information about how we process it.
- Rectification. You can ask us to correct inaccurate or incomplete data.
- Erasure. You can ask us to delete your personal data where there is no good reason for us to keep it.
- Restriction. You can ask us to limit how we use your data, for example while a dispute about accuracy is being resolved.
- Portability. You can ask us to provide data you gave us in a structured, commonly used and machine-readable format, or to send it to another controller where this is technically feasible.
- Objection. You can object to processing based on legitimate interests or on direct marketing. We will stop marketing immediately, and we will stop other legitimate-interest processing unless we can show compelling grounds that override your interests.
- Withdraw consent. Where we rely on consent, you can withdraw it at any time.
- Automated decisions. You have rights relating to solely automated decision-making, as described in section 3.
To exercise a right, email [email protected]. You can also delete your account yourself using the steps on our account deletion page. We will respond within one month; if a request is complex we may extend that by up to two further months and will tell you why. We may ask for information to confirm your identity, and we will not charge a fee unless a request is manifestly unfounded or excessive.
10. Children
The Services are not intended for children under 13, and we do not knowingly create accounts for them. The minimum age to use Connect, Intel and Social is 13.
In the EEA, where processing is based on consent, a child must be at least 13 years old to give that consent, in line with the Norwegian age of digital consent under the Personal Data Act. Where we have reason to believe a User is under 13, we will not process their personal data on the basis of consent without verifiable consent from a parent or guardian. Social features that involve public sharing are restricted for younger Users, and we limit recommendations and messaging for accounts identified as belonging to minors. If we learn that a child under 13 has provided personal data without valid consent, we will delete the account and the associated data. A parent or guardian who believes a child has done so should contact [email protected].
11. App tracking and Apple App Tracking Transparency
None of Connect, Intel or Social uses your personal data for cross-app tracking as Apple defines it, and none of the three apps uses data for third-party advertising. We do not follow you across apps and websites owned by other companies, and we do not sell data to data brokers or advertising networks. Our iOS privacy manifests declare NSPrivacyTracking as false.
Because we do not track you across other companies' apps and websites, we do not show the App Tracking Transparency (ATT) prompt for advertising purposes, and declining such tracking does not apply to our apps today. If we ever introduce a feature that constitutes tracking under Apple's rules, we will request your permission through Apple's App Tracking Transparency framework before any tracking begins. Until you grant that permission, we will not access the device's advertising identifier or track you across other companies' properties, and you will be able to decline without losing access to core features. We would also update this policy and our App Store privacy labels before any such change takes effect. The App Privacy page mirrors those labels.
12. Changes to this policy
We review this policy regularly and update it when our processing changes. The effective date and version number at the top of the page always reflect the current version, and we keep earlier versions on request.
If a change is material, we will notify you in the app or by email before it takes effect, and we will give you reasonable notice, normally at least 30 days, so that you can review the change and, where relevant, exercise your rights or close your account. Where the law requires your consent for a new processing activity, we will ask for it separately. Continued use of the Services after a change takes effect means the updated policy applies.
13. Contact and complaints
For any question about this policy or about how we handle your personal data, contact our data-protection contact at [email protected], or write to us at SAMMES AS, Øvrehusvegen 37E, 4054 Tjelta, Norway. For general enquiries, use [email protected] or see our support page.
If you believe we have not handled your data lawfully, you have the right to lodge a complaint with the Norwegian supervisory authority, Datatilsynet (the Norwegian Data Protection Authority), Postboks 458 Sentrum, 0105 Oslo, Norway, datatilsynet.no. You may also complain to the supervisory authority in the EEA country where you live or work, or where the alleged infringement took place. We would appreciate the chance to resolve your concern directly first.