Privacy Policy
Last updated: 02.02.2026
1. Introduction
Hansen Protection AS ("we", "us", "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and protect personal data when you visit our website, use our services, or interact with us in a business or consumer context.
This policy applies to users worldwide, including users in the EU/EEA, the United Kingdom, the United States, and Canada.
2. Data Controller
Hansen Protection AS
Tykkemyr 27, 1597 Moss, Norway
Email: [email protected]
Hansen Protection AS is the data controller responsible for the processing of personal data described in this policy.
3. Legal Bases for Processing (GDPR)
Where applicable under the GDPR and UK GDPR, we process personal data based on one or more of the following legal grounds:
- Consent
- Performance of a contract
- Legal obligation
- Legitimate interests, where such interests are not overridden by your rights
4. Personal Data We Collect
4.1 Data you provide directly
We may collect the following personal data:
- Contact forms: first name, last name, email address, phone number, customer group, message content
- Account creation: first name, last name, email address, phone number
- Newsletter subscriptions: name, email address
- Orders and invoicing:
- Name
- Company name (if applicable)
- Address
- Phone number
- Email address
- Customer communication via email or forms
Payment details are handled directly by third-party payment providers and are not stored by us.
4.2 Data collected automatically
When you visit our website, we may collect technical and usage data, including:
- IP address
- Browser type and version
- Device information
- Operating system
- Referring URLs
- Pages viewed, interactions, and session duration
- Approximate location (country/city level)
This data is collected through analytics, marketing, and functionality-related tools.
6. Purpose of Processing
We process personal data for the following purposes:
- Operating and maintaining our website
- Processing orders and payments
- Managing user accounts
- Responding to inquiries and customer support
- Sending newsletters and marketing communications
- Analytics and website optimization
- Marketing, advertising, and retargeting
- Compliance with legal obligations
- Fraud prevention and security
7. Marketing Communications
We may send marketing communications by email if:
- You have given explicit consent, or
- You are an existing customer and the communication relates to similar products or services, where permitted by law
You may withdraw consent at any time using the unsubscribe link or by contacting us.
8. Third-Party Services and Data Sharing
We share personal data with trusted third-party service providers where necessary, including:
Analytics & UX
- Google Analytics (GA4)
- Hotjar
Marketing & CRM
- HubSpot
- Mailchimp
- Sleeknote
- Google Ads
- Meta Platforms (Facebook, Instagram, Threads)
Payments
- Klarna
- Vipps
- Nets Checkout
Infrastructure & Email
- Microsoft 365 (Outlook)
- On-premise email systems
- ProtonMail
- Website and e-commerce hosted via Gurusoft CMS
(See Gurusoft's privacy policy for infrastructure details)
These providers act as data processors or independent controllers, depending on the service.
9. International Data Transfers
Some third-party providers are located outside the EU/EEA. Where personal data is transferred internationally, we ensure appropriate safeguards are in place, such as:
- EU Standard Contractual Clauses (SCCs)
- Adequacy decisions
- Equivalent legal mechanisms
10. Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy, including legal, accounting, and reporting obligations.
Retention periods vary depending on the type of data and applicable laws.
11. Your Rights
EU/EEA & UK users (GDPR)
You have the right to:
- Access your personal data
- Rectify inaccurate data
- Request erasure
- Restrict processing
- Object to processing
- Data portability
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
California residents (CCPA/CPRA)
You have the right to:
- Know what personal data is collected
- Request deletion
- Correct inaccurate data
- Opt out of sale or sharing (where applicable)
- Not be discriminated against for exercising your rights
To exercise your rights, contact: [email protected]
12. Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or misuse. No system is completely secure, and we cannot guarantee absolute security.
13. Children's Privacy
Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children.
14. Changes to This Policy
We may update this Privacy Policy from time to time. The latest version will always be available on our website.
15. Contact
For privacy-related questions or requests, contact:
[email protected]
