Legal
Privacy Policy
Links and resources
- Terms of Service
- Privacy Policy
- Data Processing Agreement
- Contact
Last updated: 16 September 2026
This Privacy Policy applies to journalia.no and the services provided by Journalia AS. It is written in Norwegian; this is a translation. In the event of conflict between language versions, the Norwegian version prevails.
Who we are
Journalia AS, org. no. 933 860 078, Oslo, Norway. Privacy questions: hei@journalia.no
Our two roles
2.1 Processor: for the content customers put into the service, that is audio, documents, transcripts and drafts, and the personal data they contain, the customer is the controller. We process that content on the customer's documented instructions under a data processing agreement. If you are a patient, client, citizen or employee of a customer, direct requests about your data to that organisation. Requests we receive, we pass on. 2.2 Controller: for the data we need in order to run the business, that is user accounts, support, billing, security and the website. The rest of this Privacy Policy concerns the data for which we are the controller.
What we process, and why
Account and contact details. We store your name, your work email address, where you work and what your role is. We need this to give you access to the service and to keep track of the customer relationship. We do it because we have an agreement with the organisation you work for, and because we need to know who is using the service. Some of these details come to us from the organisation you work for when your account is set up. Usage and technical data. We see which features are used and when, and we store information about your device, your IP address and the logs the system produces. We do this because we need it to run the service, spot faults and misuse, and make the service better. We do not use it to monitor individuals. Support correspondence. When you contact us, we keep your message and our reply. Without it we can neither help you nor fix the fault you are reporting. Billing data. We store what we need to invoice you and keep our accounts. Invoicing follows from the agreement, and the accounts are something the law requires of us. Marketing contacts. If you sign up for a newsletter or an event, we store your contact details so we can send you what you asked for. We only send it if you have said yes, or if you are already a customer of ours. You can unsubscribe at any time. Cookies and website analytics. Our website uses cookies to work, and to show us how the site is used. Anything not needed for the site to function is only set if you have said yes in the consent banner.
We do not sell personal data, and we do not share it with others so they can market things to you.
Retention
Data for which we are the controller is kept for as long as it is needed for the purpose, and is then deleted or anonymised. Accounting records are kept for as long as the bookkeeping rules require. Retention of customer content is set by the customer and follows the data processing agreement.
Where we process
Processing takes place within the EU/EEA. For customer content, transfer out of the EEA happens only on the customer's documented instruction. For the data for which we are ourselves the controller, transfer happens only on a valid basis under Chapter V of the GDPR, such as an adequacy decision or the EU Standard Contractual Clauses.
Sub-processors and other recipients
We use third parties to deliver our services, including for hosting, AI processing and support. They process personal data on our behalf and strictly in accordance with the GDPR and the data processing agreements we have entered into. A current list of sub-processors is available on request from hei@journalia.no.
Security
We maintain technical and organisational measures appropriate to the risk, in accordance with Article 32 GDPR, including encryption in transit and at rest, access control on a need-to-know basis, logging, and testing at planned intervals. The measures that apply to customer content are described in the data processing agreement.
Your rights
You may request access, rectification, erasure, restriction and data portability, and you may object to processing or withdraw a consent. Contact us at hei@journalia.no. We reply within the time limits set out in the GDPR. You may lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no), or with the supervisory authority where you live or work.
Changes
We update this policy when needed. The current version is always available on journalia.no. We notify customers of material changes by email or in the service.