Capassa
Privacy

Your privacy matters to us.

Last updated: 21 July 2026

At Capassa we believe you should have full control over your own data. We only collect personal data when it is necessary in order to deliver our services, safeguard security or fulfil our legal obligations.

In short

  • You own your own data.
  • We never sell personal data.
  • Data is used only to deliver Capassa.
  • You can request access or erasure at any time.

Who is the data controller?

Capassa AS is the data controller for the personal data processed through our services.

Company

Capassa AS

Organisation number

920 860 966

Address

Hovfaret 13, 0275 Oslo

What data do we collect?

We collect personal data when you use Capassa or get in touch with us. We do not process more data than is necessary in order to deliver the service.

SituationPersonal data
Creating an accountName, email address, telephone number
Signing inSign-in information and security logs
BankID verificationThe data necessary to confirm your identity
Connecting an accounting systemThe information necessary to connect the company's accounting data to Capassa
Contact with customer serviceName, contact details and the content of the enquiry
Use of the serviceInformation about how the service is used, technical logs and error messages

What do we use the data for?

We use personal data in order to:

  • create and administer user accounts
  • authenticate users and protect their accounts
  • deliver analyses, reports and insight in Capassa
  • connect the company to relevant accounting systems
  • provide customer support
  • improve the service and develop new features
  • safeguard information security
  • fulfil statutory requirements

We never use personal data to sell information about our users.

Legal basis for processing

We process personal data on the basis of the General Data Protection Regulation (GDPR). Depending on the situation, the processing takes place because:

  • it is necessary in order to perform the agreement with you
  • we have a legal obligation
  • you have given your consent
  • we have a legitimate interest in delivering and further developing the service in a secure manner

Accounting data

Capassa processes financial data in order to deliver analyses, forecasts, reports and decision support.

Accounting data always belongs to the company that has connected to the service. Capassa uses this data solely in order to deliver the features the customer has chosen to use.

Artificial intelligence (AI)

Capassa uses artificial intelligence to make financial information easier to understand and use. The AI features analyse only data that the customer has itself given access to through Capassa.

We do not use customers' company data to train open language models or to make it available to other customers.

Sharing of personal data

We only share personal data when it is necessary in order to deliver the service. This may include our data processors and technology suppliers, for example within:

  • cloud storage
  • authentication
  • email distribution
  • customer support
  • operations and security

All data processors are contractually obliged to process the data securely and in accordance with the GDPR. We never sell personal data.

Where is the data stored?

Capassa uses Microsoft Azure, in data centres in Norway and Western Europe. Data is encrypted both in transit and at rest. Access to data is restricted according to the principle of least privilege, and only authorised persons have access when it is necessary.

How long do we store the data?

We store personal data for as long as it is necessary in order to:

  • deliver the services
  • perform the agreement with the customer
  • fulfil statutory requirements
  • handle any disputes

When the data is no longer necessary, it is deleted or anonymised.

Your rights

You have the right to:

  • obtain access to what personal data we hold about you
  • request rectification of inaccurate data
  • request erasure when the conditions are met
  • restrict the processing
  • object to the processing where the law permits it
  • receive a copy of your own data (data portability)
  • withdraw your consent where the processing is based on consent

Information security

We work continuously to protect personal data against unauthorised access, loss and misuse. This includes, among other things:

  • encryption
  • access control
  • secure authentication
  • logging
  • monitoring
  • regular security updates

Concrete, not just legal

This is how we protect your data

BankID verification

Identity is confirmed with BankID for automatic onboarding and access to the Data room.

Secure storage in Microsoft Azure

Data is stored in data centres in Norway and Western Europe.

Encryption

Data is encrypted both in transit and at rest.

Role-based access control

Each user sees only what is relevant to their role.

Controlled sharing of accounting data

Shared only with those the company has itself given access.

AI with limited access

Analyses only data the customer has itself given access to. Does not train open models on company data.

Cookies

Capassa uses cookies to ensure that the website works as it should, to improve the user experience and to analyse traffic.

Read the cookie policy

Changes to this privacy policy

We may update this privacy policy if our services change or the legislation requires it. In the event of significant changes we will inform users in a clear manner.

Complaints

If you believe that our processing of personal data is not in accordance with the applicable regulations, you have the right to contact the Norwegian Data Protection Authority (Datatilsynet) or the relevant supervisory authority in the country where you live.

Contact us

If you have questions about privacy or about how we process personal data, you are always welcome to contact us.

capassa@capassa.com