Your privacy matters to us.
Last updated: 21 July 2026
At Capassa we believe you should have full control over your own data. We only collect personal data when it is necessary in order to deliver our services, safeguard security or fulfil our legal obligations.
Who is the data controller?
Capassa AS is the data controller for the personal data processed through our services.
Company
Capassa AS
Organisation number
920 860 966
Address
Hovfaret 13, 0275 Oslo
What data do we collect?
We collect personal data when you use Capassa or get in touch with us. We do not process more data than is necessary in order to deliver the service.
| Situation | Personal data |
|---|---|
| Creating an account | Name, email address, telephone number |
| Signing in | Sign-in information and security logs |
| BankID verification | The data necessary to confirm your identity |
| Connecting an accounting system | The information necessary to connect the company's accounting data to Capassa |
| Contact with customer service | Name, contact details and the content of the enquiry |
| Use of the service | Information about how the service is used, technical logs and error messages |
What do we use the data for?
We use personal data in order to:
- create and administer user accounts
- authenticate users and protect their accounts
- deliver analyses, reports and insight in Capassa
- connect the company to relevant accounting systems
- provide customer support
- improve the service and develop new features
- safeguard information security
- fulfil statutory requirements
We never use personal data to sell information about our users.
Legal basis for processing
We process personal data on the basis of the General Data Protection Regulation (GDPR). Depending on the situation, the processing takes place because:
- it is necessary in order to perform the agreement with you
- we have a legal obligation
- you have given your consent
- we have a legitimate interest in delivering and further developing the service in a secure manner
Accounting data
Capassa processes financial data in order to deliver analyses, forecasts, reports and decision support.
Accounting data always belongs to the company that has connected to the service. Capassa uses this data solely in order to deliver the features the customer has chosen to use.
Artificial intelligence (AI)
Capassa uses artificial intelligence to make financial information easier to understand and use. The AI features analyse only data that the customer has itself given access to through Capassa.
We do not use customers' company data to train open language models or to make it available to other customers.
Sharing of personal data
We only share personal data when it is necessary in order to deliver the service. This may include our data processors and technology suppliers, for example within:
- cloud storage
- authentication
- email distribution
- customer support
- operations and security
All data processors are contractually obliged to process the data securely and in accordance with the GDPR. We never sell personal data.
Where is the data stored?
Capassa uses Microsoft Azure, in data centres in Norway and Western Europe. Data is encrypted both in transit and at rest. Access to data is restricted according to the principle of least privilege, and only authorised persons have access when it is necessary.
How long do we store the data?
We store personal data for as long as it is necessary in order to:
- deliver the services
- perform the agreement with the customer
- fulfil statutory requirements
- handle any disputes
When the data is no longer necessary, it is deleted or anonymised.
Your rights
You have the right to:
- obtain access to what personal data we hold about you
- request rectification of inaccurate data
- request erasure when the conditions are met
- restrict the processing
- object to the processing where the law permits it
- receive a copy of your own data (data portability)
- withdraw your consent where the processing is based on consent
Information security
We work continuously to protect personal data against unauthorised access, loss and misuse. This includes, among other things:
- encryption
- access control
- secure authentication
- logging
- monitoring
- regular security updates
Concrete, not just legal
This is how we protect your data
BankID verification
Identity is confirmed with BankID for automatic onboarding and access to the Data room.
Secure storage in Microsoft Azure
Data is stored in data centres in Norway and Western Europe.
Encryption
Data is encrypted both in transit and at rest.
Role-based access control
Each user sees only what is relevant to their role.
Controlled sharing of accounting data
Shared only with those the company has itself given access.
AI with limited access
Analyses only data the customer has itself given access to. Does not train open models on company data.
Cookies
Capassa uses cookies to ensure that the website works as it should, to improve the user experience and to analyse traffic.
Read the cookie policyChanges to this privacy policy
We may update this privacy policy if our services change or the legislation requires it. In the event of significant changes we will inform users in a clear manner.
Complaints
If you believe that our processing of personal data is not in accordance with the applicable regulations, you have the right to contact the Norwegian Data Protection Authority (Datatilsynet) or the relevant supervisory authority in the country where you live.
Contact us
If you have questions about privacy or about how we process personal data, you are always welcome to contact us.
capassa@capassa.com