← Back

Privacy policy

Kerta Onboarding is a service that helps companies provide their employees with structured training plans. This policy describes what personal data we process, why, and what rights you have.

Controller

If you are an employee at a customer

Your employer is the controller of data about you. Kerta is a processor, processing the data on the employer's behalf under a data processing agreement.

  • Name and email address
  • Role, start date, and age indicator when relevant (under-18 flag)
  • Profile photo if uploaded by you or your manager
  • Training module status (not started, completed, not applicable)
  • Sign-in metadata (last sign-in timestamp)

If you are an account administrator

If you are a manager or administrator who sets up an account for your company, Kerta is the controller for the information needed to provide the service to you as a customer — name, email, company name, and billing details where applicable.

Legal basis

  • Contract (GDPR art. 6(1)(b)): for delivering the service itself.
  • Legal obligation (art. 6(1)(c)): accounting and bookkeeping.
  • Legitimate interest (art. 6(1)(f)): security, debugging, and abuse prevention.
  • Consent (art. 6(1)(a)): for analytics (Google Analytics) — you decide via the consent banner.

Hosting and transfers

Personal data is stored in Microsoft Azure in the Norway East region (Oslo). We do not transfer personal data outside the EEA without a valid transfer mechanism.

Sub-processors we use

  • Microsoft Azure — storage and hosting (Norway East, Oslo).
  • Microsoft Azure OpenAI — only for the optional AI features (training-plan suggestions and translations). Only role and training text is sent, never employee names or emails. Processing stays within the EEA but may run in an Azure region other than Norway East.

We notify the employer (data controller) of any new sub-processor before it is used, so the employer can object.

Retention

  • Active employees: as long as the employment and the agreement with the employer run.
  • Employees who leave: hidden from the team list immediately, and their access (the share link) is revoked. Name, email address and profile photo are automatically anonymised 12 months after the departure date. We keep the identity that long so the employer can document completed training — for example at an inspection. The training history itself (which modules were completed, and when) remains in anonymised form afterwards.
  • Ended customer relationships: when the account is cancelled it goes read-only. The employer can undo for 30 days, and all the account's data is automatically and permanently deleted 90 days after cancellation — shorter on request.
  • Accounting data: 5 years from the start of the accounting year (Norwegian Bookkeeping Act).
  • Security log data: 12 months.

Your rights

You have the right to access, correction, erasure, data portability, to object to processing, and to withdraw consent. Requests can be sent to your employer (for training data) or directly to Kerta at dan@kerta.no. You can also complain to the Norwegian Data Protection Authority.

Data portability (GDPR art. 20): the account administrator can download a complete copy of the company's data as JSON at any time, self-serve under Settings → Subscription & data. The export stays available after cancellation, right up until the data is deleted.

Security

We use TLS encryption in transit, encryption at rest for blob storage, Microsoft sign-in for access control, and logging of all data access.

Changes

We notify of material changes to this policy by email to the account administrator or by updated text on this page.