Privacy Policy
ZAGR (Zamble Gruppen AS)
Org.nr. 936 648 967
Contact: contact@zagr.no
Last updated: July 27, 2026
1. Who we are
ZAGR (Zamble Gruppen AS) is a Norwegian advisory firm providing AI governance and compliance services to organisations. We are the data controller (behandlingsansvarlig) for the personal data described in this policy.
For any question about this policy, or to exercise your rights, contact contact@zagr.no.
We are not required to appoint a Data Protection Officer under Article 37 GDPR, as we do not carry out large-scale processing, do not process special categories of data as a core activity, and are not a public authority.
2. Our approach: we do not take your data
ZAGR provides governance advisory, not data processing. Our engagements are structured so that client personal data is not transferred to ZAGR. Where we need to inspect a system containing personal data, we do so in the client's own environment, and where examples are required we use pseudonymised or synthetic data.
This means we act as a data controller for our own limited processing - described below - and not as a data processor on behalf of clients. Where an engagement would require us to process personal data on a client's behalf, we enter into a data processing agreement (databehandleravtale) before that processing begins.
3. What we process, why, and on what basis
3.1 Website visitors
Our website is hosted on Framer. Framer collects aggregated, cookieless visit statistics (page views and similar) which do not identify individual visitors.
We set no cookies and store nothing on your device. There is no analytics tag, no advertising pixel, and no consent banner, because none is required.
Our host (Framer) processes technical server data such as IP addresses for the purpose of delivering and securing the site. These server logs are retained only as long as necessary for security monitoring and technical diagnostics, after which they are deleted or anonymized.
Legal basis: legitimate interest, Article 6(1)(f) - operating and securing our website.
3.2 Contact form enquiries
Our contact form collects your name, email address, topic (selected from a dropdown - e.g. AI Risk Diagnostic) and message, and routes the submission to our email. We use it only to respond to your enquiry.
Legal basis: legitimate interest, Article 6(1)(f) - responding to a business enquiry addressed to us. Where the enquiry leads towards an engagement, Article 6(1)(b) - steps prior to entering a contract.
3.3 Meeting bookings
Booking a call takes you to Calendly, a separate website operated by Calendly LLC. Any data you enter there is subject to Calendly's own privacy policy. We receive your name, email address, chosen meeting time and any additional information you choose to share to help prepare for the meeting.
We do not use automated meeting recording or transcription. If we ever introduce it, we will tell you before any recording begins and you can decline.
Legal basis: Article 6(1)(f), and Article 6(1)(b) where a booking is a step towards an engagement.
3.4 Correspondence
We use Google Workspace for email. Correspondence is retained so that we can maintain an accurate record of what was discussed and agreed.
Legal basis: Article 6(1)(f) for general business correspondence; Article 6(1)(b) for correspondence with clients under an engagement.
3.5 Business contacts and pipeline records
We maintain records of organisations and individuals relevant to our business development in Notion. These records contain professional information: name, job title, employer, professional contact details, publicly available profile links, and our own notes on the status of the commercial relationship.
Legal basis: legitimate interest, Article 6(1)(f) - identifying and managing potential client relationships. We have carried out and documented a balancing assessment for this processing.
3.6 If we contacted you first
If you did not contact us, we may have obtained your professional details from publicly available sources - typically your employer's website, public professional networking profiles, or a referral from a mutual contact.
The categories of data involved are: name, job title, employer, and professional contact details.
Legal basis: legitimate interest, Article 6(1)(f) - business-to-business outreach to individuals in a professional capacity, where our services are relevant to their organisational role.
You can object at any time, with no need to give a reason, by replying to any message from us or writing to contact@zagr.no. We will remove you from our records and will not contact you again.
3.7 Accounting and invoicing
For clients, we process the contact and billing details necessary to issue invoices, using Fiken (Norwegian accounting software).
Legal basis: legal obligation, Article 6(1)(c) - bookkeeping obligations under bokføringsloven.
3.8 AI tools
We use AI assistants for research, analysis and drafting. As an AI governance firm we hold our own use to the standards we advise on.
Personal data entrusted to us by clients is never entered into these tools.
Our own business records - including professional contact details and our commercial analysis - may be processed using AI assistants. We minimise the personal data involved, use pseudonymised or aggregated information where the task allows, and do not enter special categories of personal data. The providers of these tools are listed in section 4.
Notion includes AI features as part of the product. We have disabled these features in our workspace settings and do not use them. Framer's platform may include AI-related features as part of its product; we do not use Framer's AI capabilities in a way that processes personal data.
Where we use AI models running locally on our own hardware, no personal data is transferred to a third-party provider.
We also use other AI-assisted tools for structural and content work that does not involve personal data.
Legal basis: legitimate interest, Article 6(1)(f).
3.9 Client engagement delivery
During diagnostic engagements and other client work, we may conduct interviews and observe systems or processes on the client's premises or via video. Findings from interviews are recorded by role (e.g. "recruiter," "technical lead") rather than by name, unless a named individual is designated as an accountable owner in a deliverable such as a tiltaksplan - in which case that name appears only in the document delivered back to the client, not retained separately in our own records.
We do not record interviews or on-site sessions without the participant's prior knowledge and agreement.
Where a client shares documents or evidence containing personal data as part of an engagement, this is processed under a data processing agreement (databehandleravtale), agreed before that processing begins, as described in section 2.
Legal basis: Article 6(1)(b), performance of a contract with the client.
3.10 References and testimonials
If a client agrees to act as a reference, provide a testimonial, or be named in a case study, we retain their name, role, organisation and the agreed wording for as long as the permission stands. This is separate from and does not extend our general engagement records.
Legal basis: consent, Article 6(1)(a). You may withdraw consent at any time by contacting contact@zagr.no, and we will stop using the reference or testimonial going forward.
4. Who else has access
We use the following service providers, who process personal data on our behalf under data processing agreements:
Google (Workspace)
Email and document hosting
USA (EU-US Data Privacy Framework) https://cloud.google.com/terms/data-processing-addendum
Calendly
Meeting scheduling
USA (EU-US Data Privacy Framework) https://calendly.com/legal/data-processing-addendum
Notion
Business contact records
USA (Standard Contractual Clauses) https://www.notion.com/help/gdpr-at-notion
Anthropic (Claude)
AI-assisted research, analysis and drafting for our own business records
Ireland (EEA) https://www.anthropic.com/legal/data-processing-addendum
We do not sell personal data and we do not share it for advertising purposes.
We may disclose personal data where we are legally required to do so.
Where we work alongside other independent consultants on an engagement, relevant information may be shared with them under confidentiality obligations equivalent to those in this policy.
5. How long we keep it
Website statistics
Aggregated only, not personal data
Contact form enquiries that do not proceed
12 months
Business contacts and pipeline records
24 months from last contact
Client engagement records and correspondence
As long as necessary to establish, exercise or defend legal claims, and in any case for the statutory accounting period below
Accounting records
5 years after the end of the financial year (bokføringsloven)
References and testimonials
Until consent is withdrawn
We review our records annually and delete what is no longer needed.
6. Your rights
Under the GDPR you have the right to:
request access to the personal data we hold about you
have inaccurate data corrected
have your data erased, where we have no continuing basis to keep it
request restriction of processing
object to processing based on our legitimate interests
receive your data in a portable format, where applicable
withdraw consent, where processing is based on consent
To exercise any of these, write to contact@zagr.no. We will respond within one month.
Where a request would reveal the personal data of others, or our confidential business information, we may need to limit what we disclose accordingly.
7. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal effects or otherwise significantly affects you.
8. Complaints
If you believe we have handled your personal data incorrectly, we would like to hear from you first at contact@zagr.no. You also have the right to complain to the Norwegian Data Protection Authority:
Datatilsynet
Postboks 458 Sentrum, 0105 Oslo
postkasse@datatilsynet.no
9. Changes
We will update this policy when our processing changes, and will change the date at the top when we do.