Skip to main content

Privacy Policy

Last Updated: March 14, 2026

1 — Introduction and Controller Identity

This Privacy Policy explains how Sotra Link AS (“Sotra Link AS”, “we”, “us”, or “our”) collects, uses, discloses, and protects your personal data when you visit our website sotralink.no, contact us, or use our consulting and training services. We operate from Norway and provide professional, educational, and informational services to clients across Canada.

Data Controller: Sotra Link AS, SmĂĄlonane 14, 5353 Straume, Norway. You can contact us at [email protected] for any privacy question or request. We have assessed that a formal Data Protection Officer appointment is not required. Nevertheless, privacy matters are handled with priority by our management team.

Effective date of this policy: March 14, 2026. By accessing our website or submitting a contact form, you acknowledge this Privacy Policy and agree that we may process your data as described, subject to your rights under applicable law.

2 — Personal Data We Collect

We collect only the information necessary to provide our services, operate our website, and respond to your requests. Categories include:

We do not intentionally collect special‑category data (for example, health, religious beliefs, political opinions), financial account details, or government IDs through our website. Please do not include sensitive information in free‑text fields. If you believe you have shared such data inadvertently, contact us to request deletion.

3 — Why We Process Your Data and Legal Bases (GDPR Art. 6)

Automated Decision‑Making and Profiling (Art. 22): we do not engage in automated decision‑making or profiling that produces legal or similarly significant effects on individuals.

4 — Cookies and Similar Technologies

We use cookies and similar technologies to run our website, remember preferences, analyze usage, and—only with consent—support marketing measurement. Our categories are aligned with the consent controls available on the site and explained in our Cookie Policy:

Beyond cookies, marketing and analytics may involve pixel tags and server‑side integrations (for example, hashed identifiers processed by advertising platforms). These activate only after you provide consent through the cookie banner or preferences panel. You can change your choices anytime using “Manage cookie preferences” in the site footer.

5 — Consent and Withdrawal

Users in the EEA, including Norway, are shown a consent notice. Analytics and marketing technologies are off by default and activate only if you provide explicit, informed consent (GDPR Art. 6(1)(a)). Your choice is stored in the cookie_consent cookie for up to 12 months. You may withdraw consent at any time via the “Manage cookie preferences” link in the footer or by clearing cookies in your browser. Withdrawal will not affect the lawfulness of processing based on consent before withdrawal.

6 — Sharing with Service Providers and Advertising Partners

We share limited personal data with third parties who support our website, security, analytics, and advertising (if consented). These parties act as processors or independent controllers depending on their tools and purposes. Typical recipients include:

We do not sell personal data. We instruct our providers not to use data collected via our website for their own independent commercial purposes unrelated to providing the contracted services to us. Where required, we execute appropriate data processing agreements and provide only the minimum data necessary.

7 — International Data Transfers

Because some providers are located outside the EEA/UK (including the United States), personal data may be transferred internationally. Where applicable, we rely on the EU‑US Data Privacy Framework (and the UK/Swiss extensions) for certified providers. If a provider is not certified or a different route is appropriate, we use the European Commission’s Standard Contractual Clauses (SCCs, 2021/914) or the UK IDTA as a fallback, together with supplementary measures as needed. You can contact us for more information about relevant safeguards.

8 — Retention Periods

9 — Your Rights

If you reside in the EEA (including Norway) or UK, you may have the following rights under GDPR/UK GDPR, subject to conditions and exemptions:

To exercise your rights, email [email protected] with enough detail for us to verify your identity and understand the request. We aim to respond within 30 days, extendable by up to 60 days for complex requests. You also have the right to lodge a complaint with your supervisory authority. In Norway, the supervisory authority is the Norwegian Data Protection Authority (Datatilsynet).

10 — Children’s Privacy

Our website and services are not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us data without verifiable parental consent, please contact us and we will delete the information promptly.

11 — Do Not Track

Some browsers offer “Do Not Track” (DNT) signals. Our website does not currently respond to DNT signals. Third‑party providers referenced in this policy may have their own DNT handling statements and mechanisms. Consent controls on our site govern whether analytics and marketing technologies load.

12 — Account and Data Deletion Requests

We do not provide end‑user accounts on this website. To request deletion of personal data we hold about you (for example, messages you sent or contact details), email [email protected] with the subject “Data Deletion Request”. Once we verify your identity, we will complete the request within 30 days unless a longer period is legally required. We may retain limited information where necessary for legal obligations or to establish, exercise, or defend legal claims.

13 — Business Transfers

If Sotra Link AS is involved in a merger, acquisition, asset sale, financing, reorganization, or insolvency event, personal data may be transferred to a successor entity as part of the transaction. If such a transfer materially changes the purposes for which your data is used, we will provide a notice on our website and, where required, seek your consent.

14 — California (CCPA/CPRA)

While our primary service market is Canada and we are established in Norway, the site may receive visits from California residents. Under the California Consumer Privacy Act (as amended by CPRA), the following categories of personal information may have been collected and disclosed to service providers for business purposes during the past 12 months: identifiers (name, email, IP address, device identifiers), internet/network activity (pages viewed, interactions), and inferences (interests, preferences) for advertising where consented. We do not sell personal information. We may “share” personal information for cross‑context behavioral advertising only when you have opted into marketing cookies via our consent controls. California residents can exercise rights to know, delete, correct, and opt‑out of sale/sharing by emailing [email protected] with the subject “California Privacy Request”. We may need to verify your identity and, if using an authorized agent, receive proof of authorization.

15 — Virginia (VCDPA)

For Virginia residents, the Virginia Consumer Data Protection Act grants rights to access, correct, delete, and obtain a copy of personal data, and to opt out of targeted advertising. We do not sell personal data or engage in profiling that produces legal or similarly significant effects. Requests may be sent to [email protected] with the subject “Virginia Privacy Request”. If we decline a request, you may submit an appeal within 60 days by emailing us with the subject “Appeal of Refusal — Privacy Request”. Unresolved concerns may be raised with the Virginia Attorney General.

16 — Nevada

Nevada residents may submit a verified request directing us not to sell certain personal information. Although we do not sell personal information as defined under Nevada law, you may email [email protected] with the subject “Nevada Do Not Sell Request”.

17 — Security

We implement administrative, technical, and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. Measures include HTTPS/TLS encryption, access controls, least‑privilege principles, and periodic reviews. No method of transmission or storage is completely secure; however, we work to reduce risk systematically and address issues promptly if identified.

18 — Changes to This Policy

We may update this Privacy Policy from time to time to reflect operational or legal changes. Material changes will be announced via a site notice at least 14 days before they take effect, unless immediate changes are required by law or security concerns. The “Last Updated” date at the top of this page reflects the most recent revision.

19 — Contact

If you have questions, want to exercise your rights, or wish to make a complaint, please contact us:

You also have the right to contact your local supervisory authority. In Norway, this is the Norwegian Data Protection Authority (Datatilsynet). We prefer to resolve concerns directly and will do our best to respond quickly and thoroughly.