1. Introduction
Envra processes personal data when you visit our websites, create an account, use our services, or otherwise use the Envra platform.
This Privacy Policy explains what personal data we process, why we process it, the legal basis for processing, how the data is protected, how long it is retained, and your rights.
2. Roles and Responsibilities
Envra may act both as a data controller and a data processor.
Envra as Data Controller
Envra acts as data controller for information related to:
-
account and user management
-
subscriptions and billing
-
support and customer communication
-
security and abuse prevention
-
onboarding and communication
-
Envra-owned websites and services
-
documentation of legal acceptance
Envra as Data Processor
When customers use Envra for analytics, tracking, and reporting on their own websites or services, Envra processes data on behalf of the customer.
In such cases, the customer is normally the data controller and Envra acts as the data processor.
3. Personal Data We Process
We may process:
-
names
-
email addresses
-
phone numbers
-
company information
-
billing and subscription information
-
IP addresses
-
browser, device, and user agent information
-
visitor and session identifiers
-
page views and events
-
technical and security logs
-
UTM parameters and attribution data
-
performance metrics and error data
-
support inquiries
-
information about acceptance of terms and privacy policy
4. Analytics and Visitor Data
Envra may process analytics and visitor data, including:
-
page views
-
clicks and CTA events
-
form and conversion events
-
search events
-
scroll and engagement data
-
performance data
-
client-side errors
-
referrer data
-
campaign data
-
device, OS, and browser
-
geographic information based on IP
Such data is processed to provide customers with insights into the use of their own websites and services.
Envra may also use aggregated and anonymized analytics data for operations, statistics, security, capacity planning, and improvement of the service where permitted under applicable law.
5. Purpose of Processing
Personal data is used for:
-
providing the service
-
analytics and reporting
-
authentication and access management
-
security and abuse prevention
-
troubleshooting and performance improvements
-
onboarding and customer communication
-
billing and subscription management
-
documentation of legal acceptance
-
development of new features and services
6. Legal Basis
We process personal data based on:
Contract
When processing is necessary to provide the service, manage accounts, subscriptions, support, and customer communication.
Legal Obligation
When processing is necessary to comply with accounting, bookkeeping, or other legal requirements.
Legitimate Interest
When processing is necessary for secure operation, abuse prevention, technical stability, logging, support, and service improvement.
Consent
Where consent is required, for example for non-essential cookies, marketing, or certain third-party integrations.
7. Cookies and Tracking
Envra uses cookies, localStorage, sessionStorage, and similar technologies for:
-
authentication
-
session management
-
analytics and attribution
-
security and abuse prevention
-
improving the service
More information is available at /cookies.
8. Google and Microsoft Login
When using Google or Microsoft login, we receive information such as your name, email address, and unique identifier.
We do not receive your password.
Google and Microsoft act as independent data controllers for their authentication processing.
9. Sharing of Information
We share information with subprocessors and service providers where necessary to operate the service.
Relevant providers may include:
-
Hetzner
-
Stripe
-
Mailchimp
-
Google
-
Microsoft
-
OpenAI
- Runway
-
other relevant service providers
An updated list is available at /subprocessors.
We do not sell personal data.
10. Transfers Outside the EEA
Some providers may process data outside the EEA.
Such transfers are carried out in accordance with applicable regulations and appropriate safeguards, such as standard contractual clauses or equivalent mechanisms.
11. Security
We use organizational and technical security measures, including:
-
role and access management
-
site and company isolation
-
CSRF protection
-
rate limiting
-
security logging
-
password hashing
-
monitoring and abuse prevention
Security incidents are handled in accordance with applicable regulations.
12. Retention
Personal data is not stored longer than necessary for the relevant purpose.
Retention periods may vary depending on subscription plans and service types.
Analytics and event data is retained according to the applicable subscription plan, configuration, and retention policy.
Following subscription termination or cancellation, Envra may maintain a limited grace period during which historical data and settings are temporarily retained for possible service reactivation.
During the grace period, tracking and new data collection may be disabled or restricted.
If the subscription is not reactivated before the grace period expires, Envra may anonymize or deactivate data, identifiers, websites, and related resources in accordance with the applicable lifecycle policy.
Anonymization may include removal or nulling of identifying information, visitor and session identifiers, IP addresses, user agent data, and links between analytics events and customer/site identity.
Security and rate-limit logs are generally retained for limited periods.
Accounting and payment data is retained according to legal requirements.
Backup data may remain for a limited period after deletion before final overwriting.
13. Your Rights
You have the right to:
-
access
-
rectification
-
deletion
-
restriction
-
data portability
-
object to processing
-
withdraw consent
You may also file a complaint with the Norwegian Data Protection Authority.
14. Automated Decisions
Envra does not make automated decisions that have legal or similarly significant effects on you.
15. Contact
Envra AS
Organization no.: 937 896 131
Email: legal@envra.ai