Effective date: 10 August 2026
This Privacy Policy explains how Etain AS, a Norwegian limited liability company with registration number 920 998 704, having its registered address at Drammensveien 123, 0277 Oslo, Norway (“Etain”, “we”, “us”) handles personal data in connection with the Etain Platform, including Intelligent Workspaces and associated support and service operations (the “Service”).
This Policy should be read with the applicable Customer Terms, User Terms, Data Processing Agreement (the “DPA”), Service Level Policy, and any Order Form. Where Etain processes personal data contained in a customer workspace on a customer’s behalf, the DPA and the relevant customer’s instructions govern that processing.
Etain’s role depends on the category of personal data concerned.
Customers and workspace owners control the data, files, documents and other content uploaded to, generated in, or otherwise made available through their workspace (“Workspace Owner Data” or “Customer Data”). Where that data contains personal data, the relevant customer or workspace owner is normally the controller, and Etain acts as its processor. Etain processes that data only to provide, secure, maintain and support the Service, in accordance with the customer’s documented instructions, the DPA and applicable law.
If you are a user of a customer workspace, questions or requests concerning personal data in that workspace, including requests for access, correction or deletion, should normally be sent to the relevant workspace owner or customer.
Etain acts as an independent controller for personal data it processes for its own legitimate business purposes, such as account administration, customer relationship management, billing, security, compliance and Service telemetry, subject to applicable law.
Depending on how the Service is used, Etain may process the following categories of personal data:
Usage Data does not include workspace inputs, outputs or Customer Data, except where such data has been aggregated or de-identified.
Etain processes personal data only where a valid legal basis applies. Depending on the context, these are:
We use Workspace Owner Data only as necessary to provide the Service and as instructed by the relevant customer, including to:
Etain does not use Customer Personal Data to train, retrain or improve general-purpose or multi-tenant AI or machine-learning models, and does not permit its sub-processors to do so, unless the customer has expressly agreed in writing. This does not prevent transient processing required to produce a requested output, customer-instance-specific contextual processing, or processing required to provide and secure the Service.
Etain may use data in an aggregated and de-identified form that does not identify a customer or individual for lawful internal purposes, such as analytics, benchmarking, service improvement, product development and statistical analysis.
The Service may use artificial intelligence and machine-learning technologies to analyse information, generate context and produce outputs. AI processing of Workspace Owner Data occurs on behalf of, and under the instructions of, the relevant customer.
AI-generated outputs are probabilistic and may be inaccurate, incomplete or misleading. They are provided for informational and assistive purposes and must be reviewed and validated by a person before they are relied upon. The Service does not provide legal, financial, regulatory or other professional advice.
We do not sell Workspace Owner Data. We may disclose personal data only as necessary and permitted by applicable law, including to:
Etain will not transfer Customer Personal Data outside the EU/EEA without the relevant customer’s prior written consent where required under the DPA. Where a transfer is permitted, Etain will ensure that an appropriate transfer mechanism and supplementary safeguards are used where required by applicable data-protection law.
Etain implements planned and systematic technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include access controls and a need-to-know approach for personnel, confidentiality obligations, security reviews and controls, and operational backup and recovery arrangements. No method of transmission or storage is completely secure, but we work to maintain a level of security appropriate to the risk.
If Etain becomes aware of a personal data breach affecting Customer Personal Data, we will notify the relevant customer without undue delay and provide information reasonably required for the customer to meet its notification obligations. We will cooperate with the customer on reasonable investigation, mitigation and remediation steps.
We retain personal data only for as long as necessary for the purposes described in this Policy, to provide the Service, comply with legal obligations, resolve disputes and enforce agreements.
Upon cessation of services involving Customer Personal Data, Etain will delete Customer Personal Data in accordance with the DPA, normally within 10 business days. Data in backup files may be retained for up to 90 days following a deletion request. Limited data may be retained where required by law or necessary to establish, exercise or defend legal claims; such data remains protected and is not actively processed for other purposes.
Customers may request a copy of Customer Data stored by Etain in accordance with their agreement and the applicable DPA.
Subject to the conditions and limits in applicable law, individuals may have rights to request access to, rectification or erasure of personal data; restriction of or objection to processing; data portability; and withdrawal of consent where processing is based on consent.
For Workspace Owner Data, please contact the relevant customer or workspace owner first, as that organisation controls the data and is responsible for responding to requests. Etain will assist customers with such requests as required by the DPA and applicable law.
For personal data for which Etain is the controller, contact us using the details below. You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) or another competent supervisory authority.
We may update this Privacy Policy from time to time to reflect changes in the Service, our processing practices or applicable law. We will publish the updated version with a revised effective date and, where required, provide additional notice.
For questions about this Privacy Policy or Etain’s processing of personal data, please contact:
Etain AS
Drammensveien 123, 0277 Oslo, Norway
Email: info@etain.no
If Etain has appointed a data protection officer or EU/EEA representative for a particular processing activity, the applicable contact details will be made available here or in the relevant customer documentation.