01Data controller
The data controller is Jon Marius Nilsson (sole proprietorship), Norwegian organisation number 991 578 307. Mekanismer is the name of the service.
- Office address: Schweigaards gate 34, 0191 Oslo, Norway
- Postal address: Alunsjøveien 34D, 0957 Oslo, Norway
- Email: post@mekanismer.no
Questions about privacy, and all requests concerning your rights, should be sent to the email above.
02Who this policy covers
We distinguish between three situations:
- Visitors to mekanismer.no. Here Mekanismer is the data controller.
- Customers and users of the CMS and portal (the businesses we serve and the employees they give access). Here Mekanismer is the data controller for accounts, sign-in, billing and the customer relationship.
- Our customers' own websites (for example a restaurant we have built a website for). There the customer is the data controller and Mekanismer is a data processor under a data processing agreement. Each customer website has its own privacy policy explaining what that site collects. Questions about a customer website should first be directed to the business that owns it.
03Visitors to mekanismer.no
The contact form («Start et prosjekt», start a project)
When you submit the form, we store your name, email address, phone number if you provide it, and your message. We also send an email notification to ourselves with the content, so we can reply. The purpose is to answer your enquiry and, where relevant, give you an offer. The legal basis is our legitimate interest in answering enquiries and steps taken at your request before entering into a contract (GDPR Article 6(1)(f) and (b)).
To prevent abuse, we limit the number of submissions per IP address. The IP address is held in memory for a few minutes for this purpose only and is not stored with your enquiry.
No analytics or tracking on mekanismer.no
We use no analytics tools, advertising pixels or tracking cookies on mekanismer.no. The activity display on the front page shows aggregated, anonymous activity from the platform and collects nothing about you.
Cookies
We only set cookies that are strictly necessary for the service to work:
- Sign-in session (
payload-token): set when you sign in, lasts 24 hours. - Passkey challenge (
mek-passkey-challenge): short-lived, during sign-in only. - Connection state (
verif_oauth): set only for signed-in customers when they connect Google, lasts 10 minutes and protects against forged requests.
Strictly necessary cookies do not require consent (section 3-15 of the Norwegian Electronic Communications Act).
Technical logs
Our hosting provider (Vercel) logs technical information such as IP address, time and the page requested, for operations, troubleshooting and security. The logs are deleted automatically after a short period. The legal basis is our legitimate interest in a secure and stable service (Article 6(1)(f)).
04Customers and CMS users
Accounts and sign-in
For each user we store name, email address, role and which websites the user has access to. Sign-in is passwordless:
- Passkey: we store only the public key and technical information about it. Your fingerprint, face or PIN never leaves your device, and we never have access to it.
- Email sign-in link (magic link): the link is valid for 15 minutes and can be used once. We store only a hash of it.
Sign-in attempts are rate limited per IP address to prevent abuse. The legal basis is the contract with the customer (Article 6(1)(b)) and, for the customer's employees, our and the customer's legitimate interest in giving them secure access (Article 6(1)(f)).
Content entered by the customer
Text, images, videos, menus and other content the customer publishes is stored in order to display it on the customer's website. If the content contains personal data, the customer is responsible for it being lawful.
Billing
To invoice, we store company name, organisation number, contact person, email and billing address. Invoices are created in the accounting system Fiken. The legal basis is the contract and our statutory bookkeeping obligation (Article 6(1)(b) and (c), the Norwegian Bookkeeping Act).
Emails we send
We send emails needed for the service: sign-in links, notifications about forms submitted on the customer's website, operational alerts, receipts and invoices. We do not send newsletters or marketing unless you have asked for it. Emails are sent through Resend.
Translation and assistants
Customers can have their content translated automatically. The text to be translated is then sent to Anthropic (Claude). Email sent to our assistant addresses is processed the same way to draft a reply or carry out the task. Anthropic does not use this data to train its models.
05Analytics and tracking
On mekanismer.no there is no analytics or tracking (see above).
On our customers' websites we provide visitor statistics on behalf of the customer, as a data processor. The statistics work without cookies and without identifying the visitor:
- We record which page was viewed, the referring page, campaign tags (UTM), country, device type, language and events such as «form submitted».
- Unique visits are counted using a salted hash of IP address and browser that changes every day. The IP address is never stored, and it is not possible to follow a person from one day to the next.
- The data is stored with Tinybird in the EU.
The customer may also enable advertising measurement (Meta Pixel, Google Analytics, Google Tag Manager and Meta's Conversions API). It loads only after the visitor has accepted in the consent banner on the customer's website, and is described in that website's own privacy policy.
With the Conversions API, the platform reports a booking or purchase to Meta directly from the server, in addition to the pixel in the browser. Only after the visitor has accepted, the IP address, the browser (user agent) and Meta's own cookie IDs (_fbp and _fbc) are then sent together with the page address, the time, a random event code and, where relevant, the purchase amount. We store none of this.
06Google and Meta
Advertising measurement on the customer's website is set up by the customer pasting their own IDs into the portal (Meta Pixel ID, Google Analytics measurement ID, Google Tag Manager ID and the token for Meta's Conversions API). This requires no connection to the customer's Google or Meta accounts. We do not fetch any advertising or analytics figures from Meta, Google Analytics or Google Ads; the customer sees them in their own accounts there. The Conversions API token is stored with the customer's setup and is read only by our servers. The customer also pastes in Meta's domain verification code themselves, and we place it on the customer's website.
To verify the website, the customer may connect their own Google account to the platform in the portal. This is done with OAuth: the customer signs in with Google, sees which permissions we request and approves them there. We never receive the password. Mekanismer may also do the same with its own Google account, which is then listed as an owner of the website in Search Console.
What we receive and store
- Access tokens (OAuth tokens). They are stored encrypted with AES-256-GCM, never leave our servers and are never shown to anyone.
- Who connected: the account ID, name and email address of the Google account, and which permissions were granted. This is needed to know who the connection belongs to.
What we use the access for
- Website verification: with Google's Site Verification API we fetch a verification code, place it on the customer's website and confirm ownership. With the Search Console API we add the website to Search Console and submit the sitemap.
- Search performance: every night we fetch aggregated search performance data from Search Console (clicks, impressions and position per day, query, page, device and country, the first time going back 90 days) and show it in the customer's statistics. The figures are aggregated and contain no information about individuals.
The legal basis is the contract with the customer (Article 6(1)(b)): the connection is a feature the customer chooses to enable.
What we do not do
- We do not sell data or share it with advertisers or data brokers.
- We do not use the data for our own advertising or marketing.
- We do not use the data to train AI models.
- We do not use one customer's data for the benefit of another customer.
Disconnecting
The Google connection for website verification is disconnected in the portal, under Annonsesporing (ad tracking). We then delete the access token immediately and revoke the access with Google (token revocation). If the same Google account is connected to another of the customer's websites, we delete only the token for this website, so the other connection keeps working. You can also revoke access yourself in your Google Account.
When the customer relationship ends and the account is deleted, any remaining tokens are deleted automatically along with it.
Step by step, and how to request full deletion: see data deletion.
07Google API: Limited Use
Mekanismer's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice, this means that data we receive from Google:
- is used only to provide and improve the features the customer has enabled, as described above;
- is not transferred to others, except as necessary to provide these features (our sub-processors for hosting and storage), to comply with applicable law, or as part of a merger, acquisition or sale of the business;
- is not used for advertising, is not sold and is not used to determine creditworthiness;
- is not read by humans, except with the customer's consent for a specific matter (for example troubleshooting), when necessary for security purposes (for example investigating abuse), or when required by law.
08Sub-processors
We use the following providers to run the service. They process data on our behalf under data processing agreements and receive only what they need for their task.
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Hosting of mekanismer.no, the CMS and customer websites | EU (Frankfurt), US company |
| Supabase | Database for content, users, forms and connections | EU |
| Cloudflare (R2, Stream) | Storage and delivery of images and video, image processing | Global network, US company |
| Resend | Sending and receiving email | USA |
| Anthropic | Content translation and email assistants | USA |
| Tinybird | Cookieless visitor statistics for customer websites | EU |
| Fiken | Accounting and invoicing | Norway |
Some customer websites also use services chosen by the customer, for example Vipps and Mollie (payments), Bring (shipping) and PowerOffice (accounting) for an online shop, or Google and Tripadvisor to display public reviews. These are listed in the customer website's own policy. The current list of sub-processors for customer websites is available (in Norwegian) at mekanismer.no/underdatabehandlere.
Transfers outside the EEA
We store data in the EU wherever possible. Where a provider is established in the United States or may access data from there, transfers are based on the EU-U.S. Data Privacy Framework where the provider is certified, and otherwise on the EU Standard Contractual Clauses, with supplementary measures such as encryption.
Google and Meta are not our sub-processors. When a customer connects Google, we fetch data from the customer's own account there, and Google's and Meta's processing is governed by their own terms and privacy policies.
09Retention
We do not keep data longer than we need it:
| Data | How long |
|---|---|
| Contact form enquiries | As long as we follow up the enquiry. If it does not lead to a customer relationship, we delete it no later than 12 months after the last contact. |
| User accounts and passkeys | Until the user or customer deletes the account, or the customer relationship ends. |
| Sign-in link | 15 minutes, and invalid as soon as it has been used. |
| Sign-in session | 24 hours. |
| Google access tokens | Until the customer disconnects, or the customer relationship ends. |
| Search performance data from Search Console | As long as the customer relationship lasts. Deleted when the account is deleted, or earlier if the customer asks. |
| Visitor statistics for customer websites | As long as the customer relationship lasts. Contains no personal data. |
| Accounting records and invoices | Five years after the end of the financial year, as required by the Bookkeeping Act. |
| Technical logs | A short period, according to the hosting provider's fixed log retention. |
When a customer relationship ends, the customer can have their content exported. We then delete the customer's data, except what we are required to keep by law.
10Security
- All traffic is encrypted over HTTPS.
- Sign-in is passwordless, using a passkey or a one-time link.
- Google access tokens are encrypted with AES-256-GCM, and the encryption is bound to the individual customer and service.
- Access is role-based, and each customer sees only their own data.
- Forms and sign-in are protected against abuse with rate limiting.
11Your rights
Under the General Data Protection Regulation (GDPR) you have the right to:
- access the data we hold about you and receive a copy;
- have inaccurate or incomplete data corrected;
- have data erased when we no longer have a reason to keep it;
- object to processing based on legitimate interest;
- have processing restricted in certain cases;
- receive data you have provided to us in a machine-readable format (data portability).
Send an email to post@mekanismer.no. We respond within 30 days. If the request concerns a customer's website, we forward it to the customer, who is the data controller there.
If you believe we process data in breach of the rules, you can lodge a complaint with the Norwegian Data Protection Authority, Datatilsynet. We would appreciate it if you contact us first so we can put things right.
12Changes and contact
We update this policy when the service changes. The date at the top shows when it was last changed. We notify customers by email of material changes.
See also our Terms of Service and data deletion instructions. Denne erklæringen finnes også på norsk.