Privacy policy

Last updated 26 September 2026. This policy explains which personal data we process when you use ipmanager.no, and what rights you have.

Controller

Webspesialisten AS, organisation number 894 785 942, Oslo, Norway, is the controller for data about the users of the service. Contact us at info@ipmanager.no.

Two roles

  • Controller for data about accounts and use of the service: names, email addresses, sign-ins and similar.
  • Processor for the data the customer itself registers in the IP inventory, such as hostnames, MAC addresses and the names of equipment owners. There the customer is the controller, and we process the data only to provide the service. The terms and this policy constitute the data processing agreement. Contact us if you need a separate, signed agreement.

Data we process

CategoryExamplesPurposeLegal basis
AccountFirst name, last name, email, company, role, languageCreating and running the accountContract (Art. 6(1)(b))
Sign-inPassword hash, 2FA secret, hashes of recovery codesSecure sign-inContract
SessionsIP address, browser, timestampsKeeping you signed in, detecting abuseLegitimate interest (Art. 6(1)(f))
Audit logWho did what, when, from which IP and browserTraceability for the customer and securityContract and legitimate interest
API keysName, last use, IPOperations and securityContract
Service emailsRecipient, content of service messagesSign-in, password reset, notices of changesContract
Server logsIP address, time, requested URLOperations, troubleshooting and securityLegitimate interest

We do not send newsletters or marketing without consent, and we never sell data.

Cookies

We use only one necessary cookie, ipm_session, which keeps you signed in. We use no analytics, tracking or advertising, and therefore show no consent banner.

Storage and subcontractors

  • The service and database run on servers in Norway.
  • Emails from the service are sent through our email provider.
  • We do not transfer personal data to countries outside the EU/EEA.

How long do we keep data?

  • Account data is kept as long as the account exists and deleted within 30 days after the organisation is terminated.
  • The audit log is part of the customer's documentation and is kept as long as the organisation exists.
  • Sessions expire after 14 days of inactivity.
  • Server logs are kept for a short time, only as long as needed for operations and security.
  • Backups are deleted in line with our backup routine.

Your rights

You have the right of access, rectification, erasure, restriction and data portability, and the right to object to processing based on legitimate interest. Contact us at info@ipmanager.no. If the request concerns data a customer has registered in the IP inventory, we forward it to the customer.

If you believe we process data in breach of the rules, you can complain to the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no) or the supervisory authority where you live.

Security

See the security page for the measures we take to protect data.

Changes

We update this policy when needed. Material changes are announced by email to the organisation's owners.