Integration and security
For a developer overview of all APIs (Customer API, Matching API, Embed Service, Data API, PropCloud Public + Private): docs.placepoint.no/developer.
Can we integrate Placepoint with our own systems?
Yes. There are two ways in:
- Placepoint Data API - a unified gateway over PropCloud + Newsec + 3-core. 192 endpoints, grouped by tag (property, company, valuation, listings, risk, geo, search, person, plans, energy, se-properties, se-companies, ai, usage, resolve). Use this when you want to pull structured property and risk data straight into a CRM, BI tool or risk system.
- PropCloud data feeds + API - property and risk data streamed into the customer's own systems. Typically used by insurance companies for risk pricing, banks for credit assessment, and enterprise customers with automated data flows.
Other APIs on the same portal: Customer API, Matching API, Embed Service, PropCloud Public.
Get in touch at support@placepoint.no for access keys and a demo.
How do we get started with API access?
API access is managed from the API access panel in Placepoint, which administers the machine clients that read data on the user's behalf. Users with the right licence can generate a client ID and secret to integrate Placepoint with their own systems, data warehouses or automated reports. Detailed instructions and endpoints are in the developer portal: docs.placepoint.no/developer.
If you need API access that is not enabled yet, contact support@placepoint.no.
What about data security and privacy?
Placepoint is the data controller under the GDPR and has a full privacy notice describing which data is collected, why, and what rights users have. We enter into data processing agreements with third-party suppliers that process personal data on our behalf. As a user, you have the right to access, rectification, erasure and data portability.
Send privacy questions to support@placepoint.no.
What is PII, and how does Placepoint handle personally identifiable data?
PII (personally identifiable information) is information that can be linked to an individual. In a Placepoint context, this typically covers name, address, national identity number or D number, email address and phone number.
Placepoint is the data controller for such data under the GDPR and the Norwegian Personal Data Act. In transaction data, private individuals listed as owners are anonymised as Private person to protect their privacy. Professional users with a documented "legitimate interest" (estate agents, lawyers, insurance and credit businesses) can still be granted access to see the identity, enabled per customer after a specific assessment.
More: Data and sources: privacy in owner and transaction data, Account and sign-in.
Personal data in what Placepoint delivers
The fact that Placepoint does not require personal data for ordinary lookups does not mean the delivery is free of it. The following fields are personal data when the party is a natural person, and they are the part of the delivery that requires a legal basis for processing on your side:
- Registered owner and ownership share on a matrikkelenhet
- Buyer and seller in registered transactions
- Name and contact details linked to an address
- Role holders in businesses
Private individuals in transaction data are shown as Private person on standard access. National identity numbers and D numbers are not delivered through the API. In Grunnboken extracts retrieved via the MCP server, personal names and national identity numbers are removed automatically, and the agent panel follows the access level of your sign-in.
Access to the fields above is set per customer after a specific assessment of purpose and legal basis. That is also why each person signs in with their own account: access is personal, not shared across the business.
Roles under the GDPR
Placepoint is the data controller for the property and company data we collect and pass on. We are not the data processor for information you hold yourself and do not send us.
If you send personal data into a call, for example a national identity number in a lookup or a bulk extract you order, we process it on your instructions. In that case we enter into a data processing agreement under GDPR Article 28. We have a lawyer-reviewed template ready, with appendices for the purpose of the processing, sub-processors, instructions and a change log.
Passing on matrikkel and Grunnboken data takes place under our agreement with Kartverket and within section 4 of the regulations on disclosure, reuse and other processing of information from Grunnboken and the matrikkel. Which information you can receive depends on which type of business you are under that provision.
Disclosure of PII to third parties
Handing over links between name, address and phone number to a commercial operator counts as a disclosure under the GDPR. This is not prohibited, but it requires that both Placepoint (as the discloser) and the recipient (which uses the data) have a valid legal basis for processing. The main requirements are:
- Legal basis: for marketing purposes, in practice you need consent or a documented legitimate interest assessment. The "necessary for a contract" basis is not sufficient.
- Purpose limitation: data collected for one purpose cannot simply be reused for another, for example as a marketing list for a third party.
- Duty to inform: the recipient must inform each data subject about the source, the purpose and their rights, within one month at the latest or at the point of first contact.
- Reservasjonsregisteret: for marketing by phone or addressed post to consumers, the list must be screened against Reservasjonsregisteret (the Norwegian marketing opt-out register) at least monthly. Marketing by email or SMS to consumers requires prior consent under section 15 of the Norwegian Marketing Control Act, with a narrow exception for existing customer relationships.
For purely B2B contact data (company address, role holder in a business), the threshold is generally lower, provided the legal basis is documented and the duty to inform is met.
Send questions about legal basis or disclosure to support@placepoint.no.
The EU and the EEA
See Account and sign-in for information about access to Placepoint outside the EU and the EEA.