Account and login

Everything about accounts, login, user management and access in Placepoint: why each person needs their own account, how you log in and solve common login problems, where you change your profile, how users are added, replaced and removed, and which rules govern who gets access to what.
Why must each person log in with their own account?
Access to some information in Placepoint is regulated by the GDPR, and users have different access levels. Some users can see PII (names, national identity numbers, contact details), others cannot. Who gets to see what is decided per account, after a specific assessment of the legal basis for processing.
If one login is shared between several people, this distinction breaks down: we lose control of who has actually seen which personal data, and whether that person had a basis for it. To make sure each person only gets the access he or she is entitled to under the law, we require everyone to log in with their own personal account. If you want to change who has access, see User management further down the page instead of sharing a login.
Placepoint logs all use of the service to make sure information does not go astray. Two mechanisms are important to know about:
SMS verification (two-factor)
At login we sometimes require a one-time code, which is sent by SMS to the phone number linked to the account. You enter the code to complete the login. This confirms that the right person is behind the account, not just someone who has got hold of an email address and password. The first time, you register your phone number yourself in the login flow.
The code comes from the sender "msverify" and looks like this:
Use verification code 194892 for geoappb2c authentication.


Once the number is confirmed with the code, it cannot be changed. If digits from a phone number that is not yours are shown, someone has logged in with your username and password and given their own phone number.
In some places the number is shown masked as XXX XXX XXX, which is the format used by Microsoft's login solution, even though Norwegian numbers have 8 digits.
One active session at a time
An account can only be logged in on one device at a time. If you log in on a new device while the account is already active somewhere else, you will see the existing session and must choose whether to take over. The message looks roughly like this:
You are already logged in on Chrome/132 · Macintosh from Oslo, Norway. IP address 84.211.42.10, last active 3 minutes ago. Do you want to end that session and continue here? The other device will be signed out.
If you choose to continue, the other device is logged out. If two people use the same account at the same time, they will throw each other out in turn.
How long does the login last?
Once you have logged in and confirmed with the one-time code by SMS, Placepoint keeps you logged in as long as you use the service regularly. You do not need to log in again every day.
- If you use Placepoint regularly, the login is renewed automatically, and the period is counted again from the last time you were active.
- If you are completely inactive for 7 days in a row, you must log in again.
- However active you are, you must log in again after 14 days at the latest. We then send a new one-time code by SMS.
Examples:
- You log in on Monday and visit Placepoint a couple of times a week. You stay logged in, because the 7-day period moves forward each time you are active.
- You log in just before a holiday and are away for two weeks. When you are back, you must log in again with a one-time code, because you were inactive for more than 7 days.
- You use Placepoint every day. After 14 days you are still asked to log in again with a one-time code, even though you have been active the whole time.
Login and password
Where do I change my name, email and notification settings?
In the Profile panel, which you open from the user icon at the bottom of the left menu. There you can see and edit:
- First name and Last name: shown on tags, activities and project shares you create.
- Email: the account identifier. You can see the address, but you cannot change it yourself. Contact support to change email.
- Email notification for tasks: an on/off switch for notifications when someone assigns you a task or a tag.
- Active membership: which organization the account belongs to.
Click Save to update. The updated name appears immediately in all panels and in the activity list.
I have forgotten my password, how do I set a new one?
Use the Forgot your password? link to the right of the password field on the login screen to set a new password by email. If the email does not arrive within a couple of minutes, check your junk mail folder.
If you still do not get the email, the address may be linked to an old account or to a different variant of the email. Contact support with the address you are trying.
Nothing happens when I click Log in
If nothing happens when you click Log in:
- Pop-up blocker. Login opens in a separate window. Allow pop-ups for
placepoint.noin your browser. - Cookies blocked. Placepoint needs cookies to keep the session. Allow third-party cookies or whitelist
*.placepoint.no. - Expired invitation. If you were just invited, check that the link in the email is not older than 14 days. Ask support to send a new invitation if it has expired.
- VPN or company firewall. Some organisations block the identity provider Placepoint uses. Ask your IT department to check.
If none of these help, see System Requirements.
I cannot log in, even with the correct email and password
- Check the email address carefully. Even if you have a
@bedriften.noaddress, the Placepoint account may be registered on a different variant. Check with your admin. - Check whether colleagues can get in. If no one in the organization can log in, there may be an ongoing fault. Contact support in chat.
- Turn off VPN temporarily and try again. If it works then, the problem is in the network or the proxy.
- Recently invited? Open the invitation link in the email before you go straight to the console. The account is activated the first time you follow the invitation.
- If you still cannot get in, contact support with the email address the account is linked to.
A new user has not received the invitation, what do we do?
- Check that the email address given to support is spelled correctly.
- Check the junk mail folder.
- Check whether the company email server quarantines unknown senders.
- Ask support to send the invitation again. The invitation link is valid for 14 days.
What is SSO, and how do we log in with it?
Organizations that have agreed SSO (Single Sign-On with Microsoft 365 or similar) log in via a separate button, not with email and password. If you do not see the SSO button but expect to use it, check with your IT department that the SSO agreement is activated.
User management
How do we add a new user?
New users are created by support. You cannot invite users yourself from the account settings. Send the email address of the new user to support, and we will send an invitation. The user sets a password at first login. The invitation link is valid for 14 days.
How do I replace a user who is leaving?
When a colleague leaves and a new person takes their place, there are two options:
- Change the email address on the existing account. This keeps tags, 3D models and shared resources linked to the original account. Done by support.
- Have a new user created via support and remove the old one. Data linked to the old account may disappear, depending on sharing settings.
For the least risky solution, contact support and ask for an email change on the existing account.
What happens when I remove a user?
When an account is removed:
- Access to Placepoint is withdrawn immediately.
- Personal tags and 3D models may disappear, depending on sharing settings.
- The licence is freed up for the organization.
To keep data from an account that is to be removed, do one of these before deletion:
- Change sharing from "only you" to "the whole organization" where relevant.
- Ask the user to export important tags and models.
- Ask support for help with a closing export.
See 3D and visualisation for what applies specifically to shared 3D models.
A user has left without being removed, what do I do?
If a user has left without the account being removed, the email address may become invalid while the account still has access to Placepoint. This is unfortunate both for security reasons and because Placepoint handles personal information from the Matrikkel. Remove or deactivate the account as soon as you become aware of it. If you are unsure whether an account is in active use, contact support; support can give you an overview of the last login for the users in your organization.
What does it cost to change the number of users?
Changes in the number of users affect the subscription. Contact support or your account manager before you add or remove licences on a larger scale.
Access outside the EU/EEA
Why can login from a country outside the EU/EEA be blocked?
The data in Placepoint comes from sources such as the Matrikkel, Grunnboken and Brønnøysundregistrene (BRREG). Some of this data contains personal data, including owner names linked to natural persons, and is subject to the GDPR.
Under GDPR chapter V, remote access from a country outside the EU/EEA counts as a transfer of personal data to a third country, even if the data is not physically moved out of Norway. As a general rule, countries outside the EU/EEA do not have an adequate level of protection under the EU's assessment, unless the European Commission has adopted an adequacy decision for the country in question.
For a transfer to be lawful, a transfer mechanism is required, for example standard contractual clauses (SCC) combined with a transfer impact assessment, see GDPR article 46. In addition, individual data providers may have their own terms that limit distribution outside certain geographical areas. This applies in particular to data from Kartverket and the Geovekst partnership.
If a login from an IP address outside the EU/EEA is detected, the account may be temporarily blocked. This is a security measure to comply with the regulations and the data providers' terms. The affected user is informed about the block and asked to contact support@placepoint.no. Explain which country the login came from and in what context, and we will assess the case individually.
Breaches of the GDPR can be punished with an administrative fine of up to 20 million euro or 4% of the organisation's total global annual turnover, whichever is higher. If a customer circumvents these blocks or breaches Placepoint's terms in another way, for example by giving someone outside the EU/EEA access without a lawful transfer basis, the customer is responsible for the breach and any fine.
Not all data is equally sensitive in this context:
- Non-personal data (boundaries, areas, building data, maps and statistics): fewer restrictions. Much of this is open data with low risk linked to geographical access.
- Personal data (owner names for natural persons): requires a lawful transfer basis for access from third countries.
- Building types that require protection: requires special permission from Kartverket and is linked to national security.
Can employees or partners outside the EU/EEA get access?
It can be arranged, but it requires a lawful transfer mechanism under GDPR article 46, and that the data providers' terms are complied with. This is not something Placepoint offers as a standard service today. If you have this need, describe it in an email to support@placepoint.no, and we will look at the options together.
See also: System Requirements, Help and support, Integration and security.