Skip to main content
Note! These pages are generated automatically. The content may be incomplete or wrong, screenshots and videos especially. See About these help pages. We would really like your input: reach us through "Did you find what you were looking for?" at the bottom of the page, the chat at bottom right, or support@placepoint.no - we answer as fast as we can!

Privacy and data processing

These are the answers procurement, legal and data protection officers ask for before an agreement: which roles we have under the General Data Protection Regulation (GDPR), when you need a data processing agreement, where the data is stored, which sub-processors we use, and what happens when an AI tool fetches data from Placepoint.

Send any questions not answered here to support@placepoint.no.

Roles under the GDPR​

Is Placepoint a controller or a processor?​

Both, for different types of data.

  • For the property and company data we collect and pass on, including data from grunnboken (the land register), the matrikkel (the cadastre) and Brønnøysundregistrene (BRREG), we are an independent controller under GDPR Article 4(7). We decide the purpose and means of the collection, and you receive the data from us. This is not a processing assignment, and it does not give you the right to instruct us about the register data. Integration and security shows which fields in the delivery are personal data.
  • For data you enter in Placepoint yourself, such as your own datasets, projects, notes, tags and what you type in a search or lookup, you are the controller and we are the processor under Article 4(8). We process this data only to deliver the service to you.
  • For information about you as a user, such as your name, email address, phone number and login and usage data, we are the controller. This is described in the privacy policy.

For your part, you are the controller for how you go on to use the register data. This applies whether you fetch it in Fusion, through the Placepoint API or through an AI tool. If you pass it on to others, the rules in Disclosure of PII to third parties apply.

Why is the register data not a processing assignment?​

Because we do not process it on your behalf. We fetch grunnbok, matrikkel and company data from the sources, combine it and offer it to all our customers on the same terms. A data processing agreement for the register data would give each customer the right to instruct us about, and delete from, a shared dataset, and that is not possible. Instead, disclosure takes place under our agreement with Kartverket and within section 4 of the regulations on disclosure, reuse and other processing of information from grunnboken and the matrikkel. These regulations also require you, as the recipient, to have a legitimate need.

Data processing agreement​

Do I need a data processing agreement with Placepoint?​

Yes, if you enter personal data in Placepoint. In practice you do this when you upload your own datasets with names or contact details, use Placepoint Dataset MCP with your own projects, order an extract where you send us personal data as a key, or type a national identity number in a lookup. We then process the data on your behalf, and GDPR Article 28 requires a written agreement before processing starts.

The personal data fields in the Placepoint API also require a data processing agreement. If you only use the register data and the map, you do not need a data processing agreement for that. Many customers sign one anyway because procurement asks for it, and that is fine.

What does the Placepoint data processing agreement contain?​

We have a template reviewed by lawyers, based on Article 28, with four appendices:

  • Appendix A: what is processed, which categories of data subjects it covers, and the purpose.
  • Appendix B: our sub-processors, with service and country.
  • Appendix C: the instructions for the processing.
  • Appendix D: change log.

The agreement limits the assignment to the data you enter yourself. The register data is outside its scope, for the reason described above. Ask your contact person or support@placepoint.no for the agreement, and we will fill in the appendices together.

Can I use my own data processing agreement?​

Yes. We are happy to fill in your template, and have done so for municipalities, banks and insurance companies. We ask for two things in any template: that register data from the matrikkel, grunnboken and the company register is delivered by us as an independent controller and is not covered by the agreement, and that the list of sub-processors is the one we publish in the docs, so it can be kept up to date without a new round of signatures.

Storage and operations​

Where is the data stored?​

In Microsoft Azure in the Norway East region, with a replicated copy in Norway West. This covers the register data, the map layers, the user database and any datasets you upload. Some supporting services, such as error logging and the customer system, are run by suppliers with servers in the EU or the USA. The list of sub-processors shows which suppliers these are, what they process and which transfer mechanism applies.

What personal data does Placepoint process about users?​

Name, email address and phone number linked to the account, which organisation the user belongs to, and logs of logins and usage. The usage log is what lets us document who has seen which personal data, which we are required to do for data from grunnboken. It is also why each person must log in with their own account.

How is the data secured?​

  • Each user has a personal account, and access to personal data is set per account after a specific assessment of the legal basis for processing.
  • Login from countries outside the EU/EEA is blocked. See Access outside the EU/EEA.
  • All traffic is encrypted with TLS, and the databases are encrypted at rest with Azure's standard encryption.
  • Production data is replicated to another Azure region, and access to it is limited to named operations staff.
  • Events in the platform are logged, so we can trace who has done what.

If procurement needs a completed security description or a supplier questionnaire, send it to support@placepoint.no.

What happens in a security breach?​

When we discover a breach affecting data we process for you, we notify you in writing without undue delay. We tell you what happened, which data is affected and what we are doing. This gives you a basis for your own assessment under GDPR Article 33. The contact point is given in the data processing agreement.

How long does Placepoint store the data?​

Your own datasets, projects and notes stay until you delete them yourself or the agreement ends. When the agreement ends, we delete or return the data as the data processing agreement specifies, and confirm this in writing. Information about users is stored for as long as the customer relationship lasts, and after that for as long as accounting and contract rules require.

Placepoint AI and your own datasets​

Who is the controller when an AI tool fetches data from Placepoint?​

You are. Placepoint AI consists of MCP servers that answer lookups from the AI tool you have chosen, using your login and your access level. This applies to every server we offer, including future ones. The servers contain no language model, and we send no data to an AI provider. The AI tool fetches data from us on your behalf, and you decide which tool is used, which questions are asked and what the answers are used for. This makes you the controller for what happens in the AI tool, and your agreement with the AI provider governs storage, location and any training there.

This is not joint controllership under GDPR Article 26, because we decide neither the purpose nor the means of the processing in the AI tool. Our responsibility ends with what happens in our own systems.

What personal data can an AI tool get from Placepoint?​

Less than in Fusion. Placepoint MCP removes the names and national identity numbers of private individuals before the answer leaves us, and shows them as Private person, whatever access your account has otherwise. The extended access some customers have through a documented legitimate interest applies in Fusion, not in Placepoint AI. This is data minimisation under GDPR Article 5(1)(c) and data protection by design under Article 25. We chose it because the data ends up in a tool we do not control. The personal data that remains is already public: names of role holders in companies from Brønnøysundregistrene, that is the general manager and the board, and names and years of birth of shareholders from Aksjonærregisteret (the shareholder register), which Skatteetaten (the Norwegian Tax Administration) publishes. Shareholders are shown as Private person until the AI tool asks for names. National identity numbers are never delivered. Details: Personal data is not available.

What about datasets I upload through Dataset MCP?​

They are handled the same way as when you upload them in Fusion: they are stored with us in Azure Norway East, are visible only to users you have given access to the project, and are covered by the data processing agreement. You decide what you upload and whether it contains personal data. If it contains personal data, the data processing agreement must be in place first.

Does Placepoint use the data to train models?​

No. We do not train any models on customer data or usage data, and we do not share it with third parties beyond the operations suppliers in the list of sub-processors. If the AI tool you have chosen uses data for training, that is governed by your agreement with that provider, not by us.

Does the same apply to the Agent in Fusion?​

The Agent runs in Fusion with your login and follows your access level in the platform, as the Agent page describes. It is in pilot, and we enable it per organisation.

For procurement and data protection officers​

What can I ask Placepoint for?​

  • Our data processing agreement, or a completed version of your own template.
  • The list of sub-processors, with service, country and transfer mechanism.
  • The privacy policy and the terms of use.
  • A description of the security measures, or answers to a supplier questionnaire.
  • An account of which personal data is included in the delivery. See Integration and security.

Who is the contact point for privacy?​

support@placepoint.no. Your enquiry goes to the right person at Placepoint, and we answer requests for access, rectification and erasure within 30 days, as the privacy policy describes.

I am listed in grunnboken or the company register. What does Placepoint hold about me?​

What the sources have registered: for a title holder, name, year of birth and ownership share from grunnboken; for a role holder, name and role from Brønnøysundregistrene. We do not collect more about private individuals than what is in the sources, and we show private individuals as Private person to customers without a documented legitimate interest. If you want to know what is registered about you, or think something is wrong, contact us at support@placepoint.no. Errors in the source are corrected by Kartverket or Brønnøysundregistrene (BRREG), and the correction reaches us at the next update.

Sub-processors​

These are the suppliers we use to operate Placepoint, which therefore process personal data on our behalf. The data processing agreement refers to this list, so we keep it up to date here.

Last updated 07/10/2026.

VendorServiceProcessesCountry and regionTransfer mechanism
Microsoft Ireland Operations Ltd. (Azure)Hosting, databases, storage, login (Entra)All data in the platform, including your own datasets and the user databaseNorway, Norway East with a replica in Norway WestEEA
PostHog Inc. (EU service)Product analytics and feature management in FusionUser ID, events in the interfaceEU, GermanyEEA
Mixpanel Inc. (EU service)Usage analyticsUser ID, events in the interfaceEUEEA
Better Stack GmbHOperations log for the servicesUser ID, tenant ID, requests to the servicesEU, GermanyEEA
Twilio SendGrid (EU service)System email, such as invitations and notificationsName, email address, content of the notificationEU, GermanyEEA
Functional Software Inc. (Sentry)Error loggingUser ID, email address, IP address, error messagesUSAEU-US Data Privacy Framework
HubSpot Inc.Customer system, support chat and emailName, email address, phone number, enquiriesUSAEU-US Data Privacy Framework
Slack Technologies LLCMirroring of support chat to the support teamThe content of chat enquiriesEUStandard contractual clauses

What is not in the list​

Our data suppliers, such as Kartverket, Brønnøysundregistrene (BRREG) and the others on the supplier pages, are sources we fetch data from, not processors for us. They do not process any information about users or your datasets.

Map and analysis services, such as travel time and background maps, receive the coordinates and addresses in the lookup, not who asked.

You choose the AI tool you connect Placepoint AI to, and it is covered by your agreement with that provider. For the reason why: Placepoint AI and your own datasets.

See also: Integration and security, Account and login, Data and sources, Map and properties, Placepoint AI, Data processing agreement (glossary), GDPR (glossary).

Note! These pages are generated automatically. The content may be incomplete or wrong, screenshots and videos especially. See About these help pages. We would really like your input: reach us through "Did you find what you were looking for?" at the bottom of the page, the chat at bottom right, or support@placepoint.no - we answer as fast as we can!