Privacy Policy
Last Updated: March 12, 2026
1. Introduction and Controller Identity
This Privacy Policy explains how Fjord Barber Academy AS (“Fjord Barber Academy”, “we”, “us”, or “our”) collects, uses, discloses, and protects your personal data when you visit our website and interact with our services. It also describes your privacy rights and how Norwegian and European data protection laws apply to you. This policy applies to all visitors and prospective trainees who access our website and enquire about our barber courses delivered in Oslo, Norway.
Data Controller: Fjord Barber Academy AS, Torggata 13, Sentrum, 0181 Oslo, Norway. Contact email: [email protected]. Telephone: +47 22 33 45 60.
We primarily offer professional education and training. We do not process special-category data on a large scale. No Data Protection Officer is appointed at this time; privacy questions are handled by our management team at the contact details above.
2. Personal Data We Collect
Depending on your interactions with our site and services, we may collect the following categories of personal data:
- Identity and contact details: name, email address, phone number, city/region.
- Enquiry and form content: your message, course preferences, professional experience, and scheduling notes submitted via our contact form.
- Technical information: IP address, browser type and version, device/OS, language settings, and similar diagnostic data captured by our servers.
- Usage information: pages visited, time on page, referring/exit pages, scrolls and clicks, and interaction timestamps.
- Cookies and identifiers: essential cookies required for basic functionality, optional analytics cookies, and optional marketing identifiers (see Section 4).
- Conversion events: when you submit a form or complete other actions on the site, we record that event for internal reporting.
We do not intentionally collect special-category data (such as health data, religious beliefs, or political opinions), financial account details, or government identification numbers through this website. Please do not include such information in free-text fields.
3. Why We Process Data and Legal Bases
We process your personal data for the purposes and under the legal bases listed below (GDPR Article 6):
- Responding to your enquiry and providing pre-contract information regarding our barber courses: contract performance or steps prior to entering into a contract (Art. 6(1)(b)), and your consent where applicable (Art. 6(1)(a)).
- Operating, maintaining, and securing the website, preventing fraud and abuse: our legitimate interests in ensuring security and reliability (Art. 6(1)(f)).
- Analytics and performance measurement to improve the site and our services: your consent (Art. 6(1)(a)).
- Marketing, remarketing, and audience measurement: your consent (Art. 6(1)(a)).
- Compliance with legal obligations, including tax and accounting: legal obligation (Art. 6(1)(c)).
Automated Decision-Making: We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on you (Art. 22 GDPR).
4. Cookies and Similar Technologies
Our website uses cookies and similar technologies to enable core functionality, understand how the site is used, and support relevant advertising. You can manage your preferences at any time using the “Manage cookie preferences” link in the footer or the cookie banner. We group cookies into the following categories, which align with our Cookie Policy and on-site consent controls:
- Essential: required for the site to function (e.g., session continuity, consent storage). Always active and do not require consent. Typical examples: _site_session (session), cookie_consent (12 months).
- Analytics: help us measure visits and performance, often using anonymized or aggregated data. Activated only with your consent. Typical examples: _ga (2 years), _ga_XXXXXXXXXX (2 years) for Google Analytics 4.
- Marketing: support personalised advertising, remarketing, and conversion attribution. Activated only with your consent. Typical examples: _gcl_au (90 days), _fbp (90 days), _fbc (90 days when click ID is present).
Beyond browser cookies, marketing and analytics may use pixel tags and server-side identifiers derived from IP address and user-agent. These technologies are only activated after you provide consent in the EEA/UK, including Norway. You can withdraw consent at any time; withdrawal will not affect processing carried out before you withdrew consent. For complete details, see our Cookie Policy.
5. Consent Management
Visitors in the European Economic Area (including Norway) and the UK see a consent interface upon arrival. Analytics and marketing technologies are disabled by default until you grant explicit consent. Your selections are stored in the cookie_consent cookie for 12 months unless you clear your cookies earlier. You can adjust your preferences via the footer link “Manage cookie preferences” at any time.
6. Sharing with Service and Advertising Partners
We rely on carefully selected service providers to operate our website and measure performance. Where you grant consent, we may also work with advertising partners to run remarketing and audience measurement. Categories of recipients include:
- Analytics providers (e.g., Google Analytics 4) receiving cookie IDs, usage, and event data.
- Advertising partners (e.g., Google Ads, Meta) receiving page views, conversion events, and hashed identifiers for audience matching.
- Hosting, security, and content delivery providers (e.g., CDN and DDoS protection) that process IP addresses and request metadata to ensure availability and safety.
- Professional advisors (legal, accounting) where necessary to meet our legal obligations.
We do not sell personal data. We require our processors to use your data only to provide contracted services to us and not for their independent purposes. Where appropriate, we have data processing agreements and transfer safeguards in place.
7. International Transfers
Some providers are located outside Norway and the EEA, including in the United States. Where data is transferred internationally, we rely on one or more of the following safeguards: the EU–US Data Privacy Framework (and UK extension where applicable), Standard Contractual Clauses (2021/914/EU), and complementary measures. We assess transfer risks and implement appropriate technical and organisational controls to protect your data.
8. Retention Periods
We retain personal data only for as long as necessary for the purposes set out in this policy, and in accordance with legal obligations. Typical retention periods include:
- Contact enquiries and correspondence: 2 years from the last interaction.
- Analytics data: up to 14 months, or as configured by our analytics tool.
- Marketing cookies: according to their lifetime (e.g., 90 days for certain advertising cookies).
- Server logs: approximately 90 days, unless extended for security investigations.
- Cookie consent record: up to 3 years for audit purposes.
- Legal and tax records: as required by Norwegian law (typically 5–10 years depending on the record type).
9. Your Rights
Under the GDPR as applied in Norway, you have the following rights, subject to conditions and exceptions in law: right of access, rectification, erasure, restriction, portability, and objection. Where processing is based on consent, you may withdraw consent at any time without affecting prior lawful processing. You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).
To exercise your rights, contact us at [email protected]. We will respond within 30 days, extendable by an additional 60 days for complex requests. We may ask for limited information to verify your identity before acting on your request.
10. Children’s Privacy
Our site and services are intended for adults and individuals over 16 years of age. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data to us without verifiable parental consent, please contact us and we will promptly delete such data.
11. Do Not Track
Some browsers offer a “Do Not Track” (DNT) signal. Our website does not respond to DNT signals. Consent controls on our site govern whether analytics and marketing technologies are activated.
12. Account and Data Deletion Requests
If you would like to request deletion of your personal data, please email [email protected] with the subject “Data Deletion Request”. We will complete your request within 30 days of verifying your identity. We may retain certain records where required by Norwegian law or to establish, exercise, or defend legal claims.
13. Business Transfers
If we are involved in a merger, acquisition, asset sale, financing, reorganization, or insolvency event, your personal data may be transferred to a successor entity. We will notify affected users via a site notice if the transfer materially changes how your data is used, and we will honour your existing privacy choices to the extent required by law.
14. California Privacy Rights (CCPA/CPRA)
Although we are a Norway-based organisation, visitors from California may have rights under the California Consumer Privacy Act (as amended by the CPRA). Categories of personal information we may collect include identifiers (such as name, email, IP address), internet or network activity (such as browsing data), and inferences drawn from usage to tailor content. We disclose these categories to service providers and advertising partners to operate the website, measure performance, and deliver marketing where consented.
We do not sell personal information as defined by the CCPA. We may “share” personal information for cross-context behavioural advertising where you have consented to marketing cookies. California residents may exercise rights to know, correct, delete, and opt-out of sale/sharing by contacting [email protected] with the subject “California Privacy Request”. We will take reasonable steps to verify your identity and process your request within applicable timelines.
15. Virginia (VCDPA)
For visitors covered by the Virginia Consumer Data Protection Act, you may have rights of access, correction, deletion, portability, and opt-out of targeted advertising. We do not sell personal data and do not engage in profiling that produces legal or similarly significant effects. To exercise your rights, email [email protected] with the subject “Virginia Privacy Request”. If we deny your request, you may appeal by replying with the subject “Appeal of Refusal — Privacy Request”. Unresolved concerns may be directed to the Virginia Attorney General.
16. Nevada
Nevada residents may submit a verified request to opt out of the sale of personal information by emailing [email protected] with the subject “Nevada Do Not Sell Request”. We do not currently sell personal information as defined by Nevada law.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to our practices, technologies, or legal requirements. Material changes will be announced by a notice on our homepage at least 14 days before they take effect. The “Last Updated” date at the top of this page indicates when this policy was most recently revised.
18. Contact
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us using the details below:
- Legal entity: Fjord Barber Academy AS
- Address: Torggata 13, Sentrum, 0181 Oslo, Norway
- Email: [email protected]
- Phone: +47 22 33 45 60
- Supervisory authority in Norway: Datatilsynet (Norwegian Data Protection Authority)
For more information about our cookie practices and how to control them, please visit our Cookie Policy. For terms governing use of this website and our training services, please see our Terms.