Servanda
Product Pricing Contact
Legal

Privacy Policy

How we handle personal data on the website, when you contact us, and in the documents you upload for analysis.

Last updated 15 September 2026
Contents Controller Who this policy covers Visiting the website Enquiries and meetings Customer relationships Documents you upload Who we share data with Transfers outside the EU/EEA How long we keep data Security Your rights Changes to this policy Contact

1. Controller

Servanda AS org. no. 934 118 642, StartupLab, Gaustadalléen 21, 0349 Oslo, Norway, is the controller for the personal data described in this policy, except for the personal data contained in documents that customers upload for analysis, which we process on the customer’s behalf (see section 6). Questions about privacy can be sent to contact@servanda.no.

We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (personopplysningsloven).

2. Who this policy covers

This policy explains what we do with personal data about visitors to servanda.no, people who contact us or book a meeting, contact persons at our customers and partners, and individuals whose personal data appears in documents that our customers upload to the platform.

3. Visiting the website

servanda.no does not use cookies or tracking for analytics or advertising, and we do not build profiles of visitors. The following processing does take place when you load the site:

  • Server logs. Our hosting provider, Microsoft Azure (Static Web Apps), records your IP address, browser type and the pages requested in technical logs that we use to keep the site secure and available. Legal basis: our legitimate interest in running a secure website (GDPR art. 6(1)(f)). Logs are deleted after 30 days.
  • Fonts. The site loads the typefaces Archivo and Inter from Google Fonts. When your browser fetches them, Google receives your IP address. Legal basis: legitimate interest (art. 6(1)(f)).
  • Meeting booking. When you click “Book a meeting”, a booking widget from Calendly is opened. Calendly’s own privacy policy applies to the data you enter there; see section 4.

4. Enquiries and meetings

When you request a price or otherwise contact us, we process the details you give us – typically your name, work email address, company, telephone number and the content of your message. The price form on the website opens an email to contact@servanda.no; nothing you type is stored on the website itself.

We use this data to answer your enquiry, prepare a quote and follow up. Legal basis: steps taken at your request prior to entering into a contract (art. 6(1)(b)) and our legitimate interest in responding to business enquiries (art. 6(1)(f)).

Meetings are booked through Calendly, which processes your name, email address, time zone and the meeting details as our processor. Calendly, LLC is established in the United States; see section 8.

5. Customer relationships

For customers we process contact details of the people we work with (name, role, work email, telephone), the correspondence and documents relating to the engagement, quotes and invoices. We use this data to deliver the Services, manage the account, invoice and keep in touch about the engagement. Legal basis: performance of the contract (art. 6(1)(b)), legal obligations such as bookkeeping (art. 6(1)(c)) and our legitimate interest in maintaining the customer relationship (art. 6(1)(f)).

We may send existing customers information about relevant new features or services by email. You can opt out at any time by replying to the email or writing to us.

6. Documents you upload

The data rooms our customers upload – leases, title documents, technical reports, financial statements and similar – regularly contain personal data about tenants, counterparties, employees and advisors. We process this data only on the customer’s instructions, in order to analyse the property in question and produce the report. The customer is the controller; Servanda is a processor under the Data Processing Agreement that forms part of our Terms of Service.

How your documents are handled

Stored encrypted, in transit and at rest, in a dedicated single-tenant environment within the EU/EEA.

Used to analyse your deal and for nothing else. Your documents are never used to train models.

Shared only with the validation partner you have chosen and the sub-processors listed in section 7.

Deleted at the end of the engagement, or earlier at your request.

If you are an individual whose data appears in such documents, please contact the customer that uploaded them; we will assist the customer in responding to your request.

7. Who we share data with

We do not sell personal data. We share it only with:

  • Validation partners – the law firm or other expert you have chosen to validate and sign the report. The partner is an independent controller for its own processing.
  • Sub-processors that deliver parts of our service under a data processing agreement: our hosting and infrastructure provider Microsoft Azure (Static Web Apps) (EU/EEA), Calendly, LLC (meeting booking, USA) and Google LLC (web fonts). A current list of sub-processors is available on request.
  • Authorities, where we are required to do so by law or a lawful order.

8. Transfers outside the EU/EEA

Your documents and the data we process to deliver the Services are stored and processed within the EU/EEA. Where a sub-processor is established outside the EU/EEA – currently Calendly and Google, for the limited processing described above – the transfer is based on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the European Commission’s Standard Contractual Clauses.

9. How long we keep data

  • Enquiries that do not lead to a customer relationship: deleted after 12 months.
  • Customer contact data and correspondence: for the duration of the customer relationship and up to 3 years after it ends, so that we can document what was agreed.
  • Invoices and accounting records: 5 years, as required by the Norwegian Bookkeeping Act (bokføringsloven).
  • Uploaded documents and reports: deleted at the end of the engagement or on request; copies in backups are overwritten within 30 days. We keep a copy of the delivered report for as long as the customer’s agreement with us requires.

10. Security

We protect personal data with technical and organisational measures appropriate to the risk, including encryption in transit and at rest, single-tenant storage that is firewalled from other customers, role-based access control, logging of access, and confidentiality obligations for everyone who works for us. Access to customer documents is limited to the people who need it to deliver the engagement.

11. Your rights

You have the right to ask for access to the personal data we hold about you, to have inaccurate data corrected, and – in the circumstances set out in the GDPR – to have data erased, to restrict or object to our processing, and to receive data you have provided to us in a portable format. Where processing is based on consent, you can withdraw it at any time.

To exercise your rights, write to contact@servanda.no. We respond within one month. If you are not satisfied with how we handle your personal data, you can complain to the Norwegian Data Protection Authority, Datatilsynet (datatilsynet.no).

12. Changes to this policy

We update this policy when our processing changes. The current version is always available at servanda.no/privacy.html with the date of the last update. Material changes affecting customers are notified by email.

13. Contact

Servanda AS org. no. 934 118 642

StartupLab, Gaustadalléen 21, 0349 Oslo, Norway

contact@servanda.no · +47 926 08 827

Servanda

Portfolio risk management.
Commercial real estate.

Product Portfolio Screen Risk report Due diligence Pricing Method
Company Team Partners Security
Contact contact@servanda.no +47 926 08 827 Book a meeting
StartupLab
Gaustadalléen 21
0349 Oslo, Norway
© 2026 Servanda. All rights reserved.
Terms Privacy