Overview
This privacy policy describes how Condrox AI, operated by Tobias Østen (sole proprietor, Norway), handles information when you visit pcnorge.no or use the pre-release chat at chat.html. The policy is written to satisfy the requirements of the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (Personopplysningsloven).
Summary: This website does not use analytics, advertising trackers, third-party cookies, or any form of behavioral tracking. The only data stored on your device is a single flag in your browser's local storage that remembers you dismissed the pre-release banner. The pre-release chat sends your messages to the Condrox AI service for processing and receives a response. No chat history is persisted on the server beyond the duration of your session.
Data We Process
| Data Category | Where | Purpose | Retention |
|---|---|---|---|
| Pre-release banner dismissal | Browser localStorage |
Remembers that you dismissed the amber pre-release banner so it does not reappear on every page | Until you clear browser storage. No expiry set. |
| Preloader state | Browser sessionStorage |
Prevents the loading animation from flashing on every page navigation within a single session | Cleared when the browser tab is closed |
| Chat session ID | Browser sessionStorage |
Identifies your chat session so the pre-release agent can maintain conversational context within a single visit | Cleared when the browser tab is closed |
| Chat messages | Server memory only | Processed by the Condrox AI cognitive pipeline to produce a response | Not persisted to disk. Lost when the service restarts or the session expires. |
| Email correspondence | Email server (kontakt@pcnorge.no) | Used only to respond to inquiries you send us directly | Retained as long as needed to resolve your inquiry, then deleted |
| Server access logs | Hosting provider | Standard web server logs (IP address, timestamp, requested URL, user agent) for security and abuse prevention | Maximum 30 days, then automatically rotated |
What We Do Not Do
- No analytics. No Google Analytics, no Plausible, no Fathom, no self-hosted analytics. We do not measure page views, click paths, or scroll depth.
- No advertising trackers. No Google Ads, no Facebook Pixel, no remarketing tags.
- No third-party cookies. The only storage used is local/session storage on your own device, set by our own first-party code.
- No behavioral profiling. We do not build profiles of visitors, do not segment audiences, and do not sell or share data with any third party.
- No chat logging. Conversations with the pre-release chat are processed in memory and not written to disk on the server.
- No biometric or special category data. We do not collect anything covered by GDPR Article 9.
Legal Basis for Processing (GDPR Article 6)
| Processing Activity | Legal Basis |
|---|---|
| Serving the website and its static assets | Legitimate interest (Article 6(1)(f)) - necessary to deliver the service you requested |
| Storing the banner dismissal flag | Legitimate interest (Article 6(1)(f)) - necessary to provide a usable interface |
| Processing chat messages to produce a response | Performance of a contract you initiate (Article 6(1)(b)) - you send a message, we respond |
| Server access logs for security | Legitimate interest (Article 6(1)(f)) - protecting the service from abuse and attack |
| Responding to emails you send us | Performance of a request you initiate (Article 6(1)(b)) |
Your Rights Under GDPR
If you are located in the European Economic Area, Switzerland, or the United Kingdom, you have the following rights regarding any personal data we process about you:
- Right of access (Article 15). You can ask what data we hold about you.
- Right to rectification (Article 16). You can ask us to correct inaccurate data.
- Right to erasure (Article 17). You can ask us to delete your data.
- Right to restrict processing (Article 18). You can ask us to limit how we use your data.
- Right to data portability (Article 20). You can receive your data in a structured, machine-readable format.
- Right to object (Article 21). You can object to processing based on legitimate interests.
- Right to withdraw consent (Article 7). Where processing is based on consent, you can withdraw it at any time.
- Right to lodge a complaint (Article 77). You can complain to your local data protection authority. In Norway, that is Datatilsynet.
To exercise any of these rights, email kontakt@pcnorge.no with the subject "Privacy Request". We respond within 30 days.
Data Sharing and Sub-Processors
We do not sell, rent, or share your personal data with any third party for commercial purposes. The only third parties with access to limited data are:
- Hosting provider. The server hosting pcnorge.no has access to standard web server logs (IP, timestamp, URL, user agent). These are used solely for security and abuse prevention.
- Email provider. The provider hosting kontakt@pcnorge.no processes emails you send us. They do not use your data for any other purpose.
- Cloudflare. The pre-release chat endpoint is exposed via Cloudflare Tunnel. Cloudflare may process request metadata (IP, timestamp) as part of delivering the request to our server. They do not see the content of your chat messages, which are encrypted in transit via TLS.
No data is transferred outside the European Economic Area. If this changes, we will update this policy and ensure appropriate safeguards (Article 46) are in place.
Cookies and Local Storage
This website does not set any HTTP cookies. The only client-side storage used is browser localStorage and sessionStorage, which are not sent to the server with each request. You can clear this storage at any time through your browser settings. The specific keys used are:
| Storage Key | Type | Purpose |
|---|---|---|
condrox_prepub_dismissed | localStorage | Remembers that you dismissed the pre-release banner |
condrox_preloader_shown | sessionStorage | Prevents the loading animation from reappearing during a session |
condrox_session_id | sessionStorage | Identifies your chat session for conversational context |
Security
All traffic to and from pcnorge.no is encrypted via HTTPS (TLS 1.2 or higher). The pre-release chat endpoint uses TLS end-to-end. Server access logs are rotated automatically. Email correspondence is stored on a secured email server accessible only by Tobias Østen.
If you believe you have found a security vulnerability, please see our Security Architecture page for the responsible disclosure process. Do not publish vulnerability details until we have had a reasonable time to respond.
Children's Privacy
This website is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it immediately.
Changes to This Policy
We may update this privacy policy from time to time. The effective date at the top of this page indicates when the policy was last revised. Material changes will be noted on the News & Updates page. Continued use of the website after a change constitutes acceptance of the updated policy.
Contact
If you have any questions about this privacy policy or wish to exercise any of your GDPR rights, contact:
Data Controller: Tobias Østen
Email: kontakt@pcnorge.no
Location: Norway
We respond to privacy inquiries within 30 days, typically much faster.