Juridiskt

    Integritetspolicy för Vexter AS

    Senast uppdaterad: July 1, 2026

    1. Introduction

    This English Privacy Policy is provided for convenience. In case of any discrepancies between this text and the original Norwegian Privacy Policy, the Norwegian version is the authoritative text.

    This Privacy Policy explains how Vexter AS processes personal data in connection with Vexter’s services, websites, and communications.

    Vexter is a B2B platform for prospecting, sales, and follow-up of business contacts. The service is designed for use between businesses and may process business-related personal data about individuals, typically employees, users, contacts, and representatives of companies.

    This Privacy Policy covers:

    • the processing of personal data we collect directly from you, for example when you create a user account, contact us, or use the service, and
    • the processing of personal data from public sources, such as public registries, company websites, and other publicly available sources, when we maintain contact and company data on the platform.

    2. Who Is the Data Controller

    Vexter AS is the data controller for the processing of personal data described in this statement, unless otherwise expressly stated.

    Vexter AS

    Organization No.: 932 038 870

    Address: Møllergata 6, 0179 Oslo

    Email: post@vexter.io

    Privacy inquiries: privacy@vexter.io

    Phone: +47 900 18 370

    3. When Vexter Acts as Data Controller and Data Processor

    Vexter has several roles under data protection legislation and may, depending on the context, act as either a data controller or a data processor. Third parties act as independent data controllers when they process personal data made available through Vexter for their own purposes.

    Data Controller

    Vexter is the data controller for our:

    • operation and administration of our website and platform,
    • creation and management of customer relationships,
    • handling of billing, security, logging, support, and fraud prevention,
    • processing, organizing, and updating publicly available information about companies and business contacts in our database,
    • processing of information in connection with our own marketing and sales activities,
    • processing to ensure compliance with legal requirements.

    As the data controller, Vexter will determine the purposes and means of processing personal data.

    Data Processor

    When a company uses Vexter to process personal data in its own campaigns, customer lists, integrations, or lead follow-ups, the company will be the data controller and Vexter the data processor. Vexter will then process personal data on behalf of the company.

    This applies when the company:

    • enters its own contacts or customer data into Vexter,
    • uses Vexter to send out and follow up on campaigns,
    • connects to an email account, calendar, or other systems,
    • uses the platform to communicate with its own leads, customers, or other contacts.

    Such processing will be governed by a data processing agreement between the data controller and Vexter, acting as the data processor on behalf of the company.

    4. Categories of Personal Data We Process

    The information we process depends on your relationship with Vexter.

    4.1 Information about customers and users of the platform

    The information we process about our customers and users may include:

    • name,
    • work email address,
    • phone number,
    • employer, role, and team affiliation,
    • login and account information,
    • user preferences and settings,
    • billing and payment information,
    • support and communication history,
    • technical data, such as IP address, device, browser, and system logs.

    4.2 Information about companies and contacts

    Information we process from publicly available sources may include:

    • name,
    • position or role,
    • employer and affiliated company,
    • work-related email address,
    • work-related phone number,
    • publicly available information about the company where the person works,
    • publicly available information about the person’s professional role.

    People search is disabled on the Vexter platform. The system is designed for company- and role-based searches, not searches for private individuals.

    The Vexter platform is designed to present up-to-date, publicly available information about businesses. We regularly retrieve information from the Brønnøysund Register Center (every 30 days or more frequently) and publicly available company websites. This means that if you remove information related to you from such sources, the information will also be deleted from our records.

    4.3 Information Related to Campaigns and Communication

    When Vexter is used for campaigns and follow-up, the user, as the data controller, may process information such as:

    • recipient and sender,
    • work-related email address,
    • company affiliation and role,
    • content of email communications processed in Vexter,
    • send status,
    • unsubscription, blocking, or opt-out,
    • aggregated analysis of campaign effectiveness.

    Vexter is designed for B2B communication and one-to-one personalized emails, not for consumer-oriented mass mailings. Each message must be addressed to a single recipient within a company, based on publicly available business information about that specific company.

    4.4 Information We Do Not Process

    Vexter is not intended for the processing of special categories (sensitive) of personal data. We require that Vexter users do not enter sensitive information into the platform. If we discover such information, we reserve the right to delete or restrict the information, as well as suspend access to Vexter, in order to comply with legal obligations.

    5. Where We Get the Information From

    We collect personal data both directly from data subjects and from other sources.

    5.1 Information we collect directly from individuals

    We collect information directly from individuals when they:

    • create an account or order the service,
    • fill out forms on our website,
    • request a demo, contact us by email, phone, or other means.

    5.2 Information we collect from publicly available sources

    For company information and business contact details, we obtain information from:

    • Brønnøysund Register Center,
    • the Swedish Companies Registration Office and similar public registries when relevant,
    • companies’ own websites,
    • other publicly available sources of business information,
    • professional profiles and open sources that describe a person’s role or place of work.

    Since Vexter collects and updates company and contact information from publicly available sources and registries, there is normally an obligation to inform each individual directly within one month after the information was obtained.

    Vexter does not send individual notifications to each contact because:

    • The information is already publicly available and limited to name, title, employer, work email, and work phone number. Our processing therefore has minimal impact on individuals’ privacy.
    • The number of contacts is very high, variable, and frequently updated. Collecting, verifying, and sending individual notifications within the deadline would require significant resources and involve extensive email, SMS, or phone communications, which could also be perceived as spam by the recipients.

    Vexter invokes the exception to the direct individual notification requirement pursuant to GDPR Article 14(5)(b), as direct notification to every business contact in the database would require a disproportionate amount of effort. This exception is justified by the high number of ongoing updates for source synchronization, the fact that the information is limited exclusively to publicly available and professionally related contact information, and that the information has little bearing on the individuals’ private lives. Vexter also does not store information that we know has been deleted or modified from public sources.

    To safeguard the rights of data subjects, we make this information available on our website, ensure easy access to opt-out, and regularly update or delete the data in accordance with the source registries. We also require that Vexter users disclose the source of the information.

    6. Why We Process Personal Data

    We use information to provide, manage, and promote our platform. We process personal data only when we have identified a valid legal basis for processing in accordance with our purposes. At times, we may also process personal data for other purposes provided they are not incompatible with the original purposes, such as for accounting purposes, product development, and innovation.

    6.1 Operation, Delivery, and Administration of the Service

    We process personal data to:

    • create and manage accounts,
    • provide platform functionality,
    • provide access to user profiles and team features,
    • manage payments, subscriptions, and customer relationships,
    • provide customer support and follow up on inquiries.

    Legal basis for processing: Here, Vexter relies on a balancing of interests as the legal basis, where the balancing is based on our legitimate interest in operating the service and providing access to it for the appropriate users.

    6.2 Security and Prevention of Misuse

    We process personal data to:

    • protect the service, users, and infrastructure,
    • detect and address misuse, security breaches, and unauthorized use,
    • document compliance with contractual obligations and legal requirements,
    • debug, test, and improve stability and security.

    Legal basis for processing: For the minor security activities mentioned here, Vexter relies on a balancing of interests as the legal basis, where the balancing is based on our legitimate interest in ensuring the stable, secure, and lawful operation of the service, protecting Vexter, our customers, and data subjects against misuse and security incidents, including preventing unlawful use of the platform.

    Legal basis for processing: Where processing is necessary to comply with a legal obligation, such as documenting security incidents or fulfilling statutory duties, the processing is based on a legal obligation.

    6.3 Creating an overview of companies and business contacts

    We process information to:

    • collect, organize, and update publicly available information about companies and contacts,
    • enable customers to identify relevant business information in the B2B market,
    • maintain up-to-date information on companies, roles, and work-related contact information,
    • remove or update information that is no longer accurate or available.

    Legal basis for processing: For the activities mentioned here, Vexter relies on a balancing of interests as the legal basis, where the balancing is based on our legitimate interest in offering a B2B service for prospecting, establishing contacts, and sales efforts based on publicly available business information, while the processing is limited to work-related information and use in a business context.

    7. What Vexter Does Not Do

    Vexter imposes strict requirements on our customers and users regarding the use of the platform.

    Vexter does not process special categories (sensitive) of personal data, such as information regarding health, political opinions, religion, trade union membership, sexual orientation, or similar. We do not allow our users to enter special categories of personal data in free-text fields, campaigns, responses, notes, or other parts of the platform.

    Vexter does not permit targeted marketing or B2C campaigns.

    Vexter does not allow searches for individuals on the platform; the system is designed for company- and role-based searches, not searches for private individuals.

    Vexter does not sell personal data to third parties for consumer-targeted advertising.

    8. Who Are the Recipients of Personal Data

    The information from Vexter as a service is made available to our platform users, who are subject to our Terms of Use.

    Vexter shares personal data with our data processors in the EU/EEA that are necessary to provide the service. This includes providers of hosting, database services, security, encryption, email integration, calendar integration, payment processing, analytics, error monitoring, and AI-based content generation.

    We may also share information when necessary to comply with legal obligations, protect rights, prevent misuse, or respond to lawful requests from public authorities.

    8.1 Google API Services – Limited Use Disclosure

    Important Notice:

    Vexter's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

    8.1.1 How We Use Google Gmail Data

    When you connect your Gmail account, we use the Gmail API to:

    • Send emails: Send sales outreach emails on your behalf through your Gmail account
    • Read email metadata: Check for replies to your campaigns
    • Modify email status: Mark processed replies as read to prevent duplicate processing

    8.1.2 How We Use Google Calendar Data

    When you connect your Google Calendar account, we use the Google Calendar API to:

    • Check availability: Query your free/busy calendar times to show available meeting slots to prospects, preventing double-bookings.
    • Create events: Create calendar events when prospects book meetings with you through Vexter's scheduling feature.
    • Update events: Modify calendar events when meetings are rescheduled or details change.
    • Cancel events: Remove calendar events when meetings are cancelled.

    We only access calendar events and free/busy data related to Vexter's meeting scheduling feature. We do not read, modify, or delete events created outside of Vexter. Calendar data is processed in real-time and event metadata (title, time, attendees) is stored to display upcoming meetings within the Vexter interface.

    8.1.3 Data Security for Google Services

    • All OAuth tokens are encrypted using AWS KMS (production) or AES-256 encryption (development)
    • Tokens are never stored in plain text
    • Access tokens are automatically refreshed to maintain security
    • We use Gmail Push Notifications via Google Pub/Sub for real-time updates

    8.1.4 Google API Services — Limited Use Commitment

    Vexter's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

    Specifically, this means that we commit to the following:

    1. We use Google user data only for the purposes explicitly described in this Privacy Policy and as visible in the Vexter app interface.
    2. We do not sell, rent, or share Google user data with third parties for advertising, marketing, or any other purposes unrelated to the provision of Vexter’s services.
    3. We do not use Google user data to display ads or for ad targeting of any kind.
    4. We do not allow humans to read Google user data, unless:
      • we have the user’s explicit and active consent,
      • it is necessary for security reasons, such as when investigating abuse or security incidents,
      • it is necessary to comply with applicable laws, or
      • the data is aggregated and anonymized for internal operational purposes.
    5. We do not use Google user data to train artificial intelligence or machine learning models that are used outside the scope of providing Vexters’ core features to the specific user.
    6. All Google OAuth tokens are encrypted at rest using AWS KMS envelope encryption in the production environment, or AES-256 symmetric encryption in the development environment. Tokens are never stored in plain text and are automatically renewed.

    9. Transfer of Personal Data

    Vexter has restricted all storage of personal data to the EU/EEA. Our clear guiding principle is that all personal data should be processed within the EU/EEA whenever possible.

    If individual services require that personal data be transferred to or accessed by a company outside the EU/EEA, this shall only occur when there is a valid legal basis for the transfer under Chapter V of the GDPR, for example:

    • the European Commission’s decision on an adequate level of protection,
    • the EU Standard Contractual Clauses (SCCs), or
    • the EU-U.S. Data Privacy Framework, where applicable.

    You may request further information from us regarding the legal bases for data transfers used by our various subcontractors.

    10. How Long We Retain Personal Data

    We do not retain personal data longer than necessary for the purpose for which it was collected, unless we are legally required to retain it for a longer period.

    We store:

    • Account information is stored for as long as your account is active.
    • Email communications processed in the Vexter platform (in customers’ campaigns) are automatically deleted 90 days after a campaign is completed.
    • Aggregated analytics data on campaign effectiveness is deleted after 24 months. We remove identifying information from this data, and it is, for the most part, not personal data.
    • Data obtained from public sources is continuously deleted from our database if it is deleted from the public source (as soon as we become aware of the change and no later than every 30 days).

    11. Security

    We protect information through role-based access controls, encryption during transmission and storage, and secure storage within the EU/EEA. We implement technical and organizational measures to prevent unauthorized access.

    These measures include, among other things:

    • role-based access,
    • encryption during transmission and storage,
    • secure storage within the EU/EEA,
    • logging and monitoring of technical incidents,
    • procedures for handling security incidents,
    • restriction of access to personal data based on a need-to-know basis.

    Vexter also employs technical and organizational measures to ensure that personal data is processed only for authorized purposes and by individuals or vendors who need access.

    12. Your Rights

    When we act as the data controller, you, as a data subject, have rights under data protection regulations. This includes, provided the conditions are met:

    • the right to access the personal data we process about you,
    • the right to have inaccurate or incomplete information corrected,
    • the right to erasure,
    • the right to restrict processing,
    • the right to data portability,
    • the right to object to processing based on legitimate interests, and
    • the right to withdraw consent if the processing is based on consent,

    Your personal data is not subject to automated individual decision-making pursuant to GDPR Article 22.

    If your data is used for direct marketing, you may object to such processing at any time, cf. GDPR Article 21(2) and (3). If you do so, we will no longer process your personal data for such purposes.

    If you wish to exercise your rights, please contact us at privacy@vexter.io. We handle all requests regarding access, erasure, and other data protection rights without undue delay and no later than 30 days. Contact us at privacy@vexter.io to exercise your rights.

    13. Complaint to the Data Protection Authority

    If you believe that Vexter is processing personal data in violation of privacy regulations, we encourage you to contact us first, and we will do our best to answer your questions or correct any errors.

    You also have the right to file a complaint with the Norwegian Data Protection Authority if you believe that we are processing your personal data in violation of data protection laws.

    The Norwegian Data Protection Authority can be contacted at www.datatilsynet.no.

    14. Changes to the Privacy Policy

    We may update this Privacy Policy from time to time, for example, if we change our services, processing activities, vendors, or procedures.

    The current version will be available on Vexter's website at all times. In the event of significant changes, we may also notify users or customers by other means.

    Vi använder cookies

    Vi använder cookies och liknande tekniker för att förbättra din upplevelse, visa personanpassat innehåll och analysera vår trafik. Integritetspolicy