Privacy policy
Last updated: 1 March 2026. This policy explains how Petro Garden Atelier processes personal data in accordance with the EU General Data Protection Regulation (GDPR) and Norwegian privacy law.
1. Data controller
The data controller responsible for your personal data is:
Petro Garden Atelier
Strandgaten 12, 5013 Bergen, Norway
Organisation number: 923 456 781
Email: [email protected]
Phone: +47 55 32 18 44
For privacy-related enquiries, contact us at the email above with the subject line "Privacy request".
2. What data we collect
We may collect and process the following categories of personal data:
- Identity and contact data: name, email address, phone number, postal address
- Enquiry content: messages you send via our contact form, photos of your property, plot dimensions
- Contract and billing data: invoice details, payment records, project correspondence
- Technical data: IP address, browser type, device information collected via cookies (see our Cookie policy)
- Survey records: site notes and photographs taken during property visits
3. Legal basis for processing
We process personal data on the following legal bases under Article 6 GDPR:
- Contract (Art. 6(1)(b)): Processing necessary to provide planning services you request and to manage our agreement with you.
- Legitimate interests (Art. 6(1)(f)): Responding to enquiries, improving our services, maintaining business records, and protecting legal claims, where your interests do not override ours.
- Consent (Art. 6(1)(a)): Where required for non-essential cookies or optional marketing communications. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): Retaining accounting records as required by Norwegian bookkeeping legislation.
4. How we use your data
Personal data is used to:
- Respond to contact form submissions and quote requests
- Schedule and conduct site surveys
- Prepare garden and terrace planning deliverables
- Issue invoices and process payments
- Communicate about project revisions and delivery
- Comply with tax and accounting obligations
- Maintain website security and analyse aggregated traffic patterns
5. Data retention
We retain personal data only as long as necessary:
- Enquiry records without a contract: up to 24 months from last contact
- Active project files: duration of the project plus 5 years for warranty and liability purposes
- Accounting records: 5 years after the end of the financial year per Norwegian law
- Cookie analytics: up to 14 months (see Cookie policy)
- Marketing consent records: until consent is withdrawn plus 12 months for audit purposes
When retention periods expire, data is securely deleted or anonymised.
6. Sharing and processors
We do not sell personal data. Data may be shared with:
- Cloud hosting and email providers acting as data processors under written agreements
- Accounting software providers for invoicing
- Contractors you appoint, when you authorise us to share plans containing your address
- Public authorities when required by law
All processors are required to implement appropriate security measures and process data only on our documented instructions.
7. International transfers
Our primary systems are located within the European Economic Area (EEA). If any processor transfers data outside the EEA, we ensure appropriate safeguards such as EU Standard Contractual Clauses or an adequacy decision by the European Commission. You may request a copy of relevant transfer mechanisms by contacting us.
8. Security
We implement technical and organisational measures including encrypted connections (TLS), access controls on project files, password-protected devices for staff, and regular review of who has access to client data. No method of transmission over the internet is completely secure; we encourage you not to send sensitive documents via unencrypted email when alternatives are available.
9. Your rights
Under GDPR you have the right to:
- Access your personal data and receive a copy
- Rectify inaccurate or incomplete data
- Erase data where there is no compelling reason for continued processing
- Restrict processing in certain circumstances
- Data portability for data processed by automated means based on consent or contract
- Object to processing based on legitimate interests or for direct marketing
- Withdraw consent at any time without affecting prior lawful processing
To exercise these rights, email [email protected]. We respond within one month, extendable by two months for complex requests with notice.
10. Complaints
If you believe we have processed your data unlawfully, you may lodge a complaint with:
Datatilsynet
Postboks 458 Sentrum, 0105 Oslo, Norway
Website: www.datatilsynet.no
We ask that you contact us first so we can try to resolve your concern directly.
11. Changes to this policy
We may update this policy to reflect legal or operational changes. The "Last updated" date at the top will be revised, and significant changes will be highlighted on our website where appropriate.