Privacy Policy
Last updated: June 2026
This Privacy Policy explains how EndpointAI ("we", "us", "our") collects, uses, and protects your personal information when you visit endpointai.app or engage our services. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR) and applicable Norwegian law.
Who We Are
EndpointAI is a sole proprietorship (enkeltpersonforetak) based in Oslo, Norway, providing AI automation consulting and workflow services. You can reach us at fromendpointai@gmail.com.
What Data We Collect
We collect information you provide directly to us, including:
- Name and email address (when you contact us or book a call)
- Business name and website (when discussing your automation needs)
- Payment information (processed securely by Stripe — we never store card details)
- Any information you share during discovery calls or project work
We also collect limited technical data automatically, such as your browser type and the pages you visit, to improve the website experience.
How We Use Your Data
- To respond to enquiries and provide our services
- To schedule and conduct discovery calls
- To process payments for services rendered
- To send relevant updates or follow-ups (you can opt out at any time)
- To improve our website and service offering
Legal Basis for Processing
We process your data on the following legal bases under GDPR:
- Contract — to deliver services you have engaged us for
- Legitimate interest — to manage our business relationship with you
- Consent — where you have explicitly agreed (e.g. marketing communications)
- Legal obligation — where required by Norwegian law
Third-Party Services
We use the following trusted third-party services to operate our business:
- Stripe — payment processing. Stripe processes payment data securely. See stripe.com/privacy
- Calendly — appointment scheduling. See calendly.com/privacy
- Google Workspace — email and communication. See Google Privacy Policy
These providers are data processors acting on our behalf and are bound by their own GDPR-compliant privacy policies.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Client records are typically retained for five years in accordance with Norwegian accounting regulations.
Your Rights
As a data subject under GDPR, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data ("right to be forgotten")
- Object to or restrict our processing of your data
- Request portability of your data
- Withdraw consent at any time (where processing is based on consent)
- Lodge a complaint with Datatilsynet (the Norwegian Data Protection Authority) at datatilsynet.no
To exercise any of these rights, contact us at fromendpointai@gmail.com.
Data Security
We take reasonable technical and organisational measures to protect your personal information against unauthorised access, loss, or misuse. Payment data is handled exclusively by Stripe and is never stored on our systems.
Cookies
This website uses minimal cookies necessary for the site to function. We do not use tracking or advertising cookies. Third-party services embedded on this site (such as Calendly booking widgets) may set their own cookies, governed by their respective privacy policies.
Changes to This Policy
We may update this Privacy Policy from time to time. The date at the top of this page reflects the most recent revision. Continued use of our website or services after any changes constitutes acceptance of the updated policy.
Contact
Questions about this policy? Get in touch:
fromendpointai@gmail.com
EndpointAI, Oslo, Norway