Privacy Policy
Last Updated: March 14, 2026
1. Introduction & Controller Identity
This Privacy Policy explains how Cho-Eiendom AS (“we”, “us”, “our”) collects, uses, and protects personal data when you visit this website and when you contact us about our consulting and training services. Our services are designed for Canada-wide delivery, while our administrative base and registered address are in Oslo, Norway.
Cho-Eiendom AS is the data controller for the processing described in this policy, meaning we determine the purposes and means of processing your personal data.
- Legal entity: Cho-Eiendom AS
- Registered address: Fru Kroghs brygge 8, 0252 Oslo, Norway
- Email: [email protected]
- Telephone: +47 21 54 50 20
- Effective date: March 14, 2026
We do not appoint a Data Protection Officer (DPO) for this website at this time. If our obligations change, we will update this policy and provide appropriate contact details.
2. Personal Data We Collect
The personal data we collect depends on how you interact with the website. We collect information you provide directly, as well as limited technical and usage data generated when you browse the site.
2.1 Data you provide
- Identity and contact details: name, email address, phone number, organisation/company name (if provided).
- Form content: messages, project context, training needs, preferred formats (online/on-site), timing constraints, and any other details you include.
- Correspondence: emails exchanged with us and any information you include in follow-up messages.
2.2 Data collected automatically
- Technical data: IP address, browser type and version, device type, operating system, language preferences, and approximate location derived from IP.
- Usage data: pages viewed, time spent on pages, referrer URL, click paths, and basic interaction events (for example, page scroll or button clicks) when analytics is enabled.
- Cookies and identifiers: first-party cookies used for consent and session continuity, and third-party identifiers when you consent to analytics and marketing cookies.
- Conversion events: indicators that a form was submitted or a key action occurred, used for measurement when marketing cookies are enabled.
2.3 Data we do not intend to collect
We do not request or intentionally collect special-category data (such as health information, religious or political beliefs), financial account details, or government-issued identification numbers through this website. Please avoid including such information in free-text fields.
3. Why We Process Personal Data & Legal Basis (GDPR Art. 6)
We process personal data only when we have a lawful basis under the EU General Data Protection Regulation (GDPR), as implemented in Norway through the Personal Data Act (Personopplysningsloven). The legal basis depends on the purpose:
- Handling inquiries and requests (contact forms): GDPR Art. 6(1)(b) (steps prior to entering a contract) and Art. 6(1)(a) (consent where you choose to provide information and request contact).
- Providing requested information and service scoping: Art. 6(1)(b) and Art. 6(1)(f) (legitimate interest in managing client relationships and delivering information in a structured way).
- Site security and fraud prevention: Art. 6(1)(f) (legitimate interest in protecting the website, users, and our systems).
- Analytics (optional): Art. 6(1)(a) (consent) for analytics cookies and similar tracking.
- Marketing measurement and remarketing (optional): Art. 6(1)(a) (consent) for marketing cookies/pixels used to measure ads and build audiences.
- Legal obligations: Art. 6(1)(c) (compliance with applicable laws, including accounting and record-keeping where relevant).
Automated decision-making (GDPR Art. 22): We do not engage in automated decision-making or profiling that produces legal or similarly significant effects.
4. Cookies & Tracking
We use cookies and similar technologies to keep the website functional, to understand usage, and to measure advertising performance. Cookies may be first-party (set by this site) or third-party (set by service providers). Some tracking is implemented via pixel tags and may also include server-side event forwarding, depending on the tools configured.
4.1 Categories of cookies
- Essential (always active): required for the site to function and to remember your cookie choices. These do not require consent.
- Analytics (requires consent): helps us understand how the site is used and where content can be improved (for example, which pages are visited).
- Marketing (requires consent): used for advertising measurement, remarketing audiences, and conversion attribution.
4.2 Examples and typical retention
The list below describes common cookies associated with the categories above. Exact cookies can vary depending on configuration and updates by providers.
- Essential: _site_session (session continuity), cookie_consent (stores your consent choice, typically 12 months).
- Analytics: Google Analytics 4 cookies such as _ga and _ga_XXXXXXXXXX (often up to 2 years), with data retention commonly set to 14 months.
- Marketing: cookies such as _gcl_au (Google Ads, typically 90 days), _fbp and _fbc (Meta, typically 90 days).
4.3 Beyond cookies
Depending on consent and configuration, analytics and marketing measurement may include pixel tags and server-side event collection. Server-side events typically use limited identifiers (for example, IP address and User-Agent) and may include hashed contact identifiers when you submit a form, where supported by a provider. Hashing transforms data into a non-reversible representation, but it can still be considered personal data under GDPR when it can be related to a person.
For details on cookie management and a cookie inventory table, see our Cookie Policy.
5. Consent (EEA/UK)
Users in the European Economic Area (EEA) and the United Kingdom receive a consent notice under GDPR/UK GDPR. Analytics and marketing cookies activate only after explicit, informed, freely given consent (GDPR Art. 6(1)(a)). Essential cookies are required for the website to function.
Consent is recorded in the cookie_consent browser cookie (typically 12 months). You may withdraw consent at any time by selecting “Manage cookie preferences” in the site footer or by clearing cookies in your browser. Withdrawal does not affect the lawfulness of processing based on consent before it was withdrawn.
6. Sharing With Advertising & Service Partners
We use service providers to operate this website and (with consent) measure advertising performance. We do not sell personal data. Providers process data on our instructions and for the purposes described in this policy, subject to their contractual and security terms.
6.1 Google LLC
If enabled, Google services may include Google Analytics 4, Google Ads measurement, Google Tag Manager, and remarketing features. Data may include cookie identifiers, usage data, conversion events, and aggregated reporting. Privacy information: https://policies.google.com/privacy.
6.2 Meta Platforms
If enabled, Meta services may include the Meta Pixel and related measurement tools for conversion attribution and audience creation (including custom and lookalike audiences). Data may include page views, conversions, audience signals, and (where configured) hashed identifiers. Privacy information: https://www.facebook.com/privacy/policy.
6.3 Cloudflare
We may use Cloudflare for content delivery and security. Cloudflare may process IP addresses and request metadata for threat detection and performance. Privacy information: https://www.cloudflare.com/privacypolicy/.
We do not permit these providers to use site data for their own independent commercial purposes beyond providing services to us, subject to applicable terms and configurations.
7. International Transfers
We are established in Norway (EEA). Some providers we use may process data outside the EEA/UK, including in the United States. When personal data is transferred internationally, we rely on appropriate safeguards such as:
- EU-US Data Privacy Framework (DPF) (where applicable), including the UK Extension and Swiss-US DPF where relevant.
- Standard Contractual Clauses (EU 2021/914) as a fallback safeguard.
- UK International Data Transfer Agreement (IDTA) as a fallback where UK GDPR applies.
When we rely on these safeguards, we also consider supplementary measures where appropriate, such as minimisation of data shared and access controls.
8. Retention
We keep personal data only for as long as necessary for the purposes described in this policy, unless a longer period is required or permitted by law. Typical retention periods are:
- Contact submissions: up to 2 years from the last interaction to support follow-up and continuity.
- Email correspondence: for the duration of the relationship, plus up to 1 year where useful for reference.
- Server security logs: typically up to 90 days, unless needed for investigating abuse or incidents.
- Analytics data: typically 14 months (as configured in the analytics platform).
- Marketing cookies: based on cookie lifetimes (often 90 days), unless you withdraw consent earlier.
- Cookie consent record: up to 3 years for audit and compliance documentation.
- Legal and accounting records: retained as required under Norwegian law where applicable (often 5 years for certain accounting records; longer periods may apply in specific situations).
9. Your Rights
If GDPR applies to your data, you have the right to request:
- Access to your personal data (Art. 15)
- Rectification of inaccurate or incomplete data (Art. 16)
- Erasure in certain circumstances (Art. 17)
- Restriction of processing in certain circumstances (Art. 18)
- Data portability (Art. 20)
- Objection to processing based on legitimate interests (Art. 21)
- Withdrawal of consent at any time where processing is based on consent (Art. 7(3))
- Lodging a complaint with a supervisory authority (Art. 77)
To exercise these rights, contact us at [email protected]. We aim to respond within 30 days. In complex cases, this may be extended by up to 60 days, and we will inform you if an extension is needed.
Supervisory authority (Norway): Datatilsynet. Website: https://www.datatilsynet.no/.
If you are located in another EEA country, you may also contact your local authority. A directory is available via the European Data Protection Board: https://edpb.europa.eu/.
10. Children
This website is not directed at individuals under 16. We do not knowingly collect personal data from minors. If you believe a child under 16 has provided personal data without appropriate consent, please contact us and we will delete the information promptly where required.
11. Do Not Track
This website does not respond to “Do Not Track” (DNT) browser signals. Some third-party providers may offer their own mechanisms for managing tracking preferences; please refer to their documentation.
12. Data Deletion Requests
You may request deletion of personal data by emailing [email protected] with the subject line “Data Deletion Request”. To protect privacy, we may ask for information needed to verify identity before completing a request. We aim to complete deletion within 30 days where the request applies and no legal obligation requires retention.
Some records may be retained where required by law or where necessary to establish, exercise, or defend legal claims (for example, limited correspondence records).
13. Business Transfers
In the event of a merger, acquisition, asset sale, financing, reorganisation, or insolvency, personal data may be transferred to a successor entity as part of that transaction. If such a transfer materially changes how personal data is used, we will provide a notice on this website.
14. California (CCPA/CPRA)
This section applies if you are a California resident and the California Consumer Privacy Act (CCPA), as amended by the CPRA, applies to our processing.
Categories of personal information disclosed in the past 12 months: Identifiers (such as name, email, IP address, cookie IDs), internet or network activity information (such as page views and interactions), and inferences (such as interests) where marketing cookies are enabled.
Recipients: service providers and, if you consent, advertising and analytics partners.
We do not sell personal information as defined by CCPA. We may share information for cross-context behavioral advertising when marketing cookies are enabled. California residents may opt out of sharing by using our cookie preferences panel (accessible via “Manage cookie preferences” in the footer).
Your rights: you may have rights to know, delete, correct, and opt out of sale/sharing, and you have the right to non-discrimination for exercising privacy rights.
To submit a request, email [email protected] with the subject “California Privacy Request”. We will take reasonable steps to verify your identity. Authorized agents must provide written proof of authority.
15. Virginia (VCDPA)
If you are a Virginia resident and the Virginia Consumer Data Protection Act (VCDPA) applies, you may have rights to access, correct, delete, obtain a copy of your data, and opt out of targeted advertising.
We do not sell personal data and we do not engage in profiling that produces legal or similarly significant effects. You can opt out of targeted advertising by disabling marketing cookies through our cookie preferences panel.
To submit a request, email [email protected] with the subject “Virginia Privacy Request”. If we deny your request, you may appeal by emailing the subject “Appeal of Refusal — Privacy Request”. We will respond to appeals within 60 days. If your appeal is denied, you may contact the Virginia Attorney General.
16. Nevada
Nevada residents may submit a verified opt-out request by emailing [email protected] with the subject “Nevada Do Not Sell Request”. We do not currently sell personal information as defined by Nevada Revised Statutes Chapter 603A.
17. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. If we make material changes, we will publish a notice on the website at least 14 days before the change takes effect where appropriate.
The “Last Updated” date at the top of this page indicates when the policy was last revised.
18. Contact
If you have questions about this Privacy Policy or our handling of personal data, contact:
- Cho-Eiendom AS
- Fru Kroghs brygge 8, 0252 Oslo, Norway
- Email: [email protected]
- Phone: +47 21 54 50 20
Need to send an inquiry?
For consultation requests or training plans, use our contact page. We typically respond by email within 1 business day when possible.