Legal
Platform Privacy Policy
Terms
10 August 2026
Updated: December 2025
This Privacy Policy explains how Etain AS, a Norwegian limited liability company with registration number 920 998 704, having its registered address at Drammensveien 123, 0277 Oslo, Norway (“Etain”, “we”, “us”) handles personal data in connection with the Etain Platform, including Intelligent Workspaces and associated support and service operations (the “Service”).
This Policy should be read with the applicable Customer Terms, User Terms, Data Processing Agreement (the “DPA”), Service Level Policy, and any Order Form. Where Etain processes personal data contained in a customer workspace on a customer’s behalf, the DPA and the relevant customer’s instructions govern that processing.
1 Roles and Scope
Etain’s role depends on the category of personal data concerned.
1.1 Workspace Owner Data
Customers and workspace owners control the data, files, documents and other content uploaded to, generated in, or otherwise made available through their workspace (“Workspace Owner Data” or “Customer Data”). Where that data contains personal data, the relevant customer or workspace owner is normally the controller, and Etain acts as its processor. Etain processes that data only to provide, secure, maintain and support the Service, in accordance with the customer’s documented instructions, the DPA and applicable law.
If you are a user of a customer workspace, questions or requests concerning personal data in that workspace, including requests for access, correction or deletion, should normally be sent to the relevant workspace owner or customer.
1.2 Etain-Controlled Data
Etain acts as an independent controller for personal data it processes for its own legitimate business purposes, such as account administration, customer relationship management, billing, security, compliance and Service telemetry, subject to applicable law.
2 Personal Data We Process
Depending on how the Service is used, Etain may process the following categories of personal data:
Account and professional information, such as name, work email address, organisation, role, workspace affiliation and account-access information.
Workspace Owner Data, including personal data contained in files, documents, messages, prompts, inputs, outputs and other content a customer or its users elect to upload, create, connect or generate through the Service.
Technical and usage data, including information about system performance, feature usage, interactions with the Service, error logs and similar telemetry data.
Support and communications data, including information contained in support requests, service correspondence and feedback.
Security and compliance data, including data relevant to investigating suspected misuse, fraud, security incidents or legal claims.
Usage Data does not include workspace inputs, outputs or Customer Data, except where such data has been aggregated or de-identified.
3 Why We Process Personal Data and Our Legal Bases
Etain processes personal data only where a valid legal basis applies. Depending on the context, these are:
Performance of a contract: to provide the Service, administer user accounts, deliver support and fulfil our obligations under applicable agreements.
Legitimate interests: to operate, protect, maintain, troubleshoot, improve and develop the Service; manage customer relationships; prevent fraud and misuse; and establish, exercise or defend legal claims. We balance these interests against the rights and freedoms of affected individuals.
Legal obligation: to meet applicable legal, regulatory, accounting, tax, security or law-enforcement requirements.
Consent: where consent is required by applicable law. Consent can be withdrawn at any time, without affecting processing that occurred before withdrawal.
Processor instructions: where Etain processes Workspace Owner Data on behalf of a customer, the customer’s documented instructions and the DPA provide the applicable Article 28 GDPR framework; the customer remains responsible for identifying the appropriate lawful basis for that processing.
4 How We Use Workspace Owner Data
We use Workspace Owner Data only as necessary to provide the Service and as instructed by the relevant customer, including to:
store, structure, organise, index and retrieve Customer Data;
generate contextual representations, embeddings and indexes within the relevant customer instance;
perform AI-enabled processing, including retrieval-augmented generation and contextual reasoning;
generate outputs in response to user inputs;
provide support, maintenance, security, incident prevention, detection and investigation; and
comply with applicable law or enforce our contractual rights where permitted.
Etain does not use Customer Personal Data to train, retrain or improve general-purpose or multi-tenant AI or machine-learning models, and does not permit its sub-processors to do so, unless the customer has expressly agreed in writing. This does not prevent transient processing required to produce a requested output, customer-instance-specific contextual processing, or processing required to provide and secure the Service.
Etain may use data in an aggregated and de-identified form that does not identify a customer or individual for lawful internal purposes, such as analytics, benchmarking, service improvement, product development and statistical analysis.
5 Artificial Intelligence Functionality
The Service may use artificial intelligence and machine-learning technologies to analyse information, generate context and produce outputs. AI processing of Workspace Owner Data occurs on behalf of, and under the instructions of, the relevant customer.
AI-generated outputs are probabilistic and may be inaccurate, incomplete or misleading. They are provided for informational and assistive purposes and must be reviewed and validated by a person before they are relied upon. The Service does not provide legal, financial, regulatory or other professional advice.
6 Disclosure of Personal Data
We do not sell Workspace Owner Data. We may disclose personal data only as necessary and permitted by applicable law, including to:
Etain personnel, consultants and contractors who have a genuine need to know the information and are bound by appropriate confidentiality obligations;
approved sub-processors and service providers that help us provide the Service, such as cloud-infrastructure, AI-model and related technology providers, subject to applicable contractual data-protection requirements;
the relevant customer or workspace owner, where they administer the workspace and its users;
competent authorities or other third parties where disclosure is required by law, a valid legal process or to protect rights, security and property; and
professional advisers, auditors, insurers and potential transaction counterparties, subject to appropriate confidentiality and legal safeguards.
7 International Transfers
Etain will not transfer Customer Personal Data outside the EU/EEA without the relevant customer’s prior written consent where required under the DPA. Where a transfer is permitted, Etain will ensure that an appropriate transfer mechanism and supplementary safeguards are used where required by applicable data-protection law.
8 Security
Etain implements planned and systematic technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include access controls and a need-to-know approach for personnel, confidentiality obligations, security reviews and controls, and operational backup and recovery arrangements. No method of transmission or storage is completely secure, but we work to maintain a level of security appropriate to the risk.
9 Personal Data Incidents
If Etain becomes aware of a personal data breach affecting Customer Personal Data, we will notify the relevant customer without undue delay and provide information reasonably required for the customer to meet its notification obligations. We will cooperate with the customer on reasonable investigation, mitigation and remediation steps.
10 Retention and Deletion
We retain personal data only for as long as necessary for the purposes described in this Policy, to provide the Service, comply with legal obligations, resolve disputes and enforce agreements.
Upon cessation of services involving Customer Personal Data, Etain will delete Customer Personal Data in accordance with the DPA, normally within 10 business days. Data in backup files may be retained for up to 90 days following a deletion request. Limited data may be retained where required by law or necessary to establish, exercise or defend legal claims; such data remains protected and is not actively processed for other purposes.
Customers may request a copy of Customer Data stored by Etain in accordance with their agreement and the applicable DPA.
11 Your Rights
Subject to the conditions and limits in applicable law, individuals may have rights to request access to, rectification or erasure of personal data; restriction of or objection to processing; data portability; and withdrawal of consent where processing is based on consent.
For Workspace Owner Data, please contact the relevant customer or workspace owner first, as that organisation controls the data and is responsible for responding to requests. Etain will assist customers with such requests as required by the DPA and applicable law.
For personal data for which Etain is the controller, contact us using the details below. You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) or another competent supervisory authority.
12 Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the Service, our processing practices or applicable law. We will publish the updated version with a revised effective date and, where required, provide additional notice.
13 Contact Us
For questions about this Privacy Policy or Etain’s processing of personal data, please contact:
Etain AS
Drammensveien 123, 0277 Oslo, Norway
Email: info@etain.no
If Etain has appointed a data protection officer or EU/EEA representative for a particular processing activity, the applicable contact details will be made available here or in the relevant customer documentation.