Privacy Policy
Last updated: January 1, 2026
1. Introduction
B-Hip AS ("we," "us," or "our") is committed to protecting the privacy and personal data of all individuals who visit our website and use our services. This Privacy Policy explains how we collect, use, store, and protect your personal information in accordance with the Norwegian Personal Data Act (Personopplysningsloven), the General Data Protection Regulation (GDPR) (EU) 2016/679, and other applicable data protection legislation in Norway and the European Economic Area (EEA).
By accessing our website or submitting information through our contact forms, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please do not use our website or submit any personal information.
2. Data Controller
The data controller responsible for the processing of your personal data is:
If you have any questions about this Privacy Policy or the processing of your personal data, please contact us using the information above.
3. Personal Data We Collect
We may collect and process the following categories of personal data:
3.1 Information You Provide Directly
- Contact information: Full name, email address, and phone number when you submit our contact form.
- Program preferences: Selected program and preferred learning format as indicated in the contact form.
- Communication content: Any message or comment you include when contacting us.
- Consent records: Records of your consent to be contacted and to our Privacy Policy.
3.2 Information Collected Automatically
- Technical data: IP address, browser type and version, operating system, device type, screen resolution, and language preferences.
- Usage data: Pages visited, time spent on pages, referring URLs, and navigation patterns on our website.
- Cookie data: Information collected through cookies and similar tracking technologies as described in our Cookie Policy.
4. Legal Basis for Processing
Under the GDPR and Norwegian data protection law, we process your personal data based on one or more of the following legal grounds:
- Consent (Article 6(1)(a) GDPR): When you provide explicit consent through our contact form, including consenting to be contacted and to the processing of your personal data for the stated purpose.
- Legitimate interest (Article 6(1)(f) GDPR): When processing is necessary for our legitimate interests, such as improving our website, ensuring security, and analyzing website usage patterns, provided these interests are not overridden by your fundamental rights and freedoms.
- Legal obligation (Article 6(1)(c) GDPR): When processing is necessary for compliance with a legal obligation to which we are subject under Norwegian or EU law.
5. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
- To respond to your inquiries and contact form submissions.
- To provide information about our fitness coaching education programs.
- To communicate with you regarding your selected program interests and preferences.
- To improve the functionality, content, and user experience of our website.
- To analyze website traffic and usage patterns for internal statistical purposes.
- To ensure the security and integrity of our website and systems.
- To comply with applicable legal obligations and regulatory requirements.
6. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data to third parties for marketing purposes. We may share your personal data in the following limited circumstances:
- Service providers: We may share data with trusted third-party service providers who assist us with website hosting, email services, analytics, and technical infrastructure. These providers process data only on our behalf and in accordance with our instructions and applicable data protection law.
- Legal requirements: We may disclose personal data if required to do so by law, court order, or governmental regulation, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business transfers: In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity, subject to the same privacy protections described in this policy.
7. International Data Transfers
As our service area covers Canada and our organization is based in Norway, personal data may be transferred between Norway and Canada or to other countries where our service providers operate. When data is transferred outside the EEA, we ensure that appropriate safeguards are in place, including:
- Transfers to countries recognized by the European Commission as providing an adequate level of data protection (adequacy decisions).
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Other legally recognized transfer mechanisms under the GDPR.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Specifically:
- Contact form data: Retained for up to 24 months from the date of submission, unless you request earlier deletion or we need to retain records for legal compliance.
- Website analytics data: Retained in anonymized or aggregated form for statistical purposes for up to 26 months.
- Consent records: Retained for the duration of the processing activity plus an additional period necessary to demonstrate compliance with GDPR requirements.
When personal data is no longer needed, it is securely deleted or anonymized so that it can no longer be linked to you.
9. Your Rights Under GDPR
Under the GDPR and Norwegian data protection law, you have the following rights regarding your personal data:
- Right of access (Article 15): You have the right to request a copy of the personal data we hold about you.
- Right to rectification (Article 16): You have the right to request correction of inaccurate or incomplete personal data.
- Right to erasure (Article 17): You have the right to request deletion of your personal data, subject to certain legal exceptions.
- Right to restriction of processing (Article 18): You have the right to request that we restrict the processing of your personal data in certain circumstances.
- Right to data portability (Article 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
- Right to object (Article 21): You have the right to object to the processing of your personal data based on legitimate interests.
- Right to withdraw consent: Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days, as required by law.
10. Complaints
If you believe that your personal data has been processed in violation of applicable data protection legislation, you have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet):
Datatilsynet
Norwegian Data Protection Authority
P.O. Box 458 Sentrum
0105 Oslo, Norway
We encourage you to contact us first so that we can address your concerns directly.
11. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze website traffic, and improve our services. For detailed information about the types of cookies we use, their purposes, and how you can manage your cookie preferences, please refer to our Cookie Policy.
12. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- HTTPS encryption (SSL/TLS) across all pages of our website.
- Secure form processing with server-side validation and spam protection.
- Access controls limiting data access to authorized personnel only.
- Regular review and updating of our security practices.
While we take all reasonable steps to protect your data, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security of your personal data.
13. Children's Privacy
Our website and services are intended for adults only. We do not knowingly collect or process personal data from individuals under the age of 18. If we become aware that we have inadvertently collected personal data from a minor, we will take immediate steps to delete such data from our systems.
14. Third-Party Links
Our website may contain links to third-party websites or services. We are not responsible for the privacy practices, content, or data collection methods of these third parties. We encourage you to review the privacy policies of any third-party websites you visit.
15. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Continued use of our website following any changes constitutes your acceptance of the revised Privacy Policy.
16. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of Norway, including the Norwegian Personal Data Act and the GDPR. Any disputes arising from or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of Norway.
17. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please contact us: