Privacy Policy GDPR / DSGVO

Data protection
The protection of your personal data is important to me. I process personal data exclusively in accordance with applicable legal provisions, in particular the General Data Protection Regulation GDPR and relevant Norwegian data protection legislation.

Controller
BYOM
Owner: Karin Gutenbrunner
Skjoldenveien 9
1832 Askim
Norway
Phone: +47 47 38 27 40
Email: karin@byom.com

BYOM is registered as a sole proprietorship in the Norwegian Central Register Brønnøysundregistrene under organisation number 923 657 746 and is subject to VAT MVA.

Types of data processed
I process personal data that you provide in the context of contacting me or working with me. This includes in particular
• name, contact details and billing information
• contents of enquiries and agreements
• structured counseling and session notes
• organisational notes related to scheduling and cooperation

In the context of psychosocial counseling or coaching, information relating to mental or physical health may be disclosed. Such data constitutes special categories of personal data pursuant to Article 9 GDPR.

Purposes of processing
Data is processed exclusively for the following purposes
• responding to enquiries
• scheduling and communication
• provision of counseling, coaching and supervision services
• documentation of the cooperation
• invoicing and accounting
• compliance with legal obligations

Legal bases for processing
Processing is based on the following legal grounds
• Article 6 paragraph 1 b GDPR for performance of a contract or pre contractual measures
• Article 6 paragraph 1 f GDPR based on my legitimate interest in professional organisation, documentation and communication
• Article 6 paragraph 1 c GDPR to fulfil statutory retention obligations
• Article 9 paragraph 2 a GDPR where special categories of personal data are disclosed in the context of counseling, based on your explicit consent

Systems used and data processing
The following systems are used to provide my services
• Squarespace for website and contact form
• Google Workspace Google Drive, Google Docs, Google Sheets, Google Calendar, Google Meet, AppSheet for documentation, scheduling, online sessions and internal organisational processes
• Fiken.no for invoicing and accounting
• paper documents stored in a secured folder in my private work area

All relevant service providers are subject to data processing agreements or equivalent data protection safeguards.

Third country transfers
Some service providers are based in the United States. This may involve transfers of personal data to third countries.
Google and Squarespace are certified under the EU U.S. Data Privacy Framework, ensuring an adequate level of data protection. Additional safeguards such as standard contractual clauses are applied where relevant.

Cookies and website analytics
This website is used for informational purposes.
Squarespace may use technically necessary cookies as well as analytics cookies. Analytics and statistics functions may be enabled or disabled.
Where analytics cookies are used, this is done exclusively on the basis of your consent via an appropriate cookie banner.

Confidentiality
All information obtained in the course of my work is treated confidentially. Content from counseling, coaching or supervision processes is not disclosed to third parties unless there is a legal obligation or you have given explicit consent.

Storage and deletion
Personal data is stored only for as long as necessary for the stated purposes or as required by statutory retention obligations. Thereafter, the data is deleted or anonymised.

International clients
The company is based in Norway. Data processing takes place within the European Economic Area EEA. Norway is fully subject to the GDPR.
Services are predominantly provided online. There is no physical establishment outside Norway.

Your rights
You have the right at any time to
• access your stored personal data
• rectification of inaccurate data
• deletion or restriction of processing
• data portability
• object to processing
• withdraw consent given

You also have the right to lodge a complaint with a data protection supervisory authority. The competent authority is

Datatilsynet
P.O. Box 458 Sentrum
0105 Oslo
Norway
www.datatilsynet.no