EN

/

NO

Privacy Policy

Privacy Policy for Frank Legal AS Last updated: 12 June 2026

Frank Legal AS is a consultancy firm providing legal services. Frank Legal AS is not a law firm and is not subject to the duty of confidentiality applicable to solicitors under the Courts Act. However, all our employees are bound by a contractual duty of confidentiality.


Frank Legal AS is the data controller for the processing of personal data described in this privacy policy.

Privacy is important to us. This privacy policy explains how we collect, use, share and protect personal data, and what rights you have. Frank Legal AS is the data controller for the processing described here.

If you have any questions about how we process personal data, or wish to exercise your rights, please contact us at hei@frank.legal.


1. Who does this privacy policy apply to?

This privacy policy applies to contact persons at customers and potential customers, users of our digital services and individuals who contact us. It also applies to individuals mentioned in documents, cases or correspondence shared with us.

In addition, it applies to suppliers, partners, other business contacts, job applicants and candidates in recruitment processes.


2. What personal data do we process?

The personal data we process depends on the nature of your contact with us and the services you use.

We may process contact and user information, such as name, email address, telephone number, job title, employer, role, account details, access rights, login history, technical logs and communications with us.

We may process information about the organisation you represent, such as company name, registration number, address, billing details, payment status and information necessary for our internal customer control and risk management.


When you ask us to assist with a legal matter, we may process the content of your enquiry, documents, agreements, emails, correspondence, case descriptions, notes, assessments and information about other individuals involved in the case.


In certain cases, this may include special categories of personal data, such as health data or information regarding trade union membership, if necessary to handle the case.


We may also process information regarding criminal offences or breaches of the law if this is relevant and necessary for the legal matter.


When using our digital tools, AI assistant or chat functions, we may process the content you enter, documents you upload, responses and drafts generated by the service, technical logs, usage data, metadata and feedback.


When you visit our website, we may process technical information such as your IP address, browser type, device type, operating system, time of visit, which pages you visit, and information from cookies or similar technologies.


When you communicate with us via email, video conference or other electronic channels, we may process the content of the communication, contact details, time, metadata and technical information related to the communication.


We ask that you do not share more personal data than is necessary for us to provide the service or respond to your enquiry.


Providing us with personal data is voluntary. If you do not provide us with the necessary information, we may in some cases be unable to respond to your enquiry, establish a customer relationship, provide the service or fulfil our legal obligations. Where the processing is based on consent, you may withdraw your consent at any time.


3. Where do we obtain personal data from?

We receive personal data directly from you, from the company you represent and from other users at the client. We may also receive information from documents and correspondence shared with us, from public registers, from suppliers and partners, from technical systems and from others involved in a case.


When we receive information about persons other than the person who contacts us directly, this is normally because the information forms part of a legal enquiry, a document, an agreement, a dispute or an internal assessment with which the client has asked us to assist. The client is responsible for ensuring that there is a legal basis for sharing such information with us.


4. Why do we process personal data?

We process personal data in order to:

  • respond to enquiries, assess whether we can assist, follow up with clients and provide relevant information about our services

  • establish and manage client relationships, provide access to the service, manage user roles, administer subscriptions and follow up with the client

  • provide legal services, including assessing legal issues, drafting documents, providing opinions, reviewing contracts and providing other services requested by the customer

  • provide digital tools and AI features, such as chat, document analysis, search, summarisation, drafting and workflows

  • protect the service, prevent misuse, detect errors, manage security incidents and ensure stable operation

  • quality-assure, correct errors and further develop our services, to the extent possible using aggregated, anonymised or pseudonymised data

  • handle invoicing, payment, accounting and compliance with bookkeeping and tax obligations

  • send marketing communications and carry out customer follow-up within the framework of applicable regulations

  • document matters, handle complaints, pursue claims, defend ourselves against claims or safeguard legal interests


5. Legal basis

We process personal data only where we have a legal basis under data protection regulations. Processing to respond to enquiries, follow up on potential customers, manage customer relationships with businesses, secure the service, document work, improve the service and handle legal claims is normally based on our legitimate interest under Article 6(1)(f) of the GDPR.


Processing to provide services to you or the business you represent is based on a contract, cf. Article 6(1)(b) of the GDPR, where you yourself are a party to the contract. Where the customer is a business, the processing is based on legitimate interest, cf. Article 6(1)(f) of the GDPR.


Processing for invoicing, accounting and statutory obligations is based on a legal obligation under Article 6(1)(c) of the GDPR, and in some cases also on legitimate interest under Article 6(1)(f) of the GDPR.

Marketing is based on consent under Article 6(1)(a) of the GDPR or on legitimate interest under Article 6(1)(f) of the GDPR where permitted by the regulations.

When we process special categories of personal data, we do so only when necessary and where we have a specific legal basis under Article 9 of the GDPR.

The relevant legal basis for special categories of personal data will normally be Article 9(2)(f) of the GDPR, where processing is necessary for the establishment, exercise or defence of legal claims. In cases where the customer chooses to upload material containing such information to our digital tools, the processing may also be based on explicit consent under Article 9(2)(a) of the GDPR.


When we process information relating to criminal offences or breaches of the law, we do so only where necessary for the service in question, to handle legal claims, or where the processing is otherwise permitted under Article 10 of the GDPR, Section 11 of the Personal Data Act and relevant Norwegian law.


6. Use of AI and automated tools

We may use AI and other automated tools to support the delivery of our services.


Such tools may be used to understand and categorise enquiries, suggest drafts, search and summarise documents, analyse document volumes, operate AI assistants and chat functions, quality-assure work processes and improve the service.


AI-generated results within the service are intended to support the client's legal work. The client is responsible for assessing and quality-assuring the content in light of their specific situation.


When you use the AI assistant, chat functions or other digital tools, we may process the content you enter, documents you upload, technical logs, metadata and feedback.


We do not make decisions that have legal effects on you, or that similarly affect you to a significant extent, based solely on automated processing.

When we use AI providers who process personal data on our behalf, this is done under a data processing agreement.


Personal data from customers shall not be used to train the providers' AI models.


We do not use customer data to train our own AI models without the customer's express and documented prior consent.


7. Who do we share personal data with?

We share personal data only where it is necessary, lawful and relevant to the purpose of the processing.

We may share personal data with IT, operations, hosting, security and support providers, as well as AI and technology providers. We may also share data with providers of email, CRM, analytics, payment and invoicing services, as well as with accountants, auditors and other administrative service providers.


We may also share personal data with public authorities where we are obliged to do so. We may share information with courts, tribunals, counterparties, advisers, partners or external professionals if necessary to provide the service or handle a case, normally following agreement with the customer.


Suppliers who process personal data on our behalf may only process the data in accordance with our instructions and under a data processing agreement.

We do not sell personal data.


8. Transfer outside the EEA

We do not transfer personal data to countries outside the EEA unless there is a valid legal basis for transfer under Chapter V of the GDPR.


If such a transfer takes place, we will use a valid legal basis for the transfer, such as the European Commission's adequacy decision or standard contractual clauses, combined with necessary risk assessments and supplementary measures.


9. How long do we store personal data?

We store personal data for as long as is necessary for the purposes for which it was collected, and thereafter for as long as we are required or entitled to store it by law, contract or to address potential legal claims.

Customer and contact details are stored for as long as the customer relationship lasts, and thereafter normally for up to 3 years for follow-up, documentation and handling of any claims.


User accounts, access data, technical logs and security logs are normally deleted or anonymised within 12 months of storage no longer being required. Longer storage may occur where necessary for documentation, security, troubleshooting or handling legal claims.

Case information and legal deliverables are stored for as long as necessary to provide the service, document the work and handle potential legal claims.

Generally, case information is deleted or anonymised no later than 5 years after the assignment has been completed, unless longer storage is necessary due to specific legal claims, disputes or other lawful requirements.


AI chat, conversation history and uploaded documents that form part of a client assignment may be stored as part of the case file. Such storage takes place for as long as is necessary to provide the service, document the work or handle potential legal claims.


AI chat and uploaded documents not linked to a client assignment are normally deleted or anonymised within 12 months. Longer storage may occur where necessary for security, troubleshooting, abuse prevention or handling legal claims.


Invoicing and accounting information is stored in accordance with accounting regulations, normally for 5 years after the end of the financial year.

Contact details for marketing purposes are stored for as long as consent is valid or the customer relationship exists, and will be deleted without undue delay after consent has been withdrawn or you have opted out of direct marketing.


When personal data is no longer necessary, we delete or anonymise it.


The retention period for recruitment data is set out in section 13.


10. Cookies

We may use cookies and similar technologies on the website and in our digital services.


Cookies may be used to make the website and service function, remember choices and settings, ensure security, understand how the website and service are used, improve the user experience and measure the effectiveness of content and marketing.


Essential cookies are used to ensure that the website and service function.


Other cookies, such as analytics or marketing cookies, are only used after you have given your active consent via our consent solution (cookie banner), cf. Section 2-7b of the Electronic Communications Act and Article 6(1)(a) of the GDPR.


Further information about cookies, their purpose, duration and how you can change your settings can be found in our cookie policy at frank.legal/cookies.


11. Social media

Frank Legal AS has corporate accounts on social media platforms such as LinkedIn, and uses these platforms to share professional content, market our services and receive enquiries.


When you follow us, comment, send us messages or otherwise interact with our content, we may process your name, profile picture, account information and the content of the communication. We may also process aggregated statistics on how our content is used.

This processing is based on our legitimate interest in marketing our services and maintaining contact with existing and potential customers, cf. Article 6(1)(f) of the GDPR.


The platforms themselves are data controllers for their own processing of personal data. In certain cases, we are joint controllers with the platform under Article 26 of the GDPR, for example where the platform provides aggregated statistics on interaction with our corporate page. The essential content of the joint controller arrangement is made available to data subjects upon request. The platforms may also transfer personal data to countries outside the EEA. We encourage you to read the individual platform's privacy policy for further information.


12. Marketing and newsletters

We may send you information about the service, legal updates, invitations to events and webinars, and other marketing material.


For this purpose, we process your name, email address, job title, employer and any preferences regarding what you wish to receive. We may also process statistics on how the marketing material is used, for example whether an email has been opened or whether you have clicked on links. The purpose is to tailor the content and measure the effectiveness of the marketing.


The processing is based on consent under Article 6(1)(a) of the GDPR, or on legitimate interest under Article 6(1)(f) of the GDPR where an existing customer relationship exists, cf. Section 15(2) of the Marketing Act.

For events and webinars, we may also process registration information, participant lists and any dietary preferences or allergies. In some cases, participant lists may be shared with other participants or with partners who are co-organising the event with us.


You may opt out of direct marketing at any time by clicking the unsubscribe link in the marketing material or by contacting us at hei@frank.legal.


13. Recruitment

When we recruit new employees, we process personal data relating to applicants and candidates.


We may process contact details, applications, CVs, diplomas, certificates, reference letters and similar documents. We may also process information regarding education, work experience and skills, as well as notes and assessments from interviews and other meetings during the recruitment process.


If the recruitment process includes skills or personality tests, or reference checks with previous employers, we also process the results of these.


The purpose is to assess applicants for relevant positions, carry out the recruitment process and document that we have complied with applicable requirements under the Equality and Anti-Discrimination Act, data protection regulations and other relevant rules.

The processing is based on our legitimate interest in recruiting suitable employees under Article 6(1)(f) of the GDPR, and on pre-contractual measures under Article 6(1)(b) of the GDPR. Tests, reference checks and storage beyond the recruitment process itself are based on consent under Article 6(1)(a) of the GDPR, which you may withdraw at any time.


Applications from candidates who are not hired are normally deleted within 6 months of the recruitment process being concluded, unless you have consented to longer storage with a view to future positions. Applications from candidates who are hired are transferred to the personnel file and stored as part of the employment relationship.


14. Your rights

You have rights under data protection regulations.

Access: You may request access to the personal data we process about you and obtain a copy of the data.

Rectification: You may ask us to correct inaccurate or incomplete data.

Erasure: You may ask us to erase personal data if the conditions for erasure are met.

Restriction: You may ask us to restrict processing in certain cases.

Data portability: You may request data portability where the conditions for this are met.

Objection: You may object to processing based on legitimate interest.

Withdrawal of consent: If the processing is based on consent, you may withdraw your consent at any time.

If you object to direct marketing, we will cease processing for this purpose.


Your rights may be restricted in certain cases. This applies, for example, if we have a legal obligation to retain the data, if the data is necessary to handle legal claims, or if access or erasure would affect the rights and freedoms of others.


To exercise your rights, please contact us at hei@frank.legal. We may ask you to verify your identity before we process your request.


15. Information security

We use technical and organisational measures to protect personal data against unauthorised access, alteration, erasure, loss or other unlawful processing.


Access to personal data is granted only to those who have a legitimate business need for it, and all those with access are subject to confidentiality obligations.


Security measures may include, among other things, access control, encryption where relevant, logging, role-based access, security requirements for suppliers, incident management, and deletion or anonymisation when data is no longer necessary.


Security measures are reviewed and updated regularly.

In the event of a personal data breach that poses a high risk to the rights and freedoms of individuals, we will notify those affected without undue delay in accordance with Article 34 of the GDPR. Suspected security breaches can be reported to us at hei@frank.legal.


16. Complaints to the Data Protection Authority

If you believe that our processing of personal data is in breach of data protection regulations, you may lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).


The Data Protection Authority's website is datatilsynet.no.


You may also lodge a complaint with the data protection authority in the EU/EEA country where you live or work, or where you believe the infringement has occurred.

We encourage you to contact us first so that we can assess the matter and attempt to resolve any issues.


17. Changes to the privacy policy

We may update this privacy policy from time to time, for example in the event of changes to our services, the technology we use, our suppliers, applicable regulations or how we process personal data.


The latest version will be available at frank.legal.

In the event of significant changes, we will provide information in an appropriate manner, for example on the website, within the service or via email.


18. Contact us

If you have any questions about this privacy policy or how we process personal data, please contact us at hei@frank.legal.


Frank Legal AS Company registration number: 936 860 370 Slemdalsveien 1 0369 Oslo Email: hei@frank.legal Website: frank.legal