Legal

Your privacy, in plain language.

What we collect, why we collect it, how long we keep it, and what you can do about it. No legal jargon where we can help it.

Last updated 1 May 2026

At a glance

Four things to know before you read the rest.

Certified by external auditors

ISO 9001 and ISO/IEC 27001 across the company. GDPR by default.

EU-first hosting

Scout Portal and our internal data on Microsoft Azure in the EU. HubSpot CRM in the US under the EU-US Data Privacy Framework.

No selling, no profiling, no buying

We don't sell your data. We don't share it for ad profiling. We don't buy or enrich data from brokers.

You're in control

Withdraw consent any time. Ask us what we have. Ask us to delete it. Email contact@scoutdi.com — we respond within 30 days.

What we collect

Who's behind the policy.

ScoutDI AS — Sluppenvegen 25, N-7037 Trondheim, Norway. Org. nr. 920 197 744.

For any privacy question, write to contact@scoutdi.com. We're the controller for everything covered here.

What we collect.

  • What you give us — name, work email, company, role and phone number when you submit a form, book a demo, subscribe, or contact support.
  • Scout Portal account data — identifier, role, organization, authentication metadata and audit-log entries from actions you take in the platform.
  • Technical data from your visit — IP address, browser, device, pages viewed, referring URL. Set via cookies (see our cookies policy).

We collect this directly from you. We do not buy or enrich your data from third-party brokers.

Why we use it.

Under GDPR Article 6(1), every purpose has a legal basis. Here's how that maps for us:

  • Respond to enquiries, schedule demos, deliver requested serviceslegitimate interest and contract where you're an existing customer.
  • Operate Scout Portal and provide supportcontract.
  • Send product updates and event invitationsconsent. Unsubscribe any time.
  • Analytics and marketing cookiesconsent, captured via the cookie banner.
  • Meet legal and regulatory obligationslegal obligation.

We do not sell your personal data. We do not buy or enrich personal data from data brokers. We use a LinkedIn Pixel to retarget visitors who have already engaged with us on LinkedIn — this is opt-in via the cookie banner (Marketing category) and you can withdraw consent at any time.

Who has access

Inside ScoutDI.

Access is limited to employees who need the data for their role. All employees are bound by confidentiality. We may share data with public authorities when we're legally required to.

Processors we work with.

Each of these is bound by a Data Processing Agreement with ScoutDI AS:

  • HubSpot — CRM and marketing automation. Hosted in the United States.
  • Microsoft 365 — email, collaboration, file storage. Hosted in the EU.
  • Microsoft Azure — Scout Portal hosting, scoutdi.com website delivery, and chat/feedback backend. Hosted in the EU.
  • Google Analytics 4 — aggregated website analytics. Hosted in the United States. Runs on Google’s default configuration; full IP is processed at collection and not pseudonymised before transmission.
  • LinkedIn (LinkedIn Pixel) — retargets visitors who have engaged with our LinkedIn presence. Activated only after Marketing consent is given. Hosted by LinkedIn Ireland (EU) and LinkedIn Corporation (US).

When data leaves the EU.

Some of our processors operate outside the EU/EEA. We rely on the following safeguards:

  • HubSpot LLC (United States) — certified under the EU-US Data Privacy Framework. Standard Contractual Clauses apply where the framework does not cover a transfer.
  • Google LLC (United States) — certified under the EU-US Data Privacy Framework. Standard Contractual Clauses for transfers not covered by the framework.
  • LinkedIn Corporation (United States) — certified under the EU-US Data Privacy Framework. Standard Contractual Clauses apply where the framework does not cover a transfer.

What you control

Your rights.

Under the GDPR you have the right to:

  • Ask us what data we have on you
  • Correct inaccuracies
  • Ask us to delete your data
  • Restrict or object to certain processing
  • Receive your data in a portable, machine-readable format
  • Withdraw consent at any time, where processing is based on consent

To exercise any of these, email contact@scoutdi.com. We respond within 30 days.

If you believe we're not respecting your rights, you can lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) at datatilsynet.no.

How long we keep it.

We keep personal data only as long as we need it for the purpose it was collected for, then delete or anonymize it.

  • Contact data from website forms: up to 24 months from last interaction.
  • Scout Portal account data: for the duration of the active commercial relationship. On termination or extended inactivity, data is removed in line with the customer's deletion request or during periodic account review.
  • Analytics data: anonymized after 14 months.
  • Financial and contractual records: 5 years, per the Norwegian Bookkeeping Act (bokføringsloven).

The detail

Automated decision-making.

ScoutDI does not make automated decisions that produce legal or similarly significant effects on you (GDPR Art. 22). A human is always in the loop.

Children's data.

Our services are aimed at industrial customers. We don't knowingly collect personal data from children under 16.

Security.

ScoutDI is ISO 9001 and ISO/IEC 27001 certified. We use appropriate technical and organizational measures to protect your data.

Changes to this policy.

When we update this policy, we change the “last updated” date at the top. Check back periodically if it matters to you.