Skip to content
fakktura

Last updated: May 2026

Privacy Policy

This privacy policy explains how fakktura handles personal data when you use the service. We process no more data than necessary, and we never sell it.

1. Data controller

fakktura is provided by HEM, a sole proprietorship registered in Norway with organisation number 924 807 342 and business address Folke Bernadottes vei 6, 0862 Oslo. “fakktura” is the trading name HEM uses for this service. HEM is the data controller for the personal data processed about you as a user.

Privacy enquiries can be sent to us by post to the address above, or through your account in fakktura. The service is not directed at children under 16, and we do not knowingly process personal data about minors.

2. What data we process

We process the following categories of data:

  • Account data: name, email address, phone number and password stored encrypted, plus data related to two-factor authentication.
  • Business data: organisation number, business name, address and VAT status of the business you keep books for.
  • Accounting data you enter: invoices, quotes, credit notes, customers and suppliers, products, expenses, vouchers, payments and ledger entries.
  • Bank data: if you connect your bank, account numbers and bank transactions retrieved for reconciliation.
  • Attachments: receipts, invoices and other documents you upload as vouchers.
  • Usage and technical data: sign-in and activity logs, IP address and data necessary for security, operation and troubleshooting.

Some data is retrieved from public sources rather than directly from you: business data from the Brønnøysund Register Centre by organisation-number lookup, and exchange rates from Norges Bank.

3. Our role — controller and processor

For data about you as a user and about your account, HEM is the data controller.

For the accounting data you enter — including personal data about your customers and suppliers — you are the data controller, and fakktura acts as a data processor on your behalf. The terms of service and this privacy policy govern how fakktura processes that data on your behalf.

4. Purpose of the processing

The data is used to deliver the service: to keep double-entry books, create and send invoices, calculate and file the VAT return, export SAF-T and give you secure access to your account.

Technical data is used for operation, security and troubleshooting. We do not use your personal data for marketing or profiling.

5. Legal basis

The processing rests on several bases in the General Data Protection Regulation (GDPR):

  • Contract (art. 6(1)(b)) — we need the data to deliver the service you have requested.
  • Legal obligation (art. 6(1)(c)) — the Norwegian Bookkeeping Act requires accounting records to be retained.
  • Legitimate interest (art. 6(1)(f)) — in the secure and stable operation of the service.

6. Storage and deletion

Accounting records are retained for as long as Norwegian law requires. Under the Bookkeeping Act, accounting records must be kept for at least five years after the end of the financial year, and part of the material must be electronically available for three years and six months. We therefore do not delete or anonymise accounting data before the retention period ends, even if you close your account.

Account data that is not accounting material is deleted when you close your account. Technical logs are kept only for a limited period for security and troubleshooting.

7. Processors and third parties

To deliver the service we use a few sub-processors, only to the extent necessary: server operation and storage with a provider within the EEA, error monitoring, and email delivery — for example invoices and notifications — where this is in use. All sub-processors are bound by a data processing agreement.

When you file a VAT return or send an EHF e-invoice, the necessary data is transmitted to the Norwegian Tax Administration and to the recipient of the invoice. This happens on your instruction, as part of the service you have asked for. We never sell personal data.

8. Where the data is stored

All accounting information and other personal data is stored on servers within the EEA, in line with the requirements of the Norwegian Bookkeeping Act and its regulations for the retention of accounting records.

9. Your rights

You have the right to access, rectification, erasure, restriction and data portability for the personal data we process about you. The right to erasure is limited for accounting records we are legally required to retain.

You can exercise your rights by contacting us by post or through your account. If the request concerns personal data in your own books — for example about one of your customers — it is you, as the data controller, who handles it.

10. Complaint to the Data Protection Authority

If you believe we process personal data in breach of the rules, you have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet). We would appreciate it if you contacted us first, so we can try to resolve the matter directly.

datatilsynet.no

11. Cookies

fakktura uses only necessary cookies: a secure session cookie that keeps you signed in, and cookies required for the security of the service. We use no third-party tracking or marketing cookies.

12. Changes to this policy

We may update this policy from time to time. The version in force at any given time is published on this page with an updated date.