NORWAY · LEGAL
Privacy Policy
Benford Revisjon AS (company reg. no. 838 070 442)
Benford Revisjon AS (“Benford”, “we”, “us”) is committed to taking good care of the personal data we process. This policy explains what personal data we process in connection with audit, assurance and advisory engagements, why we process it, who we share it with, how long we retain it, and what rights you have. It also covers our website (benford.no) and our audit platform (portal.benford.no).
1. Data controller
Benford Revisjon AS is the data controller for the personal data we collect and use in our own business. In some engagements we may act as a data processor on behalf of a client – in that case the client is the data controller, and enquiries about rights should be directed there.
The audit platform is built and operated by our sister company Benford Teknologi AS together with Benford Revisjon AS. Benford Teknologi AS is the data controller for the usage statistics. For everything else in the platform, Benford Revisjon AS is the controller and Benford Teknologi AS acts as its data processor. You can use the contact address in section 12 for either.
2. What information we collect and why
We process personal data about, among others:
contact persons, board members, general managers and owners at our clients
employees of the client, where such information forms part of accounting and audit material
customers, suppliers and others who are identifiable in the client’s accounts
contact persons at our own suppliers and business partners
visitors to our website and users of our audit platform
The information is used to carry out audit, assurance and advisory work, to administer the client relationship, and to fulfil the obligations we have as an audit firm. Our legal bases are the obligations that apply to audit firms, the engagement agreement with the client, our legitimate interest in running and improving our services, and, for optional cookies on our website, your consent.
3. Client due diligence
As an audit firm, we are required to carry out client due diligence on clients before we can begin an engagement. This includes, among other things, identity verification and screening against official lists. Information from the due diligence process is retained and may in certain cases be reported onward to the authorities.
4. Who we share personal data with
We may share personal data with:
public authorities, where we are obliged to do so
suppliers that operate the systems we use (we have entered into data processing agreements with them), including our analytics provider PostHog
We do not sell personal data, and we do not share it with others for their own marketing purposes.
5. How long we retain the information
We retain personal data for as long as is necessary for the purpose for which it was collected, and for as long as we are required to do so by law. Once the retention obligation has ended, we delete or anonymise the information.
6. Cookies and analytics
On our website, statistics cookies (PostHog, Google Analytics) and marketing cookies are only set if you accept them in the cookie banner. You can change your choice at any time via the “Cookies” link.
session (cookie), platform. Login session, necessary. Stored for up to 90 days, or 30 days idle.
Theme, language, last opened audit (local storage), platform. Your settings, necessary. Stored until cleared.
bf_consent (cookie), website and platform. Remembers your answer to the cookie banner, necessary. Stored for 1 year.
bf_attr (cookie on the website, session storage in the platform), website and platform. Measures which advert led to an enquiry, marketing, set with your consent. Stored for 90 days, or until the tab closes.
ph_… and __ph_… (cookie, local storage and session storage), website. Statistics, and remembering that you accepted, set with your consent. Stored for 1 year.
_ga, _ga_…, _gcl_au, _gcl_aw (cookie, Google Ireland Ltd), website. Statistics and advertising measurement, set with your consent. Stored for 90 days to 2 years.
7. Use of artificial intelligence
We may use AI-based tools as support in our engagements, for example for analysis and drafting. We use only closed solutions that have been assessed and approved by us, client information is not used to train AI models, and all professional assessments and conclusions are made by the auditor.
8. Information security
We have technical and organisational measures in place to protect personal data against unauthorised access, alteration and loss. These include access controls, encryption and secure storage, as well as confidentiality undertakings and training for our employees.
9. Transfers outside the EEA
As a general rule, we store personal data in Norway or in other countries within the EEA. If we exceptionally transfer information outside the EEA, we ensure that this is done in a manner that safeguards your privacy. Google Analytics and Google Ads on our website may transfer data to Google in the United States under the EU-US Data Privacy Framework, with standard contractual clauses as a fallback.
10. Your rights
You have the right, among other things, to:
obtain access to the personal data we process about you
have inaccurate information corrected and incomplete information completed
have information erased where we no longer have a basis for processing it
require that processing be restricted in certain situations
receive information you have provided to us yourself, in a machine-readable format
object to processing based on legitimate interests
withdraw a consent you have given
As auditors, we are subject to a duty of confidentiality which in some cases takes precedence over the right of access. This means that we cannot always grant access to information concerning the relationship with a client without that client’s consent.
11. Changes to this policy
We update this policy as needed, for example where there are changes to our services or systems. The current version is always available on our website.
12. Contact us and right to complain
If you have questions about this policy or about how we process personal data, you can contact us at kontakt@benford.no. You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) if you believe that we are processing personal data in breach of the rules (www.datatilsynet.no).
Last updated: September 2026