LEGAL
Privacy Policy
How WISE Group collects, uses and protects personal data in connection with the Orbalux platform, our monitoring systems and this website.
EFFECTIVE
1 July 2026
VERSION
2.1
GOVERNING LAW
Norway · GDPR
DATA RESIDENCY
European Union
1 · Who we are
Orbalux is operated by WISE Group. Unless your contract names a different entity, the data controller is Automasjon og Data AS, our Norwegian parent company. Where you contract with one of our other registered entities, that entity is the controller for your account and this policy applies unchanged.
CONTROLLER · NORWAY
Automasjon og Data AS
Vassbotnen 23, 4033 Stavanger, Norway
Org. no. NO 961 433 371 MVA
GROUP ENTITIES
WISE Group — Muir Matheson Ltd SC698303
WISE Group — RUP Ltd SC812160
WISE Group France — Marseille
2 · Data we process
We collect only what is needed to provide, secure and support the service. We do not buy personal data from third parties, and we do not build advertising profiles.
| CATEGORY | WHAT IT INCLUDES | SOURCE |
|---|---|---|
| Account | Name, work email, employer, job role, user group and permissions | You or your administrator |
| Authentication | Hashed credentials, session tokens, sign-in timestamps, IP address | Collected on use |
| Audit trail | Alarm acknowledgements, threshold changes, report exports, configuration edits | Collected on use |
| Support | Correspondence, tickets, call notes, diagnostic logs you send us | You |
| Website | Pages viewed, referrer, approximate region, device and browser type | Cookies · see §10 |
| Monitoring | Sensor readings from your assets — see §4 for why this is not normally personal data | Your instruments |
We do not knowingly collect special category data. Please do not send us health, biometric or similar sensitive information through support channels.
3 · Lawful basis
CONTRACT · ART 6(1)(b)
Creating accounts, delivering dashboards and reports, providing support and administering your subscription.
LEGITIMATE INTEREST · ART 6(1)(f)
Securing the platform, preventing abuse, maintaining audit trails, and improving reliability. Balanced against your rights and recorded internally.
LEGAL OBLIGATION · ART 6(1)(c)
Accounting and tax records, and retention of certification-relevant evidence where class or a regulator requires it.
CONSENT · ART 6(1)(a)
Optional analytics cookies and marketing emails. You may withdraw consent at any time without affecting the service.
4 · Monitoring data and your assets
The bulk of what Orbalux stores is measurement data — wind, wave, motion, tension, structural response. It describes physical conditions and equipment, not individuals, and is therefore not normally personal data.
Two exceptions are worth naming plainly. First, an audit trail entry links a named user to an action, such as acknowledging an alarm. Second, some deployments include CCTV where footage may capture identifiable people. In both cases you are the controller of that data and we act as your processor under a written data processing agreement.
Your measurement data is yours. We do not use it to train models, benchmark other clients, or share it commercially. Aggregated engineering insight is only published with your written agreement, and never in a form that identifies your asset.
5 · How long we keep it
| DATA | PERIOD | REASON |
|---|---|---|
| Account records | Contract + 12 mo | Reinstatement and handover |
| Sign-in and security logs | 13 months | Incident investigation |
| Audit trail | Per contract | Class and certification evidence |
| Measurement data | Per contract | You set the retention window |
| CCTV footage | 30 days | Default unless you specify otherwise |
| Support correspondence | 3 years | Recurring-fault history |
| Invoices and accounts | 5 years | Norwegian Bookkeeping Act |
7 · International transfers
Orbalux is hosted in the European Union and your data stays there by default. Norway is part of the EEA, so transfers between our Norwegian operation and the EU require no additional mechanism.
Where a support engineer outside the EEA needs access — for example our UK teams — we rely on the UK adequacy decision, or on Standard Contractual Clauses together with a transfer impact assessment. Access is time-boxed, logged in the audit trail and limited to what the task requires.
8 · Security
IN TRANSIT
Encrypted, outbound-only publishing from your network — no inbound firewall rule needed. Certificate-based authentication on every link.
AT REST
Encrypted storage in EU data centres, tenant separation between clients, and backups held to the same standard.
ACCESS
Role-scoped permissions, least-privilege staff access on a need-to-know basis, and a full audit trail of configuration changes.
INCIDENTS
Where a breach is likely to risk your rights we notify Datatilsynet within 72 hours and inform affected clients without undue delay.
No system is absolutely secure. If you believe an account has been compromised, contact us immediately using the details in §11.
9 · Your rights
Under the GDPR you may exercise the following rights free of charge. We respond within one month, and will tell you if we need longer.
- Art 15Access — a copy of the data we hold about you
- Art 16Rectification — correct anything inaccurate
- Art 17Erasure — deletion where no basis to keep it remains
- Art 18Restriction — pause processing while a matter is resolved
- Art 20Portability — your data in a machine-readable format
- Art 21Objection — object to legitimate-interest processing
If your data sits in a client-controlled environment we will refer you to that client as controller and support them in responding. You also have the right to lodge a complaint with the Norwegian Data Protection Authority, Datatilsynet, or your local supervisory authority.
11 · Contact us
For any privacy question, a data subject request, or a copy of our sub-processor list, contact our privacy team. Please put "Privacy request" in the subject line so it reaches the right desk.
PRIVACY TEAM
Automasjon og Data AS
Vassbotnen 23, 4033 Stavanger, Norway
Telephone +47 51 12 30 80
privacy@wisegroupsystems.com
Changes to this policy
We review this policy at least annually. Where a change materially affects how we handle your data we will notify account administrators by email and post a notice in the application at least 30 days before it takes effect. Superseded versions are retained and available on request.