LEGAL

Privacy Policy

How WISE Group collects, uses and protects personal data in connection with the Orbalux platform, our monitoring systems and this website.

EFFECTIVE

1 July 2026

VERSION

2.1

GOVERNING LAW

Norway · GDPR

DATA RESIDENCY

European Union

1 · Who we are

Orbalux is operated by WISE Group. Unless your contract names a different entity, the data controller is Automasjon og Data AS, our Norwegian parent company. Where you contract with one of our other registered entities, that entity is the controller for your account and this policy applies unchanged.

CONTROLLER · NORWAY

Automasjon og Data AS

Vassbotnen 23, 4033 Stavanger, Norway

Org. no. NO 961 433 371 MVA

GROUP ENTITIES

WISE Group — Muir Matheson Ltd SC698303

WISE Group — RUP Ltd SC812160

WISE Group France — Marseille

2 · Data we process

We collect only what is needed to provide, secure and support the service. We do not buy personal data from third parties, and we do not build advertising profiles.

CATEGORYWHAT IT INCLUDESSOURCE
AccountName, work email, employer, job role, user group and permissionsYou or your administrator
AuthenticationHashed credentials, session tokens, sign-in timestamps, IP addressCollected on use
Audit trailAlarm acknowledgements, threshold changes, report exports, configuration editsCollected on use
SupportCorrespondence, tickets, call notes, diagnostic logs you send usYou
WebsitePages viewed, referrer, approximate region, device and browser typeCookies · see §10
MonitoringSensor readings from your assets — see §4 for why this is not normally personal dataYour instruments

We do not knowingly collect special category data. Please do not send us health, biometric or similar sensitive information through support channels.

3 · Lawful basis

CONTRACT · ART 6(1)(b)

Creating accounts, delivering dashboards and reports, providing support and administering your subscription.

LEGITIMATE INTEREST · ART 6(1)(f)

Securing the platform, preventing abuse, maintaining audit trails, and improving reliability. Balanced against your rights and recorded internally.

LEGAL OBLIGATION · ART 6(1)(c)

Accounting and tax records, and retention of certification-relevant evidence where class or a regulator requires it.

CONSENT · ART 6(1)(a)

Optional analytics cookies and marketing emails. You may withdraw consent at any time without affecting the service.

4 · Monitoring data and your assets

The bulk of what Orbalux stores is measurement data — wind, wave, motion, tension, structural response. It describes physical conditions and equipment, not individuals, and is therefore not normally personal data.

Two exceptions are worth naming plainly. First, an audit trail entry links a named user to an action, such as acknowledging an alarm. Second, some deployments include CCTV where footage may capture identifiable people. In both cases you are the controller of that data and we act as your processor under a written data processing agreement.

NOTE

Your measurement data is yours. We do not use it to train models, benchmark other clients, or share it commercially. Aggregated engineering insight is only published with your written agreement, and never in a form that identifies your asset.

5 · How long we keep it

DATAPERIODREASON
Account recordsContract + 12 moReinstatement and handover
Sign-in and security logs13 monthsIncident investigation
Audit trailPer contractClass and certification evidence
Measurement dataPer contractYou set the retention window
CCTV footage30 daysDefault unless you specify otherwise
Support correspondence3 yearsRecurring-fault history
Invoices and accounts5 yearsNorwegian Bookkeeping Act

6 · Sharing and processors

We never sell personal data. We share it only in these situations:

  • With WISE Group entities, where a shared engineering or support team serves your account.
  • With service providers acting on our instructions under a data processing agreement — EU cloud hosting, email delivery, CRM and helpdesk tooling.
  • With your own nominated parties, such as a class society or a duty holder, where you ask us to deliver reports to them.
  • Where law requires it, or to establish and defend legal claims.
  • To a successor entity in the event of a merger or acquisition, subject to this policy.

A current list of sub-processors is available on request from the address in §11, and we will give you advance notice of any material change so you can object.

7 · International transfers

Orbalux is hosted in the European Union and your data stays there by default. Norway is part of the EEA, so transfers between our Norwegian operation and the EU require no additional mechanism.

Where a support engineer outside the EEA needs access — for example our UK teams — we rely on the UK adequacy decision, or on Standard Contractual Clauses together with a transfer impact assessment. Access is time-boxed, logged in the audit trail and limited to what the task requires.

8 · Security

IN TRANSIT

Encrypted, outbound-only publishing from your network — no inbound firewall rule needed. Certificate-based authentication on every link.

AT REST

Encrypted storage in EU data centres, tenant separation between clients, and backups held to the same standard.

ACCESS

Role-scoped permissions, least-privilege staff access on a need-to-know basis, and a full audit trail of configuration changes.

INCIDENTS

Where a breach is likely to risk your rights we notify Datatilsynet within 72 hours and inform affected clients without undue delay.

No system is absolutely secure. If you believe an account has been compromised, contact us immediately using the details in §11.

9 · Your rights

Under the GDPR you may exercise the following rights free of charge. We respond within one month, and will tell you if we need longer.

  • Art 15Access — a copy of the data we hold about you
  • Art 16Rectification — correct anything inaccurate
  • Art 17Erasure — deletion where no basis to keep it remains
  • Art 18Restriction — pause processing while a matter is resolved
  • Art 20Portability — your data in a machine-readable format
  • Art 21Objection — object to legitimate-interest processing

If your data sits in a client-controlled environment we will refer you to that client as controller and support them in responding. You also have the right to lodge a complaint with the Norwegian Data Protection Authority, Datatilsynet, or your local supervisory authority.

10 · Cookies

The Orbalux application uses strictly necessary cookies for sign-in and session security. These cannot be switched off without breaking the service. On wisegroupsystems.com we also use optional analytics cookies, and these are set only after you consent.

TYPEPURPOSECONSENT
EssentialSession, sign-in, CSRF protectionNOT REQUIRED
PreferenceTheme choice, default station, unitsNOT REQUIRED
AnalyticsAggregated page views on the public siteOPT-IN
AdvertisingNone — we do not run ad or tracking pixelsNOT USED

11 · Contact us

For any privacy question, a data subject request, or a copy of our sub-processor list, contact our privacy team. Please put "Privacy request" in the subject line so it reaches the right desk.

PRIVACY TEAM

Automasjon og Data AS

Vassbotnen 23, 4033 Stavanger, Norway

Telephone +47 51 12 30 80

privacy@wisegroupsystems.com

Changes to this policy

We review this policy at least annually. Where a change materially affects how we handle your data we will notify account administrators by email and post a notice in the application at least 30 days before it takes effect. Superseded versions are retained and available on request.

© 2026 WISE Group. All rights reserved.