Skip to content

Business Privacy Notice

How Apperah handles personal data in business accounts and relationships.

Effective:
2026-06-29
Last updated:
2026-09-01
Version:
v1.2

1. Who is responsible

Apperah AS is the controller of the personal data described here. For data-protection matters, contact us at dpo@apperah.com.

2. What we process

  • Identity and contact details of business representatives (name, role, email, phone).
  • Verification signals used to confirm a claim (e.g., business email/domain, documents you provide).
  • Communications with you.
  • Billing and tax data — if and when you pay Apperah (in-product billing has not yet launched), handled via our third-party payment provider (our Merchant of Record).
  • Business/venue information enriched from public sources — some of which we did not get directly from you (for example, a publicly listed business contact). We are transparent about this under GDPR Article 14.
  • Portal sign-in data — if you sign in to the business portal with Google, Facebook, or Apple, we receive your OAuth identity (identifier, email, name) from that provider; the portal also uses strictly necessary session and security cookies.
  • Consent-action records — when you grant or withdraw a consent in the portal (such as the event-image consent below), we record the change together with the IP address and browser details of the action, so we can demonstrate the consent trail (GDPR Art. 7(1)).
  • Onboarding and verification — to set up and confirm your business account (Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interests).
  • Enrichment of venue/business information — legitimate interests (Art. 6(1)(f)).
  • Payments — to take payment via our payment provider and meet bookkeeping duties (Art. 6(1)(b) and (c)).
  • Fraud prevention — legitimate interests and legal obligation (Art. 6(1)(f) and (c)).

4. Who receives it

Our service providers process data on our behalf. Notably, our payment provider handles payments — and acts as an independent controller for its own tax and fraud purposes. Service providers help with data enrichment. We do not sell your data.

4a. Controls you have over your venue’s content

  • Event images. We show images from your venue’s public event pages only with your consent. You can grant or withdraw this at any time in the portal; when you withdraw, stored references to those images are removed and future collection stops.
  • Happenings visibility. You can choose per event whether it appears in the app’s Happenings feed.

5. International transfers

Where data goes outside the EEA (for example, to our payment provider or an AI provider), we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses, as described in the EU-bloc addendum.

6. How long we keep it

For the life of the business account, plus any period required by law (for example, billing records under the Norwegian Bookkeeping Act for five years).

7. Your rights

You can access, correct, delete, or object to the processing of your data, and opt out of enrichment from public sources where available. To exercise your rights, contact privacy@apperah.com. You can also complain to your data-protection authority.

More