Privacy
Last updated 12 August 2026
Vollar Development (Norway) operates Ingati. This describes what personal data we hold, why we are allowed to, how long we keep it, and how to have it removed.
Who we are
Vollar Development, Norway. For anything on this page, including requests to see or delete what we hold, write to personvern@ingati.com. We aim to answer within 30 days, which is the limit the GDPR sets.
You can complain to Datatilsynet, the Norwegian Data Protection Authority, at any time.
If you are a customer
| What | Why | How long |
|---|---|---|
| Name, email address, password (hashed) | To give you an account. Without it there is no login. | While your account exists |
| Company name, organisation or VAT number | To bill you, and to work out the right tax | While your account exists; invoices for 5 years |
| Billing records | Legal obligation — Norwegian bookkeeping law | 5 years after the financial year |
We never see your card.Payment happens on Stripe's own pages. We store an identifier that lets us ask Stripe about your subscription, and nothing else.
Websites you ask us to scan
When you point Ingati at a site, we fetch its pages and store what we find so we can show you the report. If those pages contain personal data — a contact page naming your staff, for instance — we hold it on your instruction and on your behalf. You decide what happens to it; we only process it to produce your reports, and we delete it as scans age out.
In data protection terms you are the controller and we are your processor. The terms of service set that out formally.
If we contacted you and you are not a customer
We run a crawler that visits business websites and records what it finds, including contact details published on those sites, so we can tell a company when their site has problems we can fix. If you have heard from us, this is why.
| What | Why | How long |
|---|---|---|
| Your website address, and technical findings about it | To judge whether the site has problems worth writing to you about | Ongoing |
| Contact details published on your site — email, phone, social profiles | So a person can write to you about those findings | 180 days, then automatically erased |
Our basis is legitimate interest. We only read what your site serves to any visitor, we obey robots.txt, and the crawl is shallow — roughly eleven requests. We weighed our interest in finding customers against your interest in being left alone, and the things that make it fair are: the details were published by you for the purpose of being contacted, the context is business-to-business, we delete them after 180 days, and you can stop it at any time.
You can object, and we will stop. Email personvern@ingati.com with your domain name. We erase the contact details and add the domain to a permanent do-not-crawl list, so it does not come back the next time another site links to you. We do not need a reason, and we will confirm when it is done.
Who else sees any of it
| Who | What they get | Why |
|---|---|---|
| Stripe | Your email, company name, VAT number, billing address, card details | Payments and subscriptions |
| Resend | Recipient address and message content | Sending email — verification, receipts, reports |
| Brønnøysundregistrene | One organisation number, once | Checking a Norwegian company is real, at signup |
| HMRC | One VAT number, once | Checking a UK VAT number is real, at signup |
Nobody else. We do not sell anything to anyone, and the scan engine sends nothing outward except requests to the site being scanned.
What we deliberately do not do
No analytics, no advertising pixels, and no cookie beyond the one that keeps you signed in — which is why there is no cookie banner. We do not seek special-category data (health, beliefs, and so on), and nothing here makes an automated decision about a person.
Your rights
You can ask for a copy of what we hold, ask us to correct or delete it, object to processing, or ask for it in a portable form. Write to personvern@ingati.com.
One honest limit: records we must keep by law — invoices, for five years under Norwegian bookkeeping rules — survive a deletion request. Everything else goes.
Security
Passwords are stored hashed with bcrypt, never in a readable form. Sign-in and password-reset links are stored hashed too, expire, and work once. Card details never reach our systems.