Base 12

Privacy Policy

Last updated: February 3, 2026

1. Introduction

Base 12 AS ("Base 12", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our CRM service ("the Service").

Base 12 AS is a company registered in Norway. We operate as a B2B service provider, primarily handling business contact information on behalf of our clients.

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use the Service.

2. Data We Collect

2.1 Information You Provide

  • Account information: email address, name, and organization details
  • Business contact data: company names, contact persons, email addresses, phone numbers, and other business information you enter into the CRM
  • Communications: correspondence with us, including support requests
  • User preferences: settings and configurations within the Service

2.2 Information Collected Automatically

  • Usage data: how you interact with the Service, features used, and actions taken
  • Device information: browser type, operating system, and device identifiers
  • Log data: IP addresses, access times, and pages viewed
  • Analytics data: aggregated usage patterns and performance metrics

2.3 Information from Third-Party Services

When you connect third-party services to Base 12, we may receive information from those services:

  • Microsoft 365: calendar events, email metadata, and contact information when you authorize the integration
  • Other integrations: data necessary to provide the connected functionality

3. How We Use Your Data

We process your data based on the following legal bases under GDPR:

3.1 Contract Performance

  • Providing and maintaining the Service
  • Processing transactions and managing your account
  • Delivering customer support
  • Sending service-related communications

3.2 Legitimate Interests

  • Improving and developing the Service
  • Analyzing usage patterns to enhance user experience
  • Detecting and preventing fraud, abuse, or security incidents
  • Enforcing our terms of service

3.3 Consent

  • Sending marketing communications (where you have opted in)
  • Using optional features that require explicit consent

3.4 Legal Obligations

  • Complying with applicable laws and regulations
  • Responding to legal requests and preventing harm

4. Data Sharing

We do not sell your personal data. We may share your information in the following circumstances:

4.1 Service Providers

We work with third-party service providers who assist us in operating the Service. These providers are contractually obligated to protect your data and may only use it for the purposes we specify:

  • Cloud hosting and infrastructure (data storage and processing)
  • Analytics services (usage analysis and product improvement)
  • Email delivery services (transactional emails)
  • Authentication services (secure login)

4.2 Legal Requirements

We may disclose your information if required to do so by law or in response to:

  • Valid legal processes (court orders, subpoenas)
  • Government requests that meet applicable legal standards
  • Protection of our rights, privacy, safety, or property
  • Emergency situations involving potential threats to safety

4.3 Business Transfers

If Base 12 is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your data is transferred and becomes subject to a different privacy policy.

5. Data Storage and Security

5.1 Data Location

Your data is primarily stored and processed in the European Economic Area (EEA). When we use service providers located outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

5.2 Security Measures

We implement appropriate technical and organizational measures to protect your data:

  • Encryption of data in transit and at rest
  • Regular security assessments and updates
  • Access controls and authentication requirements
  • Employee training on data protection
  • Incident response procedures

5.3 Data Breach Notification

In the event of a data breach that poses a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.

6. Your Rights

Under GDPR and applicable Norwegian data protection law, you have the following rights regarding your personal data:

6.1 Right of Access

You can request a copy of the personal data we hold about you and information about how we process it.

6.2 Right to Rectification

You can request correction of inaccurate or incomplete personal data.

6.3 Right to Erasure

You can request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for its original purpose.

6.4 Right to Restrict Processing

You can request that we limit the processing of your personal data in certain circumstances.

6.5 Right to Data Portability

You can request to receive your personal data in a structured, commonly used, and machine-readable format.

6.6 Right to Object

You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.

6.7 Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that significantly affect you.

To exercise any of these rights, please contact us at privacy@base12.no. We will respond to your request within 30 days.

7. Cookies and Tracking

7.1 Essential Cookies

We use essential cookies that are necessary for the Service to function properly. These cookies enable core functionality such as security, authentication, and session management.

7.2 Analytics

We use PostHog for product analytics to understand how users interact with our Service. This helps us improve the user experience and develop new features. PostHog collects:

  • Page views and navigation patterns
  • Feature usage and interactions
  • Performance metrics
  • Error reports

Analytics data is processed in accordance with GDPR and is used solely for product improvement purposes.

7.3 Managing Cookies

You can control cookies through your browser settings. Note that disabling essential cookies may affect the functionality of the Service.

8. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Account data: retained while your account is active and for a reasonable period after closure
  • Business data in the CRM: retained according to your organization's data retention settings
  • Analytics data: retained in anonymized form for product improvement
  • Legal records: retained as required by applicable laws

When data is no longer needed, it is securely deleted or anonymized.

9. International Transfers

As a Norwegian company, we primarily process data within the EEA. When we transfer personal data outside the EEA, we ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Other appropriate safeguards as required by GDPR

You can request information about the specific safeguards applied to your data by contacting us.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last updated" date
  • Sending an email notification for significant changes

We encourage you to review this Privacy Policy periodically for any changes.

11. Contact Information

If you have questions about this Privacy Policy, your personal data, or wish to exercise your rights, please contact us:

Base 12 AS

Email: privacy@base12.no

Address: Nedre Banegate 41, 4014 Stavanger, Norway

11.1 Supervisory Authority

If you are not satisfied with our response or believe we are processing your personal data in violation of applicable law, you have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet):

Datatilsynet

Website: www.datatilsynet.no

Email: postkasse@datatilsynet.no