This Privacy Policy lays out how SaveOCEAN (“SAVEOCEAN AS” or “we”) collects, stores and uses information about you when you access our websites and services or applications.
Scope of This Policy
This policy applies to personal data we collect when you:
- register for use the SAVEOCEAN AS applications;
- subscribe to our newsletter;
- contact us, book a demo, donate or participate in events;
- enter into a commercial or collaboration agreement with us.
This privacy policy was last updated on 02 June 2026.
1. Important Terms
“Personal Data” is any information that relates to an identified or identifiable living individual, such as name, email address, location etc.
Different pieces of information, which collected together can lead to the identification of a particular person, also constitute Personal Data.
Processing: Any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
2. The Purpose of Processing Personal Data
2.1 Processing Personal Data in Order to Provide the Services
When registering to our applications to access SaveOCEAN services via a Miscrosoft or Google account we Process Personal Data.
We also Process Personal Data of Customer’s employees, agents, representatives, partners and other persons as “Authorized Users” .
The Personal Data Processed is related to data as e-mail addresses together with first and last name as registered into 3rd party systems such as Microsoft and Google accounts. The e-mail addresses are Processed in order to connect Authorized Users to their account into our SaveOCEAN applications.
The legal basis for this processing is our legitimate interest in providing these features, cf. Article 6 (1) (b) of the GDPR. Retention of the data is for the life of the account. Deleted within 30 days of account closure request.
2.2. Processing Personal Data to Personalize the Services
We Process Personal Data of Authorized Users who wish to personalize the Services we provide.
The Personal Data Processed are profile pictures, first and last names names, email addresses and GPS location, login history and timestamps, booking history, quest process and gamification data (as part of OceanQuest)
The legal basis for the Processing of Personal Data to personalize the Services is consent, cf. Article 6 (1) (b), Art. 6(1)(a) of the GDPR. Retention of the data is for the life of the account. Deleted within 30 days of account closure request.
2.3 Processing Personal Data for Marketing Purposes
We store the e-mail address and name of persons who sign up for our e-mail newsletter, contact forms and our applications. We delete your e-mail address and name immediately if you unsubscribe. You may unsubscribe to our newsletters by clicking on the unsubscribe link at the end of every newsletter you have received.
The legal basis for the Processing of Personal Data for marketing purposes is consent, cf. Article 6 (1) (a) and 6(1)b of the GDPR.
2.4 Enterprise Employee Data (Corporate SaveOCEAN applications Licenses
When a company purchases an Enterprise license, that company’s employees may join a branded portal using SSO (Single Sign-On). In this context SaveOCEAN processes:
- Employee name and corporate e-mail address (supplied by the employer)
- Field quest participation records, including GPS data
- Training hours and activity reports used in the employer’s CSRD / ESRS reporting
- Bookings of services
SaveOCEAN acts as a data processor on behalf of the enterprise client (the data controller). Processing is governed by a Data Processing Agreement (DPA) concluded with the enterprise client. Employees wishing to exercise their data rights should contact their employer in the first instance; we will cooperate with any controller-directed erasure or access request.
Legal basis (for SaveOCEAN’s processing): Art. 6(1)(b) — performance of the enterprise service contract.
Retention: As instructed by the enterprise client, subject to applicable law and the DPA
2.5 Processing Personal Data on Collaboration Partners and Contractors
We Process Personal Data on collaboration partners and contractors with the purpose of delivering services and the exchange of services. Personal Data Processed may be names, phone numbers, addresses, e-mail addresses and invoice information. The legal basis for Processing this data is the formal agreement SaveOCEAN has entered into with each collaboration partner and contractor.
2.6 Donation data
Donations are processed via Donorbox, WordPress or other similar tools as independent payment processor. SaveOCEAN does not receive or store payment card details. The processor own privacy policy governs donor data. We may receive your name and e-mail address from the processor solely for the purpose of acknowledging your donation and issuing tax receipts where applicable. Retention: 5 years for accounting purposes.
3. The Use of Cookies
We use cookies on our website http://saveocean.net.
4. Security
We have implemented appropriate technical and organizational measures ensuring that personal data is processed on a level of security appropriate to the risk, e.g. ensuring confidentiality, availability and integrity of the personal data.
5. Recipients of the Personal Data and the Use of Subcontractors
We do not disclose and/or share your personal data to third parties except where it is necessary for fulfilling our legal obligations.
We have secured that the processing is in accordance with the requirements of GDPR by entering into data processing agreements and ensure that the personal data is not used for any other purpose.
6. Your Rights.
Under the GDPR you have the following rights:
• Ask us to correct inaccurate or incomplete personal data,
• Request deletion of your personal data. You can also delete your account directly within SaveOCEAN’s applications (OceanQuest, BlueBerth, etc)
• Note: field quest GPS records are retained in anonymised/hashed form for audit integrity even after account deletion. We will inform you of any such limitation when we respond to your request.
If consent is the legal basis for processing of your personal data, you may at any time withdraw your consent by contacting us.
7. Recipients, Subprocessors, and International Data Transfers
We do not sell your personal data. We share data only where necessary with the following categories of recipients:
- Cloud infrastructure and hosting providers (e.g., providers using servers within the EU/EEA where possible)
- Authentication providers (Microsoft Azure AD, Google OAuth) — used for SSO login
- E-mail service providers — used for newsletter delivery
- Payment processor: Donorbox , Stripe, Vipps, Paypal etc
8. Children and Minors
We do not knowingly collect personal data from children under 13 without verifiable parental consent. If you are under 13, please do not register without a parent or guardian’s involvement.
Where OceanQuest is used in an educational setting and minors between 13 and 15 may participate, we require the educational institution to ensure appropriate consents are in place in accordance with applicable national law. Norwegian law sets the digital consent threshold at 13 years (personopplysningsloven § 5).
If we become aware that we have inadvertently collected personal data from a child under the applicable age threshold without proper consent, we will delete it promptly. Please contact us at ceo@saveocean.net if you believe this has occurred.
9. Contact Information
If you have any questions on how we process your personal data, please contact: ceo@saveocean.net
10. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes to our services, legal obligations, or regulatory guidance. When we make material changes we will:
- Update the effective date at the top of this policy;
The current version of this policy is always available at https://saveocean.net/privacy-policy/.
