---
title: Privacy Policy
---

[![Logo-Frid](https://www.frid.app/hubfs/Press/Frid_Logo_RGB_Solid_Color.png)](https://www.frid.app?hsLang=en)

- [English](https://www.frid.app/en/privacy-policy)
- [Norsk](https://www.frid.app/privacy-policy)

- [PRODUKT](https://www.frid.app/produkt?hsLang=en)
- [PRISER](https://www.frid.app/priser?hsLang=en)
- [ARTIKLER](https://www.frid.app/blog?hsLang=en)
- [OM OSS](https://www.frid.app/om-oss?hsLang=en)
- [BEDRIFT](https://www.frid.app/bedrift?hsLang=en)

- [English](https://www.frid.app/en/privacy-policy)
- [Norsk](https://www.frid.app/privacy-policy)

[BLI MED](https://www.frid.app/meld-deg-p%C3%A5?hsLang=en)

# **Privacy Policy for Frid**

**Version 2.0 — effective from 7 September 2026.** Replaces the version of 5 February 2024.

*This is a translation of the Norwegian privacy policy («Personvernerklæring for Frid»). In the event of any discrepancy, the Norwegian version prevails.*

**1. About this policy**

In this privacy policy, "Frid", "we", "us" and "our" mean **Visonomic AS**, Norwegian organisation number 925 610 453. Frid is the name of our service.

This policy explains what personal data we process about you, why we process it, the legal basis on which we do so, how long we keep it, who we share it with, and what rights you have. It applies when you use the Frid app (iOS and Android), our websites at frid.app, and when you contact customer support.

We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), the Norwegian Personal Data Act, the Norwegian Financial Contracts Act and the Payment Services Directive (EU) 2015/2366 (PSD2).

This policy does not apply to third-party services you choose to use through Frid — for example your bank or the App Store. Those have their own privacy policies.

**1.1 Data controller**

Visonomic AS is the data controller for the processing described here.

Visonomic AS  
Bakken 19, 6631 Batnfjordsøra, Gjemnes, Norway  
E-mail: [post@frid.app](mailto:post@frid.app)  
Telephone: (+47) 57 00 63 33

**1.2 Privacy contact**

We have a designated privacy contact who is your point of contact for all questions about privacy and about exercising your rights.

E-mail: [privacy@frid.app](mailto:privacy@frid.app)

Enquiries sent here are answered whatever they concern — access, rectification, erasure, a complaint, or simply a question about how we process your data.

**1.3 In brief**

- The core of Frid is retrieving your account information from your banks and giving you an overview, a budget and guidance. We retrieve bank data only once you have connected a bank yourself, and only from the banks and accounts you choose.
- The regulated account information service is provided by **Tink AB**, which is licensed as an account information service provider. Tink's licence covers Tink's own service, not Frid's business more broadly. See section 6.
- Frid has an **AI assistant**. When you use it, your question and the financial data needed to answer it are sent to **Anthropic PBC**. Anthropic is a US company, stores data in the United States by default, and may process the request in several countries outside the EEA. The assistant can also carry out actions in the app at your request — some of which cannot be undone.
- We never sell your personal data, and we do not use it to assess your creditworthiness.
- If the app is provided through your employer, your employer **never** sees your transactions, balances, budget or individual health check result. Your employer receives aggregated figures — which are aggregated, but not anonymous. See section 10, which sets out exactly what they see, and what counts even if you do not complete the health check.
- You can delete your account in the app. We then delete your data, subject to the exceptions in section 16.

### 2. What personal data we process

**2.1 Data you give us yourself**

| Category | Content |
| --- | --- |
| Identification and contact details | Name, e-mail address, mobile number, date of birth, language preference. If you sign in with Vipps or Apple, we receive several of these from them instead — see section 2.4. We do **not** ask for your home address, and we do not process it |
| Sign-in | User identifier, whether your e-mail address is verified, one-time codes used for verification, and which sign-in method you use — e-mail and password, Vipps or Apple. If you use Vipps or Apple, we store a link to your account with them, not your sign-in credentials |
| Financial data you enter yourself | Debts and assets you record (type, name, amount), budgets and budget items, savings goals, recurring expenses and rules, your own categories and categorisations, subscriptions you track |
| Household | The composition of your household, used to calculate a reference budget — see section 8 |
| Financial health check | Your answers to the health check, and the resulting score and colour code — see section 10 |
| Employer affiliation | Company e-mail address or e-mail domain, and a registration code, if you link your account to an employer |
| The alert button | If you use the alert button in the app, we store the e-mail address and telephone number you provide, the reasons you tick, the time, and whether you allow the person following up to see your health check result — see section 10.4 |
| Profiling answers | Your answers to questions in the app about goals, financial situation, how you experience your finances, income bracket, assets, debt, gender, age group, household type and type of neighbourhood — see section 11 |
| Content you share with us | Messages to customer support, answers in the app's content feed, images or documents you choose to upload |
| Conversations with the AI assistant | The questions you ask, the answers you receive, and attachments you upload in a conversation |

**2.2 Data we retrieve from your banks**

Where you have given explicit consent, we retrieve the following via Tink AB:

- Which banks you have connected, and the status of each connection
- Accounts held with those banks: account number, account name, account type, balance and currency
- Transactions: date, amount, description and counterparty, together with the bank's own categorisation
- Technical information about the consent and the connection, including when it expires

We do **not** retrieve BankID credentials, passwords or any other bank log-in details. Authentication takes place at your bank.

**2.3 Data generated when you use Frid**

| Category | Content |
| --- | --- |
| Calculated data | Categorisations, monthly and periodic aggregations, forecasts and budget performance that Frid computes from your transactions |
| Usage data | When you were last active, the times of day at which you sign in (stored per week), which app version you use |
| Content preferences | Which types of content you want to receive, and a profile of your usage pattern that determines which content you are shown — see section 11 |
| Device and notifications | Device type and operating system, app version, and a notification key ("push token") tied to your device |
| Error and crash data | Technical information about faults in the app, including device model, operating system version and where in the app the fault occurred |
| Subscription | Subscription type, the source of the subscription, and a customer reference held with the payment provider |
| Sharing | Which accounts you have shared with whom, and the status of the invitation — see section 9 |

**2.4 Data we receive from others**

- **From Vipps, when you sign in with Vipps:** name, first name, surname, e-mail address, whether the e-mail address is verified, date of birth and mobile number. These are verified details from Vipps, and they populate your Frid profile so that you do not have to enter it yourself. We do **not** receive your national identity number or any BankID data from Vipps.
- **From Apple, when you sign in with Apple:** name and e-mail address. If you use Apple's private e-mail relay, we receive only the relay address, not your real one.
- **From other Frid users:** if someone shares an account with you, we receive data about their account and transactions so that it can be displayed to you.
- **From your employer:** where your employer has an agreement with us, we may receive an e-mail domain and information about the periods in which the health check is to be carried out.
- **From Stripe:** notice that a subscription has been created, renewed or cancelled, and a customer reference. We do not receive your card number.
- **From Apple and Google:** notice of purchases made in the App Store or Google Play, if you buy a subscription there.

**2.5 Special categories of personal data**

We do not ask you for data about health, religion, beliefs, political opinions, trade union membership, ethnicity, genetics, biometrics or sexual matters, and the service is not built to infer such data about you. Even so, we will not claim that such data can never appear in the material we process. That would not be accurate, and you should know where the boundaries lie:

- **Transactions can reveal it.** A payment to a hospital, a trade union, a religious community or a political party says something about you. We do not extract that kind of information from your transactions, we do not categorise them by such characteristics, and we do not build profiles of health or belief from them. But the text your bank sends us is what it is, and we store it.
- **What you write to the assistant.** You decide what you write and what you upload as attachments. If you write something about your health, it is processed as part of the conversation and sent to Anthropic, as set out in section 7. We do not ask you for such data, and we recommend that you do not provide it.
- **Pregnancy.** If you state that someone in the household is pregnant, that is health data. The field is optional. We use it to calculate the reference budget, and the information currently also forms part of the profile that determines which content you are shown in the app, as set out in sections 8 and 11. The legal basis is **explicit consent**, Article 9(2)(a) GDPR, which you give by choosing to provide it after reading this. If you remove the information in the app, the processing ends.
- **The health check.** If you complete a financial health check through an employer, your answers include whether your finances affect your sleep and health. That processing rests on your consent, as set out in section 10, and, for the answers concerning health, on explicit consent under Article 9(2)(a).

We do not use such data to assess you as a customer, we do not share it with employers, advertisers or anyone else, and it plays no part in any credit assessment.

### 3. Purposes, legal basis and retention

The table below is the binding overview. Where a section elaborates, it is cross-referenced.

| Purpose | Data | Legal basis | Retention |
| --- | --- | --- | --- |
| Creating and administering your user account, authenticating you | Identification, contact details, sign-in | Contract, Art. 6(1)(b) | For as long as the account is active |
| Retrieving and displaying account information from your banks | Bank data, section 2.2 | Contract, Art. 6(1)(b) — the processing is necessary to deliver what you have asked for. In addition, Article 94(2) PSD2 requires you to give explicit consent to the retrieval of your account data. That consent is contractual, is given in the bank connection flow, and is not the same as consent under the GDPR — see section 6.2 | For as long as the bank connection is active, see sections 6 and 16 |
| Calculating your overview, budget, forecasts and categorisation | Bank data, self-entered data, calculated data | Contract, Art. 6(1)(b) | For as long as the account is active |
| Reference budget for your household | Household data | Consent, Art. 6(1)(a). For information about pregnancy: explicit consent, Art. 9(2)(a) | Until you change or delete it, or the account is deleted — see section 8 |
| Answering questions put to the AI assistant and carrying out actions you request | Conversations and attachments, and the financial data necessary for the question | Contract, Art. 6(1)(b), for the feature itself. Consent, Art. 6(1)(a), for the inclusion of your financial data — you choose this in the app and can use the assistant without it | Conversation history: 12 months — see section 7.5 |
| Sharing accounts with people you choose | Sharing relationships, the accounts and transactions shared | Consent, Art. 6(1)(a) | Until sharing is withdrawn — see section 9 |
| Carrying out the financial health check and giving you the result | Health check answers, score, colour code | Consent, Art. 6(1)(a). For the answers concerning health and sleep: explicit consent, Art. 9(2)(a) | 36 months, so that you can follow your development over time |
| Aggregated report to your employer | Aggregated figures from the health check, the number of active users, and the number who have used the alert button | Consent, Art. 6(1)(a) — see section 10 | The aggregation is computed on request; the underlying data is retained as above |
| Following up with you when you use the alert button | Name, e-mail, telephone number, the reasons you state, and any permission to view your health check result | Consent, Art. 6(1)(a), and explicit consent, Art. 9(2)(a), where the follow-up covers your health check answers | For as long as the account is active, or until you ask us to delete the alert — see section 10.4 |
| Selecting which content and notifications you receive | Content preferences, profiling answers, aggregated characteristics of your finances and — where they exist — health check answers, alert button use and information about pregnancy | Legitimate interests, Art. 6(1)(f) — you may object. For health data in the profile: explicit consent, Art. 9(2)(a) — see section 11 | For as long as the account is active |
| Sending you notifications about your own finances | Notification key, calculated data | Contract, Art. 6(1)(b) | The notification key for as long as the app is installed and the account active |
| Marketing Frid to you | Contact details | Consent, Art. 6(1)(a), cf. section 15 of the Norwegian Marketing Control Act | Until you opt out — see section 12 |
| Customer support by e-mail and form, and documenting our contact with you | Messages, contact details, case data | Contract, Art. 6(1)(b), and legitimate interests, Art. 6(1)(f) | 3 years after the last contact |
| Website chat | Chat messages and the contact details you provide there | Legitimate interests, Art. 6(1)(f) | 12 months — see section 20 |
| Operations, fault correction, security and abuse prevention | Error and crash data, technical logs | Legitimate interests, Art. 6(1)(f) | Logs and crash data: 90 days |
| Understanding how the app is used, and improving it | Usage data from the app, see section 19.2 | Legitimate interests, Art. 6(1)(f) — you may object | Usage data in our own database: 24 months. At Google: see section 19.2 |
| Improving and developing the service more broadly | Aggregated data with names and identifiers removed | Legitimate interests, Art. 6(1)(f) | For as long as it remains relevant |
| Administering subscriptions and payment | Subscription data, customer reference | Contract, Art. 6(1)(b) | For as long as the subscription runs, thereafter under accounting rules |
| Meeting accounting and bookkeeping obligations | Transaction and payment documentation | Legal obligation, Art. 6(1)(c) | 5 years after the end of the financial year, cf. the Norwegian Bookkeeping Act |
| Meeting other statutory requirements and handling legal claims | As required | Legal obligation, Art. 6(1)(c), and legitimate interests, Art. 6(1)(f) | For as long as the claim or obligation subsists |

When the retention period expires, we delete the data or remove names and identifiers from it. Where names and identifiers have been removed but the data can still be traced back to you, we do not call it anonymous — it is pseudonymous, and data protection law continues to apply. We do not process your data for purposes incompatible with those set out in the table. Should we wish to use it for a new purpose, we will inform you first and obtain consent where this is required.

### 4. What we do not use your data for

To be clear about the limits:

- We do not sell personal data, and we do not share it with advertising networks in order to build profiles about you across services.
- We do not assess your creditworthiness, we calculate no credit score, and we do not supply data to credit reference agencies.
- We do not give your employer access to your financial data, your transactions or your individual health check result.
- We do not use your transactions to infer health, religion, beliefs, political opinions or trade union membership, as set out in section 2.5.
- We do not use your data to train AI models, and our agreement with Anthropic excludes the content from being used to train their models. That something is not used for training does not mean it is not stored — what Anthropic stores is set out in section 7.5.

### 5. Where your data is processed

Your data is stored in Amazon Web Services data centres. The production environment, which holds the real user data, is operated in **Stockholm, Sweden**. We also maintain a test environment in the United Kingdom, which contains test data only.

Some of our processors process data outside the EEA. This always applies to the AI assistant: Anthropic stores data in the United States by default, and may route requests to selected countries in the United States, Europe, Asia and Australia. We therefore cannot promise you that an AI request is processed in one particular country only. See sections 7.5, 13 and 14.

### 6. Bank data, consent and PSD2

**6.1 How the connection works**

Frid is not a bank, holds no licence of its own, and has no access to your accounts in its own right. The regulated account information service is provided by **Tink AB**, a Swedish company licensed as an account information service provider and supervised by the Swedish Financial Supervisory Authority (Finansinspektionen).

In practice this means:

- When you connect a bank, you do so through Tink's solution, and you thereby also enter into a relationship with Tink on Tink's terms. You are directed to your bank to authenticate. Frid does not see your log-in credentials.
- Your bank discloses the account data to Tink, which passes it to us. Tink states that its licence covers Tink's own business, not that of its customers. We therefore do not say that Frid "operates under Tink's authorisation" — we are the recipient of data from a service Tink provides.
- We use the data to deliver Frid to you, and for nothing beyond what is set out in section 3.

Bank data is stored in Frid's own bank connection service, which maintains a local mirror of the data, and in the financial database that calculates your overview. The purpose of the mirror is to allow Frid to show you your data without having to query your bank afresh each time.

**6.2 Three things that are often confused**

There are three distinct things here, and each has its own effect:

1. **The permission for bank access.** Under Article 94(2) PSD2 you must give explicit consent to the retrieval of your account data. This is a contractual consent, given in the bank connection flow, and it limits what the data may be used for. Tink itself points out that this is not the same as consent under the GDPR.
2. **The basis for our processing.** Frid's processing of bank data to give you an overview, a budget and forecasts is necessary to perform our contract with you, Article 6(1)(b) GDPR. This means the processing does not stop because a consent is withdrawn — it stops because you remove bank access, and we then have nothing left to process.
3. **The optional parts.** The AI assistant, sharing accounts with others, household data, the health check and marketing rest on consent. You can withdraw each of these separately without the rest of Frid ceasing to work.

If you remove the bank connection in the app, retrieval stops and we delete the bank data associated with that connection, as set out in section 16.

**6.3 Renewed authentication**

Regulation requires you to re-authenticate with your bank at regular intervals for the connection to continue working. If the consent expires, retrieval stops and the app asks you to reconnect. This is a regulatory requirement, not a choice we have made.

**6.4 Updating transactions**

A bank may amend, correct or reverse transactions after they were first recorded. To keep your overview accurate, we therefore periodically re-retrieve a recent time window and compare it against what we hold, rather than simply appending new transactions. This is necessary for your figures to be correct, and is not done for any other purpose.

### 7. The AI assistant

**7.1 What happens when you use it**

Frid has an AI assistant you can ask about your finances. When you send a question, we send the question and the data necessary to answer it to **Anthropic PBC** in the United States, which operates the language model. Depending on what you ask, this may include:

- your accounts, balances and transactions
- your budget and budget performance
- debts, assets and savings goals you have recorded
- recurring expenses, subscriptions and your own categories
- the reference budget for your household — as calculated amounts per category. The composition of your household, dates of birth and the information about pregnancy are not sent
- accounts others have shared with you, as set out in section 9
- earlier messages in the conversation, and attachments you upload yourself

We send only what is necessary to answer what you have asked.

You decide whether your financial data is included at all. If you decline in the app, the assistant has no access to your accounts, balances or transactions and cannot carry out actions — only your question and the conversation history are then sent to Anthropic.

**7.2 The assistant can carry out actions**

The assistant can make changes in the app at your request. It can change the category of a transaction, categorise several transactions at once, create and delete categorisation rules, create and amend budgets and budget items, create and amend rules for recurring expenses, update the cards you see in the app, and update your forecast.

Two things are worth knowing:

- **The assistant does not ask for separate confirmation before carrying out an action.** It acts on what you write. Check the changes afterwards — they appear in the app where they belong.
- **Not everything can be undone.** Categories, budgets, cards and rules you can change or set back yourself. But if you ask the assistant to **reset your bank data**, the retrieved banks, accounts and transactions are deleted and fetched again from your bank at the next synchronisation. That is a technical refresh, not an undo button: what you have afterwards is what the bank gives us anew. The same applies to deleting a categorisation rule — the rule is gone, and would have to be created again.

**A reset is not an erasure.** If you ask for your data to be deleted, or you remove the bank connection, we treat that under section 16 as an erasure request — not as an instruction to retrieve the data again.

**7.3 Automated decision-making**

The assistant does not take decisions that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. It acts on your instruction, and it does not assess creditworthiness, does not refuse services and does not report on you to anyone.

Frid categorises transactions automatically. This is automated processing, but not a decision within the meaning of Article 22 — the categorisation affects only how your figures are grouped for you, and you can override it yourself.

**7.4 AI transparency**

You are interacting with an AI system when you use the assistant, and this is made clear in the app from the first time you open it.

The EU Artificial Intelligence Act (EU) 2024/1689 sets out such transparency requirements in Article 50, applicable in the EU from 2 August 2026. The regulation has not yet been incorporated into the EEA Agreement or implemented in Norwegian law — the Norwegian government is aiming for a bill in 2027. We follow the transparency requirement regardless, because it is the right thing to do by you, not because we are obliged to.

Answers from the assistant may be incomplete, out of date or wrong. They are general information, not financial advice, and you should check them before acting. The assistant does not assess your creditworthiness and produces no credit score.

**7.5 Retention and model training**

There are three different kinds of storage here, and they should not be confused:

**With us.** Your conversation history — questions, answers and attachments — is retained for **12 months** and then deleted. You can delete a conversation sooner in the app. If you delete your account, the conversations go with it, as set out in section 16.

**With Anthropic.** Anthropic processes the request in order to produce the answer, and retains requests and answers for a period under its own rules. Content flagged by its automated safety systems may be retained for longer. Our agreement with Anthropic provides that the content is processed only to deliver the service to us, and is not used to train their models. "No model training" is therefore not the same as "no storage".

**In operational logs.** Technical logs recording that a request was sent — time, size, error codes — are retained for 90 days, as set out in section 16.4. The logs do not contain the conversation itself.

**7.6 If you would rather not use the assistant**

The AI assistant is an optional part of Frid. If you do not use it, we send none of your own data to Anthropic.

One exception you should know about: **if you have shared an account with another Frid user, that account and its transactions may be sent when the person you share with uses their assistant.** Your sharing settings do not currently control this, and we cannot switch it off for you alone. If you want to avoid it, you have to end the sharing — see section 9.

### 8. Household data and the reference budget

To calculate a reference budget for your household, you may record who lives in it. For each person we store gender, age group, date of birth, whether the person is a student, whether the person attends nursery or an after-school programme, and whether anyone in the household is pregnant. The reference budget is based on the Norwegian national reference budgets from SIFO, which give different amounts for different ages — which is why we ask about age.

Four things you should know about this:

1. **This is data about people other than you.** When you record family members, Frid becomes the data controller for their data too. You are responsible for informing the adults in your household that you have recorded them, and that they can contact us at privacy@frid.app to request access or erasure. Your consent does not automatically cover them.
2. **Data about children.** If you record children in the household, we process data about children. We process it solely to calculate the reference budget, we do not share it, and we do not use it for marketing.
3. **Pregnancy is health data.** The field is optional. We use it for two things: to calculate the reference budget correctly and — at present — as one of several characteristics in the profile that determines which content you are shown in the app, as set out in section 11. We have to state that plainly, even though we would rather it were not so. The information is not included in reports to employers, and it is not shared with anyone. If you would rather not state it, leave the field blank; if you have stated it, you can remove it in the app.
4. **Your household is not sent to the AI assistant.** If you ask the assistant about the reference budget, what is sent is the calculated amounts per category — not who lives with you, how old they are, or whether anyone is pregnant.

You can amend or delete your household data in the app at any time.

### 9. When you share accounts with others

You can invite another Frid user to view one or more of your accounts — a spouse or partner, for example. You decide which accounts you share.

What you should be aware of:

- **There is only one access level: full read access** to the accounts you share. The recipient sees the balance and transactions for the period the data covers. The recipient cannot change your data.
- Shared accounts form part of the recipient's own overview and budget, and **may be sent to the AI assistant when the recipient asks a question where they are relevant**, as set out in section 7. Read access therefore also covers AI processing at the recipient's end, and you cannot switch off that part alone today.
- You can withdraw access at any time in the app. Further sharing then stops and the accounts disappear from the recipient's overview. We cannot undo what the recipient has already seen, and answers the assistant has already given the recipient remain in the recipient's conversation history until deleted or until they expire after 12 months.
- Frid is not responsible for what the person you share with does with the data.

The legal basis for sharing is your consent, given through your action in the app.

### 10. The financial health check and the report to your employer

**10.1 The health check**

If Frid has been made available to you through your employer, you may be invited to complete a financial health check in fixed periods. This is voluntary. You receive your result as a score and a colour code, and can follow your development over time.

Your employer cannot require you to use Frid or to complete the health check, and participation must not be tied to anything in your employment. We are aware that consent given in an employment relationship is assessed strictly, precisely because the parties are not equals. Two things therefore apply: you choose for yourself, and your employer is not told what any individual chose.

**10.2 What your employer sees**

Your employer receives a periodic report for its e-mail domain, containing:

- the number of registered users who were active during the period
- the number who received a green, yellow and red colour code
- the average score
- the number who answer that they have a buffer covering two months
- the number who answer that their finances affect them negatively at work
- the number who have used the alert button in the app

The report is shown per period, and earlier periods are available alongside the most recent one.

Your employer does **not** receive your name, e-mail address, transactions, balances, budget or your individual health check result.

**10.3 An important point about anonymity**

The report is **aggregated, but not anonymous** within the meaning of the GDPR. We say so plainly, because it has consequences for you:

- In a small organisation, or where few people have responded in a period, aggregated figures can reveal something about individuals. If you are one of two respondents, the count in each colour category says a good deal.
- There is currently no lower limit on how few responses a report may be based on. We are working on introducing one, and will update this section once it is in place.
- Because the report shows several periods, changes from one period to the next can also reveal something about individuals in a small group.

**If you do not complete the health check, your answers are kept out — but that does not keep you out of the report entirely.** Two of the figures follow from having registered your work e-mail address, not from having answered: that you were active in the app during the period, and whether you used the alert button. If you do not want to appear in the report at all, you have to remove the employer affiliation in the app.

The processing rests on your consent, and the purpose — aggregated reporting to your employer — is stated here. Your employer is not told what any individual chose.

**10.4 The alert button**

The app has an alert button you can use if your finances have become difficult — for example in the event of wage deductions, a notice from the enforcement authority or a debt collector, bills you cannot pay, or expensive loans and credit.

If you use it, this happens:

- We send your name, the e-mail address and telephone number you provide, the reasons you tick, and the organisation you are registered with, to Frid's own follow-up team, so that someone can contact you.
- You decide whether the person following up may see your health check result.
- **Your employer does not receive this message.** Your employer sees only how many people in the organisation used the button during the period, as set out in section 10.2.
- The fact that you used the button also forms part of the profile that determines which content you are shown in the app over the following months, as set out in section 11.

The basis is your consent, given by submitting the alert yourself. If you want the alert deleted, contact privacy@frid.app.

### 11. Personalised content and profiling

Frid selects the content, questions and guidance shown to you in the app. The selection is based on a profile we assemble about you. Because this is profiling, you should know what that profile actually contains:

- **Your answers to questions in the app:** financial goals, what matters to you right now, financial situation, how you experience your finances, financial behaviour, income source and income bracket, assets, debt, gender, age group, household type and type of neighbourhood.
- **Characteristics of your finances:** how many banks, accounts, account groups and budgets you have, and when you last signed in.
- **About your account:** date of birth, language, subscription type, and your employer's e-mail domain if you have linked your account to one.
- **From your household:** age group, gender, student status, number of cars, and **whether anyone is pregnant**.
- **If you use the health check:** your answers, the score, the colour code — including answers concerning sleep and health — and whether you have used the alert button in recent months.

This is profiling within the meaning of Article 4(4) GDPR. It determines what you see in the app, and it has no consequences outside the app: it does not affect your price, your access to the service, any credit assessment or anything your employer sees.

The legal basis is legitimate interests, Article 6(1)(f). Our balancing is that relevant guidance serves you better than arbitrary content, that the data is already held by us for other purposes, that nothing leaves the app, and that you may object. For those parts of the profile that are health data — pregnancy and health check answers about sleep and health — we additionally rely on explicit consent under Article 9(2)(a), as set out in section 2.5.

**You may object to this profiling** under Article 21, and you may withdraw your consent to the health data by removing it in the app. Contact privacy@frid.app. You can also adjust your content preferences in the app.

### 12. Notifications, marketing and consent

**12.1 Notifications about your own finances**

We send notifications about your own finances to the app — for example when a budget is about to be exceeded or a bank connection needs renewing. This forms part of the service you have signed up for, and requires that you have permitted the app to display notifications. You can turn notifications off in your phone's settings or in the app.

**12.2 Marketing**

We market Frid to you by e-mail or SMS only if you have consented. You will find your consents under Settings in the app and can change them at any time. You can also opt out by contacting support@frid.app.

Even if you opt out of marketing, we will still send messages that are necessary for the service — for example about changes to terms, service disruptions or security.

**12.3 Consents and withdrawal**

Where processing rests on consent, that consent is voluntary, and you may withdraw it at any time without affecting the lawfulness of processing carried out up to that point. The consents are separate: you can decline the AI assistant, sharing, household data, the health check and marketing individually.

Bank access is a separate matter, as set out in section 6.2: if you remove the bank connection, retrieval stops and we delete the bank data for that connection. Frid then loses its core functionality, but you may keep the rest of your account.

### 13. Who we share data with

**13.1 Data processors**

We use suppliers that process personal data on our instructions. All are bound by a data processing agreement and may not use the data for their own purposes.

| Supplier | What they do for us | Where data is processed |
| --- | --- | --- |
| Amazon Web Services | Hosting, storage, database, sign-in, sending e-mail | Sweden (production), United Kingdom (test environment) |
| Tink AB | Retrieving account information from your banks | EEA |
| Anthropic PBC | The language model behind the AI assistant | United States |
| Google (Google Analytics, Firebase) | Website traffic measurement, and usage statistics and crash reports from the app | EEA and United States |
| Expo (650 Industries, Inc.) | Delivering push notifications and app updates | United States |
| HubSpot | Customer records, customer dialogue and our websites | EEA and United States |

This list is kept up to date. If we engage a new processor that processes your personal data, we will update this policy.

**About Tink:** Tink processes data for us under a data processing agreement, but at the same time acts as the holder of a PSD2 licence with its own obligations, and decides that part itself. There are therefore two roles within the same company. You may direct your rights to us for what we process, and to Tink for what Tink processes as an account information service provider. Tink's own terms and privacy policy govern that part.

**13.2 Independent parties we exchange data with**

These process data for their own purposes and are independent controllers. We do not determine how they use the data, and you must direct rights concerning their processing to them. Their own privacy policies govern that part.

| Party | What the exchange consists of | Where |
| --- | --- | --- |
| Vipps MobilePay AS | If you sign in with Vipps, Vipps discloses to us the identity data listed in section 2.4. Vipps is itself the controller for the sign-in | Norway |
| Apple | If you sign in with Apple, Apple discloses your name and e-mail address to us. Apple is the controller for the sign-in and for the App Store | EEA and United States |
| Stripe | Subscription payment. Stripe is a payment institution and processes your card details for its own purposes, including fraud prevention and regulatory compliance. Frid never receives your card number | EEA and United States |
| Google | App distribution and purchases in Google Play | EEA and United States |
| Your banks | Your bank discloses account data on the basis of your consent, and is itself the controller for your customer relationship | EEA |
| Meta | Visitor statistics for our Facebook page. Here we are **joint controllers** with Meta, not independent ones — see section 19.3 | EEA and United States |

**13.3 Other recipients**

- **Other Frid users**, where you choose to share an account — see section 9.
- **Your employer**, in the form of an aggregated report — see section 10.
- **Public authorities**, where we are legally obliged to disclose data. We disclose no more than the obligation requires, and we will inform you where we are permitted to do so.
- **Advisers and service providers Frid works with**, but only where you have given specific consent in the individual case. You will always be shown which data is to be shared before you consent.
- **A purchaser or merger party**, if the business is transferred in whole or in part. We will inform you in advance, and a transfer will not change the purposes set out in this policy without notice to you.

### 14. Transfers outside the EEA

Some of the parties listed in sections 13.1 and 13.2 process data outside the EEA. This always applies to the AI assistant, and may apply to website traffic measurement, usage statistics and crash reports from the app, push notifications, customer records, payment and signing in with Apple. Vipps processes in Norway, and our production environment with Amazon Web Services is located in Sweden.

Transfers take place on one of the following bases:

- **The European Commission's Standard Contractual Clauses (SCCs)** under Article 46(2)(c) GDPR, supplemented by technical and organisational measures where our assessment of the recipient country calls for it, or
- **The EU-U.S. Data Privacy Framework**, where the supplier is certified under the European Commission's adequacy decision of 10 July 2023.

For the AI assistant the basis is the Standard Contractual Clauses, which form part of the data processing agreement with Anthropic. Anthropic stores data in the United States by default and may route requests to selected countries in the United States, Europe, Asia and Australia, as set out in section 7.5.

If you want to know which of these bases applies to a particular supplier, we will tell you, and you may obtain a copy of the safeguards. Contact privacy@frid.app.

### 15. Information security

We have technical and organisational measures in place to protect your data against loss, misuse, accidental access, alteration and destruction:

- Data is encrypted both in transit and at rest.
- Access management with multi-factor authentication, and access granted on a least-privilege basis.
- Account sign-in is handled by a dedicated identity service; we do not store your passwords.
- Bank connection credentials are encrypted with separate key management.
- Protection against denial-of-service attacks at the API layer, and logging and monitoring of operations.
- Risk assessment and security testing of new features before they go into production.
- An information security management system with procedures for incident handling.
- Everyone working in and for Frid is bound by a duty of confidentiality.

If a personal data breach occurs that entails a risk to you, we will notify the Norwegian Data Protection Authority within 72 hours and inform you where the risk is high, under Articles 33 and 34 GDPR.

### 16. Erasure

**16.1 When you delete your account**

You can delete your account from the app. We then delete your financial data, your profile including your profiling answers, your household data, your conversations with the AI assistant and the attachments in them, your health check answers, any alerts you have submitted with the alert button, your subscription data, your sign-in account and the link to your bank data.

**16.2 When you remove a bank connection**

If you remove a single bank connection without deleting your account, we delete the banks, accounts and transactions belonging to that connection, and the overviews calculated from them.

Two things remain, and you should know about them:

- **Conversations with the AI assistant.** If you have asked the assistant about your finances, the answers may contain figures and transactions from those accounts. Conversations are deleted after 12 months or when you delete them yourself, as set out in section 7.5 — not automatically when the bank connection is removed.
- **Data you entered yourself**, such as budgets, your own categories, debts and assets. That is yours, and is not deleted because a bank is disconnected.

If you want all of it gone, delete your account, as set out in section 16.1.

**16.3 The bank data mirror**

Your bank data also resides in Frid's bank connection service. There, transactions are first marked as deleted, because that is how we detect that a bank has reversed a transaction. Rows so marked are then removed permanently, no later than 30 days after the account or bank connection was deleted.

**16.4 Backups and logs**

Data may remain in backups for up to 35 days after erasure. Backups are used only to restore the system in the event of a failure, never to look up data about individuals. Technical operational logs are deleted after 90 days.

**16.5 What we have to keep**

We retain accounting and payment documentation for 5 years after the end of the financial year, as required by the Norwegian Bookkeeping Act, and data we need in order to handle a legal claim for as long as the claim subsists. We also retain a record that the account has been deleted, so that we can demonstrate that your request was carried out.

**16.6 Inactive accounts**

If you have not used Frid for 24 months, we will contact you by e-mail. If we do not hear from you within 30 days, we will delete the account and the data in accordance with the rules above.

### 17. Your rights

You have the following rights. All are free to exercise, and we respond within one month. Contact privacy@frid.app.

- **Access** (Art. 15) — find out what data we hold about you and how we process it, and obtain a copy.
- **Rectification** (Art. 16) — have inaccurate or incomplete data corrected. You can correct much of it yourself in the app. If the error concerns a transaction from your bank, it must be corrected at the bank, since we reproduce what the bank reports — tell us and we will help you take it further.
- **Erasure** (Art. 17) — have data deleted, subject to the limitations in section 16.5.
- **Restriction** (Art. 18) — ask us to stop using the data without deleting it, for instance while we handle a complaint from you.
- **Data portability** (Art. 20) — receive the data you have given us, and the data we process on the basis of consent or contract, in a machine-readable format, and have it transmitted to another provider where technically feasible.
- **Objection** (Art. 21) — object to processing based on legitimate interests, including the profiling described in section 11. You have an **absolute** right to object to direct marketing.
- **Withdrawal of consent** (Art. 7(3)) — withdraw consent at any time.
- **Not to be subject to automated decision-making** (Art. 22) — see section 7.3.

**17.1 Exceptions**

In some cases we cannot meet a request in full. This applies where we are legally bound by confidentiality, where the data exists only in internal case documents and an exception is necessary for proper case handling, or where disclosure would infringe the rights of others — for example data about another person who shares an account with you. We always give reasons for a refusal, and inform you of your right to complain.

**17.2 Identification**

To protect you, we must be certain who is asking. We may therefore ask you to confirm your identity before we disclose or delete data.

**17.3 Complaints**

If you are not satisfied, we would like to hear it first, at privacy@frid.app — that way we can put things right quickly.

You are in any event entitled to lodge a complaint with the supervisory authority:

Datatilsynet (the Norwegian Data Protection Authority)  
Postboks 458 Sentrum, 0105 Oslo, Norway  
E-mail: postkasse@datatilsynet.no  
www.datatilsynet.no

### 18. Permissions the app requests

The app requests only the permissions it needs, and you can refuse or withdraw each one in your phone's settings. We cannot read the contents of your phone beyond what you grant access to, and only for the purpose stated below.

| Permission | What we use it for |
| --- | --- |
| Network and internet | Sending and receiving data between the app and our servers |
| Notifications | Sending you notifications about your own finances |
| Calendar (read and write) | Adding reminders about due dates and financial tasks, when you ask for them |
| Camera and photos | When you choose to add or share an image |
| Files and documents | When you choose to upload or share a document |
| Biometrics (Face ID / fingerprint) | Unlocking the app. Biometrics are handled by your phone; Frid never receives your fingerprint or face data |
| Clipboard | Copying values such as an account number, when you ask for it |

If you refuse a permission, the rest of the app works as normal — only the feature requiring that permission becomes unavailable.

### 19. Cookies and tracking

**19.1 Our websites**

The websites at frid.app use cookies and similar technology to make the pages work, to measure traffic, and to see which of our own pages you have visited. Cookies that are not necessary for the site to work are set only where you have consented, in accordance with the requirement in the Norwegian Electronic Communications Act for consent to the storing of information on your equipment.

We do **not** use advertising tracking pixels on our websites, and we do not add you to audiences held by advertising networks. We previously used Facebook Pixel and audience-matching services from Facebook and Google. That has been discontinued.

For traffic measurement we use **Google Analytics**. The tool is activated only where you have consented to statistics, and it then processes:

- which pages you visit, for how long and in what order
- which page or source you arrived from
- technical information about your browser, operating system and screen
- your approximate geographic location, derived from your IP address
- an identifier stored in your browser, which allows us to see that the same visitor has returned

Your IP address and that identifier are personal data. We will therefore not claim that our traffic measurement is anonymous — we do not use it to identify you by name, but the data can be linked to your browser. Google is our processor, the data may be processed in the United States, and the transfer basis is set out in section 14.

You can change or withdraw your consent in the consent settings on the website, and you can delete cookies in your browser. If you delete the necessary cookies, parts of the website may stop working. You can also block Google Analytics across all browsers using Google's own opt-out add-on.

A detailed list of the cookies we use, their purposes and their lifetimes is set out in the cookie notice at frid.app.

**19.2 In the app**

The app does not use cookies, but does collect usage statistics and crash reports through Firebase from Google, as described in sections 2.3 and 13.1. This stores information on your device.

We will say it as it is: **you are not currently asked for consent to this collection in the app, and there is no on/off switch in settings.** Collection starts when you use the app. We are working on adding both a request and a switch, and will update this section once they are in place.

Until then the basis is legitimate interests, Article 6(1)(f):

- **Crash reporting** is necessary for us to correct faults and keep the app soundly operated.
- **The usage statistics** are limited: they record which screens are opened, and errors when using the camera. They do not contain transactions, balances, budgets or the content of conversations with the assistant.

You may object to the usage statistics under Article 21 by contacting privacy@frid.app, and you can limit collection in your phone's privacy settings. How long Google retains this data follows from the settings in our Firebase and Google Analytics properties; contact us and we will tell you the current period.

**19.3 Our Facebook page**

Frid has a Facebook page. We use it to publish information, and there is no user activity on it — we therefore do not process comments, messages or other content from you via the page.

Meta nonetheless produces aggregated statistics about visits to the page, known as Page Insights. For those statistics, Frid and Meta are **joint controllers** under Article 26 GDPR. What you should know:

- The statistics are aggregated. We cannot see who you are, and we cannot link them to you as an individual.
- We do not store them ourselves. We have access to them for as long as we maintain the page.
- It is Meta that collects them, that sets cookies in your browser, and that determines how its part of the processing is carried out. Meta bears primary responsibility for informing you and for handling your rights in respect of this processing. See Meta's privacy policy.
- You may nonetheless contact us at privacy@frid.app, and we will help you further or pass the enquiry on.
- The legal basis for our part is legitimate interests, Article 6(1)(f): we have an interest in being available where our users are. If you would rather Meta did not process data about you, you can avoid visiting the page — everything of substance is available at frid.app and in the app.

This processing has nothing to do with your Frid account or your financial data. We do not link the Facebook page to your user account, and we do not use Page Insights to target anything at you.

### 20. Customer support, recordings and chat

- **Messages to customer support** — what you send us by e-mail, through a contact form or in the app — are retained for 3 years after the last contact, so that we can follow up your case and document our contact.
- **Website chat** is a different matter, and is retained for 12 months. Chat is not anonymous and can be linked to you. If a chat becomes a case we follow up further, that continued case is retained as customer support, that is for 3 years.
- **Audio or video recordings** of conversations with you are made only where you have given explicit consent in advance, for example during user testing. You are always told before recording starts, and you may decline without this affecting the help you receive. If you want access to a recording, contact support@frid.app stating the time and the telephone number used.

### 21. Age limit

Frid is for people aged **18 and over**. The service presupposes that you can operate your own bank accounts and give valid consent to account data retrieval.

If we become aware that an account belongs to a person under 18, we will delete it. If you believe a child has created an account with us, contact privacy@frid.app.

Section 8 concerns data about children in your household — they are not users of Frid.

### 22. Changes to this policy

We update this policy when our processing changes. The date and version number at the top show when it was last amended.

Where a change matters to you — new purposes, new categories of data, new recipients outside the EEA — we will notify you in the app or by e-mail well before the change takes effect.

**Continuing to use Frid does not count as consent to new privacy purposes.** If new processing requires consent, we ask for it separately, and you have to respond actively. We will never put your data to a new and incompatible purpose without informing you first.

Previous versions are available on request from privacy@frid.app.

### 23. Contact us

| Privacy and your rights | [privacy@frid.app](mailto:privacy@frid.app) |
| --- | --- |
| Customer support | [support@frid.app](mailto:support@frid.app) |
| General enquiries | [post@frid.app](mailto:post@frid.app) |
| Telephone | (+47) 57 00 63 33 |

Visonomic AS, Bakken 19, 6631 Batnfjordsøra, Gjemnes, Norway

Visonomic AS, org nr. 925 610 453  
[Fredensborgveien 22G](https://goo.gl/maps/qtWTWgyaKxkPFZTQ9)  
[0177 Oslo](https://goo.gl/maps/qtWTWgyaKxkPFZTQ9)[mailto:post@visonomic.no](mailto:post@visonomic.no)

[post@frid.app](mailto:post@frid.app)  
[(+47) 57 00 63 33](tel:+4757006333)

<https://www.facebook.com/Fridappen/><https://www.instagram.com/okonomisk_frid/><https://www.linkedin.com/company/fridappen/>

### Frid

- [Om Frid-appen](https://www.frid.app/produkt?hsLang=en)
- [Priser](https://www.frid.app/priser?hsLang=en)
- [Om Frid-teamet](https://www.frid.app/om-oss?hsLang=en)

### Ressurser

- [Blogg](https://www.frid.app/blog?hsLang=en)
- [Personvern](https://www.frid.app/privacy-policy?hsLang=en)

### Om oss

- [Last ned Frid](https://www.frid.app/meld-deg-p%C3%A5?hsLang=en)
- [Om oss](https://www.frid.app/om-oss?hsLang=en)

© 2022 Visonomic AS All rights reserved [Privacy Policy](https://www.frid.app/privacy-policy?hsLang=en)