Privacy statement for ECIT LAW Advokater AS
Organization number: 981 472 470
Last updated: 30.06.2026
1. This Privacy Policy Applies To
This Privacy Policy concerns personal data processed by ECIT Law Advokater AS (hereinafter referred to as «ECIT Law», «we», or «us»). We are the data controller for the processing of personal data described in this Privacy Policy. The purpose of this Policy is to inform you, as a client or business partner, about how we process your personal data and the purpose of such processing.
ECIT Law offers various types of legal services; therefore, unless otherwise stated, the term «case» in this Policy should be interpreted broadly to encompass all assignments we undertake in connection with our business, whether these involve consultations, document and contract reviews, litigation or other legal advice.
You will find our contact information on the last page.
2. Whose Data Do We Process
This Privacy Policy relates to our processing of personal data in connection with our legal practice.
We process personal data relating to:
-
our clients; including private clients, individuals and contact persons at corporate clients;
-
personal data about individuals related to a case (including counterparties, suppliers and business partners) or other individuals who are involved in or affected by a case in which we assist in;
-
other individuals mentioned in case documents to which we have access;
-
information about our employees;
-
information about our partners;
-
visitors to our website;
3. Purpose, Types of Personal Data and Legal Basis
Below is an overview of the purposes for which we process personal data, the types of personal data we process, and the legal basis for the processing.
Establishment and Administration of Client Relationships: When we are contacted by a client with a request to take on an assignment, we conduct a conflict of interest assessment before deciding whether to accept the assignment. This conflict of interest assessment serves a legitimate purpose. The legal basis for this is Article 6(1)(c) of the GDPR; cf. also Section 224 of the Courts of Justice Act (Domstolloven) and section 3.2 of the RGA.
For private clients, such a conflict check usually involves the processing of their full name and the nature of the case.
Generally, conflict checks carried out on behalf of business customers do not involve the processing of personal data.
In connection with the establishment of a new client relationship, we carry out a customer due diligence check (KYC assessment) in accordance with the provisions of the Anti-Money Laundering Act (hvitvaskingsloven) and associated regulations.
The customer due diligence (KYC assessment) normally consists of:
-
recording specific information in accordance with §§ 12 and 13 of the Anti-Money Laundering Act, cf. also §§ 17 and 18.
-
verifying the identity of the client and any beneficial owners.
-
and obtaining information on the purpose and intended nature of the client relationship.
Such customer due diligence (KYC assessment) is required for us to fulfil our legal obligations under §§ 4, 7, 8, 12, 13, 17 and 18 of the Anti-Money Laundering Act, as well as § 4 of the Anti-Money Laundering Regulations, cf. Article 6(1)(c) of the GDPR.
If we accept the assignment, the following contact details are recorded for private and business customers:
-
Full name of contact person(s), representatives, and owners of the client
-
National identification number and D-number (for private clients)
-
Telephone number(s) of the contact person(s), representatives, and owners of the client
-
Email address of the contact person(s), representatives, and owners of the client
-
Postal address of the client
The processing of the above personal data for private and business clients is necessary to demonstrate compliance with a legal obligation to which ECIT Law is subject, cf. Article 6(1)(c) of the GDPR.
Case Management: In certain legal assignment, we gain access to personal data concerning the client, opposing parties and other individuals affected by the case. This information may be contained in documents submitted by the client, pleadings, evidence, letters, correspondence or other case-related information. The processing is carried out primarily to enable us to provide the legal services the client has requested. For assignments where the client is a private individual, the processing of personal data relating to the client is normally necessary to fulfil the assignment agreement with the client, cf. Article 6(1)(b) of the GDPR. As regards personal data relating to other data subjects (such as opposing parties, witnesses, the client’s employees or representatives, or other third parties), the processing is normally necessary for our legitimate interests in establishing, maintaining and carrying out the client’s assignment in a responsible manner, cf. Article 6(1)(f) of the GDPR.
Knowledge Management: When working on an assignment, we often draft documents for our clients; we occasionally choose to convert these documents into templates that can be used in future cases. Such ready-made templates and models are anonymised and do not contain personal data. The legal basis for processing is our interest in utilising the knowledge we have developed in further counseling, cf. Article 6(1)(f) of the GDPR, balancing of interests.
Client Administration: We create case files and manage contact and case details in order to plan, carry out and follow up on assignments. We also record time spent, expenses and other costs, and issue invoices. Case and assignment information may also be entered into internal systems for task and resource management. Processing necessary to manage and deliver the assignment (for example, the creation of a case file, ongoing follow-up, communication and task planning) is normally carried out on the basis of Article 6(1)(b) of the GDPR for private clients, and for other data subjects on the basis of Article 6(1)(f) of the GDPR.
Storage and Retention of Case Documents: We retain case documents for 10 years after the assignment has been completed, unless the client requests that the case documents be retained for a period shorter or longer than 10 years. Lawyers are required to archive documents relating to their legal engagements in accordance with § 36 of the Lawyer Act. The legal basis for the processing of personal data is Article 6(1)(c) of the GDPR, cf. § 36 of the Lawyers Act.
Invoicing: We process contact details to issue, address and send invoices, including any references (e.g. engagement reference, invoice reference or marking) that the business client asks us to use. For private clients, we use the postal address and/or email address provided to send invoices and payment information. Information relating to invoices and payments forms part of our accounting records and is retained in accordance with applicable requirements. This processing is necessary to fulfil our obligations regarding documentation, bookkeeping and the retention of accounting records, cf. Article 6(1)(c) of the GDPR, §§ 10–12 of the Accounting Act, cf. the Accounting Regulations, Chapter 5 (sales documentation) and Chapter 7 (retention and accessibility).
IT Operations and Security: Personal data stored in our IT systems may be accessible to us and/or our suppliers in connection with operations, maintenance, updates, troubleshooting, access control, backups and other security measures. The processing is carried out to ensure the confidentiality, integrity, availability and resilience of our systems.
The legal basis is Article 6(1)(c) of the GDPR, as the processing is necessary to fulfil our obligations under the GDPR, including requirements for appropriate technical and organisational measures, see in particular Article 32 of the GDPR (as well as the principles of integrity and confidentiality in Article 5(1)(f) and the accountability requirements in Article 24). In addition, the processing may be based on Article 6(1)(f) of the GDPR, based on our legitimate interest in secure and stable operations and in preventing and detecting unauthorised access, data loss and misuse.
Newsletters and Digital Marketing: We may send newsletters and other information about our services and professional updates to (i) individuals with whom we have an existing customer relationship and (ii) individuals who have consented to receiving such communications. It is always easy to opt out via the unsubscribe link in the communication or by contacting us. Where we have an existing customer relationship and the conditions are met, communications are sent in accordance with § 15(3) of the Marketing Act. In other cases, communications are sent on the basis of consent, cf. § 15(1) of the Marketing Act and Article 6(1)(a) of the GDPR. Consent may be withdrawn at any time.
4. Who Do We Share Personal Data With
Our third-party suppliers of, amongst other things, IT services, suppliers of project and communication tools, and other partners may have access to personal data if such data is stored with the supplier or is otherwise available to the supplier in accordance with their contract with us.
We process personal data on various platforms and applications in connection with both internal and external processes. The work tools, systems and partners we use are as follows:
Project and Communication Tool Systems and IT Operation Services:
-
Microsoft Office Business Plus applications (Word, Excel, PowerPoint, Teams, Email, Calendar, Outlook, OneDrive)
-
Google Workspace Business Plus applications (Gmail, Google Docs, Google Drive, Google Meet, Google Calendar, Gemini)
-
Workshare Compare
-
Adobe
-
ECIT Solutions/Dokumentpartner
-
ECIT Sign
-
Advisor
-
Legal Plant
-
Procano AS
-
AYR AS
-
Sagalegal (Saga AI)
Accounting and Invoicing Systems:
-
Advisor
-
Tripletex
-
PowerOffice GO
Accountant, Auditor, and Other Business Partners:
-
ECIT Services AS
-
Eyedea AS
-
Cedra Norge AS
-
ECIT AS
-
ECpay
-
Sparebank 1, Ringerike/Hadeland
-
DnB (Foreign Exchange)
Marketing Tools and Systems:
-
LinkedIn
-
Facebook
-
Workplace
-
Instagram
-
Wix.com
Other:
-
Dun & Bradstreet (Bisnode)
-
Norkart
-
Ambita
-
Propware
Advisor is a provider of legal solutions, offering systems for case management, document management, knowledge management, time tracking and invoicing. Read Advisor's privacy policy here: Advisor Personvernerklæring.
ECIT Solutions/Dokumentpartner is a provider of IT operation services. Read ECIT's privacy policy here: ECIT Personvernerklæring
ECIT Sign is a solution for electronic/digital document signing. ECIT Sign provides ‘handwritten’ signatures and secure signing using eID. Read ECIT's privacy policy here: ECIT Personvernerklæring
PowerOffice Go is a system for accounting, invoicing and time recording that we and our accountant use. Read PowerOffice Go's privacy policy here: PowerOffice Go Personvernerklæring
Tripletex is a provider of legal solutions, offering systems for case management and document management. Read Tripletex's privacy policy here: Tripletex Personvernerklæring
ECIT Services AS is our authorized accountant. Read ECIT’s privacy policy here: ECIT Services Personvernerklæring
Sparebank 1, Ringerike/Hadeland is our corporate bank. Read Sparebank 1, Ringerike/Hadeland’s privacy policy here: Sparebank 1, Ringerike/Hadeland Personvernerklæring
DnB Bedrift is our corporate bank for payments in foreign currency. Read DnB’s privacy policy here: DnB Bedrift Personvernerklæring
ECPay is our partner for receivables management. They assist with the follow-up of unpaid invoices and debt collection. ECPay Personvernerklæring
We use Dun & Bradstreet (Bisnode) to carry out credit checks on new clients as part of the initial procedure when we take on an assignment. Read Dun & Bradstreet (Bisnode)’s privacy policy here: Dun & Bradstreet Personvernerklæring
Cedra Norge AS is our authorized auditor. Read Cedra’s privacy policy here: Cedra Personvernerklæring
ECIT is an accountancy and IT group with which we collaborate at various levels, both in relation to existing and new clients; this includes receiving incoming assignments via ECIT and collaborating with ECIT on assignments. Read ECIT’s privacy policy here: ECIT Personvernerklæring
Google Workspace Business Plus is a collection of cloud-based services and applications for data and mobile devices that we use for case management, document management, data storage and knowledge management. Read Google’s privacy policy here: Google Workspace Business Plus Personvernerklæring. AYR AS is a reseller and licensing partner for Google Workspace products.
Microsoft Office Business Premium is a collection of cloud-based services and applications for data and mobile devices that we use for case management, document management and knowledge management. Read Microsoft’s privacy policy here: Microsoft Office 365 Personvernerklæring. Access to Microsoft Office Business Premium applications is granted via an agreement with Procano AS.
Workshare Compare is a comparison tool for tracking changes made to documents. We use it in connection with the drafting of contracts and similar documents. Read Workshare Compare’s privacy policy here: Litera Workshare Personvernerklæring
Adobe System is a tool we use for document and image processing. Read Adobe’s privacy policy here: Adobe Personvernerklæring
Norkart is a Norwegian provider of geographic information systems (GIS). We use Norkart to obtain property information in connection with and relating to assignments we undertake for clients. Read Norkart’s privacy policy here: Norkart Personvernerklæring
Ambita is a Norwegian provider offering ICT services, systems, and products based on property and map information, including data from municipalities, housing cooperatives, power companies, and the Norwegian Mapping Authority. We use Ambita to gather property information in connection with and related to assignments we undertake for clients. Read Ambita’s privacy policy here: Ambita Personvernerklæring
Propware is a case management system and a digital user tool aimed at lawyers who assist private individuals and companies with the sale and purchase of property. The service has been developed to provide lawyers with a tool for accessing information, documentation and services typically related to estate agency assignments and lawyer-led property transactions.
Facebook/Workplace offers familiar features such as the creation of profiles, pages and groups, as well as services for chat, live video streaming and more. We use these services for both internal and external communication and marketing. Read Facebook’s (including Workplace’s) privacy policy here: Facebook Personvernerklæring
Instagram is a photo and video-sharing service that allows users to create profiles, pages, chat, and share live stories, photos and videos. We use these services for internal and external communication and marketing aimed at clients and customers. Read Instagram’s privacy policy here: Instagram Personvernerklæring
LinkedIn offers services for creating and managing business profiles and personal profiles. We use LinkedIn to engage with our professional network, access knowledge, insights and opportunities, publish content from our channels, and to reach out to and communicate with potential new customers. Read LinkedIn’s privacy policy here: LinkedIn Personvernerklæring
We use Wix.com in connection with website development. Read Wix.com’s privacy policy here: Wix.com Personvernerklæring
Saga AI is a platform for AI-assisted legal work, including the drafting and structuring of text, as well as the processing, analysis and summarisation of documents. We use Saga AI as a tool to streamline our internal case management and document production. Read Saga’s privacy policy here: Saga AI Personvernerklæring
LegalPlant is a platform for lawyers for KYC/AML management and registration, case management, workflow, client contact and more. A licence agreement has been entered into with LegalPlant, granting ECIT Law the right to use the version of the platform in force at any given time. Read LegalPlant’s privacy policy here: LegalPlant Personvernerklæring
The third parties mentioned above may only use personal data for the purposes we have specified and which are described in this privacy policy, including as set out in the privacy policies of our respective third parties.
We endeavour to ensure that all processing of personal data carried out by us (or by our partners and suppliers on our behalf) takes place within the EU/EEA. If we process personal data outside the EU/EEA (third countries), the EU’s standard contractual clauses for the transfer of personal data to third countries will be used as the legal basis (in accordance with 2010/87/EU and C-311/18), or alternatively another legal basis for such transfer under Chapter V GDPR.
In addition, processing will only take place after a risk assessment has been carried out regarding the data protection legislation in the third country in question.
5. Confidentiality
Lawyers are subject to a duty of confidentiality, enforceable by criminal sanctions, as set out in § 211 of the Penal Code (straffeloven). All information entrusted to us in connection with an assignment is treated as confidential.
We do not share personal data in any other circumstances or in any other way than as previously described in this privacy policy, unless the client explicitly requests or consents to this, or the disclosure is required by law.
6. Storage of Personal Data
We store case documents in our case management system for as long as the case is being processed. Upon closure of the case, the individual case file is transferred to our archive, where it may be retained for a further 10 years.
Accounting legislation otherwise requires us to store certain accounting documents for a specified period. Where a specific purpose requires storage for a given period, we ensure that the personal data is used exclusively for that purpose during that period.
7. Your Rights
In accordance with applicable laws about processing of personal data, you have several rights as our client. The specific rights you have depend on the circumstances.
Right to withdraw consent: If the processing is based on consent previously given for the processing of personal data (e.g. for marketing purposes), you may withdraw this consent at any time by contacting us.
Request for access: As a customer/user, you have the right to know what information we have stored about you, provided that this is not prevented by our duty of confidentiality. Such information can easily be obtained from us upon request. To ensure that personal data is disclosed to the correct person, we may ask that requests for access be made in writing, or by providing other proof of your identity as a client.
Request the Amendment or Erasure of Information: You may always ask us to correct any inaccurate information held about you, or ask us to erase your personal data. As far as possible, we will comply with requests for erasure, unless there are compelling reasons why the information cannot be erased, such as the need to retain the information for record-keeping purposes.
Request to have your data transferred (Data portability): The right to data portability allows you, as a client, upon a simple request, to access and obtain the personal information you have provided to us in order to transfer it in a machine-readable format to another law firm. If technicalities allow it, the data may in certain cases be eligible to direct transfer to the other firm.
Lodge a Complaint with the Norwegian Data Protection Authority (Datatilsynet): If you disagree with the way we process your personal data, you may lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).
8. Security
We have established procedures to handle personal data securely. These measures are of both a technical and organisational nature. We carry out regular security assessments of all key systems used for processing personal data, and agreements have been entered into which require suppliers of such systems to ensure satisfactory information security.
9. Changes to the Privacy Policy
We reserve the right to make minor changes to this Privacy Policy. You will always be able to find the latest updated version on our website. We will notify you of any significant changes.
10. Contact Us
If you have enquiries regarding our Privacy Policy or wish to exercise your rights, you can contact us:
Name of contact person: Mathias T. Gebremichael
Telephone: (+47) 467 90 069
Visiting address: SIXA, Dronning Eufemias gate 6a, 0191 Oslo, Norway
Mailing address: SIXA, Dronning Eufemias gate 6A, 0191 Oslo, Norway
Contact by email: mathias@ecitlaw.com
