Privacy Policy
Last updated: 16 August 2026
1. Scope of this Privacy Policy
This Privacy Policy explains how personal data is collected and processed through kelinor.com and in connection with enquiries, projects and services presented through the website.
KeliNor Group consists of KeliNor Group Ltd, the parent company, and its Norwegian subsidiary, KeliNor Group AS. Main Office in Sandefjord , Norway.
KeliNor Group Ltd
Company number: 07532227
Registered office: 124 City Road
London EC1V 2NX
United Kingdom
KeliNor Group AS
Organisation number: 930 082 910
Postal address: PO Box 44 Hystad
3247 Sandefjord
Norway
KeliNor Group AS is subject to Norwegian data-protection legislation and the General Data Protection Regulation as incorporated into the European Economic Area.
KeliNor Group Ltd is subject to the UK General Data Protection Regulation and the Data Protection Act 2018 where applicable.
2. Who is responsible for your personal data?
The responsible data controller depends on the activity concerned:
KeliNor Group AS is the controller when an enquiry, service or agreement concerns that company.
KeliNor Group Ltd is the controller when an enquiry, service or agreement concerns that company.
Where both companies jointly determine the purpose and manner of a particular processing activity, they may act as joint controllers and will provide further information where required.
The responsible company will normally be identified in the relevant form, offer, agreement, invoice or correspondence.
3. Personal data we may collect
Depending on how you interact with us, we may process:
your name and contact details;
your employer, organisation or business role;
information included in an enquiry, form or correspondence;
information required to prepare or perform an agreement;
project, customer, supplier or partner information;
marketing and communication preferences;
technical and security information, such as IP address, browser information and system logs, where generated through normal website operation;
information required for accounting, documentation or compliance with legal obligations.
We ask that sensitive personal information is not submitted unless it is necessary and has been specifically requested.
4. How information is collected
Personal data may be collected:
directly from you when you contact us;
when you submit information through a website form;
during discussions concerning a possible service or assignment;
through an existing customer, partner or professional contact where there is a lawful reason;
from publicly available business or professional sources;
through technical systems required to operate and secure the website.
5. Purposes and legal grounds
Personal data may be processed to:
answer enquiries and communicate with you;
take requested steps before entering into an agreement;
provide and administer contracted services;
organise projects, assignments and professional cooperation;
maintain customer, supplier and partner relationships;
operate and protect our website and technical systems;
meet accounting, reporting and other legal obligations;
send newsletters or optional marketing communications where consent or another lawful basis applies.
Depending on the circumstances, processing is based on consent, contractual necessity, compliance with a legal obligation or the legitimate interests of the relevant KeliNor company.
Where legitimate interests are used, we consider whether those interests are necessary and appropriately balanced against your rights and interests.
6. Sharing of personal data
Personal data may be shared when necessary with:
KeliNor Group AS or KeliNor Group Ltd;
authorised personnel and project resources;
hosting, email, IT and other service providers;
accountants, auditors, legal advisers and other professional advisers;
public authorities where disclosure is legally required;
named partners or subcontractors involved in a service or assignment.
We do not sell personal data.
Partners and service providers receiving personal data must process it lawfully and, where required, under appropriate contractual obligations.
7. International and cross-border processing
Our work may involve cooperation between Norway, the United Kingdom and other European countries.
Where personal data is transferred between jurisdictions, the transfer will be handled in accordance with applicable data-protection legislation. This may include reliance on an applicable adequacy arrangement or the use of other legally recognised safeguards.
8. Cookies and similar technologies
If cookies or similar technologies are used on this website, they are used in accordance with applicable data-protection and electronic-communications legislation.
Strictly necessary cookies may be used where permitted by law to support essential website functions, technical operation or security. Cookies or similar technologies that require consent are used only when valid consent has been obtained.
Where more detailed information is relevant, additional information will be provided through separate cookie information, a Cookie Policy or an appropriate consent tool. Such information supplements this Privacy Policy and applies to the specific cookies, technologies or third-party services concerned.
9. Storage and deletion
Personal data is retained only for as long as necessary for the purpose for which it was collected.
The retention period may depend on:
the duration of an enquiry, project or contractual relationship;
legal requirements concerning accounting and business documentation;
the need to establish, exercise or defend legal claims;
security and administrative requirements;
whether consent has been withdrawn.
Information that is no longer required will be deleted or anonymised, subject to applicable legal obligations.
10. Your rights
Depending on the applicable legislation and circumstances, you may have the right to:
request access to your personal data;
request correction of inaccurate information;
request deletion of information;
request restriction of processing;
object to certain processing;
request data portability;
withdraw consent at any time where processing is based on consent;
complain to the relevant supervisory authority.
In Norway, the relevant supervisory authority is Datatilsynet.
In the United Kingdom, the relevant supervisory authority is the Information Commissioner’s Office.
Requests concerning personal data may be submitted using the contact details published on this website or sent to the postal address of the responsible company.
11. Information security
We use reasonable technical and organisational measures to protect personal data against unauthorised access, loss, alteration, disclosure or misuse.
Access is limited to persons who need the information for an authorised business purpose.
12. Children
This website and our business services are not specifically directed at children. We do not intentionally collect personal data from children through the website.
13. Changes to this Privacy Policy
This Privacy Policy may be updated if our activities, website functions or legal obligations change.
The current version will always be published on this website.