Privacy Policy
Last updated: 14. July 2026
The privacy and security of the data you entrust us with are our highest priority. This Privacy Policy describes how Ledidi AS with affiliated companies “we” and “us” collect, use and share information about you when you visit our website, create a Ledidi user account, pay for any of our services, participate in events or otherwise interact with us. We also describe your rights and choices regarding the information we collect about you and how you can contact us about any privacy concerns.
We only collect personal data when we have a legal basis for doing so, and we limit our collection to the minimum information required.
When does it apply
This Privacy Policy applies to the information we collect about you when you interact with us or use our services. It describes how we handle information about you while acting in the capacity as a controller, meaning that we determine the purposes and means of the processing of personal data.
This Privacy Policy does not apply to the personal data that you store or process when you use our software applications or services related to your Ledidi user account “user content” or “content”. To the extent such user content contains personal data, you are the controller, and Ledidi acts as a processor while providing agreed upon services to you. Where AI Features are enabled in Ledidi Suite, Ledidi acts as Processor on the Customer’s (Controller’s) opt-in instruction; the processing is governed by the Data Processing Addendum.
More information about the security of our services can be found in the security documentation on our website.
Patient and participant users
Ledidi’s Customers (such as research institutions, hospitals, and registry sponsors) may make Ledidi software available directly to patients or research participants — for example through patient-reported outcome (PRO/ePRO) modules, study participant portals, or other patient-facing features within a research project or registry.
Where you access Ledidi software in this capacity, two distinct sets of processing apply, with different controllers:
- Health, study and research content: the information you provide as part of the study or registry (responses, health data, identifiers entered into the project) is processed by Ledidi as Processor on behalf of the Customer, who is the Controller. For questions about how that data is used, the legal basis for its processing, your rights regarding that data, or to withdraw from the study, please contact the Customer directly. Their study-specific privacy notice and contact details should have been provided to you at enrolment.
- Account, authentication and security log data: when you log in and use the software, we generate technical data — including IP address, device and browser identifiers, authentication events, session identifiers and access logs — for the purpose of network and information security, abuse prevention and audit logging. For this processing Ledidi is the Controller and the legal basis is legitimate interest (Article 6(1)(f) GDPR). This Privacy Policy applies to that processing. You may exercise your rights with respect to this data by contacting our Data Protection Officer at dpo@ledidi.no.
Children and minors
Ledidi does not knowingly collect personal data directly from children in its capacity as controller. The website, account creation, sales, marketing and event processing described in this Privacy Policy are directed at professional users (researchers, clinicians and administrators) and are not intended for children.
Where Ledidi software is made available to patients or research participants who are minors — for example in paediatric studies or registries — that processing falls under “Health, study and research content” above, for which the Customer is the Controller. The Customer is responsible for establishing the appropriate legal basis, for any age-appropriate information and for obtaining parental or guardian consent where required by applicable law. Questions about the processing of a minor’s study data should be directed to the Customer identified at enrolment. For the account, authentication and security log data for which Ledidi is Controller, you may contact our Data Protection Officer at dpo@ledidi.no.
Legal basis for the processing of personal data
We rely upon several legal bases to process your personal data: fulfilment of contractual obligations towards you, compliance with legal obligations, legitimate interests and, in some cases, consent (for example, marketing communications and non-essential cookies).
Where we rely on legitimate interest (Article 6(1)(f) GDPR), we have completed a documented Legitimate Interest Assessment (LIA) balancing our interest against your rights and freedoms. A summary of the relevant LIA is available on request from dpo@ledidi.no.
The following table is the authoritative reference for each processing purpose and its specific GDPR legal basis. The narrative sections that follow describe what data is collected and how it is used; for the applicable legal basis, refer to this table.
| Purpose | Legal basis (GDPR) | Details |
|---|---|---|
| Website contact forms | Art. 6(1)(f) Legitimate interest | Responding to inquiries; documentation for complaints. Retention: 3 years after last interaction. |
| Sales outreach analytics of effectiveness of email communication | Art. 6(1)(f) Legitimate interest | Establishing and maintaining customer relationships. |
| User account management | Art. 6(1)(b) Contractual necessity | Providing services per Terms of Service. |
| Service communications | Art. 6(1)(b) Contractual necessity | Service notices, security alerts, updates and feature information necessary to deliver the service. |
| Marketing communications and newsletters to data subjects that are not in an existing customer relationship, cf. the Norwegian Marketing Control Act section 15. | Art. 6 (1)(a) consent | Optional product news, newsletters and offers. Consent may be withdrawn at any time via the unsubscribe link. |
| Marketing communications and newsletters to data subjects that are in an existing customer relationship, cf. the Norwegian Marketing Control Act section 15. | Art. 6(1)(f) legitimate interest | Product news, newsletters and offers. Existing customer may opt out from offers at any time via the unsubscribe link. |
| Payment processing | Art. 6(1)(b) Contract; Art. 6(1)(c) Legal obligation | Fulfilling contractual and legal obligations (accounting, tax, fraud detection). |
| Website analytics and cookies | Art. 6(1)(a) Consent (non-essential); Art. 6(1)(f) Legitimate interest (functional) | Preserving security, improving services. See Cookie Policy. |
| Software application analytics | Art. 6(1)(f) Legitimate interest; Art. 6(1)(b) Contract | Security monitoring, performance improvement, service delivery. |
| AI Features in Ledidi Suite (study-design assistant and successor features) | Processor activity under the DPA. Ledidi processes Project Metadata on the Customer’s documented instruction (opt-in). Where the Project Metadata contains Personal Data, the Customer/Controller is responsible for establishing the applicable Art. 6 (and where relevant Art. 9) legal basis. This Privacy Policy does not provide the controller-side legal basis for such processing | Disabled by default. Operates only on Project Metadata. Human-in-the-loop required for every change. No training on Customer data. |
| AI-powered support (Freshdesk) | Art. 6(1)(f) Legitimate interest | Ticket classification and routing for faster support. |
| AI-powered CRM (HubSpot) | Art. 6(1)(f) Legitimate interest | Data enrichment, predictive analytics, customer insights. |
| AI-powered billing (Chargebee) | Art. 6(1)(f) Legitimate interest | Revenue forecasting and churn prediction. |
| AI-assisted meeting notes (Granola) | Art. 6(1)(f) Legitimate interest | Meeting documentation. Participants informed at start of meeting. |
| Events and webinars | Art. 6(1)(f) Legitimate interest | Organising events and adapting content. |
| User surveys | Art. 6(1)(f) Legitimate interest | Improving services. Participation optional. |
| Security and audit logging (incl. IP addresses) | Art. 6(1)(f) Legitimate interest | Network and information security (Recital 49 GDPR), authentication, abuse and intrusion detection, and audit trail required by ISO 27001, SOC 2 and HIPAA. A documented Legitimate Interest Assessment (LIA) is available on request. |
| Marketing measurement — server-side dispatch of commercial events (LinkedIn, Google) | Art. 6(1)(a) Consent (advertising/analytics dimensions) | Conversion milestones (e.g. account created, trial started, subscription began) forwarded server-side. Data limited to: event name, timestamp, generic commercial properties (plan, amount), a one-way hashed email, and pseudonymous web identifiers (gclid, li_fat_id). No Customer content. Consent-gated via the cookie banner; deletion fan-out to providers on withdrawal. |
| In-product engagement signals forwarded to CRM — HubSpot | Art. 6(1)(a) Consent | Generic per-account behavioural signals (login recency, activation milestones, feature-area engagement counts) used for lead scoring and behavioural email automation. No project, form, registry, study or participant content. Generated only where analytics consent has been given; consent may be withdrawn at any time |
| Targeted advertising via uploaded customer lists — Customer Match / Matched Audiences | Art. 6(1)(a) Consent (prospects) | One-way hashed email addresses uploaded to LinkedIn and Google to deliver Ledidi’s own targeted and lookalike advertising. Covered by the DPIA addendum; right to object; opt-out via dpo@ledidi.no. |
The personal data we collect
We collect the minimum required personal data depending on the purpose:
- Contact details: name, email address, phone number, position, profession, organisation and/or country.
- Communication: the content of your messages, for example, requests via our website, emails or support tickets or feedback via our surveys or questionnaires.
- Payment information.
- Website usage: information collected when you visit and use our website or software applications.
Technical and security data: IP address, device and browser identifiers (user agent), authentication events, session identifiers, and timestamps generated when you interact with our website or software applications.
Information that is collected automatically
When you visit our website (ledidi.com)
Our website uses cookies and similar technologies. Some of these cookies are functional, while others are used for analytical or marketing purposes. The use of non-essential cookies is based on your consent when you visit our website. For more information on the cookies we use on the site and their purpose, please see our Cookie Policy at https://ledidi.com/cookie-policy.
Among these technologies, we use Google Analytics 4 to measure website traffic, traffic sources and content engagement, and the LinkedIn Insight Tag to measure the effectiveness of our advertising, attribute conversions, and build retargeting and audience-measurement segments. These analytics and advertising technologies are non-essential and are activated only after you give consent through our cookie banner; the specific cookies, their providers, purposes and retention periods are set out in our Cookie Policy. For this advertising and audience measurement, Google and LinkedIn act as processors when processing personal data on behalf of Ledidi to provide the services. To the extent personal data is shared with Google or Linkedin for their own purposes, they will act as an independent controller under their respective controller- to- controller arrangement; rather than as our processors; their own privacy notices describe how they further process the data they receive.
When you use our software applications
When you access Ledidi software applications, we automatically collect technical data necessary for the secure operation of the platform. This includes your IP address, user agent (browser and device information), authentication events, session identifiers, and access timestamps. We use this information to authenticate users and maintain sessions, detect and prevent unauthorised access and abuse, maintain audit logs as required by our ISO 27001, SOC 2 and HIPAA control set, investigate technical issues, and analyse aggregated usage patterns to improve performance and reliability. Where Ledidi acts as Data Processor for Customer content, these security and audit logs are kept logically separated from that content. Ledidi is the Controller for the security and audit logs themselves, and processes them on the basis of legitimate interest (Article 6(1)(f) GDPR; see Recital 49 on network and information security). We also collect information related to your user account (the amount of data stored and processed, the number of projects, the number of collaborators and the number of projects you take part in as a collaborator).
Product usage analytics. To understand how the software is used and to improve it, we use a product-analytics service (Mixpanel) to record in-application events such as feature usage, session depth, onboarding progress and the date you were last active. The identifiers used for this purpose are pseudonymised. This product analytics operates only on account and usage metadata; it never operates on, and we do not feed into it, the content you enter into the platform — such as study, registry, participant or other Customer content. The Mixpanel analytics SDK stores and reads information on your device, so we collect this usage data only where you have given consent (Article 6(1)(a) GDPR and ekomloven). You can withdraw your consent at any time through the cookie banner or “Cookie settings”. Before activation, Mixpanel is engaged as our processor under a data processing agreement and is identified in our sub-processor list.
Personal data you provide to us
Contact forms
If you send us a message through the contact forms on our website, we collect your name, email address and the content of your message in order to respond to your request. We encourage you to be careful about disclosing any sensitive information about yourself or others. If you request a copy of our security documentation, we also collect information about your position and organisation. We store this information and any following correspondence in our customer relationship management (CRM) system.
Sales outreach
If you are approached or contacted by our sales representatives and signalise a wish to continue the dialogue, we collect your name, relevant contact details and documentation from correspondence or meetings. This data is processed in our CRM system.
Where you have asked to continue a conversation with us, our follow-up may take the form of structured business-to-business email sequences. In that case we also record delivery and engagement metrics — such as whether a message was opened, clicked, replied to or returned as undeliverable, and which step of the sequence has been reached — so that we can manage the cadence of our contact and stop reaching out when that is appropriate. We carry out this solicited outreach and the associated tracking on the basis of our legitimate interest in business development, having balanced it against your interests and rights, and you may object or opt out at any time by replying to us or contacting dpo@ledidi.no. This is separate from, and is not relied upon to send, the consent-based marketing communications described below.
Lead-source and campaign attribution. Where you consent to analytical or marketing cookies, we may capture campaign-attribution parameters (for example UTM tags identifying the campaign, source and medium that referred you). The placing and reading of those cookies is based on your consent, as described in our Cookie Policy. Once captured, we may store these attribution parameters against your contact record in our CRM (HubSpot) so that we can understand which channels and campaigns are effective; we retain them with your contact record (up to three years after your last interaction) on the basis of our legitimate interest in measuring and improving our marketing.
User account creation
When you create a user account, we collect your name, email address, phone number, organisation and country to uniquely identify you and provide you with our services. We also collect information related to your type of user licence, subscription type, and whether you have signed up for a user account as an independent user or by invitation from an organisation or another user.
User profile
You have the option to provide additional information about yourself in your user profile. This information may be shared with other users, making it easier for them to recognise one another and establish collaborations. Ledidi may also use this information (e.g. academic degree, position and role) in aggregated and anonymised form, combined with usage patterns, to better understand our users’ needs and improve our services; in that aggregated form the analysis no longer identifies you. We do not use your profile information to send you marketing or to build an individual marketing profile unless you have agreed to receive marketing communications as described below.
Communications
We distinguish between two types of communication, which rely on different legal bases and offer different choices.
Service communications
When you have created a user account, we use your email address to send you service communications: important service notices, security alerts, and useful information directly related to the operation of your account (e.g. updates, new features and improvements) in accordance with the Terms of Service. We will also notify you of significant changes to our Terms of Service or Privacy Policy. These messages are necessary to provide the service (Article 6(1)(b) GDPR) and are not marketing; you cannot opt out of them while you hold an active account.
Marketing communications and newsletters
Separately, we may send you marketing communications and newsletters — such as product news, event invitations, educational content and offers. We send these on the basis of your consent, which you may give when you sign up on our website or when you create a user account. Where permitted by the Norwegian Marketing Control Act (markedsføringsloven § 15) and applicable ePrivacy rules, we may also send marketing about our own similar products to existing customers on a soft opt-in basis, and the legal basis will be our legitimate interests (Article 6(1)(f) GDPR).
You are not automatically enrolled in marketing or newsletters by virtue of holding an account. You can withdraw your consent or opt out at any time by using the unsubscribe link at the bottom of any marketing email, or by contacting us at dpo@ledidi.no. Opting out of marketing does not affect the service communications described above, which are necessary to provide the service.
Payment
If you buy or subscribe to any of our paid services, either on your own behalf or on behalf of others, we collect your name, email address, phone number, organisation and payment details (such as payment card information or necessary information for invoicing).
Events and webinars
When you sign up for an event hosted by Ledidi (i.e. webinar, meeting, educational course), we collect your name, email address, position and organisation. We use this personal information to inform you about the event and how to attend.
User surveys
If you have a Ledidi user account, we may also send you invitations to participate in user surveys or respond to questionnaires. Participation is optional, and invitations will include a description of the purpose and how the information will be used.
We do not use personal data in any way that is not covered by the purposes detailed in this Privacy Policy unless you expressly authorise us to do so. In that case, we will ask for your specific consent.
AI features and analytics
Ledidi uses AI-enabled features in certain supporting systems to improve the quality and efficiency of our services. These AI features are used in supporting business processes and do not process the content you store in the Ledidi Suite application beyond the scope described under “AI features in Ledidi Suite” below.
AI features in Ledidi Suite
The Ledidi Suite application includes optional AI Features, such as a study-design assistant, that operate on Project Metadata (variable definitions, project names and descriptions, schedule structures, form elements, and analysis configuration). These AI Features do not access participant records, form responses, health data, or personal identifiers.
AI Features are disabled by default and must be opted in by the customer at the organisation level and by a Project Owner at the individual project level. Before AI Features are enabled on a project, the User is shown a disclaimer listing the fields the AI may access and stating that these fields are assumed not to contain personal data. An in-product notification is also displayed to the User immediately before each AI invocation, reminding the User of the obligation to keep Project Metadata free of personal data and special category data. Ledidi does not perform automated content inspection of Project Metadata for the purpose of detecting or preventing personal data; the responsibility for the content of Project Metadata sits with the Customer (Controller) and its Users.
When Ledidi Suite AI operates on data entered by the Customer on behalf of data subjects, Ledidi acts as a Processor and the processing is governed by the Data Processing Addendum. AI inference is performed through Amazon Web Services Bedrock using EU-scoped model deployments accessed via AWS PrivateLink. Prompts and completions are not retained, logged, or used to train foundation models.
AI in supporting systems
The following supporting systems utilise AI-powered features that may process limited personal data about you:
- Customer support: our support platform (Freshdesk) uses AI-powered ticket classification, summarisation, and routing to ensure faster response times. This may process your name, email address, and the content of your support request.
- Customer relationship management: our CRM platform (HubSpot) uses AI features including data enrichment, communication assistance, and predictive lead scoring. This may process your contact details and interaction history.
- Subscription management: our billing platform (Chargebee) uses AI for subscription revenue forecasting and churn prediction. This may process your subscription and billing data.
- Meeting notes: when you participate in meetings with Ledidi representatives, AI-assisted note-taking (Granola) may be used. You will be informed at the start of any such meeting.
Sensitive personal data and health data are not processed by these AI-enabled supporting systems. All AI service providers are contractually prohibited from using Ledidi data for model training.
These vendors act as Ledidi’s processors or sub-processors for the Personal Data they process on Ledidi’s behalf, under contractual terms that limit processing to Ledidi’s documented instructions and prohibit the use of that data for training their foundation models or for their own commercial purposes. Any independent-controller activity is limited to strictly necessary service operation (e.g., abuse prevention, security monitoring, billing metadata) and is disclosed in the applicable vendor’s own privacy notice. We tell you which vendors this applies to, and how to reach them, in the “Exercising your rights with AI vendors” section below.
Ledidi publishes a current list of its sub-processors, including those supporting AI-enabled features, in the Ledidi Trust Centre. The list identifies each sub-processor, its location, its purpose, and the categories of data it processes, and is updated when sub-processors are added or removed.
Automated decision-making
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you, as described in Article 22 of the GDPR. All AI-enabled features in our supporting systems are used to assist our staff, and human review is applied before any decision is communicated to you.
Ledidi Suite AI Features do not make decisions that produce legal effects concerning data subjects or similarly significantly affect them. AI-generated suggestions in Ledidi Suite are presented to a human User who must review and approve each change before it takes effect. No AI-generated change is applied automatically.
Marketing measurement and commercial signals
This section describes how we measure marketing activity after you sign in and how we use account-usage data to support our commercial relationships. It complements the cookie disclosure above and the Cookie Policy at https://ledidi.com/cookie-policy. No advertising or marketing tracking technologies run inside Ledidi software applications; clinical, research, study, registry, participant and project content never leaves the product for marketing or advertising purposes.
Conversion events (server-side measurement)
To attribute a marketing campaign to its outcome, we forward a small, defined set of commercial milestones server-side — for example that an account was created, a trial was started, or a paid subscription began. The only information that leaves Ledidi software applications for this purpose is the event name, the timestamp, generic commercial properties (such as plan name and amount), a one-way hashed version of your email address, and the pseudonymous identifiers captured when you first visited our website. No project, form, registry, study or participant content is included. This measurement is performed only where you have given the necessary consent through the cookie banner, and it stops — with a deletion request to the relevant providers — when you withdraw consent.
In-product engagement signals (HubSpot)
We forward generic behavioural signals about your account — for example how recently it has been active, which broad feature areas are being used, and which activation milestones have been reached — to our customer relationship management platform, so that our sales and customer-success teams can prioritise their work and keep our communications relevant. These are per-account behavioural metrics; they do not include the content of any project, form, registry, study, or any patient or research-participant data. These signals are generated only for accounts where analytics consent has been given, so we rely on your consent (Article 6(1)(a) GDPR). You may withdraw your consent at any time through the cookie banner or by contacting dpo@ledidi.no.
Customer Match / Matched Audiences (LinkedIn, Google)
We may upload one-way hashed email addresses to LinkedIn and Google so that we can deliver our own targeted advertising and build lookalike audiences. We rely on our legitimate interest for existing customers and on your consent for prospects, and you may object or opt out at any time via dpo@ledidi.no. The data uploaded is limited to a hashed (one-way encrypted) email address; we do not upload any project, registry, study or participant data. This processing is covered by our DPIA.
Transparency: on request we will provide a record of the marketing and conversion events transmitted about you to each provider over the preceding thirteen months. When you withdraw consent or request erasure, we delete your data from our systems and send a deletion request to each provider named in this section, using the deletion mechanisms each provider offers.
How we share your personal data
Ledidi does not sell your personal information, and we do not share it with marketers or unaffiliated third parties for their own marketing purposes. We share information about you with our trusted service providers for specific purposes such as payment processing, subscription plan management and billing, and to manage our relations with our customers and users. We may also share your personal data with third-party sub-processors providing AI enrichment, analytics, and predictive modelling capabilities. The only exception is the one-way hashed email audience lists described under “Marketing measurement and commercial signals”, which are shared with LinkedIn and Google solely to deliver Ledidi’s own advertising — never for those providers’ own marketing.
Most of these providers act as our processors or sub-processors and may only use your data on our documented instructions. A limited number of them (for example certain CRM, billing or analytics vendors) also act as independent controllers for narrowly defined, strictly necessary service operations — such as abuse prevention, security monitoring and billing metadata — as described in the “AI in supporting systems” section and in each vendor’s own privacy notice. We do not authorise any of these providers to use your data to market their own products to you. Before engaging any AI-related sub-processors, we conduct a full Transfer Impact Assessment (TIA) and ensure adequate safeguards are in place.
Amazon Web Services, Inc. (AWS) also provides the AI inference service (Amazon Bedrock) used by Ledidi Suite AI Features. AI inference runs on EU-scoped model deployments inside AWS’s managed Bedrock environment. Prompts and completions are not retained, logged, or used to train foundation models.
All our service providers are subject to contractual terms that limit their use of your personal data in accordance with applicable data protection legislation. Further, we require all our service providers to contractually commit to protecting the security and confidentiality of the personal data they process on our behalf and to have appropriate safeguards and compliance measures to ensure an adequate level of protection of personal data.
In addition to the providers already named, we use trusted service providers to operate our website and deliver its content (Sanity), to measure website and product usage (Mixpanel), and to manage our relationships and communications with prospects and customers (HubSpot). We also use Google Analytics and the LinkedIn Insight Tag to measure website and advertising performance; for that advertising and audience measurement Google and LinkedIn act as processors, as described above. If personal data is processed for own Google's or Linkedin's own purposes, the respective company will act as an independent controller. Information about prospects and customers — including names, organisations and our notes from calls and meetings — may also be stored in our internal knowledge base (Notion) for sales and customer-success purposes, on the basis of our legitimate interest in managing our business relationships; we apply retention limits to this information and delete it when it is no longer needed. Before we activate any of these providers we put a data processing agreement in place, require them to act only on our documented instructions, and identify them in our sub-processor list in the Ledidi Trust Centre.
Sub-processor list
A current list of all sub-processors used by Ledidi, including their location, purpose, and data categories processed, is accessible in the Ledidi Trust Centre and upon request. Customers are notified where required by the DPA, by email when sub-processors are added or replaced. Specific questions about the list may be directed to dpo@ledidi.no. The list is reviewed and updated at least quarterly.
International data transfers
Some of our service providers are registered outside of the EEA, and personal data may therefore be transferred to and processed in countries outside the EEA. We only use such providers on the condition that enforceable rights and effective remedies for data subjects are ensured, and we require all of them to contractually commit to protecting the security and confidentiality of the personal data they process on our behalf and to maintain appropriate safeguards.
Our principal infrastructure provider, AWS, hosts data in EU regions and is certified under the EU–U.S. Data Privacy Framework (DPF), on which we rely as the primary transfer mechanism for any onward transfer to the United States, supported by the EU Commission’s approved Standard Contractual Clauses (SCCs) as a supplementary safeguard. We carry out a Transfer Impact Assessment (TIA) for each provider to identify and implement appropriate safeguards. Contact us at dpo@ledidi.no to get a copy of the SCCs or TIA.
For AI Features in Ledidi Suite, AI inference is performed exclusively within the EEA on AWS Bedrock EU-scoped model deployments accessed via AWS PrivateLink. No Project Metadata is transferred outside the EEA for the purpose of providing AI Features.
For AI-related processing and analytics in supporting systems, some personal data may be transferred to vendors located outside the EEA, some of which may act as independent controllers for the strictly necessary service operations described above. Any such transfer will have a valid legal basis. Such transfers are subject to an adequate legal basis and safeguards that ensure the transfer is in accordance with applicable privacy legislation. These safeguards may include:
- EU–U.S. Data Privacy Framework, where the recipient is certified
- Standard Contractual Clauses (SCCs), including module 1 for controller-to-controller transfers
- Contractual regulation
- UK Addendum and Swiss-specific adaptations
We continuously monitor the adequacy of these transfer mechanisms in accordance with guidance from the Norwegian Data Protection Authority (Datatilsynet) and the European Data Protection Board (EDPB).
Retention of personal data
The specific retention period for each data category is set out in the table below. As a general rule, we delete personal data when the purpose of the processing has been achieved or within three years after your last interaction with us, unless a longer period is required by law. If you have a Ledidi user account, you may instruct us to delete your data earlier in accordance with this Privacy Policy and the Terms of Service. For data processed by AI-enabled supporting systems, the same retention periods apply — AI-processed data is not retained separately. For Ledidi Suite AI Features, no prompt or completion is stored by the AI Provider (Zero Data Retention).
| Data category | Retention period | Basis |
|---|---|---|
| Contact form inquiries | 3 years after last interaction | Legitimate interest (documentation for complaints/claims) |
| CRM and sales data | Duration of customer relationship + 3 years | Legitimate interest; legal obligations (accounting) |
| User account data | Duration of account + 3 years | Contractual necessity; legal obligations |
| Payment and billing data | Duration of subscription + 5 years | Legal obligation (Norwegian Accounting Act, bokføringsloven) |
| Website analytics (cookies) | As specified in Cookie Policy (typically 12–24 months) | Consent (non-essential); legitimate interest (functional) |
| Software application analytics | Aggregated and anonymised within 12 months | Legitimate interest |
| Support tickets (Freshdesk) | Duration of customer relationship + 2 years | Legitimate interest |
| Marketing communications and newsletters | Until you withdraw consent or unsubscribe + 30 days processing | Consent; or legitimate interest |
| Event registration data | 2 years after event | Legitimate interest |
| Granola meeting notes | 3 years after the meeting | Legitimate interest |
| AI-processed data (supporting systems) | Same as underlying data category | No separate retention |
| Ledidi Suite AI (Bedrock) | No retention (ZDR) | Contractual necessity; Processor role |
| Security and audit logs (incl. IP addresses) | 12 months for operational security logs; up to 24 months for audit logs required by ISO 27001 / SOC 2 / HIPAA | Legitimate interest; legal/contractual obligations |
| Marketing event dispatch logs (conversion events) | 90 days hot; 13 months cold; thereafter aggregated counts only | Legitimate interest |
| Lead score & in-product engagement-signal history — HubSpot | 3 years from last engagement | In-product engagement-signal history: consent (Art. 6(1)(a)), deleted on withdrawal. HubSpot AI lead scoring: legitimate interest |
| Customer Match / Matched Audiences list data | Held on the active audience list until opt-out, erasure or list refresh; no further uploads thereafter | Legitimate interest for list of names and emails/ consent for use of cookies; |
How we protect your personal data
Ledidi has implemented technical, organisational and administrative security measures to protect your personal data. We continuously seek to ensure that the data we collect is protected against loss, destruction, corruption and unauthorised access. Our security framework is updated regularly in line with technological developments. Your personal data is only accessed by a limited number of personnel who need access to data to perform their duties. When we share data with our service providers, we authorise them only to use or disclose your data to perform services on our behalf or to comply with legal requirements. Before engaging any service provider, we perform a risk assessment. Access logs and IP-based audit trails are maintained as part of our ISO 27001 control set, used solely for security, audit and operational purposes, and retained per the schedule in the table above.
Personal data is classified under Ledidi’s Data Classification Scheme and handled according to its classification level. Data classified as RESTRICTED, data classified as CONFIDENTIAL, and Sensitive Personal Data (Article 9 GDPR) are excluded from processing by AI-enabled supporting systems. AI Features in Ledidi Suite are subject to the additional controls set out below and operate under Zero Data Retention with the inference provider. All AI providers are contractually prohibited from using Ledidi data for model training.
The following additional safeguards apply to AI Features in Ledidi Suite:
- AI Features in Ledidi Suite are restricted by the tool surface to Project Metadata only. AI cannot call tools that read participant data, form responses, or any data classified as CONFIDENTIAL or RESTRICTED.
- AI inference for Ledidi Suite uses EU-scoped AWS Bedrock model deployments via AWS PrivateLink. Inference traffic does not traverse the public internet.
- Zero data retention is enforced by Ledidi’s AI provider: prompts and completions are not stored, logged, or used for model training.
Personal data breach notification
In the event of a personal data breach, Ledidi will notify the Norwegian Data Protection Authority (Datatilsynet) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with Article 34 of the GDPR, providing you with information about the nature of the breach and the measures taken or proposed to address it.
Your rights and choices
You can request access to and information about what data we store and process about you at any time. You have the right to request the correction, deletion and restrictions in the processing of your personal data, as well as the right to object to the processing of personal data about you in accordance with applicable data protection laws. You may also have the right to receive your data and transmit those data to another controller.
Consents that you have given can be withdrawn at any time. Withdrawal of your consent does not affect the legality of the storing, processing or transfer of your personal data before the withdrawal.
Any questions or concerns that you may have regarding this Privacy Policy can be sent to our Data Protection Officer at dpo@ledidi.no.
If you believe that we have not complied with your statutory rights in accordance with applicable data protection legislation, you have the right to send a complaint to the Norwegian Data Protection Authority (www.datatilsynet.no). However, we kindly ask you to contact us first so that we may address your concerns or resolve any misunderstandings.
Exercising your rights with AI vendors
For certain AI-driven processing carried out by third-party vendors acting as independent controllers in supporting systems (such as HubSpot enrichment or Chargebee analytics), you may exercise your data subject rights directly with these vendors. Ledidi will provide their contact information upon request and support you where feasible. For AI Features in Ledidi Suite, Ledidi acts as Processor, and you should direct requests to the Customer (Controller) or to Ledidi as Processor.
You have the right to object to automated processing of your personal data by AI-enabled systems, including profiling. To exercise this right, please contact our Data Protection Officer.
Updates to this Privacy Policy
We will update this Privacy Policy when required by changes in our practice or in privacy legislation. In the event of material changes to our information practices, we will point out those changes on our webpage and, in some cases, send you a notification of changes by email. Your continued use of our services after we provide such information does not, by itself, constitute consent where consent is legally required; for any change that requires your consent, we will obtain it separately before relying on it.
Contact information
If you have any concerns about privacy at Ledidi, please contact our Data Protection Officer:
Name: Anthea Van Parys
Email: dpo@ledidi.no
Postal address: LEDIDI AS, Attn: Data Protection Officer, Gaustadalléen 21, 0349 Oslo, Norway