Privacy policy and cookies

Here can you read about how we at Protector Forsikring ASA (hereinafter Protector) handle personal data and our guidelines on cookies.

Protector protects your individual rights and personal data. The reference to GDPR stands for the General Data Protection Regulation.

Last updated 19.06.2026.

Content

  1. Introduction
  2. Contact Information
  3. Handling of Personal Data
  4. Why and how do we process personal data?
  5. What information does Protector process?
  6. What legal bases does Protector use?
  7. Special categories of personal data (GDPR art. 9)
  8. Who do we disclose personal data to?
  9. How long do we store personal data about you?
  10. Your privacy rights
  11. How to complain about the processing?
  12. Cookies
  13. Use of AI (Artificial intelligence)

 

1. Introduction

What is personal data?

Personal data is information that can be linked to an identified or identifiable person, such as name, address, national identification number, email address, and/or vehicle registration number. Such information may be necessary for us to process in order to serve you as a customer.

What are cookies?

A cookie (also called an information capsule) is a small file stored on your device. A cookie stores, among other things, information about which pages you visit on the internet and what your preferred language is when browsing the internet. Cookies allow us to record how internet users navigate websites, so that we can continuously improve the user interface and websites for visitors.

What is processing of personal data?

Processing of personal data means, cf. GDPR art. 4 (2):

"any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction."

Processing of personal data requires a legal basis – i.e., a legal ground. Different legal bases may apply to different types of personal data.

 

2. Contact Information

Protector's contact information is:

  • Postal address: Protector Forsikring ASA, Pb 1351 Vika, 0113 OSLO
  • Email: info@protectorforsikring.no
  • Phone: +47 24 13 18 00
  • Organization number: 985 279 721

Controller: The controller is the one who determines the purpose and means of the processing of personal data. Protector Forsikring ASA, in its role as controller, maintains an overview of processes, business areas, and systems that process personal data, and conducts internal controls and risk assessments to ensure compliance with privacy regulations.

Data Protection Officer: If you have questions related to how we process personal data, or if you wish to invoke your rights under privacy regulations, please contact our data protection officer:

  • Email address: DPO@protectorforsikring.no

 

3. Handling of Personal Data

We process personal data necessary to provide our customers with insurance services. For example, when a person covered by insurance suffers a loss, we need personal data about the injured party so that we can fulfill our obligation under the insurance agreement. Providing personal data is voluntary, but without necessary personal data, we will not be able to calculate correct compensation for a potential loss.

Protector processes personal data in accordance with applicable privacy regulations. Your privacy is important to us, and we focus heavily on ensuring that your personal data is processed according to the principles of confidentiality, integrity, availability, and robustness.

Please note that it is not recommended to send sensitive personal data or national identification numbers via email unless the content is encrypted.

See our cookie policy for information about our use of cookies.

 

4. Why and how do we process personal data?

The purpose of our processing of your personal data is to identify you as a customer and fulfill our obligations under the insurance agreement you have with us. Our processing of personal data is handled by our skilled and competent employees. In some cases, personal data is processed by partners with whom we have a data processing agreement. We use specialized systems with sufficient security to store and process your personal data.

Only a select number of individuals process and have access to any sensitive information in our specialized systems. Physical sensitive personal data is locked in a secure area when not being processed by a case handler.

All employees at Protector are subject to confidentiality. Employees are obligated to maintain confidentiality towards external persons and businesses, as well as internally among colleagues. This duty of confidentiality does not cease if the employment relationship ends.

5. What information does Protector process?

Information processed by Protector can be categorized as follows:

  • Administrative information such as name, address, phone number, email address, and national identification number.
  • Information about insured risk and coverage scope.
  • Health information.
  • Claims information necessary to determine payment claims under an insurance policy.
  • Information about third parties due to their connection to an insurance policy, e.g., beneficiaries.

 

6. What legal bases does Protector use?

Protector processes personal data to fulfill our obligations as an insurance company. This applies to both contact information and health information that is necessary for the company to collect.

The following legal bases are relevant for Protector's operations:

  • Consent (GDPR art. 6 (1) letter a): That the data subject has consented to the processing for specific purposes. Example:
    • Recruitment
  • Performance of a contract (GDPR art. 6 (1) letter b): That the processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract. Examples of performance of contracts:
    • Customer administration, invoicing, and execution of insurance services.
    • Processing of claims.
  • Legal obligation (GDPR art 6 (1) letter c): That the processing is necessary for compliance with our legal obligation. Examples of processing based on legal obligations:
    • Bookkeeping Act
    • Tax Act
    • Accounting Act
    • Anti-Money Laundering Act
  • Our legitimate interest(s) (GDPR art 6 (1) letter f): That the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party. Examples of our legitimate interests:
    • Communication with brokers about professional events (save the date, participant registration, etc.)
    • Logging and security
    • Improving our claims submission process
    • Fraud detection
    • Training

 

7. Special categories of personal data (GDPR art. 9)

In some cases, Protector processes special categories of personal data. This includes sensitive personal data, such as health information. In these cases, we will use authorization/consent to collect personal data about you from external parties such as doctors, hospitals, other healthcare providers, and NAV (Norwegian Labour and Welfare Administration). In these cases, you will receive an authorization form stating the purpose of the processing.

The authorization limits the processing to only include the information necessary for Protector to fulfill its obligations towards you.

If consent is not given, it may affect Protector's decision on the compensation claim.

 

8. Who do we disclose personal data to?

We can only disclose personal data to third parties if privacy regulations permit it. You will be informed if we disclose personal data about you to a third party, unless it is explicitly stated by law or regulation that the disclosure must be kept confidential.

Your personal data may be disclosed to the Central Claims Register (FOSS) and the Register for Insurance Applicants and Insured Persons (ROFF), which are operated by Finans Norge Forsikringsdrift. These registers are common to the insurance industry, and their purpose is to prevent/limit insurance fraud and ensure uniform risk assessment.

Personal data may be disclosed to public authorities if required by statutory reporting obligations or disclosure duties.

In certain cases, it will be necessary for us to disclose personal data about you to fulfill our agreement with you as the insured. This applies, for example, to the use of specialists where your claim needs to be assessed by someone with particular expertise in the area. The person concerned will in such cases be subject to confidentiality and instructed to delete the information when it is no longer needed.

If it is necessary for us to use a data processor, the data processor will only process personal data according to detailed instructions from Protector. This is to ensure your rights and protect your privacy. Any data processors who receive personal data from us are subject to confidentiality through contractual agreement.

 

9. How long do we store personal data about you?

We do not store personal data longer than necessary to fulfill the purpose of the processing. If you have a customer relationship or a personal injury registered with us, personal data about you will be stored.

Due to future compensation claims that can be traced back to the insurance relationship, certain information will be stored until the statute of limitations for the relevant insurance claims expires.

Protector deletes personal data when there is no longer a legal basis for processing. This is mostly governed by the statute of limitations for claims on various insurance policies. Personal data can therefore be stored for up to 20 years

 

10. Your privacy rights

Right to access: You can request access to the information we process about you. You have the right to know the purpose and legal basis we use, what information about you we process, recipients or categories of recipients to whom personal data is disclosed, the storage period of the personal data, and where the information was obtained from. If you wish to access our processing of personal data, you must send us an access request, and we shall respond within 30 days of receiving the inquiry.

Right to rectification and erasure: If you believe that Protector has registered inaccurate or incomplete information about you, you have the right to demand rectification of the relevant personal data.

You can request that we erase personal data about you if the information is no longer necessary to fulfill the purpose of the processing. You can withdraw your consent. If consent is withdrawn, consent will no longer be the legal basis for further processing. A withdrawal of consent means that further processing is terminated unless the company can demonstrate another lawful basis for processing.

You also have the right to object to the processing of your personal data if you believe that we are not doing something correctly in relation to your personal data.

Restriction of personal data processing: You can ask us to restrict the processing of personal data if you dispute the accuracy, lawfulness, or have objected to the processing. The processing will then be limited to storage only until the information is corrected, or it can be established that our legitimate interests override your interest.

Right to data portability: You have the right to receive personal data we have stored about you in a structured, commonly used, and machine-readable format. You also have the right to request that we transfer information we have received from you to another controller if technically feasible and the processing of personal data is based on consent or contract.

Notification of a personal data breach: In the event of a personal data breach, you may have the right to be notified. Any reporting of deviations and notifications will be made in accordance with the rules applicable at any given time. In this regard, reference is made to GDPR Articles 33 and 34.

 

11. How to complain about the processing?

If you have questions or comments about our processing, please contact us in accordance with section 2 on contact information.

You can also contact the Norwegian Data Protection Authority (Datatilsynet); their job is to ensure that privacy regulations are followed. If you experience something you believe is a violation of the regulations, you can send a written inquiry to the Data Protection Authority's postal address: Datatilsynet, Postboks 458 Sentrum, 0105 OSLO.

 

12. Cookies

When you visit our website, your browser will download cookies. These are small text files exchanged between your device and this website and are used to make the website function as optimally as possible. Below is an overview of the cookies used.

As a web user, you can choose to reject the storage and use of cookies.

HTTPS and secure transfer: Our website is covered by HTTPS encryption. If you want to ensure that a page is encrypted, a padlock and/or "https" will appear in the address bar at the top of the browser instead of just "http" before the address. The purpose of encryption is to ensure secure data communication between the server (the website) and the client (your computer). This includes a digital certificate that proves that the website and its sender are authentic.

Cookies on the website: CoreTrek AS provides the publishing tool for our website and is responsible for technical development, operation, and maintenance. The cookies our website uses are:

  • To make the publishing solution work: The cookie CorePublishSesssion. The cookie is removed from your computer when you close the browser.
  • To identify the type of device and browser you are using: The cookie Ctdevicecachekey. The cookie lasts for one week and allows our website to present content to the correct type of device (PC, mobile, tablet, etc.)

Sharing: We have included the option to forward articles by email and share articles on social media. Email addresses used to forward articles are not logged. Further handling of data shared on social media is governed by your agreement with the relevant social network.

Statistics and log: When you read our web pages, information will be stored in statistics and log files.

The system does NOT store "user agent" or IP address, but stores which page the visitor has visited in a raw data table. This information is then used to generate statistics for the number of page views per object (menu item, article, file), per host, and per search term. All data in the raw data table is deleted after 2 days, and the remaining statistics then contain only summarized data that cannot be used to identify individual users.

We also do not store "user agent" or IP address in the web server's logs, but can store which pages have been visited. These logs are exclusively used for troubleshooting and security work, and no data is extracted or used from these logs. The logs are deleted after a given interval (normally 4 weeks). Only administrators of the web server (operations) have access to these.

Google Analytics: As part of our work to create a user-friendly website, we use Google Analytics to examine the usage patterns of website visitors. Google Analytics is a web analytics service provided by Google, Inc.

Google Analytics and CorePublish store information about the search terms users employ on our website. Only the search phrases are stored, and they cannot be linked to other information related to the user.

Google Analytics is set up with anonymizeIP, a function that prevents individual users from being identified. An IP address is defined as personal data because it can be traced back to a specific computer and thus to an individual.

Google is the data processor responsible for the information they collect. The collected information is stored on Google's servers and is subject to Google's privacy policy.

Consent: We use the Cookie Information service to give you insight into which cookies are used on protectorforsikring.no and to allow you to set consents for the use of cookies on the website.

You can choose which cookies you accept in these categories:

  • Functional
  • Statistical
  • Marketing

You can change your consent settings at any time.

13. Use of AI (Artificial intelligence)

To continuously improve our services and operational efficiency, we may utilise tools based on Artificial Intelligence (AI) and machine learning.

How and Why, We Use AI:

We use these technologies to support our team in processing and analysing information more effectively. This allows for faster, more consistent service. Our use of AI includes, for example:

  • Generating Internal Summaries: creating automated summaries of individual claim or underwriting files to help our handlers get a quicker overview of complex cases.
  • Managing and Prioritising Caseloads: Allowing our claims handlers to search and analyse information across multiple active, open claim files to help them plan, prioritise, and action their daily work.
  • Analysing Data for Service Improvement: Identifying broad trends, performing root-cause analysis, and creating aggregated reports from multiple claims or policies to improve our services and risk assessments. (Note: This type of strategic analysis is performed using anonymised or aggregated data where individual data subjects cannot be identified).
  • Extracting Information: Automating the extraction of key data points from large documents for use in internal reporting and analysis.

How We Protect Your Data and Your Rights:

Your privacy is our highest priority, and we have implemented strict technical and organizational measures to ensure your data is always processed securely:

  • Human Oversight: The tools are for internal assistance only. All significant decisions in your case are always made by one of our human case handlers.
  • Secure Data Access: To perform these tasks, the AI model is granted temporary and purpose-limited access to data already existing within our records. This may include both general and sensitive personal data (such as health information).
  • No Storage in the AI Model: Your personal data is not stored or retained in the AI model itself after the task has been completed.
  • No Training of Public Models: Data from your case is not used to train any external, public, or commercial AI models.
  • Secure Data Processors: We use recognised enterprise technology providers (such as Google) under a strict Data Processing Addendum (DPA) that ensures all processing occurs within the EU/EEA and in full compliance with GDPR.