Privacy Policy

Last updated: 12/30/2025

1. Introduction and Legal Basis

DVSbil.no ("we," "us," or "our") is committed to protecting your privacy and personal data in accordance with the General Data Protection Regulation (GDPR), the Norwegian Personal Data Act (Personopplysningsloven), and other applicable data protection laws. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our vehicle marketplace platform.

Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Contract Performance: To fulfill our contractual obligations when you use our services, create listings, or engage in transactions
  • Legal Obligation: To comply with Norwegian laws, including tax regulations, consumer protection laws, and vehicle registration requirements
  • Legitimate Interest: To improve our services, prevent fraud, ensure platform security, and facilitate transactions between users
  • Consent: For marketing communications and non-essential cookies (you may withdraw consent at any time)

2. Information We Collect

Personal Information

When you create an account or use our services, we collect:

  • Identity Information: Full name, email address, phone number, and date of birth (for age verification)
  • Business Information: Organization number (organisasjonsnummer) if you are a professional seller, business name, and business address
  • Account Information: Username, password (encrypted), profile picture, and account preferences
  • Payment Information: Payment method details (processed securely through third-party providers), billing address, and transaction history
  • Communication Data: Messages exchanged with other users through the platform, support tickets, and feedback

Vehicle Information

When you post vehicle advertisements, we collect:

  • Vehicle Details: Make, model, year, mileage, VIN (Vehicle Identification Number), registration number, and technical specifications
  • Condition Information: Condition reports, service history, accident history, and vehicle photos
  • Listing Information: Pricing, listing description, location data, and listing status
  • Transaction Data: Sale price, transaction date, buyer/seller information, and payment confirmation

Usage and Technical Information

We automatically collect:

  • Device Information: IP address, device type, operating system, browser type and version, and device identifiers
  • Usage Data: Pages visited, time spent on pages, search queries, clicks, and interactions with the platform
  • Location Data: General location information based on IP address and location data you provide for vehicle listings
  • Log Data: Server logs, error reports, and system performance data

3. How We Use Your Information

We use the collected information for the following purposes:

  • Service Provision: To provide, maintain, and improve our vehicle marketplace platform, including facilitating transactions, processing payments, and managing user accounts
  • Transaction Facilitation: To facilitate communication between buyers and sellers, generate sales contracts based on seller status, and process payments through third-party providers (PayPal, Stripe)
  • Legal Compliance: To comply with Norwegian laws, including tax reporting obligations, consumer protection requirements, and vehicle registration verification
  • Security and Fraud Prevention: To detect, prevent, and investigate fraud, security breaches, and unauthorized access to protect users and the platform
  • Communication: To send important updates, transaction notifications, security alerts, and respond to your inquiries and support requests
  • Marketing: To send marketing communications (with your consent) about new features, promotions, and relevant vehicle listings
  • Analytics and Improvement: To analyze platform usage, improve user experience, develop new features, and conduct research

4. Information Sharing and Disclosure

We do not sell your personal information. We may share information in the following circumstances:

  • With Other Users: Vehicle listings, seller contact information (as provided), and public profile information are visible to other users to facilitate transactions
  • Service Providers: We share data with trusted third-party service providers who assist in operating our platform, including payment processors (PayPal, Stripe), cloud hosting providers, email services, and analytics providers. These providers are contractually obligated to protect your data
  • Legal Requirements: We may disclose information when required by law, court order, or government regulation, including to Norwegian tax authorities (Skatteetaten), the Norwegian Public Roads Administration (NPRA), or law enforcement agencies
  • Business Transfers: In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of the transaction, subject to the same privacy protections
  • Protection of Rights: We may disclose information to protect our rights, property, or safety, or that of our users, including investigating potential violations of our Terms of Service

5. Data Security

We implement comprehensive security measures to protect your personal information:

  • Encryption: We use industry-standard encryption (TLS/SSL) for data in transit and encryption at rest for sensitive data stored in our databases
  • Access Controls: We implement strict access controls, authentication measures, and role-based permissions to ensure only authorized personnel can access your data
  • Secure Payment Processing: Payment information is processed through PCI-DSS compliant third-party providers (PayPal, Stripe). We do not store full payment card details on our servers
  • Regular Security Assessments: We conduct regular security audits, vulnerability assessments, and penetration testing to identify and address security risks
  • Data Backup and Recovery: We maintain regular backups and disaster recovery procedures to ensure data availability and integrity
  • Employee Training: Our staff receive regular training on data protection and security best practices

While we implement robust security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your data to the best of our ability.

6. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience:

  • Essential Cookies: Required for the platform to function, including authentication, session management, and security features
  • Functional Cookies: Remember your preferences, language settings, and login status
  • Analytics Cookies: Help us understand how users interact with our platform to improve functionality and user experience
  • Marketing Cookies: Used to deliver relevant advertisements and track campaign effectiveness (with your consent)
  • Third-Party Cookies: Set by third-party services (e.g., payment providers, analytics services) subject to their respective privacy policies

You can control cookie settings through your browser preferences. However, disabling certain cookies may limit platform functionality.

7. Your Data Protection Rights (GDPR Rights)

Under GDPR and Norwegian data protection laws, you have the following rights:

  • Right of Access: You have the right to request access to and receive a copy of your personal data we hold
  • Right to Rectification: You can request correction of inaccurate or incomplete personal data
  • Right to Erasure (Right to be Forgotten): You can request deletion of your personal data, subject to legal retention requirements (e.g., tax records, transaction history for legal compliance)
  • Right to Restrict Processing: You can request that we limit how we use your personal data in certain circumstances
  • Right to Data Portability: You can request a copy of your data in a structured, machine-readable format
  • Right to Object: You can object to processing based on legitimate interests or for direct marketing purposes
  • Right to Withdraw Consent: If processing is based on consent, you can withdraw consent at any time
  • Right to Lodge a Complaint: You have the right to file a complaint with the Norwegian Data Protection Authority (Datatilsynet) if you believe we have violated your data protection rights

To exercise these rights, please contact us at contact@dvsbil.no or through your account settings. We will respond to your request within one month (may be extended to two months for complex requests).

8. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law:

  • Account Data: Retained while your account is active and for 3 years after account deletion, unless longer retention is required for legal compliance
  • Transaction Data: Retained for 5 years to comply with Norwegian tax and accounting regulations (Skatteetaten requirements)
  • Legal Records: Retained as required by applicable laws, including consumer protection laws (5-year complaint period for professional sellers)
  • Marketing Data: Retained until you withdraw consent or opt-out, then deleted within 30 days
  • Usage Logs: Retained for up to 12 months for security and analytics purposes

After the retention period expires, we will securely delete or anonymize your personal data in accordance with our data retention policies.

9. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States (for payment processing and cloud services). We ensure appropriate safeguards are in place:

  • Standard Contractual Clauses: We use EU-approved Standard Contractual Clauses (SCCs) with service providers outside the EEA
  • Adequacy Decisions: We transfer data to countries with adequacy decisions from the European Commission
  • Payment Providers: Payment processors (PayPal, Stripe) are subject to their own data protection frameworks and contractual obligations

By using our services, you consent to the transfer of your data to these countries, subject to the safeguards described above.

10. Children's Privacy

Our services are not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at contact@dvsbil.no. If we become aware that we have collected personal information from a child under 16, we will take steps to delete such information promptly.

11. Data Protection Officer and Contact Information

If you have questions, concerns, or wish to exercise your data protection rights, please contact us:

DVSbil AS
Oslo, Norway

Email: contact@dvsbil.no

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational, legal, or regulatory reasons. We will notify you of any material changes by:

  • Posting the updated policy on our website with a new "Last updated" date
  • Sending email notifications to registered users for significant changes
  • Displaying a prominent notice on the platform

Your continued use of our services after changes become effective constitutes acceptance of the updated Privacy Policy. We encourage you to review this policy periodically.