top of page

Privacy Notice for RITEK AS

Last updated: 21 September 2026

Language versions
The Norwegian and English texts are intended to have the same meaning. In the event of conflict, ambiguity or any difference in interpretation between the language versions, the Norwegian version shall prevail.

1. Introduction

RITEK AS respects your privacy and processes personal data in a secure, lawful and transparent manner. This privacy notice describes which personal data we process, why we process it, how it is used, with whom it may be shared, how long it is retained, and which rights you have under the General Data Protection Regulation (GDPR) and Norwegian data protection legislation. The notice also applies to the processing of contact details in connection with agreements, deliveries, customer and supplier relationships, cooperation partners and project execution where RITEK AS is the data controller.

2. Data controller

RITEK AS is the data controller for personal data processed in connection with the company’s activities.

Contact information
RITEK AS
Rinnvegen 46
7609 Levanger
Email: post@ritek.no
Phone: +47 74 02 86 00

Privacy enquiries may be sent to post@ritek.no.

3. Personal data we process

We may process information about customer and supplier contacts, visitors, job applicants, website users, employees, consultants and temporary personnel. This may include:

  • name, position, workplace, telephone number and email address

  • correspondence, contract and agreement references and visitor information

  • CVs, applications, diplomas, certificates, competence and experience information

  • IP address, cookies, browser and device information

  • information necessary for employment, access control, HSE, training, security follow-up and compliance with legal requirements

4. Purposes of processing

Personal data is processed to:

  • deliver goods and services and respond to enquiries

  • manage customer and supplier relationships and perform contracts

  • comply with legal obligations

  • administer access and visits and safeguard personnel security

  • protect the company’s assets and information

  • recruit employees, manage HSE and quality systems and improve our services and websites

5. Contact details under agreements and legal basis

When RITEK AS enters into, administers or follows up agreements with customers, suppliers, cooperation partners or other third parties, we may process contact details of employees and representatives of the contracting parties. The purpose is to perform and document the contractual relationship, including:

  • administrative follow-up of the agreement and exchange of information

  • delivery of goods and services, invoicing and document management

  • security follow-up and other necessary tasks related to the contractual relationship

 

Such information may include name, position, employer, professional identifier, email address, telephone number, postal address, agreement references and relevant correspondence. Where required by the agreement, the customer, the project or applicable regulations, we may also process supplementary information such as nationality, date of birth, residential address, education, qualifications, certifications, authorisations and project roles. The processing is based on GDPR Article 6(1)(b), (c), (f), and, where consent is required, Article 6(1)(a).

6. Visitor registration, access control and CCTV

To safeguard security at our locations, RITEK AS uses access and visitor control. During visits, we may register name, company, contact person, arrival and departure time, visit area and any visitor cards or access rights. The purpose is to protect employees and visitors, prevent unauthorised access, comply with customer and authority requirements and ensure traceability in the event of security incidents. RITEK AS may also use CCTV where necessary to prevent crime, protect assets, protect employees and visitors, and document security incidents. Areas under CCTV surveillance will be clearly marked.

7. Personnel security, security clearance and RFV

RITEK AS operates in sectors that may be subject to specific security requirements. In connection with security clearance, authorisation, customer requirements and projects subject to the Norwegian Security Act, we may process necessary personal data to verify identity, document qualifications, comply with authority requirements and meet contractual requirements from customers. When processing visit requests and Request for Visit (RFV), RITEK AS may register name, date of birth, citizenship, employer, position, security clearance level, authorisation information and purpose of the visit. The information is used only to administer the visit and comply with requirements set by customers, cooperation partners or authorities.

8. Supplier and customer due diligence

To meet contractual, regulatory and security requirements, RITEK AS may carry out necessary checks of customers, suppliers and cooperation partners. This may include contact details, company information, roles and responsibilities, signing authority, qualifications and certifications, as well as information necessary for export control or security assessments.

9. Cookies

The website uses cookies to ensure necessary functionality, analyse traffic and improve the user experience. Visitors may manage cookies through their browser settings.

10. Sharing of personal data

Personal data is shared only where necessary for a legitimate purpose, to fulfil agreements, comply with legal requirements, meet security requirements or address other documented needs. Recipients may include:

  • IT providers and operational service providers

  • accounting and audit firms

  • public authorities

  • customers, cooperation partners, contracting parties and end customers where necessary

  • subcontractors and service providers involved in the performance, security follow-up or administration of an agreement

 

External providers processing personal data on our behalf are subject to data processing agreements.

11. Retention and deletion

Personal data is retained only for as long as necessary for the purpose, as long as required by law, or as long as necessary to document and follow up a contractual relationship. Contact details processed in connection with contracts and agreements are normally retained for as long as the contractual relationship continues and thereafter for the period necessary for documentation, follow-up, claims handling, accounting, legal requirements, security requirements or other legitimate purposes. Where relevant, this may involve retention for up to five years after termination of the agreement, unless a longer or shorter retention period follows from law, agreement or a specific need. When the information is no longer necessary, it is deleted, anonymised or archived in accordance with applicable regulations.

12. Information security

RITEK AS works systematically to protect personal data through organisational, technical and physical security measures. These measures may include access control, logging, encryption, secure storage, employee training and regular risk assessments. Only authorised personnel are granted access to personal data where this is necessary to perform their work.

13. Your rights

You have the right to:

  • request access to your personal data

  • request rectification of inaccurate information

  • request deletion where permitted by law

  • restrict processing

  • receive personal data in a structured format

  • object to processing based on legitimate interests

  • withdraw any consent you may have given

  • ​

Requests may be sent to post@ritek.no. Where processing is based on legitimate interests, RITEK AS will assess whether there are compelling legitimate grounds for continued processing.

14. Transfers outside the EU/EEA

If personal data is transferred to countries outside the EU/EEA, this will only take place where a lawful transfer basis exists and necessary safeguards have been established, such as the European Commission’s Standard Contractual Clauses, an adequacy decision or other appropriate safeguards under the GDPR. When using international suppliers, technology services or cooperation partners, RITEK AS assesses the need for additional measures to ensure that personal data receives a level of protection consistent with European and Norwegian data protection requirements.

15. Complaint to the Norwegian Data Protection Authority

If you believe that our processing of personal data is not in accordance with applicable regulations, you may contact the Norwegian Data Protection Authority at www.datatilsynet.no. We encourage you to contact RITEK AS first so that we can try to resolve the matter.

16. Changes to this notice

RITEK AS may update this privacy notice when necessary. The current version will be available at www.ritek.no at all times.

bottom of page