Privacy Policy for Nordlys Fotostudio
Effective date: 20 May 2026
1. Introduction and company information
This privacy policy explains how Nordlys Fotostudio collects, uses, stores, shares, and protects personal data in connection with its photo-studio services, including portrait sessions, event photography, image editing, booking administration, customer communication, and related services.
Nordlys Fotostudio is the data controller for the processing of personal data described in this policy.
- Company name: Nordlys Fotostudio
- Address: Torggata 12, 0181 Oslo, Norway
- Email: [email protected]
- Phone: +47 22 38 74 61
2. Data collection and processing
Nordlys Fotostudio may collect and process the following categories of personal data:
- Identification and contact information: name, address, email address, telephone number, and similar contact details.
- Booking and service information: appointment details, service preferences, communication history, invoices, payment status, and customer notes.
- Image and media data: photographs, video recordings, edited files, previews, and related metadata created during photo sessions.
- Technical data: IP address, device information, browser type, log data, and website usage information, where applicable.
- Communication data: messages sent by email, contact forms, telephone, or social media channels.
- Consent-based materials: testimonials, marketing permissions, and model release information where provided.
Personal data is generally collected directly from the individual concerned, through bookings, inquiries, contracts, studio visits, correspondence, and use of the website or other digital services. In some cases, data may also be received from third parties, such as payment providers, booking platforms, or business partners acting on behalf of the customer.
3. Purpose of data processing
Nordlys Fotostudio processes personal data for the following purposes:
- to manage inquiries and communicate with customers and potential customers;
- to schedule, confirm, and administer photo sessions and related services;
- to perform contracts and deliver requested photography services;
- to edit, store, and deliver photographs and other media files;
- to issue invoices, process payments, and maintain accounting records;
- to comply with legal obligations, including bookkeeping and tax requirements;
- to improve services, customer experience, and internal operations;
- to send marketing communications where permitted and consented to;
- to protect the studio, customers, staff, and property, including through security measures;
- to establish, exercise, or defend legal claims.
4. Legal basis for processing
Nordlys Fotostudio processes personal data only where a valid legal basis exists under applicable Norwegian privacy law. Depending on the context, the legal basis may include:
- Performance of a contract: when processing is necessary to provide photography services, manage bookings, deliver images, or handle customer requests related to a contract.
- Consent: when the individual has given clear consent, for example for marketing communications, publication of images, or use of optional customer testimonials.
- Legal obligation: when processing is required to comply with accounting, tax, or other statutory obligations.
- Legitimate interests: when processing is necessary for the legitimate interests of Nordlys Fotostudio or a third party, provided that such interests are not overridden by the individual’s privacy rights and freedoms. This may include customer service, business administration, fraud prevention, and security.
Where special categories of personal data or sensitive image content are involved, Nordlys Fotostudio will apply additional safeguards and rely on an appropriate legal basis where required.
5. Data sharing and third parties
Nordlys Fotostudio may share personal data with third parties only when necessary and appropriate for the purposes described in this policy. Such third parties may include:
- payment service providers and banks;
- accounting, auditing, and bookkeeping service providers;
- IT, cloud storage, website hosting, backup, and maintenance providers;
- booking and customer management platforms;
- email and communication service providers;
- professional advisers, such as lawyers or insurers;
- public authorities where required by law;
- subcontractors involved in editing, printing, delivery, or related services.
Third parties are permitted to process personal data only to the extent necessary to perform services for Nordlys Fotostudio or to comply with legal requirements. Where required, data processing agreements and appropriate confidentiality obligations are used.
6. Data transfer to third countries
Nordlys Fotostudio primarily aims to store and process personal data within Norway or the European Economic Area (EEA). However, some service providers may process data outside the EEA, including in third countries.
Where such transfers occur, Nordlys Fotostudio will ensure that appropriate safeguards are in place, such as:
- an adequacy decision by the relevant authorities;
- standard contractual clauses or equivalent transfer mechanisms;
- additional technical and organizational measures where appropriate.
If you would like more information about international data transfers, you may contact Nordlys Fotostudio using the contact details below.
7. Storage duration
Nordlys Fotostudio retains personal data only for as long as necessary for the purposes for which it was collected, or as long as required by law.
- Customer and booking data: retained for the duration of the customer relationship and for a reasonable period thereafter for administration, follow-up, and legal protection.
- Accounting and tax records: retained for the period required by applicable law.
- Photographs and media files: retained according to the agreed service terms, customer instructions, studio workflow, and any applicable legal or contractual retention requirements.
- Marketing data: retained until consent is withdrawn or the individual objects, unless further retention is permitted by law.
- Security and log data: retained for a limited period necessary for security, troubleshooting, and abuse prevention.
When personal data is no longer needed, it will be deleted, anonymized, or securely archived in accordance with internal procedures and legal requirements.
8. User rights
Subject to applicable law, individuals have the following rights regarding their personal data processed by Nordlys Fotostudio:
- Access: the right to request confirmation of whether personal data is being processed and to receive a copy of that data.
- Rectification: the right to request correction of inaccurate or incomplete personal data.
- Erasure: the right to request deletion of personal data in certain circumstances.
- Restriction: the right to request that processing be limited in certain situations.
- Data portability: the right to receive certain personal data in a structured, commonly used, machine-readable format and, where technically feasible, to have it transmitted to another controller.
- Objection: the right to object to processing based on legitimate interests and, in some cases, to direct marketing.
Requests may be subject to legal exceptions and limitations, including where retention is required by law or where processing is necessary to establish, exercise, or defend legal claims.
9. Withdrawal of consent
Where processing is based on consent, that consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
If consent is withdrawn, Nordlys Fotostudio will stop the relevant processing unless another lawful basis applies. This may affect the ability to provide certain optional services, such as marketing communications or publication of images that were previously approved by consent.
10. Right to complain
If you believe that Nordlys Fotostudio has processed your personal data in a way that does not comply with applicable privacy law, you have the right to lodge a complaint with the relevant supervisory authority in Norway.
You may also contact Nordlys Fotostudio directly so that any concerns can be reviewed and addressed promptly.
11. Data security
Nordlys Fotostudio implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration, disclosure, or destruction. These measures may include:
- access controls and role-based permissions;
- password protection and secure authentication;
- encrypted storage or secure transfer where appropriate;
- regular backups and recovery procedures;
- staff confidentiality obligations and internal training;
- physical security measures for studio premises and equipment;
- review of third-party providers and data processing arrangements.
No method of transmission or storage is completely secure, but Nordlys Fotostudio takes reasonable steps to protect personal data in line with the nature of the data and the risks involved.
12. Contact information
For questions about this privacy policy, your personal data, or the exercise of your rights, please contact:
- Nordlys Fotostudio
- Address: Torggata 12, 0181 Oslo, Norway
- Email: [email protected]
- Phone: +47 22 38 74 61
13. Changes to privacy policy
Nordlys Fotostudio may update this privacy policy from time to time to reflect changes in legal requirements, business practices, services, or technology. The latest version will be made available through the appropriate communication channels.
Where changes are material, Nordlys Fotostudio may provide additional notice as appropriate. We encourage individuals to review this privacy policy periodically to stay informed about how personal data is processed.