MIMEA ← Back to website
Privacy

Privacy Policy

Last updated: 18 August 2025

This Privacy Policy describes how MIMEA AS ("we", "us", "our") processes personal data when you visit our websites or contact us. We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Norwegian Personal Data Act (personopplysningsloven). Rules on cookies follow from the Norwegian Electronic Communications Act (ekomloven) § 2-7 b.

1) Controller and contact

MIMEA AS
Gjellebekkstubben 7, 3420 Lierskogen, Norway
Email: post@mimea.no
Contact form: https://www.mimea.no/

The controller is the entity that determines the purpose of the processing of personal data and the means to be used.

2) Data collection when visiting the website (server logs)

For purely informational visits, we only collect data that your browser automatically transmits to our server (so-called "server logs"):

  • which page/URL you visit,
  • date and time of access,
  • amount of data transferred,
  • referring page (referrer URL),
  • browser used and version,
  • operating system,
  • IP address (where applicable in abbreviated/anonymised form).

Purpose and legal basis: The processing is based on our legitimate interest (GDPR Art. 6(1)(f)) in ensuring technical delivery, stability, security and error correction.
Storage period: Log data is deleted when no longer necessary for the purpose, 30 days as a rule, or kept longer if necessary to detect or investigate security incidents.

3) Hosting and Content Delivery Network (CDN)

3.1 Wix

We use Wix for hosting and publishing the website:
Wix HQ, Nemal Tel Aviv St 40, Tel Aviv-Yafo, Israel
Additional entity: Wix Inc., 500 Terry A. Francois Blvd, San Francisco, CA 94158, USA

All data collected via the website may be processed on Wix' servers. We have entered into a data processing agreement (GDPR Art. 28) with Wix.

Third-country transfers: For transfers to Israel, the EU Commission's adequacy decision applies (GDPR Art. 45). Wix.com Ltd. and the relevant Wix entities are certified under the EU-US Data Privacy Framework (DPF), including the UK Extension to the EU-US DPF and the Swiss-US DPF. Transfers to the USA are therefore covered by the DPF, with the EU Standard Contractual Clauses (SCC) applied as an additional safeguard (GDPR Art. 46).

3.2 Cloudflare (CDN and security)

We use Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA, for fast content delivery and protection against attacks (e.g. DDoS). This involves processing usage data (e.g. IP address, requests) in log files.

Purpose and legal basis: performance and security (GDPR Art. 6(1)(f)). A data processing agreement (Art. 28) has been entered into.
Transfers: Cloudflare, Inc. is certified under the EU-US Data Privacy Framework (DPF), including the UK Extension to the EU-US DPF and the Swiss-US DPF. Transfers to the USA are covered by the DPF, with the EU Standard Contractual Clauses (SCC) as a fallback safeguard.

4) Contacting us

When you contact us (e.g. via the contact form or email), we process the information you provide (name, email, message) to respond to your enquiry and administer it technically.

Legal basis: our legitimate interest in responding to enquiries (GDPR Art. 6(1)(f)). If the enquiry concerns the conclusion or performance of a contract, the basis is Art. 6(1)(b).
Storage period: the information is deleted when the matter is concluded, unless statutory retention obligations require otherwise.

5) Cookies and consent management

We use a consent tool ("cookie banner") to obtain valid consent for cookies and similar technologies.

  • Necessary cookies are used to deliver the service you have requested.
  • Analytics/marketing and other non-necessary cookies are only set after your consent.

Legal basis:

  • for storing or accessing information on devices: the Norwegian Electronic Communications Act (ekomloven) § 2-7 b (consent, with an exception for what is strictly necessary to deliver an explicitly requested service),
  • for further processing of personal data: GDPR Art. 6(1)(a) (consent) or (f) (legitimate interest) for necessary technical cookies, and Art. 6(1)(c) for the obligation to document consents (GDPR Art. 7(1)).

Consent management: You can change or withdraw your consent at any time via the "Cookie settings" link on the website. The consent tool may store the time, choices, a pseudonymous identifier and IP address to document consent.

Provider: CookieYes (consent banner). Where data is transferred outside the EEA, this is covered by an adequacy decision and/or the EU Standard Contractual Clauses (SCC).

6) Accounting / tools

We use a cloud-based accounting system to process incoming and outgoing invoices and bookkeeping (partly automated). This may involve processing personal data (e.g. contact details of suppliers/customers).

Legal basis: compliance with legal obligations (bookkeeping and tax rules) under GDPR Art. 6(1)(c), and our legitimate interest in efficient administration (Art. 6(1)(f)).
A data processing agreement (Art. 28) is in place with our accounting provider.

7) Recipients of personal data

Access to information is granted only to employees who need it to perform their tasks. External recipients may be:

  • data processors (hosting, CDN, IT operations, accounting, etc.),
  • public authorities where required by law.

8) Third-country transfers

If personal data is transferred to countries outside the EEA, this takes place on the basis of:

  • an adequacy decision (GDPR Art. 45),
  • appropriate safeguards such as the EU Standard Contractual Clauses (SCC) (Art. 46), and/or
  • your explicit consent (Art. 49(1)(a)).

9) Storage period

We store personal data for as long as necessary for the purposes described here or to fulfil legal obligations (e.g. bookkeeping rules).

  • For processing based on consent, the information is stored until consent is withdrawn.
  • For processing based on legitimate interest, the information is stored until you object, unless we can demonstrate compelling legitimate grounds that override your interests.

10) Obligation to provide data

There is in principle no statutory or contractual obligation to provide personal data. Some services (e.g. the contact form) nevertheless require minimum information; without it, the service cannot be provided.

11) Automated decisions / profiling

We do not carry out automated individual decisions, including profiling, within the meaning of GDPR Art. 22.

12) Your rights

You have the following rights under the GDPR:

  • access (Art. 15),
  • rectification (Art. 16),
  • erasure (Art. 17),
  • restriction of processing (Art. 18),
  • data portability (Art. 20),
  • object to processing based on legitimate interest (Art. 21),
  • withdraw consent (Art. 7(3)).

You may also lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) if you consider that our processing infringes the rules. Contact information is available on Datatilsynet's website.

Right to object (Art. 21 GDPR)
IF WE PROCESS DATA BASED ON OUR LEGITIMATE INTEREST, YOU MAY, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, OBJECT TO THE PROCESSING AT ANY TIME.
IF WE PROCESS DATA FOR DIRECT MARKETING, YOU MAY OBJECT TO SUCH PROCESSING AT ANY TIME; THIS ALSO APPLIES TO PROFILING TO THE EXTENT IT IS RELATED TO SUCH MARKETING.

13) Information security

We implement appropriate technical and organisational security measures (encryption, access control, backups, etc.) to protect personal data, and review these measures regularly.

14) Changes to this policy

We may update this Privacy Policy when laws, services or technologies change. The version in force at any time is available on our website.

© 2026 MIMEA AS  •  Legal Notice  •  Website