Ir al contenido principal
Volver

Política de Privacidad

Last updated: September 9, 2026

1. Data Controller

Sertio AS (org. no. 937 286 643, Ulvenveien 123D, 0665 Oslo, Norway), operating the Sertio platform (sertio.no), is the data controller for personal data collected through this service.

Contact: martin@sertio.no

2. Personal Data We Collect

3. Purpose of Processing

4. Legal Basis

5. Sharing of Personal Data

We share personal data with:

We never sell personal data to third parties.

When your employer has enrolled you

Your employer sees your name, email, how far you have come, whether you have passed, the course certificate number, when the course certificate expires, and the status of the extinguishing exercise. They do not see your answers, your date of birth or your address.

Your employer sees nothing until you have confirmed yourself that you belong to the company. If you are added to a list without confirming, the row stays empty for the employer.

For as long as you are linked to the company, your employer also sees course certificates you earned before being enrolled. The reason is that the employer must be able to document that you have the training, regardless of who paid for it.

If your employer removes you from the list, the link ends. The employer then sees no further progress. What remains is a frozen snapshot of your status on the day you were removed.

Sertio and your employer are two independent controllers. We decide how we deliver the course and issue the course certificate; your employer decides how the information is used in its own internal control.

6. Analytics and Insights

We use PostHog (EU-based, Frankfurt) for product analytics. PostHog collects:

PostHog data is stored in the EU (Frankfurt) with a DPA (Data Processing Agreement) in place. You can withdraw consent at any time via the cookie settings.

We also use Google Analytics 4 for traffic and usage analytics. Analytics cookies are only set if you consent to statistics in the cookie banner; without consent, only anonymous, cookieless signals are sent (Google Consent Mode). Google Analytics does not store IP addresses. Data may be transferred to Google in the US under the EU-US Data Privacy Framework. Retention at Google: 14 months.

To measure the effect of our ads we use the Meta Pixel. The pixel does not load until you consent to marketing in the cookie banner. Once consent is given, it reports that you visited the page and, on a completed purchase, the amount and currency. We never send names, email addresses, phone numbers or other identifiers to Meta, and we do not use Meta's automatic advanced matching. Data may be transferred to Meta in the US under the EU-US Data Privacy Framework. You can withdraw your consent at any time via the cookie settings.

Our ads also appear in ChatGPT. To measure whether they lead to sales we use OpenAI's measurement pixel. The pixel does not load until you consent to marketing in the cookie banner. Once consent is given, it reports that you visited the page and, on a completed purchase, the amount and currency. We never send names, email addresses, phone numbers or other identifiers to OpenAI, and we do not use OpenAI's automatic advanced matching. Sertio and OpenAI act as independent controllers for this data. Data may be transferred to OpenAI in the US under the EU Standard Contractual Clauses. You can withdraw your consent at any time via the cookie settings.

7. Customer Chat and Messaging Channels

WhatsApp: You can voluntarily contact us via WhatsApp. Meta (WhatsApp) then processes message data according to its own terms and privacy policies. We see your phone number and the messages you send us.

Do not share sensitive personal data (e.g. national identity numbers or health information) in chat or WhatsApp — use email if needed.

8. Retention and Deletion

9. Your Rights

You have the right to:

10. Cookies

We use necessary cookies for authentication (Supabase Auth). Analytics cookies (Google Analytics, PostHog) and marketing cookies (Google Ads, Meta) require your consent and can be declined or withdrawn via the cookie banner.

If you arrive through the link or QR code of one of our partners, we set the sertio_partner_ref cookie, but only if you have consented to marketing cookies. It remembers which partner you came from for 30 days, so the partner is credited if you buy the course. It holds the partner code and a timestamp, nothing else. It is signed, cannot be read by the browser, and is not used for marketing or profiling. If you do not consent, it is not set.

11. Security

We use industry-standard security measures: encrypted data transfer (TLS), encrypted passwords, Row Level Security in the database, and regular security reviews.

12. Changes

We may update this privacy policy. Significant changes will be notified via email and/or in the service. Continued use after notification constitutes acceptance of the changes.