Privacy Policy
Effective date 1st September 2026
Your privacy matters to us. VOKT exists because organisations should be able to use their own information without handing it to someone else, and we hold ourselves to the same standard with the information we collect about you.
A few principles guide how we do that:
We ask for the least information we need, and we tell you why we need it.
We keep information only for as long as there is a reason to keep it.
We keep it in the European Economic Area, and we tell you exactly where.
We name every company that handles it on our behalf.
We never sell it, and we never use it to train a model.
This policy explains all of that in full.
Sections
- Who We Are and What This Policy Covers
- Information We Collect
- How and Why We Use Information
- Sharing Information
- Where We Store Information
- Transferring Information
- How Long We Keep Information
- Security
- Your Choices
- Your Rights
- Information We Process for Our Customers
- Automated Decisions and Model Training
- Children
- Changes to This Policy
- How to Reach Us
- Change Log
Who We Are and What This Policy Covers
VOKT is a business operating system. It connects to the systems, databases and documents an organisation already uses, and lets that organisation search, understand and automate its own work.
VOKT is operated by Frostbyte Holding AS. We are established in Norway. Norway is a party to the Agreement on the European Economic Area, which is how the General Data Protection Regulation applies to us.
This policy applies to information we collect when you visit vokt.ai or ocr.vokt.ai, when you sign in to your VOKT account, when you ask us for a demonstration, and when you correspond with us.
It does not apply to the information inside a customer's VOKT environment. When an organisation connects its own systems to VOKT, that organisation decides what goes in and why. We handle it on their instructions. There is a section further down that explains this, and it matters if you are trying to work out who to contact about your own information.
Information We Collect
We collect information about you only where we have a reason to. It reaches us in three ways.
Information You Give Us
Contact details. When you request a demonstration or write to us, you give us your name, your business email address, and usually your company name and role. You may give us a telephone number.
Account details. If an account is created for you, we hold your name, your business email address, your sign in credentials, and the role you have been given in that account.
Correspondence. When you write to us, we keep a copy of what you sent and what we replied.
Information We Collect Automatically
Log information. Like every web server, ours records the technical details of each request: your IP address, browser type, operating system, the page that referred you, and the date and time. This happens whether or not you have an account.
Usage information. Within an account, we record what was done and when, so that the account holder has a reliable record and so that we can investigate problems and misuse.
Cookies and similar technologies. We store a small amount of information on your device and read it back. Our Cookie Policy explains what, why, and how to turn off everything that is not essential.
Information From Other Sources
We do not buy personal data, and we do not build profiles from outside sources. If you sign in using another service, we receive the information that service passes to us in order to authenticate you.
How and Why We Use Information
We use information about you for these purposes:
To reply to you when you ask us something or request a demonstration
To create, run and support accounts
To keep the service secure, and to detect and prevent misuse
To keep an accurate record of what happened in an account, which our customers rely on for their own audit and compliance obligations
To understand how the website is used, so we can improve it
To meet our legal, accounting and regulatory obligations
Our Legal Grounds
European data protection law requires us to have a lawful basis for each use. Ours are:
Performance of a contract. Creating and running an account, and providing the service to the organisation you belong to.
Legitimate interests. Replying to someone who has approached our business; keeping the service secure; maintaining an accurate activity record; and understanding and preventing problems. In each case we have considered whether our interest is outweighed by your rights, and we have concluded it is not. You can object to any of this, and we explain how below.
Consent. Anything that is not essential, including non essential cookies. You can withdraw consent at any time, and withdrawing it does not make what happened before unlawful.
Legal obligation. Retaining accounting records, and responding to lawful requests from a public authority.
Sharing Information
We do not sell personal data. We share it only in the situations below.
The companies that run our infrastructure. We name them, and they are all established in the European Economic Area:
Hetzner Online GmbH, a German company, which hosts our infrastructure in Helsinki, Finland
Nebius B.V., a Netherlands company, which performs model inference on endpoints in Finland and France
Professional advisers. Our lawyers, accountants and auditors, where they need it to advise us.
Legal and regulatory requirements. We may disclose information where we are required to by law, or in response to a valid order from a court or public authority. We disclose no more than we have to.
Business transfers. If our business is sold or merged, information about you would be among the assets transferred. This policy would continue to apply to it, and we would tell you.
With your permission. Anything else, only if you have asked us to.
Where We Store Information
In our standard configuration, everything stays in the European Economic Area. The application, the database, uploaded files and backups are held in Helsinki, Finland. Model inference runs on endpoints in Finland and France. Nothing leaves the European Economic Area.
Customers can also run VOKT on their own infrastructure, or in a fully isolated configuration with no connection to the internet at all. In those cases the information never reaches us.
A customer may choose to connect credentials for a model provider outside the European Economic Area. If they do, information from that environment goes to that provider on their instruction, and the residency described above no longer applies to that environment. We show a warning and require an explicit acknowledgement before that takes effect.
Transferring Information
In our standard configuration there is no transfer of personal data outside the European Economic Area, so no transfer safeguard is required. If that ever changes, we will rely on the Standard Contractual Clauses approved by the European Commission, or another safeguard permitted by Chapter V of the General Data Protection Regulation, and we will update this policy.
How Long We Keep Information
We discard information when there is no longer a reason to keep it and no law requires us to.
Enquiries and demonstration requests. We keep these while we are in contact with you and for a reasonable period afterwards, so that we can pick up a conversation where it left off. If you ask us to delete them, we will.
Account details. For as long as the account exists. When an account is closed, we delete the details, except where we need to retain something to meet a legal obligation or to resolve a dispute.
Correspondence. For as long as needed to handle the matter and to keep a record of what was agreed.
Server logs. For a short period, long enough to investigate a problem or a security incident, and no longer.
Activity records. These form part of the audit record our customers depend on, and are kept for the life of the account. Some entries cannot be individually removed without breaking the integrity of the record, and where that is the case we will tell you and explain what we can do instead.
Accounting records. For the period Norwegian accounting law requires.
Security
No service is perfectly secure, but we take this seriously and we can show our work.
Separation between customers. Each customer's data is walled off from every other customer's at the database level, enforced by the database itself rather than by application code. The application connects using a role that cannot bypass that separation.
An activity record that cannot be quietly altered. Every meaningful action is written to a log that cannot be edited or deleted once written. Each entry is cryptographically linked to the one before it, so any alteration, deletion or reordering of the record becomes detectable. We can verify the record and demonstrate that it is intact.
Access control. Access to personal data is limited to the people who need it to do their work, and everyone with access is under a duty of confidentiality.
Your Choices
Give us less. You do not have to give us anything. If you do not complete the demonstration form we cannot reply to you, and if you do not provide what an account requires we cannot create one. There is no other consequence.
Turn off non essential cookies. Use the cookie settings on the site. The site works either way.
Stop hearing from us. Every marketing message we send has an unsubscribe link, and you can also just tell us. We will still send messages about your account and any legal notices.
Close the account. You can ask for an account to be closed at any time.
Your Rights
If the General Data Protection Regulation applies to you, you have the following rights over the information we hold as controller.
Access. To be told whether we hold information about you, to receive a copy, and to be told how we use it.
Correction. To have anything inaccurate put right, and anything incomplete completed.
Erasure. To have information deleted where we no longer need it, where you withdraw consent and there is no other basis, or where we have handled it unlawfully.
Restriction. To have us pause our use of your information while a question about its accuracy or lawfulness is worked out.
Portability. To receive the information you gave us in a structured, commonly used, machine readable format, and to have us send it to another organisation where that is technically possible.
Objection. To object to any use we base on legitimate interests. If you object to direct marketing, we stop, with no balancing exercise.
Withdrawing consent. To withdraw consent at any time where consent is what we rely on.
Complaining. To complain to a supervisory authority. Ours is Datatilsynet in Norway. You can also complain to the authority where you live or work.
To use any of these, write to us using the details at the end of this policy. We will reply within one month. If your request is complicated we may take up to two months more, and if so we will tell you within the first month and explain why. There is no charge. We may ask you to confirm who you are first, so that we do not hand your information to somebody else.
If we refuse a request, we will tell you in writing and explain why, and you can complain to a supervisory authority or go to court.
Information We Process for Our Customers
This is the part people most often need, so we will be plain about it.
When an organisation uses VOKT, it connects its own systems, databases and documents. That organisation decides what goes in and what it is used for. In the language of the law, they are the controller and we are the processor. We act on their instructions, under a written agreement and a Data Processing Agreement that meets Article 28 of the General Data Protection Regulation.
So if your personal information sits inside some organisation's VOKT environment, and you want to see it, correct it, or have it deleted, that organisation is who to ask, not us. They control it. If you contact us instead, we will not act on the request ourselves, but we will pass it to them promptly, and we will help them answer it.
We encourage every customer to publish a privacy policy of their own that accurately describes what they do with the information they hold.
Automated Decisions and Model Training
Automated decisions. We do not make decisions about you that produce legal effects or similarly significant effects based solely on automated processing. The VOKT platform does process information automatically to produce answers and run tasks, but a customer decides how to use it and remains responsible for the decisions they take. Every answer is attributed to a source, and every action is recorded.
Model training. We do not use personal data to train, fine tune or otherwise improve any machine learning model, and we require the same of the companies that perform inference for us.
Children
VOKT is sold to organisations and is not directed at children. We do not knowingly collect information from a child. If you think a child has given us information, tell us and we will delete it.
Changes to This Policy
We may update this policy. When we do, we will revise the effective date at the top and record what changed in the change log below. If a change materially affects how we use your information, and we have a way of contacting you, we will.
How to Reach Us
Frostbyte Holding AS,
Årdalsvegen 35, 6884 Øvre Årdal, Norge
Org. nr. 934 881 982
Supervisory authority: Datatilsynet, Norway, www.datatilsynet.no
Change Log
First published 1st september 2026