Data controller
Black Table AS (company reg. no. 937 910 967) is the data controller for personal data processed via blacktable.no. We're based in Færder, Vestfold, Norway. Contact: post@blacktable.no.
Privacy
How we collect, use and protect your personal data. Last updated: June 2026
Black Table AS (company reg. no. 937 910 967) is the data controller for personal data processed via blacktable.no. We're based in Færder, Vestfold, Norway. Contact: post@blacktable.no.
We only collect data you give us yourself, plus what's necessary to run the service safely.
We process personal data to respond to inquiries, run the booking flow, and protect the service from abuse. Inquiries are stored and followed up in our internal customer and lead system. The legal basis is contract performance and legitimate interest (GDPR art. 6(1)(b) and (f)).
Form submissions (booking, contact, get started) are kept while the project relationship is active, then deleted on request or when accounting obligations expire (5 years after the last transaction). If a submission doesn't result in an engagement, it is deleted no later than 12 months after receipt. Rate-limit data is deleted automatically within 1–24 hours. Aggregated usage statistics from Vercel Analytics contain no personal data and follow Vercel's standard retention policy. Our hosting provider retains request logs per their standard policy (about 30 days).
We use the following services to run blacktable.no. Each processes data on our behalf under a data-processing agreement or standard EU contractual clauses.
Some of the third-party services we use (Google Workspace, Cloudflare, Upstash, Vercel, Resend, Anthropic and ScreenshotOne) may transfer data to the United States. These providers comply with the EU Commission's Standard Contractual Clauses (SCC) and/or the EU-US Data Privacy Framework. You have the right to receive information about the safeguards used. Contact us at post@blacktable.no for details.
We may contact businesses we believe could benefit from our services. For this we process information from public sources: the Norwegian Business Register (company information), the business's own website (contact email and phone published there), and Google (maps and ratings). We also run an automated performance check of the website and an AI-based quality score to prioritise who we reach out to. The legal basis is legitimate interest (GDPR art. 6(1)(f)): reaching relevant potential clients. The data is stored in our internal customer system and automatically deleted no later than 12 months after it was added, unless we have made contact and taken the conversation further (in which case the client retention period applies). You can object to this processing at any time and request access, rectification or erasure — email post@blacktable.no and we will remove you. You can also lodge a complaint with the Norwegian Data Protection Authority.
We use no tracking cookies and no third-party analytics. Browser storage is limited to:
You have the right to:
To exercise these rights, email post@blacktable.no. We will respond within 30 days. You can also lodge a complaint with the Norwegian Data Protection Authority (datatilsynet.no).
We update this policy as needed. The date at the top shows when it was last changed.
Questions about privacy or processing of your data: post@blacktable.no. Complaints about our processing can be lodged with the Norwegian Data Protection Authority (Datatilsynet).