Skip to content

Privacy

Privacy Policy.

How we collect, use and protect your personal data. Last updated: June 2026

Data controller

Black Table AS (company reg. no. 937 910 967) is the data controller for personal data processed via blacktable.no. We're based in Færder, Vestfold, Norway. Contact: post@blacktable.no.

What we collect

We only collect data you give us yourself, plus what's necessary to run the service safely.

  • Booking flow (/book). Your name, email address, chosen time slot and an optional short project note.
  • Contact form (/contact). Your name, email address, optional company, optional project type, and message.
  • Get started form (/kom-i-gang). Project details: desired project type, budget range, existing website/domain/hosting, content status, desired structure, references, and contact information (name, email, optional phone). If we take the request further, the content may be processed by an AI tool to create an internal design brief, and we may capture screenshots of the reference sites you provide (see third-party services below).
  • Technical data. IP address and user-agent, used briefly for rate-limiting and standard request logging at our hosting provider.
  • Bot check. Cloudflare Turnstile processes browser signals to distinguish humans from bots on the booking and contact forms.
  • Usage statistics. Vercel Analytics collects aggregated page views and performance data (Web Vitals) to understand which pages are used and how fast the site loads. Cookie-free, no cross-site tracking, and no identifying information about visitors.

Purpose and legal basis

We process personal data to respond to inquiries, run the booking flow, and protect the service from abuse. Inquiries are stored and followed up in our internal customer and lead system. The legal basis is contract performance and legitimate interest (GDPR art. 6(1)(b) and (f)).

Retention

Form submissions (booking, contact, get started) are kept while the project relationship is active, then deleted on request or when accounting obligations expire (5 years after the last transaction). If a submission doesn't result in an engagement, it is deleted no later than 12 months after receipt. Rate-limit data is deleted automatically within 1–24 hours. Aggregated usage statistics from Vercel Analytics contain no personal data and follow Vercel's standard retention policy. Our hosting provider retains request logs per their standard policy (about 30 days).

Third-party services (sub-processors)

We use the following services to run blacktable.no. Each processes data on our behalf under a data-processing agreement or standard EU contractual clauses.

  • Supabase. Database for booking data and project records. EU region.
  • Vercel. Hosting, request logs, and cookieless usage analytics (Vercel Analytics).
  • Google Workspace. Calendar integration for booking; sends the customer the invitation email with the Meet link.
  • Cloudflare. Turnstile bot check on forms.
  • Upstash. Short-lived cache for rate-limiting (EU region).
  • Resend. Email delivery (notification to us, confirmation to you) from the contact and get started forms. USA.
  • Anthropic (Claude). AI assistance that processes the get started form (project details and screenshots of reference sites you provide) to create an internal design brief. We do not send your name or email address here. Run manually by us. USA.
  • ScreenshotOne. Captures screenshots of the reference sites you provide in the get started form, as input for the design assessment. Traffic may be routed via servers in the USA.

Transfers outside the EEA

Some of the third-party services we use (Google Workspace, Cloudflare, Upstash, Vercel, Resend, Anthropic and ScreenshotOne) may transfer data to the United States. These providers comply with the EU Commission's Standard Contractual Clauses (SCC) and/or the EU-US Data Privacy Framework. You have the right to receive information about the safeguards used. Contact us at post@blacktable.no for details.

Prospecting and B2B marketing

We may contact businesses we believe could benefit from our services. For this we process information from public sources: the Norwegian Business Register (company information), the business's own website (contact email and phone published there), and Google (maps and ratings). We also run an automated performance check of the website and an AI-based quality score to prioritise who we reach out to. The legal basis is legitimate interest (GDPR art. 6(1)(f)): reaching relevant potential clients. The data is stored in our internal customer system and automatically deleted no later than 12 months after it was added, unless we have made contact and taken the conversation further (in which case the client retention period applies). You can object to this processing at any time and request access, rectification or erasure — email post@blacktable.no and we will remove you. You can also lodge a complaint with the Norwegian Data Protection Authority.

Cookies and browser storage

We use no tracking cookies and no third-party analytics. Browser storage is limited to:

  • bt-cookie-consent. A flag in localStorage that remembers you've read this banner. Contains no personal data.
  • cf_chl_*. Strictly necessary cookies set by Cloudflare Turnstile during the bot check on the booking form.

Your rights

You have the right to:

  • Access the personal data we hold about you
  • Correction of inaccurate data
  • Deletion of your data
  • Restriction of processing
  • Data portability: delivery in a common format
  • Object to processing
  • Lodge a complaint with the Norwegian Data Protection Authority (datatilsynet.no)

To exercise these rights, email post@blacktable.no. We will respond within 30 days. You can also lodge a complaint with the Norwegian Data Protection Authority (datatilsynet.no).

Changes to this policy

We update this policy as needed. The date at the top shows when it was last changed.

Contact

Questions about privacy or processing of your data: post@blacktable.no. Complaints about our processing can be lodged with the Norwegian Data Protection Authority (Datatilsynet).