Legal · Privacy

Privacy Policy

Last updated 22 July 2026

This Privacy Policy sets out the personal data Brigg processes, the purposes for which we process it, and the rights you have over it. It is intended to be readable as well as legally accurate.

1.Data controller

Nora Software AS (Norwegian company registration number 931 407 449) is the data controller for the personal data processed in connection with the Brigg service. We process your data in accordance with Norwegian data protection law and Regulation (EU) 2016/679 ("GDPR").

If you have any questions about privacy or about this Policy, please contact us at personvern@brigg.no.

Where parts of the Service are delivered by sub-processors, their terms govern the underlying processing they perform on our behalf.

2.What we process, and why

We process personal data in order to provide the Brigg service and perform our agreement with you. The categories of data we process in each context are set out below.

When you and others use the Service

Your use. When you use Brigg, we process:

  • Identification data (name and email address)
  • Voice audio, where you use microphone-enabled features
  • Meeting notes, which may contain personal data
  • Publicly available information from LinkedIn and Google search results (for example, employment information)
  • Usage data from the website (see below)
  • If you connect your Google or Microsoft account, we process Google or Microsoft user data (see below)
  • Where you have enabled speaker identification, Brigg may capture transient screenshots to determine who is speaking. Screenshots are processed in memory and are never stored by us; they are processed via cloud-hosted language models located in the EU.

If you use voice transcription, we may:

  • Temporarily record your voice and share it with a sub-processor to convert it to text. The recording is deleted as soon as practicable, and in any event within 24 hours.
  • Apply machine learning to utterances and meeting notes in order to summarize them and surface relevant information, suggestions and prompts.

Your content and AI outputs. Meeting notes, transcripts, AI-generated summaries and similar content belong to you. We process this content solely to deliver the Service to you. We do not use your content or AI outputs to train our models or for any purpose other than delivering the Service.

Legal basis: performance of the contract with you, or steps taken at your request, pursuant to GDPR Article 6(1)(b). You may delete your account, and all data we hold about you, from your account settings.

In order to provide the Service's core functionality, the data described above must be stored. Such storage is in the mutual interest of all users and represents a legitimate interest. The processing has only a minimal impact on your privacy because the data is overwhelmingly business-related and of low personal sensitivity. Our legitimate interest therefore prevails over your privacy interests for this use.

Google and Microsoft user data

Brigg ensures that information we receive from Google or Microsoft APIs is processed in accordance with their respective rules. We comply with Google's API Services User Data Policy, including the Limited Use requirements, and with Microsoft's API Terms of Use. Notwithstanding any other provision of this Policy, Brigg's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

If you authorize Brigg to access your Google or Microsoft account, we process:

  • Profile information, including email address and name
  • Events from your Google or Microsoft calendar
  • Contacts from your Google or Microsoft account

Limited Use of Google user data. Brigg complies in full with Google's Limited Use requirements for data obtained from Google Workspace APIs. Specifically:

  • We use Google user data only to provide or improve user-facing features in the Brigg user interface — for example, meeting preparation, calendar display and contact lookups. We do not use Google user data for any other purpose.
  • We do not transfer Google user data to third parties, except (a) where necessary to provide or improve user-facing features in Brigg and with your consent, (b) for security purposes (for example, to investigate abuse), (c) to comply with applicable law, or (d) as part of a merger, acquisition, or sale of assets where the recipient is bound by these same requirements.
  • We do not allow humans to read Google user data, except (a) where you have provided your affirmative consent to view specific messages, files or other data, (b) where strictly necessary for security purposes (for example, to investigate abuse), (c) where necessary to comply with applicable law, or (d) in aggregated and anonymized form for internal operations.
  • We do not, and will not, use or transfer Google user data for the purposes of serving ads, including retargeting, personalized or interest-based advertising. We do not sell Google user data to third parties, including advertising platforms, data brokers or any information resellers.
  • We do not use Google user data to develop, improve, train or fine-tune any generalized or foundational AI or machine learning model, and we do not permit any AI provider that processes Google user data on our behalf to do so. AI-driven features in Brigg are delivered by third-party AI model providers acting as sub-processors; they process Google user data solely to perform the requested feature in the moment, under contractual terms that prohibit using it to train or improve their models, and they do not retain it for that purpose.

We do not share Google or Microsoft user data with third parties other than for the purposes of data storage.

All user data is stored in encrypted form and is transmitted only over encrypted connections.

Legal basis: performance of the contract with you, or steps taken at your request, pursuant to GDPR Article 6(1)(b).

Our copy of your Google or Microsoft account information (name, email and profile picture) will be deleted if you delete your account. You may also revoke Brigg's access to your Google account at any time at myaccount.google.com/permissions.

When you visit our website

When you visit brigg.no, we collect the following from your device:

  • IP address
  • Date and time of the visit
  • Name and URL of the file requested
  • Browser type and version
  • Other information transmitted by your browser (such as operating system, the name of your service provider, and approximate geographic origin)
  • Form data (where you submit a form)

We process this data solely to ensure the website functions correctly, for sales and marketing, and to assess the security and stability of the system as well as for analytics and administration. This processing applies only to website-visit data and never to Google or Microsoft user data.

This data is deleted after 30 days.

Legal basis: performance of the contract with you, or steps taken at your request, pursuant to GDPR Article 6(1)(b). For marketing, sales and analytics purposes, the legal basis is Brigg's legitimate interests pursuant to GDPR Article 6(1)(f).

When you contact us by email

If you contact us by email, we process:

  • Your name
  • Your email address
  • Any other personal data you choose to share with us

This processing is necessary to perform the contract with you or to take steps at your request pursuant to GDPR Article 6(1)(b).

Email marketing

We send newsletters by email so that you can receive information and offers. Subscription is voluntary, and you will only receive email from us if you have consented (GDPR Article 6(1)(a)) or where we have a legitimate interest (GDPR Article 6(1)(f)). You may unsubscribe at any time, either by contacting us or by using the unsubscribe link at the bottom of any newsletter.

To keep newsletters relevant to you, we may — where you have consented — use information about you to tailor the content. We never use Google or Microsoft user data for marketing purposes, including to build or enrich our marketing list or to tailor newsletter content.

We measure open rates and prepare aggregated statistics and analyses to improve our newsletters.

The legal basis for marketing is our legitimate interest in delivering relevant information (GDPR Article 6(1)(f)). Marketing is necessary to operate the business and represents a very limited intrusion on your privacy.

If you delete your account, or ask us to, we will remove your data from the marketing database.

Error reporting

We use error-reporting tools that may contain personal data. Such data is processed solely to test and resolve compatibility issues, to fix bugs and to maintain the quality of the Service. Legal basis: performance of the contract with you pursuant to GDPR Article 6(1)(b). Personal data contained in error reports is deleted after 30 days.

3.Cookies

Cookies are text files placed on your device to collect standard log information and visitor behavior. When you visit our website, we may collect information automatically through cookies or similar technology (such as local storage).

How we use cookies

Brigg uses a first-party cookie to keep you signed in to the Service. It expires after one year.

How to control cookies

You may configure your browser to refuse cookies. If you do so, some features of the website may stop working as intended.

4.Where we process your data

Sub-processors (third-party services)

We do not use third parties to process your data without a legitimate and lawful basis.

We process your personal data with third parties only as described in this Policy, and we never sell personal data. Sub-processors are responsible for their own processing of personal data for their own purposes.

LinkedIn

We maintain a page on LinkedIn to promote our products, services and company. LinkedIn allows us to see posts, likes, followers, comments, messages and aggregated statistics on visitor interaction with our pages. LinkedIn processes personal data in the United States and other countries listed in its privacy policy. The EU Standard Contractual Clauses (SCCs) form the basis for transfers from the EEA to the United States. The substantive part of the processing is performed by LinkedIn as data controller — please refer to LinkedIn's privacy policy for further details.

Business transactions

Relevant personal data may also be shared with third parties such as legal advisors, consultants, buyers and prospective buyers in connection with a business transaction, including any planned or completed merger, acquisition or share transfer (including transfers in connection with insolvency or bankruptcy proceedings). Confidentiality agreements or professional duties of confidentiality will protect your personal data.

5.Security

We work continuously to protect your personal data and other confidential information. Our security measures include physical, technical and administrative safeguards.

All persons who process personal data at Brigg are trained in how to handle personal data securely. We maintain procedures and access controls to prevent loss or accidental disclosure. We follow industry standards for software and guidelines for the protection of personal data and other confidential information.

Any breach of our security practices is documented. We have procedures and capabilities to detect and respond to security and privacy incidents. If we detect such a breach, we notify our management, assess the risk associated with the incident and report to the Norwegian Data Protection Authority (Datatilsynet) where required. You will also be notified as a user where the breach poses a high risk to your privacy.

6.Data retention

We keep and use personal data only for as long as we have a basis for the processing. This may mean minutes, hours, days, months or years, depending on the category of personal data in question. Please see the purposes set out in Section 2.

7.Your rights

Under applicable law, you have certain rights in respect of the processing of your personal data, including:

  • Information on how we collect and process your data
  • Access to, and a copy of, the data we hold about you, together with the right to rectification and updating
  • Restriction of processing or erasure of data in certain cases
  • Withdrawal of any consents you have provided, in certain cases
  • Data portability — to take your data with you in a commonly used format

Please contact us at personvern@brigg.no to exercise your rights or if you believe our processing is in breach of applicable law.

If you believe that we are processing your data in breach of your rights, you have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) or another supervisory authority. We would appreciate it if you contacted us first so that we can attempt to resolve or clarify the matter.

8.Changes

We may update this Policy. Where changes are material, we will notify you in the Service or by email. The date at the top of this page indicates when it was last updated.

Questions about privacy?

Write to us at personvern@brigg.no and we will respond as quickly as we can.