Privacy
Controller
Restoradar is run by a private individual, Sindijs Supins. Contact: kontakt@restoradar.no. The service may later be transferred to a company. You will be told before that happens.
What we collect
- Registration and account: work email, organisation number and password (stored only as a one-way hash). We look the organisation number up in the Central Coordinating Register for Legal Entities (Enhetsregisteret, run by the Brønnøysund Register Centre) and store the company’s name and organisational form, to check that accounts belong to real companies. Purpose: to give you access to the service and to contact you about your account. Legal basis: the agreement on the use of the service – the terms of use you accept when registering (GDPR art. 6(1)(b)). Kept for as long as the account exists; you can delete it yourself under “My account”. Registrations that are never confirmed are deleted after 30 days.
- Optional answers in the form (industry, region, needs and willingness to pay): used to develop the service and its prices. Legal basis: legitimate interest (art. 6(1)(f)); you can leave the fields empty. Deleted together with the account.
- Login log: time, IP address and browser of each login attempt, to protect accounts against misuse. Every login also needs a one-time code sent to your email. Legal basis: legitimate interest in security (art. 6(1)(f)). Kept for 12 months, also after an account has been deleted.
- Export log: for each Excel export, the account and company that exported, the time, the data date, the filters, whether it was the whole list or restaurants chosen in it (and how many), which restaurants were in the file (Mattilsynet’s ids), the number of rows and of new restaurants, an export ID and a checksum of the file, and the IP address. The file itself is marked with the company that exported it and with the export ID. Purpose: to enforce the export limit per company; accountability – to be able to tell the owner of a restaurant, if they ask, which companies have received it; and to prevent and trace misuse of the lists (for example a list that is passed on or published). Legal basis: legitimate interest (art. 6(1)(f)). Kept for 12 months, also after an account has been deleted. In addition we store which restaurants (Mattilsynet’s ids) the company has exported in the current month, so that exporting them again that month does not count against the limit; this list is deleted when the month is over.
- Requests for a larger quota: your message, who sent it (your account), the company and the time. The request is also sent to us by email. Purpose: to answer you and to adjust the company’s limits. Legal basis: the agreement on the use of the service – a step you ask us to take (GDPR art. 6(1)(b)). Kept until the request has been answered and for 12 months after that, or until you delete your account.
- Remove / correct a business: the business, your message and your email. Purpose: to handle the request. Legal basis: legitimate interest (art. 6(1)(f)). Kept for 12 months after the request is handled; the block list itself is kept for as long as the service exists.
- Business data: inspection results and company names from public registers (Mattilsynet, the Brønnøysund Register Centre), and newly registered restaurants, bars and caterers from the business register (name, address, industry code, registration date and the main entity). We do not show contact details or names of people.
Sole proprietorships
When a restaurant is run as a sole proprietorship (enkeltpersonforetak), its name and where it is can be personal data about the owner. We take them from Mattilsynet’s open data on smiley (smilefjes) inspections, which Mattilsynet publishes itself. The purpose is to show suppliers which restaurants have had findings; the legal basis is legitimate interest (GDPR art. 6(1)(f)). For these restaurants – and for any whose company we cannot identify – we never show the owner’s name, the street address or the organisation number, not on the site and not in Excel exports: only the restaurant’s name, the municipality, the findings and the link to Mattilsynet’s own inspection report. Names are shown only to registered, verified companies. We do not notify each owner individually, because the information comes from a public source and that would take disproportionate effort (art. 14(5)(b)); this text is the information. You can ask us which companies have exported your restaurant to Excel in the last 12 months – we log which restaurants were in each file (see the export log above). If you run a sole proprietorship and do not want to be shown, use “Remove / correct a business” – we remove the restaurant within 72 hours, and it stays removed after later data updates.
Cookies and tracking
We use one technical session cookie (rr_session), only when you fill in a form (to protect it against forgery) or are logged in (to keep you logged in, up to 14 days). Browsing the lists without logging in sets no cookies. We use no analytics or advertising cookies and no third-party scripts or fonts.
Visit statistics
We count visits with Matomo on our own server – without cookies and without third parties. The IP address is shortened before it is stored, and we only look at totals: which pages are visited, where visitors come from (a link or a search engine), country and type of device. If your browser has “Do Not Track” turned on, the visit is not recorded. Legal basis: legitimate interest in improving the website (art. 6(1)(f)). Individual visits are deleted after 6 months; only totals are kept.
Where the data is stored
On a server in Germany (EU). Emails from the service are sent through an email provider in the EU/EEA. We do not sell or share personal data.
Your rights
You can ask for access, correction or deletion and object to processing – email kontakt@restoradar.no. You can delete your account yourself under “My account”. You can also complain to the Norwegian Data Protection Authority (Datatilsynet).