Skip to content

Privacy policy

What happens to what you send us

Last revised 2026-08-31. Norway applies the General Data Protection Regulation through the EEA Agreement, so the Regulation and the Norwegian Personal Data Act (personopplysningsloven) both apply to this site.

1. Who is responsible

The controller is STAKE GUNHILD, a Norwegian sole proprietorship (Enkeltpersonforetak), organisation number 969090813, of Valdresvegen 489, 3550 Gol, Norway.

Contact for any data-protection question, including access, correction, deletion and objection requests: info@stakegunhild.com, or the postal address above. There is no statutory requirement for this undertaking to appoint a data protection officer, and none has been appointed — requests go directly to the controller.

2. What is collected, and on what legal basis

Two forms on this site collect personal data, and each rests on a named Article of the GDPR. Neither of them relies on consent, and neither asks for it — see clause 3 for why that is deliberate.

2.1 Bulk supply enquiry form

Purpose: To answer your enquiry about buying forage in bulk, and to quote against what is actually in store.
Legal basis: GDPR Article 6(1)(b) — steps taken at your request before entering into a contract.
Retention: 24 months from your last message, then deleted.

  • Company nameWe sell business to business, so we need to know which business is asking.
  • Contact e-mailThe only way we can answer you.
  • CropDifferent crops have different availability and different collection windows.
  • Estimated volumeA band rather than a figure — enough to say whether it can be met at all.
  • Delivery termsCollection at Gol and delivery elsewhere are different quotes.
  • MessageWhatever else matters: timing, bale handling, analysis requirements.
  • Availability notices (optional)Optional. Ticking it is consent under Article 6(1)(a) and nothing depends on it.

2.2 Contact form

Purpose: To read and answer your message.
Legal basis: GDPR Article 6(1)(f) — our legitimate interest in answering correspondence sent to us; Article 6(1)(b) where the message is a step towards a contract.
Retention: 12 months from your last message, then deleted.

  • NameSo a reply can be addressed to a person.
  • E-mailThe only way we can answer you.
  • Telephone (optional)Optional. Only used if you ask to be called.
  • SubjectSo the message reaches the right part of the operation.
  • MessageWhat you want to say.

2.3 What is recorded in the background

A request to a web server is recorded by that server. Rather than claim otherwise, here is what is recorded and whether it is tied to what you sent.

  • A keyed hash of your IP addressRate limiting, so the form cannot be used to flood the mailbox. Linked to your submission — the hash is stored on the row. Deleted with the submission.
    The raw IP address is never written to the database. What is stored is a SHA-256 hash keyed with the organisation number, which counts requests and identifies nobody afterwards.
  • Web-server log linesDiagnosing faults and detecting abuse of the server itself. Not linked to a submission. 30 days, then rotated away.
    The request line, status and timestamp, as any web server records them. This is the processing most privacy policies quietly omit.
  • The version of the notice you were shownSo that, in a dispute, it is possible to establish what you were actually told at the time. Linked to your submission. Deleted with the submission.
    Stored alongside which GDPR Article the row rests on, rather than a consent flag that would misdescribe the basis.

Web-server log lines are kept for 30 days. The application itself never writes a raw IP address to the database.

4. Who else sees it, and where

Your data is not sold, not shared for anyone else’s purposes, and not used for profiling or automated decision-making. One processor is involved, because a website has to run on a server:

  • Namecheap, Inc.Hosting provider (processor). Runs the server this site and its API are served from, and therefore processes everything sent to it. Processing location: Phoenix, Arizona, United States.

Transfers outside the EEA. The server is in Phoenix, Arizona, United States — a third country for GDPR purposes. That transfer rests on GDPR Art. 46(2)(c) — European Commission Standard Contractual Clauses, concluded with the hosting provider as processor. You may ask for information about that arrangement at the address in clause 1.

The location above was established from inside the server on 2026-08-31 rather than from an IP-geolocation database — three such databases returned three different cities for this address, and none of them was used. First-hop gateway 209.188.23.5 answers at 0.47 ms and is an ARIN allocation to CWIE, 3402 E. University Dr., Phoenix, AZ 85034, US; host rDNS evangelist-dichoree.vpsrdns.web-hosting.com under AS22612 Namecheap. Measured 31.08.2026 from inside the server.

5. Your rights

Under the GDPR you may:

  • ask what is held about you and get a copy (Article 15);
  • have inaccurate data corrected (Article 16);
  • have data erased where the conditions are met (Article 17);
  • ask for processing to be restricted (Article 18);
  • receive the data you gave us in a portable format (Article 20);
  • object to processing based on legitimate interests (Article 21) — if you object to us holding your message, say so and it will be deleted unless there is a compelling reason not to, which there will very rarely be;
  • withdraw consent for the optional availability notices at any time (Article 7(3)).

Requests go to info@stakegunhild.com. If you are not satisfied with how a request is handled you may complain to Datatilsynet, the Norwegian Data Protection Authority, at datatilsynet.no, or to the supervisory authority in your own country.

6. Cookies and similar storage

This site sets no cookies for analytics or advertising unless you switch them on, and loads no third-party script, font, map or embedded video. Every request the page makes goes to stakegunhild.com — which you can confirm in your browser’s network tab rather than take on trust.

Every storage key that can be written, what it does and how long it lasts is listed in the cookie policy, and your choice can be withdrawn in one click from the footer of any page.

7. Security and retention

Submissions are stored in a database on the server described in clause 4, reachable only over an encrypted connection. Rate limiting and a honeypot field protect the forms from automated abuse. Access is limited to the holder of the undertaking.

Retention is enforced rather than promised: enquiries 24 months, contact messages 12 months, server logs 30 days.

8. Changes to this policy

The current version is 2026-08-31. Where a change affects how your data is handled, the notice attached to the forms carries a new version number, and the version you were shown is recorded with your submission — so a later rewrite of this page cannot change what you were told at the time.