For questions about your data, or to make a request about it, write to support@equitia.net
Version 4, in effect from Sep 3, 2026 (en)
Version: 2026.1
Effective date: 3 September 2026
Supersedes: version dated 9 August 2024
Equitia by Antos, a Norwegian sole proprietorship (enkeltpersonforetak), is the data controller for the personal data described in this policy.
Supervisory authority. If you are unhappy with how we handle your personal data you have the right to complain to the Norwegian Data Protection Authority (Datatilsynet), Postboks 458 Sentrum, 0105 Oslo, at datatilsynet.no. If you live in another EEA country you may complain to your local authority instead.
We have not appointed a Data Protection Officer, as we are not required to under GDPR Article 37. Privacy enquiries are handled at the address above.
There are two different kinds of data here and they are governed differently.
Data about you as our customer. Your account, billing, support and website-usage data. We are the controller. This policy covers it.
Data inside the services you rent from us. Anything you or your users upload, store, transmit or process on your VPS, web hosting or game server. This includes your website's visitor data, your databases, your email, and your game server's player data. You are the controller. We are only the processor. This policy does not cover it.
You are responsible for handling that data lawfully, for having your own privacy policy where required, and for responding to the rights requests of your own users. Where you need a Data Processing Agreement from us, contact support@equitia.net.
| Data | Why |
|---|---|
| Name and email address | Account identification and service notices |
| Billing address and postal address | Invoicing and VAT |
| Company name and VAT number (business customers) | Invoicing and VAT treatment |
| Account credentials (password, stored hashed) | Authentication |
| Support ticket content and ticket attachments | Resolving your requests |
| Data | Why |
|---|---|
| IP address and user-agent string at the moment you accept our Terms | Evidence of contract formation and of consent to recurring billing |
| IP address and user-agent when you enable AutoPay, together with the Terms version and timestamp | Evidence of your authorisation for recurring charges, as set out in section 6 of the Terms |
| Login IP addresses and session data | Account security and fraud prevention |
| Server logs, page views, referring URLs, device and browser characteristics | Security, diagnostics, and operating the website |
| Data | Why |
|---|---|
| Country of issue of your payment instrument | Required VAT evidence |
| IP-derived location | Required VAT evidence |
| Billing address country | Required VAT evidence |
| Truncated card details (last four digits, card brand, expiry) | Identifying your payment method in the Client Area |
| Payment mandate reference | Operating AutoPay |
We do not store full card numbers or CVV. Those go directly to Stripe or Vipps MobilePay.
VAT rules require us to hold at least two non-contradictory pieces of evidence of your location, which is why we collect location signals from more than one source. This is a legal obligation, not a choice, and you cannot opt out of it while remaining a customer.
Our Services are not directed at children and we do not knowingly collect data from anyone under 13, which is the age of consent for information society services in Norway. You may not create an account if you are under 13. We do not verify age when you sign up, so this is a condition of using the Services rather than a check we perform. If we learn that we hold data from a child under 13, we delete it.
We ask that you do not send us special-category data (health, biometric, political, religious, trade union, sexual orientation) or national identity numbers through support tickets. If you do, we will delete it.
| Purpose | Legal basis |
|---|---|
| Creating and operating your account; providing the Services | Performance of a contract (Art. 6(1)(b)) |
| Billing, taking payment, and processing recurring charges | Performance of a contract |
| Keeping accounting records and VAT evidence | Legal obligation (Art. 6(1)(c)), under Norwegian bokføringsloven and VAT law |
| Recording IP, timestamp and Terms version at acceptance and at AutoPay opt-in | Legitimate interests (Art. 6(1)(f)), for evidencing agreements and defending payment disputes |
| Fraud prevention, abuse handling, network security | Legitimate interests |
| Handling your support tickets, including AI-assisted drafting | Performance of a contract, and our legitimate interest in operating support efficiently |
| Service announcements and outage notices | Performance of a contract |
| Marketing email | Consent (Art. 6(1)(a)), given by confirming your email address, with an opt-out in every message |
| Site analytics | No personal data is processed, so no legal basis is required. See section 10 |
We use the following third parties. Each processes personal data only for the purposes described below, on our instructions and under the terms of our agreement with them.
| Subprocessor | What they do | What they receive | Location |
|---|---|---|---|
| Stripe (Stripe Payments Europe, Ltd.) | Card payment processing | Name, email, billing address, card data, payment amounts | Ireland / EU, with transfers to the US |
| Vipps MobilePay AS | Mobile payment processing and recurring mandates | Name, payment amounts, mandate reference | Norway / EEA |
| OpenRouter, Inc. | Routes AI requests to inference providers | Redacted ticket text, as described in section 6 | United States |
| AI inference providers, accessed through OpenRouter | Draft support replies | Redacted ticket text | Varies by request, as described in section 6 |
| Fiken AS | Accounting, where an account is connected | Name, billing address, invoice and payment records | Norway |
Error tracking runs on our own self-hosted infrastructure. Application error traces, which may identify the account an error occurred on, are not sent to any third party.
Email delivery runs on our own mail server, operated by Equitia by Antos on our own hardware. No third-party email provider receives your messages, and there is no subprocessor for transactional email.
Our servers are hardware we own and operate, housed in a datacentre in Sweden, within the EEA. We rent space, power and connectivity; the facility does not administer our systems, does not hold credentials to them, and is not given access to customer data.
Customer data stored on our Services stays within the EEA. The only personal data leaving it is what the third parties in the table above receive for the purposes listed there.
BTCPay Server is self-hosted by Equitia. Cryptocurrency payments processed through it do not involve a third-party payment processor, which means the transaction data is held by us rather than shared. Blockchain transactions are public and permanent by design and we cannot delete them.
Our billing panel is built and self-hosted by Equitia. Account, invoice and consent data held in it is not shared with a third-party billing vendor.
We no longer use PayPal. Any historical PayPal transaction records are retained only as part of our accounting records.
We may also disclose data to law enforcement or regulators where legally required, and to a debt collection agency where an invoice goes unpaid.
We do not sell personal data.
We maintain this list at equitia.net/legal/subprocessors. We will notify you by email at least 30 days before we add a new subprocessor, change what an existing one does, or stop using one. Changes that have been announced and have not yet taken effect are shown on that page with the date they apply from.
The register is a disclosure, not an agreement: there is nothing for you to accept, and a change to it never interrupts your use of the Services.
We use an AI service to help draft replies to support tickets. Because this involves sending your ticket content outside our own infrastructure, we describe it separately rather than burying it in a list.
Some subprocessors process data outside the EEA, principally in the United States. Where that happens we rely on the European Commission's Standard Contractual Clauses, and on the EU–US Data Privacy Framework where the recipient is certified.
You may request a copy of the safeguards in place by emailing privacy@equitia.net.
Deletion is carried out by a scheduled cleanup process in our billing panel. It works in two independent parts.
Account cleanup. An account becomes eligible for cleanup after 365 days of inactivity, and only if it has no live Service and no Prepaid Balance. Orders that were started but never paid are cleared on a shorter clock. Before we act on an account we email you in advance, and nothing happens until that notice period has passed, so an inactive account is never touched without warning.
An account with an active Service is never swept.
What happens then depends on whether the account has billing history:
Support tickets attached to an account that is stripped rather than deleted are not themselves removed. The ticket text remains, because it is bound to the billing record we have to keep. Ticket attachments are still deleted on their own schedule, 12 months after the ticket closes.
There is a limit to this worth stating plainly. Stripping the account fields removes the identifiers we hold in our own records. It does not rewrite the contents of what you wrote. If you included your name, address or other details in the body of a ticket, that text remains as written. Please bear this in mind when contacting support, and include no more personal detail than your question requires.
Attachment cleanup. Files uploaded to support tickets are deleted a set period after the ticket is closed. This removes files only; it never removes accounts. The text of the ticket is retained, so the support history remains complete and readable, but the attachments it refers to will no longer be there.
Deletion removes your data from our live systems. For web hosting, a copy may remain in our rotating backups for up to approximately 12 months until pruned in the ordinary course.
Backup snapshots cannot be selectively edited: removing one person's data from a snapshot would destroy the integrity of the whole snapshot. Where you exercise your right to erasure, we therefore delete from live systems immediately and allow the backup copy to expire on its normal rotation. During that window the data is not used for any purpose, is not accessible through normal operation, and is not searched for individual records.
VPS and game server contents are not backed up by us at all. See Terms §12.
| Data | Retention |
|---|---|
| Invoices, payment records and accounting documentation | 5 years after the end of the financial year they relate to, as required by bokføringsloven § 13 |
| Inactive accounts with no live Service and no Prepaid Balance | 365 days of inactivity, after 30 days advance email notice |
| Unpaid, never-completed orders | 30 days from the date the order was started |
| Support ticket attachments | 12 months after the ticket is closed |
| Support ticket text | Deleted with the account where there is no billing history. Where accounting records must be kept, the account is stripped of identifying details and the ticket text is retained alongside them |
| Account details (name, email, address) | For the life of the account, then removed by the cleanup described above |
| VAT and location evidence | Tied to the accounting retention period above |
| Terms-acceptance and AutoPay consent records | For the life of the mandate plus 24 months |
| Prepaid Balance records | Retained while a balance remains, as balances do not expire |
| Server and access logs, and application error traces | 90 days |
| Customer content on terminated Services | Removed from live systems per the Terms: at Period End Date, immediately on immediate cancellation, at the dunning termination stage, or 7 days after a prepaid Service pauses. Web hosting data may persist in backups, as described above |
| Web hosting backups | Rotating schedule of 3 latest, 7 daily, 4 weekly, 6 monthly and 1 yearly. Data can persist up to approximately 12 months before it is pruned |
The general criteria we apply: we keep personal data for as long as it is needed to provide the Services to you, for as long as we are legally required to keep it, and for as long as it may be needed to establish, exercise or defend legal claims. When none of those apply, we delete or anonymise it.
Support ticket text does not have its own clock. It follows the account, which means it is deleted with accounts that have no billing history, and retained where accounting law requires the underlying records to be kept. Attachments are removed earlier, on the schedule above, in every case.
You have the right to:
To exercise any of these, email privacy@equitia.net. We will respond within one month. We may need to verify your identity first.
Note that erasure requests cannot override our legal obligation to retain accounting records, and we cannot delete a Terms-acceptance or payment-consent record while it is needed to defend a dispute. Where accounting records must be kept, we strip the identifying details rather than deleting the record. See section 8 for what that means in practice, and for how erasure interacts with backups.
Cookies we set. Only cookies the Services need in order to work: your login session, security and anti-forgery tokens, your cart while you are ordering, and two preferences the panel has to remember to show you the right thing, being your language and your light or dark theme.
There are no advertising cookies, no retargeting cookies and no third-party cookies. We do not build profiles of your interests and we do not share anything with advertising networks.
Analytics. We measure how the site is used with our own self-hosted analytics, running on our own infrastructure. It sets no cookies and stores no identifier that could recognise you on a later visit. It records which page was viewed, as a page type rather than a full address, so an invoice you open is counted as "an invoice page" and never as which invoice. Web addresses that could identify you or carry a sign-in link are excluded entirely, and nothing is loaded at all if your browser sends a Do Not Track or Global Privacy Control signal.
Because none of this involves cookies or personal data, there is no cookie banner to click through and nothing to opt out of.
You can block cookies in your browser, though you will not be able to sign in if you do.
We apply administrative, physical and technical measures to protect personal data, including encryption in transit, hashed password storage, access controls limiting personal data to staff who need it, and regular malware scanning.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Unauthorised access to data held on our systems is unlawful and we will pursue it.
Breach notification. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify Datatilsynet within 72 hours and notify you without undue delay where the risk is high.
We may email you about Services similar to those you already have. We only send marketing email to addresses that have confirmed a subscription by clicking a link we sent them, whether or not you are already a customer. Every such email contains an unsubscribe link that works in one click. You can also email support@equitia.net to opt out of all marketing.
Opting out of marketing does not stop service-critical email such as invoices, renewal notices, dunning notices, low-balance warnings, security alerts and maintenance notices. Those are part of the Service and cannot be unsubscribed from while you hold an account.
We will post changes here and update the version number. Where a change materially affects how we use your data, we will notify you by email. Previous versions are archived at equitia.net/legal/archive.
support@equitia.net
Privacy: privacy@equitia.net
Equitia by Antos, Feldbergveien 31, 3520 Jevnaker, Norway
Org. nr. 934 018 168
Last updated: 3 September 2026
The providers that process data on our behalf are listed under Subprocessors.