Zonara AS is the data controller for the personal data processed through our websites and services.
Company information:
- Legal name: Zonara AS
- Organisation number: 933 342 522
- Address: Drammensveien 288, 0283 Oslo
- Managing director: Anders Eidval
- Telephone: +47 459 67 125
- Privacy email: personvern@zonara.no
- General contact: post@zonara.no
Questions about privacy may be sent to personvern@zonara.no.
When you visit our websites, we process the following:
- Technical data: When you visit the website, our hosting provider (Vercel) processes your IP address, browser type, page and time in technical logs. This is necessary to deliver the website and protect it against misuse, and the logs are deleted automatically within 30 days.
If you send us an email via the contact link on the website, we process your name, your email address and the content of the message.
When you use the Zonara app, we process:
- Identity data: Name, national identity number, date of birth, email address, telephone number
- Driving licence data: Driving licence class, validity, validation against the driving licence register of Statens vegvesen
- Organisational affiliation: Which company you belong to, role, access rights
- Position and vehicle data: GPS position of the vehicle, driving log, driving pattern, distance, time
- Reservations and bookings: Which vehicles you reserve, time, purpose
- Vehicle technical information: Fuel, battery, odometer reading and similar data obtained from the vehicle manufacturer
- Vehicle register data: Information obtained from Statens vegvesen about registered vehicles
- Login data: Time of login, IP address, device, session ID
- Activity log: Actions you perform in the app (audit log) for security and troubleshooting purposes
- Communication: Outgoing email and SMS sent from the service
- Payment data: Processed by our payment provider (we do not store card information ourselves)
National identity numbers are processed only where there is a legitimate need for secure identification, cf. personopplysningsloven § 12. Specifically, we use the national identity number for:
- Identification at BankID login
- Validation of driving licences against the driving licence register of Statens vegvesen
The national identity number is not shown in the interface, is not shared with unauthorised parties, and is stored encrypted. Access is limited to the systems and persons with a need for it in the course of their duties.
We check the number against the manufacturer's connected service, without information about the owner. Zonara does not store the number or the response. The value may appear in technical logs, which are deleted within 90 days.
| Purpose | Legal basis (GDPR) |
|---|---|
| Operating the website and improving the user experience | Legitimate interest, Art. 6(1)(f) |
| Delivering the Zonara service to our customer (your employer) | Agreement with the customer, Art. 6(1)(b) and (f) |
| Validating driving licences against Statens vegvesen | Legal obligation / legitimate interest, Art. 6(1)(c) and (f) |
| Identification via BankID | Agreement and legitimate interest, Art. 6(1)(b) and (f) |
| Security, troubleshooting and audit log | Legitimate interest, Art. 6(1)(f) |
| Invoicing and accounting | Legal obligation, Art. 6(1)(c) |
| Marketing (upcoming newsletter) | Consent, Art. 6(1)(a) |
| Data type | Retention period |
|---|---|
| Website visit data | Up to 30 days |
| User account in the app | For as long as the agreement with the customer runs |
| Vehicle and driving logs | For as long as the agreement runs, then deleted or anonymised within 90 days |
| Audit log / activity log | 12 months |
| Login log | 12 months |
| Invoicing and accounting data | 5 years (regnskapsloven § 13) |
| Email sent to us | Up to 24 months, then deleted unless there is an active customer relationship |
After the customer relationship has ended, all personal data is deleted or anonymised within 90 days, except data that must be retained longer by law.
The SaaS service itself is operated within the EU on Microsoft Azure, region West Europe (the Netherlands). This covers the database, identity services, monitoring and backups.
Data is encrypted at rest with AES-256, and encryption keys are managed in a customer-managed key store. All data traffic is encrypted with TLS 1.2 or later. Access to data is protected by role-based access control and mandatory two-factor login.
No customer data from the SaaS service is transferred outside the EU.
Certain support services use providers outside the EU. For such transfers, the European Commission's standard contractual clauses (Standard Contractual Clauses, SCC) are used as the transfer mechanism, cf. GDPR Art. 46.
We share personal data with the following categories of recipients:
We use data processors within the following categories:
- Hosting and infrastructure (Microsoft Azure, region West Europe)
- Identity and login services (BankID broker)
- Map data
- Connected services for vehicle data
- Email and SMS dispatch
- Payment processing
- Domain registration and website hosting
All data processors have entered into a written data processing agreement with Zonara, cf. GDPR Art. 28. A complete and up-to-date list of data processors is available to customers who have entered into an agreement, and can also be obtained on request to personvern@zonara.no.
- Statens vegvesen: We send requests to the driving licence register and the vehicle register of Statens vegvesen to validate driving licences and obtain vehicle information.
- Our customer (your employer): The company that has an agreement with Zonara has access to data about its employees in the service.
- Public authorities: If we have a legal obligation to disclose information (for example the police, the tax authority, the data protection authority).
We never sell personal data to third parties.
We use:
- Strictly necessary cookies: For the website to function (session, security)
The website uses no tools for statistics, analytics or tracking.
We do not use Google Analytics, Meta Pixel, LinkedIn Insight Tag or other marketing pixels.
When newsletter sign-up is launched, consent will be obtained separately before a sign-up is stored.
The app uses technical cookies and local storage that are necessary for login and functionality. These are not optional.
We have implemented technical and organisational measures to protect personal data, including:
- AES-256 encryption at rest
- Customer-managed encryption keys
- TLS 1.2+ encryption for all data transfer
- Role-based access control (RBAC)
- Two-factor login (MFA) required for all administrators and users
- Logging and monitoring
- Regular backups
- Procedures for handling security incidents
In the event of a personal data breach, we notify Datatilsynet within 72 hours where required, and the affected individuals without undue delay.
You have the following rights under the General Data Protection Regulation:
- Access: Obtain access to the personal data we process about you
- Rectification: Have incorrect or incomplete data corrected
- Erasure: Request erasure of data («the right to be forgotten»)
- Restriction: Request that the processing be restricted
- Data portability: Receive your data in a machine-readable format
- Objection: Object to processing based on legitimate interest
- Withdrawal of consent: Where processing is based on consent, you may withdraw it
To exercise your rights, contact us at personvern@zonara.no. We respond within 30 days.
You have the right to lodge a complaint with Datatilsynet if you believe we process your personal data in breach of the rules.
Datatilsynet Postboks 458 Sentrum, 0105 Oslo Telephone: 22 39 69 00 Email: postkasse@datatilsynet.no Website: www.datatilsynet.no
We may update this policy in the event of changes to the service or the rules. The version number and date at the top of the document will reflect the changes. Material changes will be notified separately to registered users.
Questions about this policy or about how we process personal data may be sent to:
Zonara AS Drammensveien 288, 0283 Oslo Email: personvern@zonara.no Telephone: +47 459 67 125

