Privacy Policy

Last updated: September 16, 2025

Diri AS takes privacy seriously. This Privacy Policy explains how we process personal data when providing our services, operating our website, and carrying out other activities that involve the processing of personal data.

We comply with applicable privacy legislation, including the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act.

1. Who we are

Diri AS (company reg. no. 925 336 556) is headquartered in Gjøvik, Norway.
We provide a SaaS platform for risk management and compliance, as well as related services.

Contact details

2. Scope of this policy

This Privacy Policy applies to:

When we process personal data on behalf of our customers in our SaaS platform, we act as a data processor. The customer is the data controller, and this relationship is governed by a Data Processing Agreement.

3. How we process personal data

a) When we are the data controller

We act as a data controller in the following situations:

b) When we are the data processor

When you or your organization use our platform (app.diri.ai), we process personal data on behalf of the customer. This may include:

We only process personal data in line with the customer’s instructions and the applicable Data Processing Agreement.

4. Legal basis for processing

We process personal data on the following bases:

5. What data may we process

We may process the following types of personal data:

We generally do not process sensitive personal data, except where you voluntarily provide such information in recruitment processes.

6. Your rights

You have the right to:

You may exercise these rights by contacting us at privacy@diri.no. You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).

7. Data retention

We retain personal data only as long as necessary for the purposes for which it was collected, or as long as we are legally required.

8. Data security

We use organizational, technical, and physical security measures to protect personal data, including access control, encryption, backup routines, logging, and regular security audits.

9. Sharing and transfer of personal data

a) Sub-processors

We rely on sub-processors to deliver our services. All are subject to Data Processing Agreements. As of today, these include:

An up-to-date list is always available in our Data Processing Agreement.

b) Transfers outside the EU/EEA

As a rule, personal data is processed within the EU/EEA. Some services (e.g. LinkedIn for recruitment) may involve transfers to the United States. In such cases, we use valid transfer mechanisms, such as the EU Standard Contractual Clauses (SCCs).

10. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The latest version will always be published on our website, with the date of last update. If significant changes are made, we will provide additional notice.

11. Contact us

If you have questions about privacy or wish to exercise your rights, please contact us at: