Privacy Policy

Last updated: January 1, 2026

1. Introduction

Bipa AS ("we," "us," or "our") is committed to protecting the privacy and personal data of individuals who visit our website, use our services, or communicate with us. This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you interact with our website and coaching education programs.

Bipa AS is a company registered in Norway. Our registered address is Gamle Eigerøyveien 30, 4373 Egersund, Norway. We serve participants throughout Canada with online coaching and personal development education programs.

By using our website or submitting information to us, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this policy, please do not use our website or services.

2. Data Controller

The data controller responsible for your personal data is:

Bipa AS

Gamle Eigerøyveien 30

4373 Egersund, Norway

Email: [email protected]

As a company registered in Norway, we process personal data in accordance with the Norwegian Personal Data Act (Personopplysningsloven) and the European Union General Data Protection Regulation (GDPR), Regulation (EU) 2016/679. Where applicable, we also comply with relevant Canadian privacy legislation, including the Personal Information Protection and Electronic Documents Act (PIPEDA).

3. What Personal Data We Collect

We may collect the following categories of personal data depending on how you interact with our website and services:

3.1 Information You Provide Directly

  • Contact information: Full name, email address, phone number
  • Inquiry details: Selected program of interest, preferred learning format, messages or comments submitted through our contact form
  • Enrollment information: Data provided during the registration or enrollment process for our coaching and educational programs
  • Communication records: Content of emails, messages, or other correspondence you send to us

3.2 Information Collected Automatically

  • Technical data: IP address, browser type and version, operating system, device type, screen resolution
  • Usage data: Pages visited, time spent on pages, referral source, click patterns, navigation paths
  • Cookie data: Information collected through cookies and similar tracking technologies as described in our Cookie Policy

3.3 Information from Third Parties

We may receive limited information from third-party analytics services or advertising platforms if you arrived at our website through an advertising campaign. This data is typically aggregated and anonymized and does not directly identify you.

4. How We Use Your Personal Data

We process your personal data only for specific, legitimate purposes. These include:

  • Responding to inquiries: To process and respond to your contact form submissions, emails, or other communications
  • Program administration: To manage enrollment, deliver educational programs, and communicate with participants about program schedules and materials
  • Service improvement: To analyze website usage patterns and improve the structure, content, and performance of our website and educational programs
  • Legal compliance: To comply with applicable laws, regulations, and legal processes under Norwegian, European, and Canadian law
  • Communication: To send you information about our programs or services, but only where you have given your explicit consent to receive such communications
  • Security: To detect, prevent, and address fraud, unauthorized access, or other security concerns related to our website

5. Legal Basis for Processing

Under the GDPR and Norwegian data protection law, we process your personal data based on the following legal grounds:

  • Consent (Article 6(1)(a) GDPR): When you submit a contact form with the consent checkbox selected, or when you opt in to receive communications from us
  • Contractual necessity (Article 6(1)(b) GDPR): When processing is necessary to fulfill a contract with you, such as providing an educational program you have enrolled in
  • Legitimate interest (Article 6(1)(f) GDPR): When processing is necessary for our legitimate business interests, such as improving our website and services, provided that your rights and freedoms do not override these interests
  • Legal obligation (Article 6(1)(c) GDPR): When processing is required to comply with a legal obligation under Norwegian, European, or Canadian law

6. How We Share Your Personal Data

We do not sell, rent, or trade your personal data to third parties. We may share your data in the following limited circumstances:

  • Service providers: We may share data with trusted third-party service providers who assist us in operating our website, processing forms, hosting data, or analyzing website usage. These providers are contractually bound to process data only on our behalf and in accordance with this Privacy Policy and applicable data protection laws.
  • Legal requirements: We may disclose your data if required by law, regulation, legal process, or governmental request under the jurisdiction of Norway, the European Economic Area, or Canada.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity, subject to the same privacy protections described in this policy.

7. International Data Transfers

As Bipa AS is registered in Norway and serves participants in Canada, your personal data may be transferred between Norway (within the European Economic Area) and Canada or other jurisdictions where our service providers operate.

The European Commission has recognized Canada as providing an adequate level of data protection for commercial organizations subject to PIPEDA. Where data is transferred to countries not covered by an adequacy decision, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.

You may request more information about the safeguards we use for international data transfers by contacting us at [email protected].

8. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Specific retention periods include:

  • Contact form submissions: Retained for up to 24 months from the date of submission, unless a longer retention period is required for ongoing communication or legal purposes
  • Program enrollment data: Retained for the duration of the program and up to 36 months after completion for record-keeping and follow-up purposes
  • Website analytics data: Aggregated and anonymized analytics data may be retained indefinitely. Identifiable analytics data is retained for up to 14 months
  • Communication records: Retained for up to 24 months from the date of the last communication

When personal data is no longer needed, we securely delete or anonymize it in accordance with our data management procedures.

9. Your Rights

Under the GDPR, Norwegian data protection law, and applicable Canadian privacy legislation, you have the following rights regarding your personal data:

  • Right of access: You have the right to request a copy of the personal data we hold about you
  • Right to rectification: You have the right to request correction of inaccurate or incomplete personal data
  • Right to erasure: You have the right to request deletion of your personal data, subject to certain legal exceptions
  • Right to restrict processing: You have the right to request that we limit the processing of your personal data in certain circumstances
  • Right to data portability: You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transfer it to another controller
  • Right to object: You have the right to object to the processing of your personal data based on legitimate interests
  • Right to withdraw consent: Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days, as required by applicable law.

10. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to improve functionality, analyze usage, and enhance your browsing experience. For detailed information about the types of cookies we use, how they work, and how you can manage your cookie preferences, please refer to our Cookie Policy.

You can control cookies through your browser settings. Most browsers allow you to refuse or delete cookies. However, disabling cookies may limit the functionality of certain features on our website.

11. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • HTTPS encryption across all pages of our website
  • Secure server infrastructure with regular security updates
  • Access controls limiting data access to authorized personnel only
  • Secure form processing with server-side validation and spam protection
  • Regular review of data processing procedures and security practices

While we take reasonable steps to protect your data, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security of your personal data.

12. Children's Privacy

Our website and services are designed for adults. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have inadvertently collected personal data from a minor, we will take immediate steps to delete such data. If you believe we have collected data from a minor, please contact us at [email protected].

13. Third-Party Links

Our website may contain links to external websites or services that are not operated by us. We are not responsible for the privacy practices or content of third-party websites. We encourage you to review the privacy policies of any external sites you visit.

14. Supervisory Authority

If you believe that our processing of your personal data violates the GDPR or Norwegian data protection law, you have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet):

Datatilsynet (Norwegian Data Protection Authority)

Postboks 458 Sentrum

0105 Oslo, Norway

Website: datatilsynet.no

Canadian residents may also direct privacy complaints to the Office of the Privacy Commissioner of Canada (OPC) if they believe their rights under PIPEDA have been violated.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data processing practices, legal requirements, or business operations. When we make material changes, we will update the "Last updated" date at the top of this page.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data. Continued use of our website after changes to this policy constitutes your acknowledgment of the updated terms.

16. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:

Bipa AS

Gamle Eigerøyveien 30

4373 Egersund, Norway

Email: [email protected]

We aim to respond to all privacy-related inquiries within 30 days of receipt.