Privacy policy
How Goscore AS collects, uses, shares and protects personal data — as the controller for this website and its enquiry form, and as an authorised Norwegian credit reference agency supervised by Datatilsynet.
Who we are and how to contact us
Goscore AS is the data controller for the personal data described in this policy. Registered office: Lars Hilles gate 30, 5008 Bergen, Norway. Company registration number 922 707 324.
For any question about this policy, or to exercise any of the rights in section 08, write to max@goscore.me.
What personal data we process
This website is a static marketing site. We process personal data in two distinct situations, and they are worth separating.
When you contact us through this website
The enquiry form collects your name, your organisation, your work email address, an optional phone number, the test you selected, and whatever you write in the message field. We also record the time of the enquiry and the page it came from.
When you simply browse this website
Our hosting provider processes your IP address and request metadata in order to serve the page and protect the service against abuse. If — and only if — you accept analytics cookies, Google Analytics also processes a pseudonymous identifier and usage data. See the cookie policy for the detail.
When we deliver services to a lender
In our lending-intelligence services we process consented account and transaction data under PSD2, together with credit information. In that context the lender is normally the controller and Goscore acts as processor, or as an independent controller where we act in our capacity as a credit reference agency. Those services are governed by the agreement with the lender, not by this website policy.
Purposes and legal basis
We rely on the following legal bases under Article 6 of the GDPR.
| Purpose | Legal basis |
|---|---|
| Answering an enquiry and taking steps at your request before entering a contract | Article 6(1)(b) — steps prior to a contract |
| Keeping a record of business correspondence and prospective-customer contact | Article 6(1)(f) — our legitimate interest in running and documenting our commercial activity |
| Analytics and tag management | Article 6(1)(a) — your consent, given through the cookie banner and withdrawable at any time |
| Serving and securing the website | Article 6(1)(f) — our legitimate interest in a functioning, protected service |
| Processing consented financial data in our services | Article 6(1)(a) consent for account information services, with credit assessment resting on the basis established by the lender |
Credit reference agency processing
Goscore AS is an authorised Norwegian credit reference agency (kredittopplysningsforetak) supervised by Datatilsynet.
Where we process credit information, Norwegian credit reference rules apply in addition to the GDPR. A data subject who has been the subject of a credit enquiry is entitled to be notified of the enquiry and to receive, on request, information about the data used in the assessment and where it came from. Requests of that kind are handled at the address in section 01.
No credit reference processing takes place through this website. It happens only within our contracted services.
Sharing and data processors
We do not sell personal data and we do not share it for anyone else’s marketing. We use a small number of processors, each under a data processing agreement.
| Recipient | Role | What it processes |
|---|---|---|
| Cloudflare, Inc. | Hosting, CDN and security for goscore.me | Request metadata and IP address |
| Google Ireland Ltd. | Tag management and analytics | Pseudonymous usage data — only after you consent |
| Our email provider | Delivery of enquiries from the form to our inbox | The contents of your enquiry |
Processors used to deliver our lending services to a lender are listed in the agreement with that lender.
Transfers outside the EEA
The website is served from Cloudflare’s European network. Some of the providers above are established in, or have parent companies in, the United States and may process data outside the EEA.
Where that happens we rely on the European Commission’s Standard Contractual Clauses, together with the EU–US Data Privacy Framework where the recipient is certified under it, and we apply supplementary technical measures such as encryption in transit.
Retention periods
| Data | Retention |
|---|---|
| Enquiries submitted through the contact form | 24 months from our last contact with you, unless the enquiry becomes part of a customer relationship — in which case it follows that relationship |
| Analytics data | As configured in Google Analytics, and no longer than 14 months |
| Server and security logs | Short-lived, as retained by our hosting provider for abuse protection |
| Accounting records | Five years after the end of the financial year, as required by the Norwegian Bookkeeping Act |
Your rights
Subject to the conditions in the GDPR, you have the right to:
- access the personal data we hold about you, and receive a copy of it;
- have inaccurate data corrected and incomplete data completed;
- have your data erased where we no longer have a basis for keeping it;
- restrict our processing while a question about it is resolved;
- object to processing we base on legitimate interest;
- receive data you gave us in a portable, machine-readable form; and
- withdraw a consent at any time, without affecting processing already carried out on it.
To exercise any of these, write to max@goscore.me. We answer within one month; if a request is complex we may extend that and will tell you why.
Automated decisions and profiling
This website makes no automated decisions about you and does not profile visitors.
Our services support lenders in assessing creditworthiness. Goscore supplies affordability and risk evidence together with the reasons behind it; the lender sets the policy and takes the decision. Where a decision produces legal effects or similarly significant effects for you, the lender must provide meaningful information about the logic involved, and you have the right to obtain human intervention, express your point of view and contest the decision. Direct such a request to the lender in the first instance; we will support them in answering it.
Security
The site is served over TLS with HTTP Strict Transport Security, a content security policy and standard hardening headers.
Internally we apply role-based access control, least-privilege access to production systems, encryption in transit and at rest, logging of administrative access, and periodic review of the above. Personal data in our services is segregated per client.
Complaints to Datatilsynet
If you believe we have handled your personal data incorrectly we would like to hear from you first, at the address in section 01.
You also have the right to complain to the Norwegian Data Protection Authority: Datatilsynet, Postboks 458 Sentrum, 0105 Oslo — datatilsynet.no. If you live or work in another EEA country you may complain to your local supervisory authority instead.
Changes to this policy
We publish the current version here with its date. When a change materially affects how we process personal data, we will say so on this page, and we will contact you directly where the law requires it.