Privacy notice
How Fastpath AS processes personal data.
This English version is a translation provided for convenience. The Norwegian version is the authoritative text; if the two differ, the Norwegian text prevails.
Last updated: 2 September 2026 · Version 2026-09-02
Fastpath AS (org. no. 920 497 837, “Fastpath”) provides consulting services and the Waysayer service platform. This notice explains which personal data we process, why, for how long — and what rights you have.
Questions about this notice or about your rights can be directed to our privacy contact at personvern@fastpath.no. Fastpath does not have a data protection officer.
Who does this apply to?
The notice is divided by situation. Jump to the part that applies to you. You may belong to more than one: a contact person at a customer who also has a Waysayer account reads both Part B and Part C2; someone who requests a demo belongs to Part A for the enquiry and Part C2 when the demo is used.
Waysayer is delivered by Fastpath AS, also when the platform is shown on the customer’s own domain and with the customer’s logo.
The common sections after the audience parts apply where Fastpath is the controller. They do not affect everyone in the same way — notice of changes, for example, only goes to those we can reach by e-mail or through an account.
Personal data
Personal data is any information or assessment that can be linked to you as an individual — for example name, e-mail address, telephone number or IP address.
Part A — The website and enquiries
This part applies to you when you use fastpath.no, contact us, activate a demo or subscribe to the newsletter. Fastpath is the controller.
| What we process | Why | Legal basis | How long |
|---|---|---|---|
| Name, e-mail address, telephone number, organisation, role and the content of the enquiry | Respond to you and follow up what you have asked us about | Legitimate interest in communicating with and following up those who contact us (Art. 6(1)(f)) | Up to 12 months, unless a customer relationship is established |
| Name, e-mail, organisation name and organisation number on demo activation, together with the selected demo scenario and the status of the access | Check the organisation against open data from the Brønnøysund Register Centre, set up the correct demo access, secure the service and avoid several active demos for the same organisation. Information about the organisation may be supplemented from the Brønnøysund Register Centre. | Legitimate interest in delivering the demo you request and preventing misuse (Art. 6(1)(f)) | While the demo is active, and up to 12 months after it is deactivated |
| E-mail address for the newsletter | Send you the newsletter | Consent (Art. 6(1)(a)) — you can unsubscribe at any time | Deleted within 30 days of unsubscribing |
| IP address, browser settings and technical information about the request | Secure operation and protection against misuse | Legitimate interest (Art. 6(1)(f)) | Short-term, according to operational and security needs and the hosting provider’s current retention practices |
Cookies
Fastpath’s current website setup does not use cookies or browser storage for advertising or behavioural tracking. The hosting provider nevertheless processes technical data necessary to deliver and protect the website. If we adopt analytics or advertising tools that require consent, we will ask for consent and update this section.
Part B — Customers and contact persons
This part applies to you as a customer, or as a contact person at a customer. Fastpath is the controller.
| What we process | Why | Legal basis | How long |
|---|---|---|---|
| Name, e-mail, telephone number, title and role, and correspondence between you and us | Enter into and perform the agreement, deliver the Services and provide support | Performance of a contract where you are the contracting party yourself (Art. 6(1)(b)); otherwise legitimate interest in entering into and following up the customer relationship (Art. 6(1)(f)) | For as long as the customer relationship lasts, and thereafter up to 12 months |
| Order and invoicing details | Invoice and meet bookkeeping obligations | Legal obligation (Art. 6(1)(c)) | As required by applicable accounting and bookkeeping legislation |
| E-mail address and contact details for necessary service messages | Send information about operations, security, support and changes relevant to the customer relationship | Performance of a contract where you are the contracting party yourself (Art. 6(1)(b)); otherwise legitimate interest in following up the customer relationship (Art. 6(1)(f)) | For as long as the customer relationship lasts, and thereafter for as long as necessary to document the communication |
| E-mail address and contact preferences for marketing | Send marketing about Fastpath’s own, similar services | Consent where required. In an existing customer relationship we may send such marketing when the conditions in the Norwegian Marketing Control Act are met. You can always opt out. | Until you withdraw consent or opt out, or the customer relationship no longer provides a basis for the communication |
| Information about contact preferences, including opting out of being contacted | Respect your choices | Legal obligation where the law requires an opt-out; otherwise legitimate interest in respecting and documenting the choice (Art. 6(1)(c) and (f)) | For as long as necessary to respect the choice |
The content the customer enters into Waysayer is something else. There, the customer is the controller and Fastpath the processor. The processing is governed by the Data Processing Agreement (DPA), which is a mandatory part of the agreement, and by the Customer Terms section 10. Part C describes what this looks like for the individual user.
Part C — Users of Waysayer
Two roles, briefly explained
What you are invited to — a workspace, a survey, a page, a form — is administered by a Workspace owner. The party that determines the purpose of the processing and its essential parameters is the controller when data protection law applies. In a customer workspace this is usually the Customer. Fastpath is then the processor for that content and processes it within the Customer’s documented instructions, the data processing agreement and statutory obligations. Where Fastpath itself determines the purpose — for example in a workspace we use towards customers, prospects or other external parties — Fastpath is the controller.
Where Fastpath itself needs data to operate the platform — a user account, sign-in, or logs needed to deliver and secure the service — Fastpath is the controller. The rest of Part C distinguishes between you as a user of Waysayer without an account, and you who have one.
The content of a workspace may in some cases include special categories of personal data or data about children. The controller must have a legal basis for the processing and choose a setup suited to the purpose. Where Fastpath is the processor, we process the content within the Customer’s instructions and do not use it for our own purposes.
Part C1 — Without an account
Parts of Waysayer can be used without signing in — for example responding to a survey or a form, booking a meeting, opening a shared link or reading a page the owner has published. What is available without an account depends on what the owner has set up.
In that case, the party that invited you or published the function is usually a customer of ours. The customer is normally the controller for the purpose and for what you submit, while Fastpath is the processor. Where Fastpath itself determines the purpose, Fastpath is the controller. The data comes from the party that invited you and from what you provide yourself.
This privacy notice is information, not a consent. The User Terms apply to the use itself without an account and shall be made available in connection with the function you use.
Fastpath and our subcontractors process technical data about the request, such as IP address, URL, time and browser information, in order to deliver and protect the service. We limit the content of application logs and use cryptographic digests where appropriate. Security and access data are normally retained for up to 90 days, but providers’ technical logs may have other short retention periods that follow from the service and its configuration.
Your browser may store a draft of what you fill in on your own device, so that your input is not lost. How long the draft remains depends on the function and the browser. You can remove it by clearing browser data.
How long your responses and content are stored is decided by the party that invited you. Where Fastpath is the processor, we delete according to the owner’s instructions.
Questions about what you have been invited to should be directed to the party that invited you.
Part C2 — With an account
In a customer workspace, the Customer is normally the controller for the content, while Fastpath is the processor. Where Fastpath determines the purpose, Fastpath is the controller. Fastpath is also the controller for the processing we ourselves determine in order to administer your account, sign-in and the security of the Services.
Access to an account arises in one of three ways: Fastpath creates the first administrators, a Workspace owner invites you (a customer, or Fastpath), or you request access yourself, for example by activating a demo. Your e-mail address, and name where provided, comes from the party that created or invited you — or from you, if you requested the access yourself. When you sign in, you can provide or update your name.
An invitation is usually valid for 14 days. You can be a member of several workspaces with different owners, using one and the same account. The Workspace owner decides what you can see and do, and can remove your access at any time.
When necessary, you will be asked to accept the Waysayer User Terms. That is an agreement between you and Fastpath, not a consent under the GDPR.
What Fastpath processes about you
| What we process | Why | Legal basis | How long |
|---|---|---|---|
| E-mail address, and name where provided | Identify you, give you access and send necessary service messages, such as invitations, one-time codes and account notifications | Performance of the User Terms (Art. 6(1)(b)) | For as long as the account exists, see “When your access is removed” |
| Membership of workspaces and your role in each of them | Control what you have access to | Performance of the User Terms (Art. 6(1)(b)) | For as long as the membership lasts |
| Invitations — who invited you, and when you accepted | Document how your access arose | Performance of a contract (Art. 6(1)(b)) and legitimate interest in traceability (Art. 6(1)(f)) | For as long as the account exists and thereafter for as long as necessary to document the access |
| Sign-in and security events: IP address, browser and time | Secure operation, and detecting and handling misuse | Legitimate interest in security, protection against misuse and stable operation (Art. 6(1)(f)) | Normally up to 90 days; longer where necessary to handle a specific incident or a legal claim |
| Operational and security logs from use of the platform | Troubleshooting, stable operation and detecting misuse | Legitimate interest (Art. 6(1)(f)) | Normally up to 90 days; longer where necessary to handle a specific incident or a legal claim |
| Support correspondence linked to a customer relationship | Respond and resolve the matter as part of the delivery to the customer | Performance of a contract where you are the contracting party yourself (Art. 6(1)(b)); otherwise legitimate interest in following up the delivery (Art. 6(1)(f)) | For as long as the customer relationship lasts, and thereafter up to 12 months |
| Support correspondence not linked to a customer relationship | Respond to you and resolve the matter | Legitimate interest (Art. 6(1)(f)) | Up to 12 months after the matter is closed |
| Which version of the User Terms you accepted, and when | Document the contractual relationship between you and Fastpath | Performance of a contract (Art. 6(1)(b)) and legitimate interest in being able to document the conclusion of the agreement (Art. 6(1)(f)) | For as long as necessary to document the contractual relationship |
The table describes categories, not a detailed list of every single technical event. Which data is recorded depends on the function, the security need and the hosting provider concerned.
Records of who created or changed something inside a workspace — for example “last modified by” on a record — are part of the content of the workspace, not an operational log with us. There, the Workspace owner is the controller, and the record lives as long as the content it belongs to.
Who can see the data about you
- The Workspace owner sees that you are a member, your e-mail address, your role, and records belonging to what you do in the workspace — for example that you have accepted an invitation, or that you have carried out an action in a process, a form or other content the organisation has set up. What is recorded there follows from how the organisation uses and configures the platform.
- Other users in the same workspace see what the Workspace owner has decided they should see.
- At Fastpath, access is limited to those who need it for operations and support.
- The sub-processors for Waysayer, see the list for the platform at fastpath.no/en/sub-processors. Fastpath’s own office and business tools appear in a separate part of the list and are not part of the platform infrastructure.
Sign-in and browser storage
How you sign in depends on how the workspace is set up. It may be e-mail and password, a passkey (WebAuthn), a one-time code by e-mail, sign-in via a social identity provider, or single sign-on (SSO) through the customer’s own identity provider where the customer has enabled it.
When sign-in takes place via an identity provider, we receive the data the provider sends us to identify you — typically e-mail address and name. The provider processes the sign-in under its agreement with you or with the customer.
The portals use cookies and other browser storage for sign-in, security, the selected workspace, language settings and unsaved drafts. Fastpath does not use this storage for advertising or behavioural tracking. If we later adopt optional analytics or other non-essential storage, we will provide information and ask for consent where required.
E-mail and other messages
Fastpath sends e-mail needed to give you access and operate the platform — for example invitations, one-time codes and notifications about your account.
E-mail, messages and other communications that an organisation sets up in Waysayer, including what an automation or integration sends, are the customer’s processing. Fastpath is the processor for it. The organisation determines the content and the recipients.
Agents you connect
You may connect an AI agent or other integration to Waysayer if the workspace allows it. The connection may receive personal data and other content covered by the permissions it has been given. The provider you choose processes the data under its own terms and its own privacy practices, unless it is provided by Fastpath as part of the Services. You must therefore have the right to share the data and assess the provider before the connection is activated.
Waysayer limits agent access to the permissions delegated to that connection. You or the Workspace owner can revoke the access.
When your access is removed
The Workspace owner administers membership and can remove your access to its workspace. You then lose access to the content there, while the content and necessary activity records remain under the owner’s control. Questions about a particular membership should normally be directed to the owner. Fastpath does not decide ordinary access questions on the owner’s behalf, but may act where necessary for security, statutory obligations or closure of your central account.
You can ask Fastpath to close your central account. This ends sign-in and access through the account, but does not automatically delete content for which the Workspace owner is the controller, or necessary records of actions already taken. We assess the request under the data protection rules and may ask you to contact the owner about data the owner controls.
Accounts without active memberships are deleted or anonymised no later than 24 months after the last sign-in. Certain data may be retained longer where necessary for a specific security incident, a legal obligation, or to establish, exercise or defend a legal claim. It is deleted when that specific need ends. An active membership does not prevent you from asking to close the account.
When a customer’s agreement with Fastpath ends, the customer has 30 days to export its data. Thereafter, deletion and any further retention are handled under the Customer Terms, the Data Processing Agreement and applicable law. This follows from the Customer Terms section 10 and the Data Processing Agreement.
Who to contact about what
| If it concerns … | Contact |
|---|---|
| the content of a workspace — what is registered about you there, rectification, deletion, why you were invited, who sees what | the organisation that owns the workspace. It is the controller for the content. |
| your central user account, closing the account, sign-in, security logs or this notice | personvern@fastpath.no |
If you do not get a reply from the Workspace owner, you can let us know. We cannot decide the matter on the Customer’s behalf, but can pass on the enquiry and assist the Customer where the data processing agreement requires it.
When we retain data longer than stated
The retention periods above are the main rule. We may retain specific data longer where there is a specific and documented need with a legal basis — for example to meet a statutory obligation, handle a specific security incident, or establish, exercise or defend a legal claim.
In that case we separate out or restrict access to what is actually needed for the purpose, reassess the need and delete when the specific need no longer exists.
Subcontractors and processors
The sub-processors for Waysayer provide the infrastructure and services the platform is built on. Fastpath also uses Waysayer in its own business, so the same platform list applies when we use the product ourselves. A separate part of the list covers fastpath.no and selected marketing and informational pages about Waysayer published by Fastpath. That part does not include the Waysayer platform itself or publicly accessible pages delivered through its modules. Our office and business tools are not the primary infrastructure for content in customers’ workspaces. They may nevertheless process an enquiry you send directly to Fastpath, and encrypted backups may contain Waysayer-related personal data processed in the course of Fastpath’s work.
The core solution and the primary data storage are mainly hosted by cloud providers within the EEA, currently including Amazon Web Services in Stockholm. Certain functions such as DNS, firewall, routing, e-mail and maps may use global provider networks. The fastpath.no website and selected marketing and informational pages about Waysayer may also be hosted by a provider other than the core platform provider. Which providers are used at any time is listed at fastpath.no/en/sub-processors.
We share your personal data with subcontractors when needed for the purpose for which it was collected. We enter into a data processing agreement or another relevant contractual basis depending on the provider’s role. We may also disclose personal data where required by law, or to establish, exercise or defend a legal claim.
Who the subcontractors are, what they are used for and where they process data is listed at fastpath.no/en/sub-processors, divided between Waysayer, websites and marketing pages, and Fastpath’s own business. That is the list we keep up to date, and it takes precedence over the examples above.
Transfers outside the EEA
We locate primary storage and core operations in the EEA where practical and agreed.
Some subcontractors nevertheless process data outside the EEA. Services for DNS, firewall and routing, for example, are delivered through global networks. Where processing takes place outside the EEA, we rely on a relevant transfer mechanism, such as an adequacy decision by the European Commission, the EU–US Data Privacy Framework or the EU Standard Contractual Clauses (SCCs).
Where each subcontractor processes data is listed at fastpath.no/en/sub-processors.
For the content the customer processes in Waysayer, the use of sub-processors and transfers are additionally governed by the Data Processing Agreement between Fastpath and the customer.
Security
We use technical and organisational measures appropriate to the data, the use and the risk, to protect personal data against unlawful or unauthorised processing.
The measures include encryption in transit and at rest where relevant, access control, backups and logging of security events.
Internally, we limit access based on tasks and need. We use authentication and access controls for the operating environments and review access as part of our security work. Subcontractors are given only the access needed for the service they provide.
Your rights
The rights below apply to the data for which Fastpath is the controller. You exercise them by sending an e-mail to personvern@fastpath.no. You are entitled to a reply without undue delay, and normally within one month at the latest. For complex or numerous requests, the deadline may be extended by up to two months; in that case we notify you within the first month.
- Access: You can request a copy of the data we process about you as controller.
- Rectification: You can ask us to correct or supplement data that is inaccurate or misleading.
- Erasure: You can request erasure when there is no longer a basis for the processing, when you withdraw a consent, or when the data was collected unlawfully.
- Restriction: You can ask for the processing to be restricted in certain situations.
- Data portability: Where the GDPR gives you that right, you can receive the data you have provided to us in a machine-readable format.
- Objection: You can object to processing based on legitimate interest, including communications about our services.
- Withdraw consent: Where the processing is based on consent, you can withdraw the consent at any time. This does not affect the lawfulness of the processing before the withdrawal.
If the right concerns content in a workspace in Waysayer, you must contact the organisation that owns the workspace. There, Fastpath is the processor, and we can only assist the customer in responding to you. See “Who to contact about what” in Part C.
We respond to a request for erasure within the deadlines above. When the conditions for erasure are met, we carry out the erasure without undue delay. Legal obligations, the Customer’s responsibility as controller or the need to defend legal claims may limit what Fastpath can delete.
Automated decisions
Fastpath does not use the data for which we are the controller regarding the website, the account or platform security to make decisions that are based solely on automated processing and have legal effects for you or similarly significantly affect you.
A Customer may configure processes, integrations or automations in its workspace. The Customer is responsible for the purpose and for informing you where such use is covered by the rules on automated decisions. Questions about this should be directed to the Workspace owner.
Complaints to the Norwegian Data Protection Authority
If you believe we are processing your personal data incorrectly, we hope you will tell us first at personvern@fastpath.no. You have in any case the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet), which supervises data protection law in Norway. See datatilsynet.no.
Changes to this notice
Fastpath may update this notice from time to time. The current version is available at fastpath.no/personvern (Norwegian) and fastpath.no/en/privacy (English), with the version number and date at the top. For material changes, we notify those we have an e-mail address or an account to reach — by e-mail, or in the platform where relevant.
Contact
Fastpath AS
Org. no. 920 497 837
Solveien 52, 1394 Nesbru, Norway
Privacy contact: personvern@fastpath.no
Fastpath does not have a data protection officer.