Privacy Policy
Last updated: 2 May 2026
1. Introduction
This Privacy Policy describes how Stack Seven AS, Terrasseveien 31 E, 1363 Høvik, Norway, company registration number 938 211 795 ("Stack Seven", "we", "us", or "our") processes personal data in connection with Policy Confirm, our websites, communications, and related business operations.
Policy Confirm is a business-to-business software-as-a-service platform used by organizations to distribute internal policies and document acknowledgements in a controlled and auditable manner. The service is intended solely for professional use by organizations and individuals invited by those organizations.
This Privacy Policy applies to website visitors, customers and prospective customers, authorized users invited to use Policy Confirm by a customer, and individuals who communicate with us for sales, support, or administrative purposes.
This Privacy Policy does not replace or override any data processing agreement entered into between Stack Seven and its customers.
2. Roles and responsibilities
When Policy Confirm is used by an organization to manage policies for its employees, contractors, or external recipients, the customer acts as the data controller for personal data relating to those individuals. The customer determines which individuals are invited to the service, which policies are distributed, how long data is retained, and the legal basis for processing end-user personal data.
In these scenarios, Stack Seven acts as a data processor and processes personal data solely on documented instructions from the customer, in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK GDPR, the Norwegian Personal Data Act, and the applicable Data Processing Agreement.
Stack Seven also acts as an independent data controller for personal data processed for its own legitimate business purposes. This includes processing related to sales and marketing activities, account administration, billing and payments, customer support, service security, fraud prevention, service improvement, and compliance with legal obligations.
A Data Processing Agreement compliant with Article 28 of the GDPR is available at policyconfirm.com/legal/dpa and applies when the customer uses the service to process personal data.
3. Categories of personal data
Depending on the context in which the service is used or an interaction takes place, Stack Seven may process personal data relating to authorized end users, customer representatives, and website visitors.
End users invited by a customer: name, work email address, organizational affiliation, policy acknowledgement status, timestamps related to actions such as sending, viewing, and confirming policies, and limited technical metadata associated with confirmations such as IP address and browser information.
Customers and business contacts: name, job title, company affiliation, business contact details, account credentials, contractual and billing information, and communications related to support or service administration.
Website visitors: technical and usage data such as IP address, device and browser information, usage logs, and information collected through cookies or similar technologies, as further described in Section 11.
Newsletter subscribers: name and email address provided through the subscription form on our website, used to send updates about Policy Confirm.
Stack Seven does not process special categories of personal data within the meaning of Article 9 of the GDPR. The service is not designed for the processing of such data, and customers are required to refrain from uploading or distributing documents containing such data through the service.
4. Purposes and legal bases for processing
When Stack Seven processes personal data on behalf of a customer as a data processor, such processing is carried out for the purpose of delivering Policy Confirm, enabling controlled policy distribution and confirmation, maintaining audit logs and proof documentation, and ensuring the security, availability, and reliability of the service. The legal basis for this processing is determined by the customer.
When Stack Seven acts as a data controller, personal data is processed on the following legal bases:
- Performance of a contract (Article 6(1)(b) GDPR) — for account creation, service delivery, billing, and customer support.
- Legitimate interests (Article 6(1)(f) GDPR) — for service improvement, security, fraud prevention, internal analytics, and direct communication with existing customers about the service.
- Legal obligation (Article 6(1)(c) GDPR) — for tax, accounting, and other regulatory record-keeping.
- Consent (Article 6(1)(a) GDPR) — for non-essential cookies, marketing communications to prospects, and newsletter subscriptions. Consent may be withdrawn at any time.
5. Data retention
Stack Seven retains personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by applicable law.
- Customer and authorized user data: retained for up to 90 days after the end of the customer's active subscription, following a 30-day export period, unless otherwise agreed with the customer or required by law.
- Trial account data: retained for up to 90 days after the end of the trial period.
- Email correspondence and support tickets: retained for up to 24 months, unless a longer retention period is necessary to meet legal, accounting, or dispute-resolution requirements.
- Billing and payment data: retained in accordance with applicable accounting, tax, and financial regulations (typically 5 years under Norwegian law).
- Audit logs, confirmation records, and proof documentation: may be retained for longer periods where necessary to support compliance, auditability, and contractual obligations, subject to customer instructions and applicable law.
- Newsletter and marketing data: retained until the individual unsubscribes or objects to processing.
- Website analytics data: retained for up to 14 months.
After the applicable retention period expires, personal data is deleted or anonymized in accordance with Stack Seven's internal deletion routines.
6. Sub-processors
Stack Seven engages a limited number of carefully selected sub-processors to operate and deliver Policy Confirm. Sub-processors are bound by written agreements imposing data protection obligations no less protective than those set out in our Data Processing Agreement, in accordance with Article 28(4) of the GDPR.
A current list of sub-processors, including their roles, processing locations, and applicable transfer mechanisms, is published at policyconfirm.com/legal/subprocessors and forms part of this Privacy Policy.
7. International data transfers
Policy Confirm is offered as a global service, and personal data may be processed within the European Economic Area, the United Kingdom, the United States, and other jurisdictions, depending on the sub-processors involved.
Where personal data is transferred outside the EEA or the United Kingdom to a country that does not benefit from an adequacy decision, Stack Seven ensures appropriate safeguards are in place. These include:
- EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914)
- EU-US Data Privacy Framework, where applicable
- UK Extension to the EU-US Data Privacy Framework, where applicable
- Other lawful transfer mechanisms recognized under applicable data protection law
Details of which transfer mechanism applies to each sub-processor are available at policyconfirm.com/legal/subprocessors.
8. Security measures
Stack Seven implements appropriate technical and organizational security measures designed to protect personal data against unauthorized access, loss, alteration, or disclosure, in accordance with Article 32 of the GDPR.
These measures include role-based access controls, multi-factor authentication, encryption in transit and at rest, logging and audit trails, immutable confirmation records, regular backups, and secure development and operational practices.
Security is a core design principle of Policy Confirm, with a strong emphasis on traceability, explicit user actions, and audit readiness.
9. Data subject rights
Under the GDPR and applicable data protection law, individuals have the right to:
- Access their personal data
- Request rectification of inaccurate or incomplete data
- Request erasure of their data ("right to be forgotten")
- Restrict or object to processing
- Request data portability
- Withdraw consent where processing is based on consent
- Lodge a complaint with a supervisory authority
Where personal data is processed on behalf of a customer, requests should generally be directed to the relevant customer as data controller. Stack Seven will assist customers in responding to such requests in accordance with applicable law and contractual obligations.
For personal data where Stack Seven acts as data controller, requests can be submitted to contact@policyconfirm.com. Stack Seven will respond within one month in accordance with Article 12 of the GDPR.
Individuals in Norway have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no). Individuals in other EEA countries may lodge a complaint with their local supervisory authority.
10. Automated decision-making
Stack Seven does not use personal data for automated decision-making or profiling that produces legal effects or similarly significant effects on individuals within the meaning of Article 22 of the GDPR.
11. Cookies and website analytics
Policy Confirm uses cookies and similar technologies on our website to make the site work, to understand how it is used, and to measure our advertising.
We use three categories of cookies. They are the same three shown in the cookie banner and in the cookie declaration — this page cannot describe a category the banner does not offer:
- Strictly necessary cookies are needed for the site to work and for services you ask for, such as the live chat. They are always on and do not require consent. They are not used to track you across other websites.
- Analytics cookies help us see which pages people read and where they get stuck, so we can improve the site. We look at patterns across visitors rather than at what any one person does. These require consent.
- Marketing cookies let us measure whether our LinkedIn advertising reaches the right people and leads anywhere. This is the category that shares data with LinkedIn. These require consent.
Cookies in the analytics and marketing categories are placed only after you consent to them, and nothing in those categories is loaded before that. Consent is obtained through a cookie banner on first visit and may be withdrawn at any time by clicking in the website footer to reopen the consent preferences.
A complete list of cookies in use, including their names, providers, purposes, and retention periods, is available in our Cookie declaration.
12. California privacy rights (CCPA/CPRA)
This section applies to residents of California and supplements the information contained elsewhere in this Privacy Policy.
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), Stack Seven acts as a "Service Provider" (or "Processor") for our business customers. We process personal information solely on behalf of our customers to provide Policy Confirm.
No sale or sharing: Stack Seven does not sell personal information and does not share personal information for cross-context behavioral advertising.
Categories of personal data collected: identifiers (name, email, IP address), professional information (job title, employer), commercial information (records of policies sent and acknowledged), and internet activity (interaction logs).
Your rights: California residents may request access to, deletion of, or correction of their personal information. If you are a user invited to Policy Confirm by your employer, please contact your employer directly, as they are the controller of your data. If you contact us directly, we will forward your request to the relevant customer.
13. Data Protection Officer and EU representative
Stack Seven is not required to designate a Data Protection Officer under Article 37 of the GDPR. Stack Seven is established within the EEA (Norway) and is therefore not required to designate an EU representative under Article 27 of the GDPR.
For all data protection inquiries, please contact: contact@policyconfirm.com.
14. Changes to this Privacy Policy
Stack Seven may update this Privacy Policy from time to time to reflect changes in the service, legal requirements, or processing practices. The most current version will always be available on our website.
Material changes will be notified to active customers by email at least 30 days before they take effect. Previous versions of this Privacy Policy are available on this page.
15. Contact information
For questions about this Privacy Policy or Stack Seven's data protection practices, please contact:
Stack Seven AS
Terrasseveien 31 E
1363 Høvik
Norway
Email: contact@policyconfirm.com