Privacy Policy

Effective date
1 January 2025
Version
1.0

Myta AS (“Myta”, “we”, “us”, “our”) is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and your rights. It applies to visitors to our website, users of our Service, and representatives of our business customers.

1. Who We Are and How to Contact Us

Myta AS is the data controller for personal data processed in connection with the use of the Service and our website. To contact us about privacy matters:

Company
Myta AS
Email
hi@myta.io
Website
myta.io

For questions about this policy or to exercise your data rights, contact our Data Protection contact at hi@myta.io.

2. Scope of This Policy

2.1 What this covers

This policy applies to personal data Myta processes as a data controller, including operating our website, managing accounts, communicating with users, ensuring security, and maintaining and improving the Service.

2.2 What this does not cover

When customer organisations use the Myta Service and submit personal data about their own employees or end users. Myta acts as a data processor on behalf of the customer. In such cases, the processing of such data is governed by the applicable agreement between Myta and the customer, including the Data Processing Agreement rather than this policy.

3. Personal Data We Collect

3.1 Data you provide directly

CategoryExamples
Account dataName, email address, job title, organisation name, password (hashed)
Billing dataBillig name, address, VAT number. Payment card details are handled by our payment processor and not stored by Myta
Profile dataProfile picture, preferences, notification settings
CommunicationsMessages you send to our support team, survey responses, feedback

3.2 Data collected automatically

CategoryExamples
Usage dataFeatures accessed, frequency of use, AI feature interactions, session duration, in-app actions
Device and access dataIP address, browser type, operating system, device type, language settings
Log dataServer logs, error reports, performance metrics
Cookie dataSee Section 10 for details

3.3 Data from third parties

We may receive data about you from:

  • Your employer or the organisation that purchased a Myta subscription on your behalf;
  • Single sign-on (SSO) providers (e.g. Google Workspace, Microsoft Azure AD), if your
  • ganisation uses SSO to access the Service; and
  • Publicly available sources, for business development and sales purposes.

4. How We Use Your Personal Data

PurposeDetails
Providing the ServiceCreating and managing your account, delivering features, authentication, and sending service-related notifications.
AI FeaturesUsing account and usage data to personalise AI-generated suggestions, goal-setting assistance, and strategic insights within the Service.
Billing and paymentsProcessing subscriptions, issuing invoices, managing renewals, and handling payment queries.
Customer supportResponding to support tickets, diagnosing technical issues, and improving support quality.
Product improvementAnalysing how users interact with the Service to prioritise feature development and improve the AI models (using anonymised or aggregated data where possible).
Security and complianceDetecting fraud, preventing unauthorised access, complying with legal obligations, and enforcing our Terms.
MarketingSending product updates, newsletters, and promotional information to existing users and prospects (with consent or opt-out, as applicable).
Partner programSharing relevant account information with authorised reseller or implementation partners involved in your subscription.

Myta does not independently disclose personal data to third-party AI service providers. Any inclusion of personal data in inputs to such AI Features is determined entirely by the customer and its users. Personal data will only be processed by third-party AI providers where the customer or its users choose to include such data in inputs to AI features. In those cases, the data is processed by third-party AI providers acting on Myta’s behalf and solely for the purpose of providing the requested functionality.

Myta does not use personal data processed in connection with the Service to train or fine-tune general-purpose AI models made available to other customers.

5. Legal Bases for Processing

We process personal data under the following legal bases (as applicable under the GDPR or similar legislation):

Legal basisWhen we rely on it
ContractTo provide the Service and fulfil our obligations under the Terms and Conditions.
Legitimate interestsProduct improvement, security monitoring, direct marketing to existing customers, fraud prevention.
Legal obligationCompliance with tax law, regulatory requirements, and responding to lawful requests from authorities.
ConsentMarketing communications to prospects; certain non-essential cookies. You may withdraw consent at any time.

6. How We Share Your Data

6.1 Service providers

We share data with trusted third-party service providers who help us operate the Service, including:

  • Cloud infrastructure providers (for hosting and storage);
  • Payment processors (for subscription billing);
  • Analytics providers (to understand Service usage);
  • Email and communication providers (for notifications and support); and
  • Identity and authentication providers.

All service providers are subject to data processing agreements and may only process data on our instructions.

6.2 Partners

If your subscription was arranged through a Myta authorised partner, we may share relevant account and usage data with that partner to the extent necessary for them to fulfil their obligations to you.

6.3 Business transfers

In the event of a merger, acquisition, or sale of all or substantially all of Myta’s assets, personal data may be transferred to the acquiring entity, subject to equivalent privacy protections.

6.4 Legal requirements

We may disclose personal data if required to do so by applicable law, court order, or governmental authority, or where we believe disclosure is necessary to protect Myta’s rights or the safety of any person.

6.5 We do not sell your data

Myta does not sell, rent, or trade personal data to third parties for their own marketing purposes.

7. International Transfers

Myta's primary infrastructure is located within the European Economic Area (EEA).

Where we transfer personal data to service providers or partners outside the EEA, we ensure that appropriate safeguards are in place, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • Transfers to countries with an adequacy decision from the European Commission; or
  • Other lawful transfer mechanisms as permitted under applicable data protection law.

This may include AI infrastructure or model providers used to deliver the AI Features, acting on Myta's behalf. You may request a copy of the relevant transfer safeguards by contacting hi@myta.io.

8. Data Retention

Data typeRetention period
Account dataDuration of the subscription + 12 months, then deleted or anonymised.
Customer-submitted data (Service content)30 days after termination, unless a data export is requested. See Terms Section 8.4.
Billing and financial records5 years from the end of the tax year, as required by Norwegian accounting law.
Support communications3 years from the date of the interaction.
Usage and analytics dataUp to 24 months (aggregated/anonymised data may be retained indefinitely).
Marketing contactsUntil opt-out or 2 years of inactivity.
Logs and AILogs and AI interaction data may be retained for a limited period for security, debugging, and service improvement purposes.

Retention periods may be extended where required by law, regulation, or for the establishment, exercise, or defence of legal claims.

9. Your Rights

Subject to applicable law, you have the following rights regarding your personal data:

RightWhat it means
AccessRequest a copy of the personal data we hold about you.
RectificationAsk us to correct inaccurate or incomplete data.
ErasureRequest deletion of your data in certain circumstances.
RestrictionAsk us to limit the processing of your data in certain cases.
PortabilityReceive your data in a structured, machine-readable format.
ObjectionObject to processing based on legitimate interests or for direct marketing.
Withdraw consentWithdraw consent at any time where processing is consent-based.
Lodge a complaintComplain to the Norwegian Data Protection Authority (Datatilsynet) at datatilsynet.no.

To exercise any of these rights, contact us at hi@myta.io. We will respond within 30 days. We may need to verify your identity before processing your request.

10. Cookies and Tracking Technologies

10.1 Types of cookies we use

TypePurposeConsent required?
Strictly necessaryAuthentication, security, session management. Required for the Service to function.No
FunctionalRemembering user preferences, language settings, and personalisation choices.No
AnalyticsUnderstanding how users navigate the website and Service to improve performance. Data is aggregated and anonymised where possible.Yes
MarketingTracking visitors across websites to deliver relevant advertising and measure campaign effectiveness.Yes

10.2 Managing cookies

You can manage your cookie preferences through our cookie consent banner, displayed on first visit to our website. You can also control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of the Service.

11. Security

Myta implements appropriate technical and organisational security measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:

  • Encryption of data in transit (TLS 1.2+) and at rest;
  • Role-based access controls and principle of least privilege;
  • Regular security assessments and penetration testing;
  • SOC 2-aligned operational practices;
  • Incident response and breach notification procedures in accordance with applicable law.

If you believe your account or personal data has been compromised, please contact us immediately at hi@myta.io.

12. Children's Data

The Service is intended for use by business professionals and is not directed at children under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will take steps to delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Service features. We will notify you of material changes by email or by prominently displaying a notice within the Service, at least 30 days before the change takes effect.

Continued use of the Service after the effective date constitutes acceptance of the updated policy.