1. Who we are

1.1 Autopix AS, organisation number 926 408 763, Gaustadalléen 21, 0349 Oslo, Norway ("Autopix", "we", "us").

1.2 Autopix is established in Norway. Norway is a party to the Agreement on the European Economic Area ("EEA"), so Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR"), applies through the EEA Agreement. 

1.3 This privacy policy explains how Autopix processes personal data in connection with the Autopix Vehicle Platform (web, iOS and Android), related transactional communications, and Autopix's own marketing to actual users. A new Retail platform and API are due at the end of 2026; retail images are processed manually by sub-processors today. Where retail processing uses the same account and infrastructure, this notice applies; a Retail-specific description will be added when that platform launches.

2. Two roles — please read this first

Art. 4(7)–(8); Art. 13; Art. 28.

2.1 Autopix acts in two different roles. Which role applies decides who you contact and which parts of this notice are about Autopix's own decisions.

Role
What it covers
Who decides purpose and means
Controller
Your Autopix user account; authentication; product analytics (when you consent); marketing / newsletters to actual users; Autopix's own website and business records (including bookkeeping)
Autopix
Processor
Client content — vehicle images, orders, VIN and plates, QC workflow, and related dealership data put into the platform by a dealership or retail customer
The Client (your employer or the dealership that invited you). Autopix processes only on the Client's documented instructions

2.2 If you use Autopix because a dealership or brand invited you, for client content the Client is the controller. Requests about that content (for example erasure of an order image) should go to the Client first. Autopix assists the Client under Art. 28(3)(e) — see section 10.

2.3 The rest of this notice focuses on processing where Autopix is controller, and summarises processor processing so you can see the full picture.

3. Personal data we process as controller

Art. 13(1)(c); Art. 4(1).

3.1 Account and service delivery

When you register, sign in or use the platform as an Autopix user, we process:

  • name, email address, phone number (where provided);
  • authentication data (passwords hashed with bcrypt; one-time codes; OAuth access and refresh tokens; session data);
  • role and organisation membership;
  • device push tokens and notification preferences;
  • privacy settings (including analytics_enabled);
  • IP address and user agent (security, rate limiting, audit logs);
  • active sessions (which you can view and revoke).

3.2 Product analytics

If you turn analytics on, we process usage data through Google Analytics 4 ("GA4") via Google Tag Manager in the web client — see section 5.

3.3 Marketing

If you are an actual user and you consent, we may process your contact details to send marketing or newsletters. Electronic marketing also remains subject to applicable ePrivacy and Norwegian marketing rules on top of the GDPR basis.

3.4 Business and legal records

In connection with your company's use of the service we may process:

  • acceptance evidence for the terms and agreements you accept in the platform — the platform terms and conditions at sign-up, and your company's package terms: signer name, signer email, IP address, user agent, timestamp and terms version, plus the agreement PDFs generated at package-terms acceptance;
  • billing and ledger events needed for Autopix's accounts (handled in PowerOffice Go);
  • audit-log entries of security-relevant actions (actor, IP, user agent).

4. Purposes and lawful bases (controller)

Art. 6; Art. 13(1)(c).

Purpose
Examples of data
Lawful basis
Create and operate your user account; authenticate you; provide the platform
Account data, credentials, sessions, push tokens
Art. 6(1)(b) — performance of the user contract
Security, abuse prevention, audit of privileged actions
IP address, user agent, audit logs, rate-limit data
Art. 6(1)(b) — necessary to provide a secure service under the contract
Product analytics (web client)
Usage data via GA4 / Tag Manager
Art. 6(1)(a) — consent, via analytics_enabled
Marketing / newsletters to actual users
Email and related contact details
Art. 6(1)(a) — consent
Bookkeeping and tax
Billing ledger, invoices in PowerOffice Go
Art. 6(1)(c) — legal obligation (including bokføringsloven)
Keep contract evidence after acceptance / termination
Signer details, agreement PDFs
Art. 6(1)(b) while the contract runs; retention after end under Art. 6(1)(c) / Art. 17(3)(e) (legal claims) — see section 9
Organisation registry lookups (Brreg / Bolagsverket)
Organisation number; for some Swedish sole traders, personal identity number
Art. 6(1)(b) — necessary to set up and verify the company account

Providing account data is required to use the service. If you do not provide it, we cannot create or maintain your account (Art. 13(2)(e)).

Withdrawing consent. Where we rely on consent, you may withdraw it at any time (Art. 7(3)) without affecting the lawfulness of processing before withdrawal. Turn analytics off in privacy settings, or contact us to stop marketing. Turning analytics off stops new collection from that point; data already sent to Google remains with Google under Google's retention unless deleted through Google's tools.

5. Cookies and the analytics consent control

Art. 6(1)(a); Art. 7.

5.1 The web client uses a cookie-consent banner wired to privacy_settings. Flags are per-user and default off.

5.2 Single operative control at launch — analytics.
analytics_enabled gates GA4 via Tag Manager. The Tag Manager container does not load at all until you grant analytics consent — a strict block, not a load-then-gate pattern.

5.3 Analytics is the only consent category shown at launch. This notice does not describe a separate third-party or marketing cookie category, because no vendor sits behind one and no control that does nothing is shown to users.

5.4 The web client uses a backend-for-frontend pattern: OAuth tokens do not reach the browser. The browser holds an encrypted session cookie while the server proxies API calls. That session cookie is necessary for the logged-in service.

5.5 GA4 is configured with Google signals off, data-sharing off, ads links off, and EU data-collection settings. Contracting entities: Autopix AS (customer) and Google Ireland Limited (Google). Analytics data still reaches Google LLC in the United States through Google's own chain — see section 8.

6. When Autopix is processor (client content)

Art. 28; Art. 13 / Art. 14 via the Client.

6.1 Dealerships and retail customers ("Clients") upload and manage client content on the platform. For that content the Client is controller. Typical categories:

  • vehicle photographs and original file names;
  • order metadata, including VIN and registration plate (treated as personal data under Art. 4(1));
  • organisation and location records the Client supplies;
  • invitation recipient email addresses (stored); share-link recipient addresses (used to send mail and never stored).

6.2 What Autopix does with client content. On the Client's instructions Autopix runs an image pipeline: programmatic preprocessing, AI segmentation, machine-learning computer vision, programmatic alignment, and compositing onto templates. 

Background compositing removes incidental persons from delivered output. Stored originals follow the Client's retention plan.

6.4 Autopix's obligations as processor are set out in the data-processing terms that bind Autopix to each Client: the Autopix Data Processing Terms — a separate document incorporated into the platform terms and conditions and accepted in the same click — or, where the Client and Autopix have signed a separate data processing agreement, that signed agreement.

6.5 Share and invitation recipients. The dealer (Client) is controller for those recipients and holds the Art. 14 notice obligation. Outbound email identifies the dealer as sender.

7. Who we share personal data with

Art. 13(1)(e).

7.1 Sub-processors (platform delivery)

Autopix uses sub-processors to host and deliver the service. The same list appears in Schedule 1 to the Autopix Data Processing Terms (incorporated into the terms and conditions). In summary:

Who
What they do
where
Amazon Web Services (AWS)
Hosting, storage, databases, CDN, SES email
Frankfurt, EEA
Laravel Vapor
Deployment platform (access to Autopix's AWS account)
US entity
3sixtyfactory Inc.
Manual editing, QC, support (may download images locally)
Philippines
Kaleido AI (remove.bg)
Background removal (≤ 60 minutes retention); optional shadows
EU, EEA
OpenAI
Classification and QC only (JSON labels)
United States
Mailgun
Transactional email (one-time codes, notices)
EU endpoint, EEA
Vumo AI
Automated AI image processing for vehicle visualisation
Poland, EEA
Treblle Inc.
API observability — JSON only, no images; sensitive fields masked before data leaves Autopix's servers; data committed to Treblle's EU ingress endpoint
US contracting entity (operating HQ Zagreb, Croatia)
Pusher Limited
Real-time Channels; Beams push transport
Channels: EU. Beams: UK
Google (FCM) / Apple (APNS)
Push delivery — onward via Pusher Beams, not called directly by Autopix
US / Ireland
Google (GA4 / Tag Manager)
Analytics when you consent
See section 5

Autopix does not use a third-party application performance or error-tracking product. API observability is Treblle.

7.2 Autopix's own processors (controller activity)

PowerOffice Go processes Autopix's accounting records. It never processes client content and is not one of the sub-processors in section 7.1.

7.3 Client-authorised integrations (not Autopix sub-processors)

Autopix transmits data on the Client's instruction to an account the Client holds with that provider. Those providers are not Autopix Art. 28 sub-processors. Processing after transmission is their responsibility and the Client's. All four process in the EEA.

7.4 Public registers

Autopix queries public registries with an organisation number. They are public registers, not Autopix processors. 

7.5 We do not sell personal data

Autopix does not sell your personal data.

8. International transfers

Art. 13(1)(f); Chapter V GDPR.

8.1 Primary hosting is AWS eu-central-1 (Frankfurt), EEA, in Autopix's own AWS account.

8.2 Where personal data leaves the EEA, or a third-country entity has remote access that counts as a transfer under EDPB Guidelines 05/2021, Autopix relies on a Chapter V mechanism:

Transfer
Mechanism
OpenAI (US) — image classification/QC
EU–US Data Privacy Framework and/or Standard Contractual Clauses ("SCCs")
3sixtyfactory (Philippines) — editing/QC
Art. 46(2)(c) SCCs, Module 3
Laravel Vapor (US entity access)
SCCs
Google LLC via GA4 (US)
Data Privacy Framework and/or SCCs
FCM / APNS (via Beams)
Data Privacy Framework and/or SCCs
Pusher Beams (UK hosting) and Pusher as UK contracting entity
UK adequacy as incorporated into the EEA Agreement
Treblle (US contracting entity)
Chapter V engaged by entity access (EDPB Guidelines 05/2021); Autopix commits the data to Treblle's EU ingress endpoint

8.3 Client images leave the EEA to OpenAI (classification/QC) and to 3sixtyfactory (editing/QC).

8.4 EXIF metadata, including GPS coordinates, is stripped from stored originals at ingest, before anything is dispatched to the editing pipeline or the QC partner.

9. Retention

Art. 5(1)(e); Art. 13(2)(a); Art. 17(3).

9.1 Your user account

  • Self-service deletion: login is revoked immediately; the account is anonymised after a 30-day grace period (cancellation window). Anonymisation is irreversible — there is no mapping table.
  • The erasure audit entry records who performed the erasure and from which IP address; it does not retain your email address.
  • What erasure does not remove: orders, order events, billable events and existing audit-log rows survive as business records. Order data, including original file names, is removed on the order retention schedule below, not on user erasure. Do not read "account deleted" as "every copy of everything you ever touched is gone."

9.2 Client images and orders (processor operations; shown for transparency)

Plan
Client access
Permanent deletion
Free
30 days from order completion
30 days after archiving (≈ 60 days effective)
Extended
12 months from order completion
30 days after archiving (≈ 13 months effective)
Unlimited
While the plan is active
On downgrade/cancellation, the target plan's schedule applies

Deletion is genuine: image files (including thumbnails and variants) and database records are hard-deleted. Database backups are retained 7 days; deleted data ages out of backups within 7 days of deletion running.

9.3 Other periods

Record
Period
GDPR export files
7 days
Auth tokens
Access 15 minutes; refresh 30 days; personal access tokens 6 months. Expired and revoked token records are deleted within 7 days of expiry
Invitations
Expired and cancelled invitation records are pruned 90 days after they lapse
Audit logs
2 years, then pruned
Application logs (CloudWatch)
One month
Billing ledger
5 years from end of accounting year (bokføringsloven § 13)
Agreement PDFs and acceptance evidence
Contract end + 5 years. The clock runs from contract end, not acceptance. User erasure does not scrub signer fields — signer name, email and IP are retained for the establishment, exercise or defence of legal claims (Art. 17(3)(e))
Company assets (logos, plate images, reference images)
Hard-deleted on asset deletion, and purged on company offboarding
remove.bg working copies
≤ 60 minutes at the vendor

10. Your rights

Arts. 12–22; Art. 77.

10.1 Where Autopix is controller

You have the right to:

  1. Access — obtain confirmation and a copy of your personal data
    (Art. 15). The platform offers a per-user self-service export.
  2. Rectification — correct inaccurate data (Art. 16).
  3. Erasure — in the circumstances in Art. 17, subject to the
    retention grounds in section 9 (including Art. 17(3)(b) and (e)).
  4. Restriction — in the circumstances in Art. 18.
  5. Portability — receive data you provided under contract or
    consent in a structured, commonly used, machine-readable format (Art. 20).
  6. Object — where processing is based on legitimate interests
    (Art. 21). Autopix does not currently rely on Art. 6(1)(f) for the controller activities listed in section 4; you always have the right to object to direct marketing (Art. 21(2)).
  7. Withdraw consent — at any time where we rely on consent
    (Art. 7(3)) — see section 4.

10.2 How to exercise rights against Autopix

Email support@autopix.no (or use in-product export / account deletion where available). We respond within one month of receipt (Art. 12(3)), with a possible extension of up to two further months for complex or numerous requests, in which case we will tell you why.

10.3 Where Autopix is processor

For personal data in client content, contact the Client (controller). Autopix will assist the Client under the applicable data-processing terms (Art. 28(3)(e)), typically within 10 business days of the Client's request to Autopix.

11. Security

Art. 32; Art. 13 does not require a full measures list — summary only.

11.1 Autopix implements appropriate technical and organisational measures. The contractual description for Clients sits in their data-processing terms with Autopix (see section 6.4). In short:

  • TLS 1.2 minimum in transit; private S3 storage; encryption at rest for storage, cache and databases, with encrypted snapshots;
  • role-based access control; 
  • privileged content-access logging, and logging of QC and public share link resolution;
  • dependency scanning on every deploy, and patching of critical vulnerabilities within 7 days and high-severity ones within 30 days;
  • personal data breach notification to Client controllers within 24 hours of Autopix becoming aware (Art. 33(2), via the Client's data-processing terms).

11.2 Autopix personnel may download client images to company-owned workstations when a task cannot be completed in the platform. Everyone with that access is bound by a written confidentiality undertaking; access is removed when a person leaves; and local copies live in a designated folder and are deleted when the task is done, and in any case within 14 days of download.

12. Children

The platform is a business service for dealership and retail professionals. It is not directed at children. Autopix does not knowingly create accounts for children.

13. Changes to this notice

Art. 13–14 ongoing transparency.

13.1 We may update this privacy policy from time to time.

13.2 We notify account holders by email only. There is no contractual notice period beyond the minimum required by applicable law.

14. Contact and complaints

Controller (for account, analytics, marketing)

Autopix AS, Gaustadalléen 21, 0349 Oslo

Privacy contact

support@autopix.no · +47 477 63 333