GDPR · EEA · Datatilsynet

Privacy Policy

A consumer digital theory-learning service with practice questions, progress tracking and paid time-limited access for Norwegian driving-licence preparation.

Last updated: 19 July 2026Effective: 19 July 2026Version: 1.0

1. About this policy and the service

This policy applies to use of the service and explains what personal data is processed, why it is processed, who receives it, how long it is retained and the rights available to data subjects.

This policy applies to the following service: A consumer digital theory-learning service with practice questions, progress tracking and paid time-limited access for Norwegian driving-licence preparation.

If translations conflict, the Norwegian text prevails. Translations are provided to make the information easier to understand.

2. Who is responsible?

MDataService is the controller for customer-account, contact-person, billing, security, support and service-operation data.

Company details
Mahmuod Data Service
Organisation number
927978792
Address
Dragehodesvingen, 1360 Fornebu, Norway
Privacy contact
teori@mdataservice.com
+4741138005
Data protection officer
No separate data protection officer has been stated. Privacy questions may be sent to the privacy contact.

3. Data we process

Depending on the features used, we may process these categories:

  • Name, user ID, role and customer account
  • Business name, email, phone and contact person
  • Login events and authentication identifiers
  • IP address, browser, device, timestamps and feature use
  • Security logs, errors, audit trail and abuse indicators
  • Email, support cases and feedback

The service is not intended for deliberate collection of special-category data. Customers must not upload health, biometric, political, religious or other sensitive data unless a valid legal basis, necessary safeguards and a written agreement are in place.

Teori App may process practice answers, scores, completed topics, learning progress and inferred weak topics when those learning functions are enabled. It does not treat an internal practice result as an official examination result.

Service-specific privacy information

Teori App processes only data needed for the account, purchase, security and selected learning functions. Learning results are internal practice indicators, not official exam results.

Account data

Full name
Yes
Email
Yes
Phone
No
Date of birth
No
Purchase data
No
Complete card data stored
No

Learning data

Progress
Yes
Answers and scores
Yes
Weak topics
Yes

Learning progress is retained for up to 365 days. After account deletion, active account data is normally removed within 30 days, except statutory accounting or dispute records.

4. Sources of data

We receive data directly from users or customers, from devices and browsers using the service, from forms and communications, and from providers or integrations the user chooses to enable.

5. Purposes and legal bases

We use personal data only for specified purposes and under a valid legal basis:

Create and manage the customer account and provide the serviceContract, GDPR Art. 6(1)(b)
Authenticate users and connect selected social accountsContract and legitimate interest in secure access, Art. 6(1)(b), (f)
Support and service communicationContract and legitimate interests, Art. 6(1)(b), (f)
Secure accounts, prevent misuse and handle incidentsLegitimate interests and legal obligations, Art. 6(1)(f), (c)
Troubleshoot and improve stability and usabilityLegitimate interests, Art. 6(1)(f); aggregated data where possible
Meet law and establish or defend legal claimsLegal obligation and legitimate interests, Art. 6(1)(c), (f)

Data needed for an account, contract, security or a selected feature must be provided for us to deliver the service. Optional data and features are identified as optional.

Learning records are used to provide progress views, explanations and optional study guidance. They are not used for a decision that legally determines whether the user may drive or take an official examination.

8. Sharing and processors

We share data only where needed to provide the service, follow customer instructions, meet legal requirements, or protect rights and security. We do not sell personal data. Providers are bound by contracts, confidentiality, security requirements and documented instructions where they act as processors.

ProviderPurposeProcessing regionPrivacy
NetlifyHosting this public privacy-policy siteGlobal infrastructurePrivacy

9. Transfers outside the EEA

Some platform and operational providers may process data outside the EEA. Where GDPR requires it, we rely on an adequacy decision or the European Commission's Standard Contractual Clauses, assess transfer risks and use supplementary technical and organisational measures. Details of the relevant transfer mechanism can be requested from the privacy contact.

10. Retention and deletion

We do not retain personal data longer than necessary. These default periods apply unless the customer agrees a shorter period or law requires longer retention:

Account and contact data
For the customer relationship and up to 30 days after closure, unless law requires longer.
Security and audit logs
Up to 12 months, with a possible extension for an incident or legal claim.
Support cases
Up to 24 months after the case closes.
Accounting and payment data
Normally 5 years, or the period required by Norwegian bookkeeping and tax law.
Backups
Remnants may remain in access-restricted backups for up to 90 days.

11. Information security

We use risk-based technical and organisational measures to protect confidentiality, integrity and availability. No solution can guarantee absolute security, but we review controls regularly and manage incidents through a documented response process.

  • Encryption in transit (TLS)
  • Encryption at rest
  • Separate encryption of platform tokens
  • Least privilege and limited API permissions
  • Role-based access
  • Multi-factor authentication for administrative access
  • Audit and security logging
  • Restricted backups and deletion cycle
  • Incident response and notification procedures
  • Security and privacy review of providers

12. Your rights

Where MDataService is the controller, subject to GDPR conditions you may request access, correction, erasure, restriction and portability, object to processing based on legitimate interests, and withdraw consent without affecting prior lawful processing. Where the customer is the controller, contact the customer first; we assist the customer as processor.

We may request reasonable information to verify identity and prevent disclosure to the wrong person. Requests are normally free of charge.

teori@mdataservice.comWe normally respond within one month and use an internal target of 30 days after identity verification. For complex or numerous requests, GDPR permits an extension of up to 2 months; we will notify you within the first month.

13. Deleting app data

You can request deletion of data connected with this service in these ways:

  1. Use any deletion option available in the account or profile settings.
  2. Send a written request to the privacy contact with the account email and service name.
  3. Do not send passwords, payment details or other secrets in the request.

After verification, we disable relevant integrations and delete data from active systems without undue delay, normally within the stated active-deletion period. Data lawfully retained is blocked from other use. Backup remnants are deleted through automatic overwrite.

teori@mdataservice.com

14. This policy website

By default, this static policy site sets no cookies, uses no analytics and has no login. Netlify may process limited technical logs to deliver the site securely. If analytics or tracking is later enabled, this policy and any required consent mechanism must be updated first.

15. Children

A user must be at least 18 to create and pay for their own account. A younger learner may use the service only where a parent or guardian lawfully creates or purchases access and provides necessary supervision. The service does not request date of birth unless that field is enabled and necessary.

16. Automated decisions and marketing

The service does not make automated decisions producing legal or similarly significant effects on individuals. We do not use customer audience data for our own direct marketing. Any optional marketing to customers is sent only with a valid basis and a clear opt-out.

17. Changes

We update this policy when processing, providers or law changes. Material changes are notified in the service or directly to customers before they take effect where practical and required. The date and version above identify the current edition.

18. Contact and complaints

Send questions or rights requests to the privacy contact. You may also complain to Datatilsynet or the supervisory authority where you live or work.

Mahmuod Data ServiceDragehodesvingen, 1360 Fornebu, Norwayteori@mdataservice.com
Datatilsynet (Norwegian Data Protection Authority)Complaint / Klage

Official guidance sources

These links document the template's legal basis and guidance; they do not replace a specific legal review of the service's actual processing.