1. About this policy and the service
This policy applies to use of the service and explains what personal data is processed, why it is processed, who receives it, how long it is retained and the rights available to data subjects.
This policy applies to the following service: A consumer digital theory-learning service with practice questions, progress tracking and paid time-limited access for Norwegian driving-licence preparation.
If translations conflict, the Norwegian text prevails. Translations are provided to make the information easier to understand.
2. Who is responsible?
MDataService is the controller for customer-account, contact-person, billing, security, support and service-operation data.
- Company details
- Mahmuod Data Service
- Organisation number
- 927978792
- Address
- Dragehodesvingen, 1360 Fornebu, Norway
- Privacy contact
- teori@mdataservice.com
+4741138005 - Data protection officer
- No separate data protection officer has been stated. Privacy questions may be sent to the privacy contact.
3. Data we process
Depending on the features used, we may process these categories:
- Name, user ID, role and customer account
- Business name, email, phone and contact person
- Login events and authentication identifiers
- IP address, browser, device, timestamps and feature use
- Security logs, errors, audit trail and abuse indicators
- Email, support cases and feedback
The service is not intended for deliberate collection of special-category data. Customers must not upload health, biometric, political, religious or other sensitive data unless a valid legal basis, necessary safeguards and a written agreement are in place.
Teori App may process practice answers, scores, completed topics, learning progress and inferred weak topics when those learning functions are enabled. It does not treat an internal practice result as an official examination result.
Service-specific privacy information
Teori App processes only data needed for the account, purchase, security and selected learning functions. Learning results are internal practice indicators, not official exam results.
Account data
- Full name
- Yes
- Yes
- Phone
- No
- Date of birth
- No
- Purchase data
- No
- Complete card data stored
- No
Learning data
- Progress
- Yes
- Answers and scores
- Yes
- Weak topics
- Yes
Learning progress is retained for up to 365 days. After account deletion, active account data is normally removed within 30 days, except statutory accounting or dispute records.
4. Sources of data
We receive data directly from users or customers, from devices and browsers using the service, from forms and communications, and from providers or integrations the user chooses to enable.
5. Purposes and legal bases
We use personal data only for specified purposes and under a valid legal basis:
Data needed for an account, contract, security or a selected feature must be provided for us to deliver the service. Optional data and features are identified as optional.
Learning records are used to provide progress views, explanations and optional study guidance. They are not used for a decision that legally determines whether the user may drive or take an official examination.
9. Transfers outside the EEA
Some platform and operational providers may process data outside the EEA. Where GDPR requires it, we rely on an adequacy decision or the European Commission's Standard Contractual Clauses, assess transfer risks and use supplementary technical and organisational measures. Details of the relevant transfer mechanism can be requested from the privacy contact.
10. Retention and deletion
We do not retain personal data longer than necessary. These default periods apply unless the customer agrees a shorter period or law requires longer retention:
- Account and contact data
- For the customer relationship and up to 30 days after closure, unless law requires longer.
- Security and audit logs
- Up to 12 months, with a possible extension for an incident or legal claim.
- Support cases
- Up to 24 months after the case closes.
- Accounting and payment data
- Normally 5 years, or the period required by Norwegian bookkeeping and tax law.
- Backups
- Remnants may remain in access-restricted backups for up to 90 days.
11. Information security
We use risk-based technical and organisational measures to protect confidentiality, integrity and availability. No solution can guarantee absolute security, but we review controls regularly and manage incidents through a documented response process.
- Encryption in transit (TLS)
- Encryption at rest
- Separate encryption of platform tokens
- Least privilege and limited API permissions
- Role-based access
- Multi-factor authentication for administrative access
- Audit and security logging
- Restricted backups and deletion cycle
- Incident response and notification procedures
- Security and privacy review of providers
12. Your rights
Where MDataService is the controller, subject to GDPR conditions you may request access, correction, erasure, restriction and portability, object to processing based on legitimate interests, and withdraw consent without affecting prior lawful processing. Where the customer is the controller, contact the customer first; we assist the customer as processor.
We may request reasonable information to verify identity and prevent disclosure to the wrong person. Requests are normally free of charge.
13. Deleting app data
You can request deletion of data connected with this service in these ways:
- Use any deletion option available in the account or profile settings.
- Send a written request to the privacy contact with the account email and service name.
- Do not send passwords, payment details or other secrets in the request.
After verification, we disable relevant integrations and delete data from active systems without undue delay, normally within the stated active-deletion period. Data lawfully retained is blocked from other use. Backup remnants are deleted through automatic overwrite.
teori@mdataservice.com14. This policy website
By default, this static policy site sets no cookies, uses no analytics and has no login. Netlify may process limited technical logs to deliver the site securely. If analytics or tracking is later enabled, this policy and any required consent mechanism must be updated first.
15. Children
A user must be at least 18 to create and pay for their own account. A younger learner may use the service only where a parent or guardian lawfully creates or purchases access and provides necessary supervision. The service does not request date of birth unless that field is enabled and necessary.
16. Automated decisions and marketing
The service does not make automated decisions producing legal or similarly significant effects on individuals. We do not use customer audience data for our own direct marketing. Any optional marketing to customers is sent only with a valid basis and a clear opt-out.
17. Changes
We update this policy when processing, providers or law changes. Material changes are notified in the service or directly to customers before they take effect where practical and required. The date and version above identify the current edition.
18. Contact and complaints
Send questions or rights requests to the privacy contact. You may also complain to Datatilsynet or the supervisory authority where you live or work.
Official guidance sources
These links document the template's legal basis and guidance; they do not replace a specific legal review of the service's actual processing.