Skip to main content

Privacy Policy

Last Updated: March 12, 2026

This Privacy Policy explains how Viom Academy (“we”) collects, uses, and protects your personal data when you visit our website and when you contact us about hair styling courses delivered in Norway. It also explains your rights under the General Data Protection Regulation (GDPR) and related Norwegian privacy rules.

1. Introduction & Controller Identity

Viom Academy provides professional hair styling courses and in-studio training sessions in Norway. This Privacy Policy applies to our website and to personal data we process when you send an inquiry, request course information, or communicate with us by email or phone.

Data Controller (the entity responsible for processing your personal data) is:

  • Legal entity: Viom Holding AS
  • Business name: Viom Academy
  • Registered/office address: Strandveien 20, 1366 Lysaker, Norway
  • Email: [email protected]
  • Phone: +47 67 10 84 26

We do not currently appoint a Data Protection Officer (DPO). If you have privacy questions, you can contact us using the details above and we will respond promptly.

Effective Date: March 12, 2026.

2. Personal Data We Collect

We collect personal data that you choose to provide and data that is generated automatically when you use our website. The specific data varies depending on how you interact with us (for example, browsing a page versus submitting a course inquiry).

  • Identity and contact data: name, email address, phone number, and the contact details you provide in a form or in direct communication.
  • Form content and messages: information you enter in the inquiry form, including course interests, your current level, and any details you include in a free-text message.
  • Technical data: IP address, browser type and version, device type, operating system, language settings, and approximate location inferred from IP (country/region level).
  • Usage data: pages viewed, time spent on pages, referrer information, click paths, and interactions that help us understand how the site is used.
  • Cookies and identifiers: data stored in cookies and similar technologies, including consent state and optional analytics/marketing identifiers (see Section 4).
  • Conversion events: events related to submitting an inquiry form or reaching confirmation pages, used to measure the effectiveness of site content and advertising only when you have consented where required.

We do not intentionally collect special-category personal data (such as health information, religious beliefs, political opinions), financial account details, or government-issued identification numbers through this website. Please do not submit such data in our contact forms.

3. Why We Process Personal Data & Legal Basis

We process personal data only when we have a lawful basis under GDPR Article 6. The purposes and legal bases below apply to typical interactions with Viom Academy.

3.1 Responding to course inquiries and communications

Purpose: to answer your questions, recommend suitable hair styling courses in Norway, confirm prerequisites, and coordinate scheduling and logistics.
Legal basis: GDPR Art. 6(1)(b) (steps prior to entering into a contract) and, where applicable, GDPR Art. 6(1)(a) (consent) when you request to be contacted or you choose to provide optional details.

3.2 Site analytics (optional)

Purpose: to understand which pages and course topics are most helpful, improve navigation, and reduce friction in inquiry flows.
Legal basis: GDPR Art. 6(1)(a) (consent) for non-essential analytics cookies and similar technologies.

3.3 Marketing measurement and remarketing (optional)

Purpose: to measure advertising performance, attribute inquiries to campaigns, and (where enabled) show relevant ads to people who have visited our site.
Legal basis: GDPR Art. 6(1)(a) (consent) for marketing cookies and similar technologies.

3.4 Security, fraud prevention, and service reliability

Purpose: to protect the website, prevent abuse, troubleshoot errors, and maintain availability.
Legal basis: GDPR Art. 6(1)(f) (legitimate interests). Our legitimate interest is keeping the site secure and stable for users in Norway and internationally.

3.5 Legal obligations

Purpose: to comply with applicable laws, respond to lawful requests, and maintain records where required.
Legal basis: GDPR Art. 6(1)(c) (legal obligation).

3.6 Automated decision-making

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects for you within the meaning of GDPR Article 22.

4. Cookies & Tracking Technologies

Cookies are small text files stored on your device. We also use similar technologies, such as pixel tags and server-side events, to keep the site functional and (with consent) to measure usage and advertising performance. You can control non-essential cookies through our cookie banner and preferences panel.

4.1 Essential cookies (always active)

Essential cookies are required for basic site functionality and security. These cookies do not require consent in the EEA/UK when they are strictly necessary.
Examples: _site_session, cookie_consent, and technical cookies used for security features such as CSRF protection.
Retention: session to 12 months depending on cookie type.

4.2 Analytics cookies (consent-based)

When enabled, analytics cookies help us understand how visitors use the site. We configure analytics to reduce unnecessary data collection, including IP anonymization where supported.
Typical cookies: _ga (2 years), _ga_XXXXXXXXXX (2 years).
Data retention: 14 months for analytics data in reporting tools, where applicable.

4.3 Marketing cookies (consent-based)

When enabled, marketing cookies are used to measure conversions, build remarketing audiences, and show relevant advertising. These technologies may include pixel tags and server-side events.
Typical cookies: _gcl_au (90 days), _fbp (90 days), _fbc (90 days when click ID is present).

4.4 Beyond cookies

In addition to cookies, tracking can include pixel tags (loaded only when configured by the site operator and subject to your consent where required), and server-side measurement (for example, events sent from our server to advertising platforms). When server-side measurement is used, identifiers may include IP address and User-Agent and may include hashed contact details for matching, depending on configuration. We aim to minimize data and only enable such features when there is a lawful basis.

5. Consent Management (EEA/UK)

Users in the EEA and UK receive a consent notice under GDPR/UK GDPR. Marketing and analytics cookies activate only after explicit, informed, freely given consent under GDPR Art. 6(1)(a).

Your consent choice is recorded in the cookie_consent cookie (typically for 12 months). You may withdraw or change your choice at any time by using “Manage cookie preferences” in the site footer or by clearing cookies in your browser.

Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.

6. Sharing With Advertising & Service Partners

We use service providers to operate the website and, where consented, to measure usage and advertising. We share only the data needed for the stated purposes and require partners to handle data securely.

We do not sell personal data. These providers may not use site data for their own independent commercial purposes beyond providing services to us, subject to their contractual and legal obligations.

7. International Transfers

Viom Holding AS is based in Norway (EEA). Some service providers we use may process data outside the EEA/UK, including in the United States. Where such transfers occur, we rely on appropriate safeguards, which may include:

  • EU–US Data Privacy Framework (DPF) where applicable (since July 2023).
  • UK Extension to the EU–US DPF where applicable.
  • Swiss–US DPF where applicable.
  • Standard Contractual Clauses (EU 2021/914) as a fallback measure.
  • UK IDTA or UK Addendum where relevant as a fallback measure.

We also apply data minimization and security controls to reduce transfer risk.

8. Data Retention

We keep personal data only for as long as needed for the purposes described in this Privacy Policy, unless a longer retention period is required by law. Typical retention periods include:

  • Course inquiries and form submissions: up to 2 years from the last interaction, so we can follow up, reference prior requests, and keep an audit trail of communications.
  • Email correspondence: for the duration of the relationship plus 1 year, unless we need to retain it longer for legal reasons.
  • Server and security logs: typically up to 90 days, unless required longer for investigation of abuse or reliability issues.
  • Analytics data: 14 months where analytics tools are enabled and consented.
  • Marketing cookies: retained according to cookie lifetimes (commonly 90 days) unless you withdraw consent earlier.
  • Cookie consent record: up to 3 years for audit purposes, depending on local compliance needs.
  • Legal and tax records: retained for the period required by Norwegian law, typically 6–10 years for invoice-related records where applicable.

When retention periods expire, we delete or anonymize personal data in a secure manner.

9. Your Rights (GDPR & UK GDPR)

If GDPR applies to your data, you have the following rights, subject to conditions and exemptions in applicable law:

  • Right of access (Art. 15): obtain confirmation and a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): correct inaccurate or incomplete data.
  • Right to erasure (Art. 17): request deletion where applicable.
  • Right to restriction (Art. 18): request that processing be limited in certain situations.
  • Right to data portability (Art. 20): receive data you provided in a structured, commonly used format.
  • Right to object (Art. 21): object to processing based on legitimate interests; you may also object to direct marketing at any time.
  • Right to withdraw consent (Art. 7(3)): withdraw consent where processing is based on consent.
  • Right to lodge a complaint (Art. 77): lodge a complaint with a supervisory authority.

To exercise your rights, email [email protected]. We normally respond within 30 days. For complex requests, this may be extended by up to 60 additional days as permitted by law.

Supervisory authority references:

10. Children

This site is not directed at individuals under 16. We do not knowingly collect personal data from minors. If you believe a child under 16 has provided personal data to us without verifiable parental consent, please contact us and we will delete the data promptly.

11. Do Not Track Signals

This website does not respond to Do Not Track (DNT) browser signals. Third-party providers may have their own DNT handling. You can manage optional cookies through our consent tools and through browser settings.

12. Data Deletion Requests

You may request deletion of your personal data by emailing [email protected] with the subject line “Data Deletion Request.” To protect your privacy, we may request additional information to verify your identity before processing the request.

We aim to complete deletion within 30 days of verifying your identity, unless we must retain limited records to comply with legal obligations (for example, recordkeeping under Norwegian law).

13. Business Transfers

In the event of a merger, acquisition, asset sale, financing, or insolvency, personal data may be transferred to a successor entity as part of the transaction. If such a transfer materially changes how personal data is used, we will provide notice on the website.

14. California Privacy Notice (CCPA/CPRA)

This section applies to California residents to the extent the California Consumer Privacy Act (as amended by the CPRA) applies to our processing. It supplements the information above.

Categories of personal information disclosed in the past 12 months may include:

  • Identifiers: name, email, IP address, device identifiers (shared with service providers and, where consented, advertising partners).
  • Internet or other electronic network activity: pages viewed and interactions (shared with analytics and advertising providers when enabled).
  • Inferences: interests or preferences inferred from site interactions (used for advertising measurement/targeting when enabled).

We do not sell personal information as defined by CCPA. We may share data for cross-context behavioral advertising when marketing cookies are enabled; California residents may opt out by rejecting marketing cookies through our cookie preferences panel.

California residents may have the right to know, delete, correct, and opt out of the sale or sharing of personal information, and the right to non-discrimination for exercising these rights. To submit a request, email [email protected] with the subject line “California Privacy Request.” We will verify your identity before completing the request. Authorized agents may submit requests with proof of authorization.

15. Virginia Privacy Notice (VCDPA)

To the extent the Virginia Consumer Data Protection Act applies, Virginia residents may have rights to access, correct, delete, obtain a copy of their personal data, and opt out of targeted advertising. We do not sell personal data and we do not engage in profiling that produces legal or similarly significant effects.

To submit a request, email [email protected] with the subject line “Virginia Privacy Request.” If we deny a request, you may appeal by emailing with the subject line “Appeal of Refusal — Privacy Request.” We will respond to appeals within 60 days. If unresolved, you may contact the Virginia Attorney General.

16. Nevada Privacy Notice

Nevada residents may submit a verified opt-out request by emailing [email protected] with the subject line “Nevada Do Not Sell Request.” We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.

17. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices, services, or legal requirements. Material changes will be announced via a notice on the website at least 14 days before the updated policy takes effect. The “Last Updated” date at the top of this page is revised whenever we publish an update.

18. Contact

For questions about privacy, your data, or this Privacy Policy, contact:

Privacy questions?

If you want to access, correct, or delete personal data related to a course inquiry, email us and include enough detail to help us locate the relevant message. We aim to respond within 30 days.