Legal

Privacy Policy

How SPJSWorks AS handles personal data on this website and in connection with Modern DFFS licenses.

Last updated: 31 July 2026

The short version

This site sets no cookies and runs no analytics or tracking of any kind. Nothing you do here is profiled, shared with advertisers, or sold. We only hold personal data you give us deliberately — when you contact support, or when you buy a license.

1. Who we are

The data controller is:

SPJSWorks AS
Uranveien 8
3152 Tønsberg
Norway
Org. nr. 937 562 888

For any privacy question or request, contact support@spjsworks.com.

2. What we do not do

  • No cookies. Browsing this site sets no cookies in your browser.
  • No analytics or tracking. There is no Google Analytics, tag manager, advertising pixel, session recorder, or similar technology on any page.
  • No profiling and no automated decision-making.
  • We never sell or rent personal data, and we do not share it for advertising.

3. What we collect, and why

Support enquiries

When you use the contact form on the Support page, you provide your name, email address, the edition and SharePoint environment you use, and your subject and message.

This is sent to us by email so we can answer you. It is not stored in a database on this website, and the form does not log your IP address. The resulting email correspondence is kept in our mailbox for as long as needed to support you.

Purchases and licensing

Payments are handled by Paddle, which acts as the Merchant of Record for our sales. Paddle collects your billing and payment details and handles tax. We never see or store your card details.

When a purchase completes, this website records the email address used at checkout together with the transaction reference, the product purchased, the amount, currency, order status and timestamps — so we can fulfil the order and answer questions about it.

License codes

To issue and support license codes, we keep a record containing the customer name, email address and the issued license code in our own SharePoint (Microsoft 365) environment. This lets us re-issue a code, verify entitlement, and handle upgrades or renewals.

PurposeLegal basis (GDPR Art. 6)
Fulfilling an order and issuing / supporting a licensePerformance of a contract — Art. 6(1)(b)
Answering support enquiriesLegitimate interests — Art. 6(1)(f) — responding to someone who contacted us
Keeping accounting recordsLegal obligation — Art. 6(1)(c) — Norwegian Bookkeeping Act

5. Who processes data on our behalf

ProviderRoleData involved
one.comWebsite hosting and outgoing emailWebsite data and support email
PaddleMerchant of Record — checkout, payment and taxBilling and payment details, purchase email
Microsoft 365SharePoint environment holding license recordsCustomer name, email, license code

We also use an external accountant who processes invoices and accounting records on our behalf, as required by law.

Some of these providers may process data outside the EEA. Where that happens, transfers rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

6. How long we keep it

  • Accounting and order records — five years after the end of the financial year, as required by the Norwegian Bookkeeping Act.
  • License records — for as long as the license is in use, so we can support, re-issue, upgrade and renew it.
  • Support correspondence — for as long as it is useful for supporting you, then deleted.

7. Your rights

Under the GDPR you have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable format. Where processing is based on consent, you may withdraw it at any time.

To exercise any of these, email support@spjsworks.com. Note that data we are legally required to retain — accounting records in particular — cannot be deleted before the statutory period ends.

If you believe we have handled your data improperly, you may lodge a complaint with the Norwegian Data Protection Authority, Datatilsynet.

8. A note about the Modern DFFS product

Modern DFFS runs inside your own SharePoint tenant. Form data entered by your users stays in your SharePoint lists — it is not sent to us, and we have no access to it. In respect of your form data, you are the data controller.

The product makes one routine outbound call to us: an anonymous license check, which transmits the license code only — no tenant name, user identity, or form content.

The optional AI Assistant

The AI Assistant is off unless an administrator turns it on, and it is a design-time tool for building forms — it is never invoked when ordinary users fill in a form. It does not send SharePoint list item data.

Used without an API key — the default — it sends nothing anywhere. The administrator copies or downloads the prompt, runs it in whatever AI tool they choose, and pastes the result back. No data reaches us or any AI provider through the product.

If an administrator enables it and enters their own AI provider API key, the form configuration being edited and that API key are passed through a relay on spjsworks.com to the AI provider they selected. That relay exists for a purely technical reason: AI provider APIs reject direct calls from a browser, so a hop is unavoidable. It is stateless — it forwards the request, streams the answer back, and stores, logs and retains nothing: not the key, not the prompt, not the response.

Organizations using an Enterprise central license do not use that relay at all. They configure their own relay endpoint inside their own network, so AI traffic never reaches SPJSWorks infrastructure.

9. Changes to this policy

If this policy changes, the revised version will be published on this page with a new “last updated” date.

10. Contact

SPJSWorks AS, Uranveien 8, 3152 Tønsberg, Norway — support@spjsworks.com