Privacy Policy

CorpActive AS (“CorpActive”, “we”, “us”, “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the rights you have under the EU/EEA General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (personopplysningsloven).

Last updated: 18 August 2026

1. Who we are

CorpActive AS is a Norwegian company providing an employee wellness and training platform, including tailored training programmes, group and corporate training, PT classes, and the CorpActive mobile application for iOS and Android.

  • Company: CorpActive AS
  • Organisation number: 928 832 252
  • Address: Dalsveien 13B, Oslo, Norway
  • Email: contact@corpactive.io
  • Telephone: +47 92 29 13 99 (Monday–Friday, 09:30–17:30 CET)

2. Scope of this policy

This policy applies to:

  • Visitors to corpactive.io and any subdomains;
  • Users of the CorpActive mobile application on iOS and Android;
  • Employees and members of organisations that have purchased CorpActive services;
  • Business contacts, prospects, and people who contact us, book a demo, or subscribe to our communications.

It does not apply to third-party websites, app stores, or services that we link to. Those operate under their own privacy policies.

3. When we are a controller and when we are a processor

Because we sell primarily to employers, our role under the GDPR depends on the context:

  • We act as a data controller for our website, our marketing and sales activities, our business contacts, our own employees and applicants, and for the operation, security, and improvement of our platform where we determine the purposes ourselves.
  • We act as a data processor where we process employee data on behalf of a customer organisation that has decided to deploy CorpActive to its workforce. In those cases the employer is the controller, our processing is governed by a Data Processing Agreement (DPA) with that employer, and you should also consult your employer’s own privacy notice. Where you wish to exercise your rights in relation to that data, we will refer your request to your employer unless applicable law requires otherwise.

4. Personal data we collect

4.1 Information you give us

  • Contact and enquiry data: name, email address, telephone number, company, job title, and the content of your message when you use our contact form, book a demo, or email or call us.
  • Account data: name, email address, password (stored in hashed form), organisation, workplace or team, language and locale, and profile photo where you choose to add one.
  • Profile and preference data: your training preferences, goals, availability, experience level, and programme personalisation settings.
  • Communications: correspondence with our support and sales teams, feedback, survey responses, and testimonials you provide.
  • Billing and contract data (for corporate customers): billing contact, invoicing address, purchase order references, and payment records. We do not store full payment card numbers; card payments are handled by our payment provider.

4.2 Health and fitness data — special category data

The CorpActive app is a wellness product, and some of the data it processes concerns your health. This includes:

  • Completed training sessions, exercises, duration, and frequency;
  • Progress, streaks, points, and leaderboard standing;
  • Self-reported information such as reported discomfort or pain, injury history, physical limitations, wellbeing check-ins, and goals;
  • Where you explicitly choose to connect them, activity metrics from Apple Health, Google Fit / Health Connect, or a wearable device (for example steps, active minutes, or heart rate).

Health data is “special category” personal data under Article 9 GDPR and receives additional protection. We process it only on the basis of your explicit consent (Article 9(2)(a)), which you may withdraw at any time in the app or by contacting us. Withdrawing consent does not affect processing carried out before withdrawal.

Health data from any connected health platform is never used for advertising and is never sold. Data obtained through Apple HealthKit or Google Health Connect is used solely to deliver features you have requested, in line with those platforms’ developer requirements.

4.3 What your employer can and cannot see

We do not disclose your individual health, injury, or session-level data to your employer. Employers receive aggregated and de-identified reporting on programme participation and engagement, and we apply a minimum group size (typically at least five participants) before any metric is reported, so that individuals cannot be singled out. Leaderboards display only the information you have agreed to display, and you can opt out of leaderboards.

4.4 Information we collect automatically

  • Device and technical data: IP address, device type and model, operating system and version, app version, browser type, language settings, and mobile device identifiers.
  • Usage data: pages and screens viewed, features used, referring URL, session duration, timestamps, and crash and diagnostic logs.
  • Cookies and similar technologies: see section 6.

The app does not collect precise geolocation unless you enable a feature that requires it and grant the corresponding permission on your device.

4.5 Information from other sources

We may receive your name, work email, and team assignment from your employer when it enrols you in the platform, and business contact details from partners, referrals, and publicly available professional sources such as company websites and LinkedIn.

5. Why we use your data and our legal bases

Purpose Data used Legal basis (Art. 6 GDPR)
Creating and administering your account; delivering the app and training programmes Account, profile, usage Performance of a contract (Art. 6(1)(b)); or legitimate interests where the contract is with your employer (Art. 6(1)(f))
Personalising training programmes and providing progress, feedback, and leaderboards Profile, health and fitness Explicit consent (Art. 6(1)(a) and Art. 9(2)(a))
Responding to enquiries, demo requests, and support tickets Contact, communications Steps prior to entering a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f))
Managing our customer relationships, contracts, and invoicing Contact, billing Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))
Aggregated and de-identified reporting to employer customers Usage, participation Legitimate interests of the employer and CorpActive in evaluating the programme (Art. 6(1)(f)), applied only to aggregated data
Security, fraud prevention, abuse detection, and debugging Device, technical, usage Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c))
Analytics and improving our website, app, and services Usage, device Consent for non-essential cookies and SDKs (Art. 6(1)(a)); otherwise legitimate interests (Art. 6(1)(f))
Marketing emails, newsletters, and advertising Contact, usage Consent (Art. 6(1)(a)); legitimate interests for business-to-business marketing to existing customers (Art. 6(1)(f))
Complying with accounting, tax, and other legal obligations Billing, contract Legal obligation (Art. 6(1)(c))
Establishing, exercising, or defending legal claims As relevant Legitimate interests (Art. 6(1)(f)); legal claims (Art. 9(2)(f)) for special category data

Where we rely on legitimate interests, we have carried out a balancing assessment to confirm that our interests are not overridden by your rights and freedoms. You can request a summary of that assessment by contacting us.

6. Cookies and similar technologies

We use cookies, pixels, local storage, and mobile SDKs on our website and in our app. Under the Norwegian Electronic Communications Act and the GDPR, we set non-essential cookies only after you have given consent through our cookie banner.

  • Strictly necessary: required to log you in, keep your session secure, remember your cookie choices, and balance server load. These cannot be switched off.
  • Analytics: for example Google Analytics, used to understand how our website and app are used so we can improve them.
  • Marketing and advertising: for example the Meta (Facebook and Instagram) pixel and the LinkedIn Insight Tag, used to measure campaign performance and show you relevant advertising on those platforms.
  • Functional: remember preferences such as language and interface settings.

You can change or withdraw your cookie consent at any time through the cookie settings link on our website, and you can control cookies through your browser settings. On mobile, you can reset or limit your advertising identifier in your device’s privacy settings. Blocking some cookies may affect how parts of the service work.

7. Who we share your data with

We do not sell your personal data. We share it only as described here:

  • Service providers (processors) who act on our instructions under a written data processing agreement, including cloud hosting and storage, email and communications, customer support tooling, analytics, payment processing, and IT security and maintenance providers.
  • Your employer or organisation, in aggregated and de-identified form as described in section 4.3.
  • Professional advisers such as auditors, accountants, insurers, and lawyers, where necessary and under a duty of confidentiality.
  • Public authorities, where we are required to disclose data by law, court order, or a valid request from a competent authority.
  • A buyer or successor, in connection with a merger, acquisition, reorganisation, or sale of assets. We will notify you if your data becomes subject to a different privacy policy.

8. International transfers

We primarily store and process personal data within the EU/EEA. Some of our service providers are located outside the EEA, including in the United States. Where we transfer personal data outside the EEA, we rely on an appropriate safeguard under Chapter V of the GDPR, such as:

  • An adequacy decision of the European Commission, including the EU–US Data Privacy Framework where the recipient is certified; or
  • The European Commission’s Standard Contractual Clauses, supplemented where necessary by additional technical and organisational measures identified in a transfer impact assessment.

You can request a copy of the relevant safeguards by contacting contact@corpactive.io.

9. How long we keep your data

Category Retention period
Account and profile data For the duration of your account, then deleted or anonymised within 90 days of account closure or of your organisation’s contract ending
Health and fitness data For the duration of your account, or until you withdraw consent or delete the data, whichever comes first
Enquiry and demo request data Up to 24 months from the last contact, unless a customer relationship begins
Customer contract and correspondence For the term of the contract plus 5 years
Accounting and invoicing records 5 years after the end of the financial year, as required by the Norwegian Bookkeeping Act
Marketing consent records Until consent is withdrawn, plus a record of the withdrawal
Server, security, and access logs Typically 12 months
Aggregated and anonymised data Indefinitely — this data no longer identifies you

We may retain data for longer where necessary to establish, exercise, or defend legal claims, or where the law requires it.

10. How we protect your data

We maintain technical and organisational measures appropriate to the risk, including encryption in transit (TLS) and at rest, role-based access control and the principle of least privilege, multi-factor authentication for administrative access, network segregation, logging and monitoring, regular backups, vendor security assessments, staff confidentiality obligations and training, and a documented incident response process. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify Datatilsynet within 72 hours and inform you where the law requires it.

No system is completely secure. Please protect your account by using a strong, unique password and by notifying us immediately if you suspect unauthorised access.

11. Your rights

Under the GDPR you have the right to:

  • Access — obtain confirmation of whether we process your data and receive a copy of it;
  • Rectification — have inaccurate or incomplete data corrected;
  • Erasure — have your data deleted where one of the grounds in Article 17 applies;
  • Restriction — ask us to limit how we use your data in certain circumstances;
  • Data portability — receive data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
  • Object — object at any time to processing based on legitimate interests, and object absolutely to processing for direct marketing;
  • Withdraw consent — at any time, without affecting the lawfulness of processing before withdrawal;
  • Not be subject to automated decision-making that produces legal or similarly significant effects (see section 12);
  • Lodge a complaint with a supervisory authority.

To exercise your rights, email contact@corpactive.io. We will respond within one month, and may extend this by up to two further months for complex requests, in which case we will tell you why. We may need to verify your identity before acting. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.

If you are unhappy with how we handle your data, you may complain to the Norwegian Data Protection Authority (Datatilsynet), P.O. Box 458 Sentrum, 0105 Oslo, Norway — www.datatilsynet.no — or to the supervisory authority in your country of residence or workplace.

12. Automated decision-making and profiling

We use automated logic to personalise training recommendations, session difficulty, and content based on your stated preferences, goals, and recorded progress. This is designed to make the service useful to you and does not produce legal effects or similarly significantly affect you. We do not use your data to make automated decisions about your employment, performance, insurance, or benefits, and we do not provide data to your employer for those purposes. You can request human review of any personalisation outcome by contacting us.

13. Participation is voluntary

Use of CorpActive is voluntary. Where your employer offers the platform, you are not required to create an account, connect a health app or wearable, join a leaderboard, or share health information in order to remain in good standing at work. You can withdraw at any time.

14. Children

Our services are directed at adults in a workplace context and are not intended for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

15. Changes to this policy

We may update this Privacy Policy to reflect changes to our services, technology, or legal obligations. We will post the updated version on this page and change the “Last updated” date. Where changes are material, we will notify you by email or through the app before they take effect. Where a change requires it, we will ask for your consent again.

16. Contact us

For any question about this policy or about how we handle your personal data:

  • CorpActive AS, Dalsveien 13B, Oslo, Norway
  • Email: contact@corpactive.io
  • Telephone: +47 92 29 13 99
  • Organisation number: 928 832 252