CorpActive AS (“CorpActive”, “we”, “us”, “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the rights you have under the EU/EEA General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (personopplysningsloven).
Last updated: 18 August 2026
CorpActive AS is a Norwegian company providing an employee wellness and training platform, including tailored training programmes, group and corporate training, PT classes, and the CorpActive mobile application for iOS and Android.
This policy applies to:
It does not apply to third-party websites, app stores, or services that we link to. Those operate under their own privacy policies.
Because we sell primarily to employers, our role under the GDPR depends on the context:
The CorpActive app is a wellness product, and some of the data it processes concerns your health. This includes:
Health data is “special category” personal data under Article 9 GDPR and receives additional protection. We process it only on the basis of your explicit consent (Article 9(2)(a)), which you may withdraw at any time in the app or by contacting us. Withdrawing consent does not affect processing carried out before withdrawal.
Health data from any connected health platform is never used for advertising and is never sold. Data obtained through Apple HealthKit or Google Health Connect is used solely to deliver features you have requested, in line with those platforms’ developer requirements.
We do not disclose your individual health, injury, or session-level data to your employer. Employers receive aggregated and de-identified reporting on programme participation and engagement, and we apply a minimum group size (typically at least five participants) before any metric is reported, so that individuals cannot be singled out. Leaderboards display only the information you have agreed to display, and you can opt out of leaderboards.
The app does not collect precise geolocation unless you enable a feature that requires it and grant the corresponding permission on your device.
We may receive your name, work email, and team assignment from your employer when it enrols you in the platform, and business contact details from partners, referrals, and publicly available professional sources such as company websites and LinkedIn.
| Purpose | Data used | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Creating and administering your account; delivering the app and training programmes | Account, profile, usage | Performance of a contract (Art. 6(1)(b)); or legitimate interests where the contract is with your employer (Art. 6(1)(f)) |
| Personalising training programmes and providing progress, feedback, and leaderboards | Profile, health and fitness | Explicit consent (Art. 6(1)(a) and Art. 9(2)(a)) |
| Responding to enquiries, demo requests, and support tickets | Contact, communications | Steps prior to entering a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Managing our customer relationships, contracts, and invoicing | Contact, billing | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Aggregated and de-identified reporting to employer customers | Usage, participation | Legitimate interests of the employer and CorpActive in evaluating the programme (Art. 6(1)(f)), applied only to aggregated data |
| Security, fraud prevention, abuse detection, and debugging | Device, technical, usage | Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) |
| Analytics and improving our website, app, and services | Usage, device | Consent for non-essential cookies and SDKs (Art. 6(1)(a)); otherwise legitimate interests (Art. 6(1)(f)) |
| Marketing emails, newsletters, and advertising | Contact, usage | Consent (Art. 6(1)(a)); legitimate interests for business-to-business marketing to existing customers (Art. 6(1)(f)) |
| Complying with accounting, tax, and other legal obligations | Billing, contract | Legal obligation (Art. 6(1)(c)) |
| Establishing, exercising, or defending legal claims | As relevant | Legitimate interests (Art. 6(1)(f)); legal claims (Art. 9(2)(f)) for special category data |
Where we rely on legitimate interests, we have carried out a balancing assessment to confirm that our interests are not overridden by your rights and freedoms. You can request a summary of that assessment by contacting us.
We use cookies, pixels, local storage, and mobile SDKs on our website and in our app. Under the Norwegian Electronic Communications Act and the GDPR, we set non-essential cookies only after you have given consent through our cookie banner.
You can change or withdraw your cookie consent at any time through the cookie settings link on our website, and you can control cookies through your browser settings. On mobile, you can reset or limit your advertising identifier in your device’s privacy settings. Blocking some cookies may affect how parts of the service work.
We do not sell your personal data. We share it only as described here:
We primarily store and process personal data within the EU/EEA. Some of our service providers are located outside the EEA, including in the United States. Where we transfer personal data outside the EEA, we rely on an appropriate safeguard under Chapter V of the GDPR, such as:
You can request a copy of the relevant safeguards by contacting contact@corpactive.io.
| Category | Retention period |
|---|---|
| Account and profile data | For the duration of your account, then deleted or anonymised within 90 days of account closure or of your organisation’s contract ending |
| Health and fitness data | For the duration of your account, or until you withdraw consent or delete the data, whichever comes first |
| Enquiry and demo request data | Up to 24 months from the last contact, unless a customer relationship begins |
| Customer contract and correspondence | For the term of the contract plus 5 years |
| Accounting and invoicing records | 5 years after the end of the financial year, as required by the Norwegian Bookkeeping Act |
| Marketing consent records | Until consent is withdrawn, plus a record of the withdrawal |
| Server, security, and access logs | Typically 12 months |
| Aggregated and anonymised data | Indefinitely — this data no longer identifies you |
We may retain data for longer where necessary to establish, exercise, or defend legal claims, or where the law requires it.
We maintain technical and organisational measures appropriate to the risk, including encryption in transit (TLS) and at rest, role-based access control and the principle of least privilege, multi-factor authentication for administrative access, network segregation, logging and monitoring, regular backups, vendor security assessments, staff confidentiality obligations and training, and a documented incident response process. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify Datatilsynet within 72 hours and inform you where the law requires it.
No system is completely secure. Please protect your account by using a strong, unique password and by notifying us immediately if you suspect unauthorised access.
Under the GDPR you have the right to:
To exercise your rights, email contact@corpactive.io. We will respond within one month, and may extend this by up to two further months for complex requests, in which case we will tell you why. We may need to verify your identity before acting. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.
If you are unhappy with how we handle your data, you may complain to the Norwegian Data Protection Authority (Datatilsynet), P.O. Box 458 Sentrum, 0105 Oslo, Norway — www.datatilsynet.no — or to the supervisory authority in your country of residence or workplace.
We use automated logic to personalise training recommendations, session difficulty, and content based on your stated preferences, goals, and recorded progress. This is designed to make the service useful to you and does not produce legal effects or similarly significantly affect you. We do not use your data to make automated decisions about your employment, performance, insurance, or benefits, and we do not provide data to your employer for those purposes. You can request human review of any personalisation outcome by contacting us.
Use of CorpActive is voluntary. Where your employer offers the platform, you are not required to create an account, connect a health app or wearable, join a leaderboard, or share health information in order to remain in good standing at work. You can withdraw at any time.
Our services are directed at adults in a workplace context and are not intended for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
We may update this Privacy Policy to reflect changes to our services, technology, or legal obligations. We will post the updated version on this page and change the “Last updated” date. Where changes are material, we will notify you by email or through the app before they take effect. Where a change requires it, we will ask for your consent again.
For any question about this policy or about how we handle your personal data: