// Privacy

PRIVACY POLICY

How we protect your personal data
// Last updated: 6 May 2026

1. Introduction

Mustvedt Sentinel (“we”, “us”) respects your privacy. This Privacy Policy explains what personal data we collect, how we use it, and your rights under the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act.

We aim to collect as little data as possible — only what we need to deliver the service.

2. Data controller

The data controller is:

Mustvedt (sole proprietorship)
Owner: Christer Mustvedt
Company no.: 937 618 719
Email: Christer@mustvedt.net
Address: Storebø, Vestland, Norway

3. Data we collect

3.1 When you use the service anonymously

You can use the free version without signing up. In that case we collect:

3.2 When you register a PLUSS account

In addition to the above:

3.3 When you use monitoring features

3.4 When you pay

3.5 When you use the mobile app

4. Purpose of processing

We process your personal data to:

5. Legal basis

Our processing relies on:

6. Retention

Data typeRetention
Anonymous scans30 days (statistics only)
PLUSS account dataActive subscription + 6 months
Invoice data5 years (Norwegian Bookkeeping Act §13)
Monitoring dataActive subscription
Logs and IP addresses90 days
Trial data (no purchase)30 days after trial ends
Marketing consentUntil you withdraw it

7. Sharing with third parties

We do not share your personal data with anyone other than:

We never sell your data to third parties for marketing.

8. Sub-processors

We use the following sub-processors:

ServicePurposeLocation
NamecheapServer hostingUSA
AnthropicAI analysis (Claude API)USA
StripePayment processing (card)Ireland / USA
Vipps MobilePayPayment processing (mobile)Norway
BrevoEmail deliveryFrance
UptimeRobotDomain uptime monitoringUSA
Umami CloudAnonymous visitor analyticsEU
VirusTotalURL/file scanningEU
LeakCheckEmail-breach lookupEU
Have I Been Pwned (HIBP)Password / email-breach lookupAustralia
ShodanPort / exposure scanningUSA
ThreatFox (abuse.ch)Threat intelligenceSwitzerland

9. International transfers

Some of our sub-processors are located outside the EU/EEA (e.g. USA, Australia). For these transfers we rely on:

10. Security

We take data security seriously and use:

If we discover a data breach, we will notify affected users within 72 hours in line with GDPR art. 33.

11. Your rights

You have the following rights under GDPR:

11.1 Right of access

You can request a copy of all information we hold about you. Send a request to Christer@mustvedt.net.

11.2 Right to rectification

If we hold incorrect or incomplete information about you, you can ask us to correct it.

11.3 Right to erasure (“right to be forgotten”)

You can ask us to delete your personal data. We will delete it as soon as we can, unless we have a legal obligation to retain it (e.g. invoice data for 5 years).

11.4 Right to restriction

You can ask us to restrict processing of your data, e.g. while a complaint is being resolved.

11.5 Right to data portability

You can ask to receive your data in a machine-readable format (JSON/CSV).

11.6 Right to object

You can object to processing based on legitimate interest or marketing.

11.7 Right to withdraw consent

If processing relies on consent, you can withdraw it at any time without affecting the lawfulness of past processing.

📧 How to exercise your rights: Send an email to Christer@mustvedt.net with “Privacy request” as the subject. We reply within 30 days.

12. Cookies and local storage

Mustvedt Sentinel uses:

12.1 Technical cookies (necessary)

12.2 Analytics cookies

We use Umami, which is privacy-friendly:

12.3 Marketing cookies

We use no marketing cookies or third-party trackers.

13. Children under 13

Mustvedt Sentinel is not directed at children under 13. We do not knowingly collect personal data from children. If you are a parent and discover that we hold data about your child, contact us immediately for deletion.

14. Changes to this policy

We may update this policy as needed. Material changes will be communicated via:

By continuing to use the service after changes, you are deemed to have accepted the new policy.

15. Complaints to a supervisory authority

If you believe we are processing your personal data in violation of GDPR, you can lodge a complaint with the Norwegian Data Protection Authority:

Datatilsynet (Norwegian DPA)
Postboks 458 Sentrum, 0105 Oslo, Norway
Phone: +47 22 39 69 00
Email: postkasse@datatilsynet.no
Web: datatilsynet.no/en/

EU residents may also contact the data protection authority in their own country of residence. We encourage you to contact us first so we can resolve the issue together.

16. Contact us

Mustvedt (sole proprietorship)
Owner: Christer Mustvedt
Company no.: 937 618 719
Email: Christer@mustvedt.net
Web: mustvedt.net/en/
Address: Storebø, Vestland, Norway