Privacy Policy
Last updated: September 2026
CC-LOG AS (“CC-Log”, “we”, “us” or “our”) respects your privacy and is committed to protecting personal data processed through the CC-Log platform, applications, website and related services.
This Privacy Policy explains how personal data is processed when CC-Log is used by organisations, their employees and other authorised users.
1. About CC-Log
CC-Log is a digital business-to-business platform provided by:
CC-LOG AS
Organisation number: 924 925 957
Norway
Email: post@cc-log.com
CC-Log provides organisations with tools for safety communication, notifications, travel safety, incident management, emergency preparedness, logging and related operational activities.
2. Our Role When Processing Personal Data
CC-Log is primarily provided to businesses and other organisations for use by their employees, contractors and other authorised users.
When an organisation uses CC-Log to process personal data relating to its employees or other users, that organisation will normally be the data controller. This means that the organisation determines why the personal data is processed and how CC-Log is used.
CC-LOG AS will normally act as a data processor and process such personal data on behalf of the customer and according to the customer’s instructions.
The customer is responsible for ensuring that its use of CC-Log has an appropriate legal basis and complies with applicable privacy, employment, health and safety legislation.
CC-LOG AS may separately act as an independent data controller for limited personal data processed for our own purposes, including customer administration, contractual administration, billing, security, support and communication with customer representatives.
3. How We Receive Personal Data
Personal data processed through CC-Log may be provided:
-
directly by the individual;
-
by the individual’s employer or another organisation using CC-Log;
-
by authorised administrators or users within that organisation;
-
automatically through the individual’s use of CC-Log;
-
through a mobile device or other connected technology where relevant functionality and permissions are enabled; or
-
through third-party services necessary to provide the requested functionality.
Customer organisations may create and administer user accounts and provide information such as names, telephone numbers, email addresses and organisational affiliations on behalf of their employees or authorised users.
Where CC-LOG AS acts as a data processor, the customer is responsible for ensuring that individuals receive the information required by applicable data protection legislation.
4. Personal Data Processed Through CC-Log
Depending on which CC-Log services and features an organisation uses, the platform may process information including:
-
Name
-
Email address
-
Telephone number
-
User and account information
-
Employer or organisational affiliation
-
User roles and permissions
-
GPS and location information
-
Travel information and travel history
-
Notifications and messages
-
SMS delivery and notification information
-
Incident and emergency information
-
Information entered into logs
-
Dates and timestamps
-
Technical and security logs
-
Device and browser information
-
IP address
-
Information relating to authentication and account access
-
Other information entered into CC-Log by the customer or its authorised users
The exact categories of personal data processed depend on how the customer organisation configures and uses CC-Log.
5. Location Data
Certain CC-Log functions may use location information, including GPS data, where this is necessary for functionality such as travel safety, employee safety, incident management or emergency preparedness.
Location information is only processed where the relevant functionality is enabled and in accordance with the customer’s configuration and instructions.
Customers are responsible for ensuring that employees and other users receive appropriate information about the use of location services and that an appropriate legal basis exists for such processing.
Device permissions may also be required before CC-Log can access location information.
The availability and accuracy of location information may depend on the user’s device, operating system, GPS availability, connectivity and other technical factors.
6. Why Personal Data Is Processed
Personal data may be processed through CC-Log in order to:
-
provide and operate the CC-Log service;
-
create and manage user accounts;
-
authenticate users and control access;
-
enable communication and notifications;
-
provide SMS-based account and safety notifications;
-
support travel safety and employee safety;
-
send alarm and emergency notifications;
-
register and manage incidents;
-
maintain emergency and incident logs;
-
provide customers with relevant operational information;
-
maintain the security and integrity of the platform;
-
troubleshoot technical problems;
-
provide customer and technical support;
-
prevent misuse, fraud and unauthorised access;
-
maintain appropriate technical and security records;
-
administer customer relationships and agreements; and
-
comply with applicable legal obligations.
When CC-LOG AS acts as a data processor, the purposes of processing are determined by the customer organisation.
7. Legal Basis for Processing
Where the customer organisation is the data controller, the customer is responsible for determining the appropriate legal basis for processing personal data through CC-Log.
Depending on the circumstances, the customer’s legal basis may include:
-
performance of a contract;
-
compliance with a legal obligation;
-
legitimate interests;
-
obligations or legitimate requirements relating to workplace safety, emergency preparedness or employment; or
-
consent where consent is an appropriate legal basis.
The applicable legal basis may vary depending on the customer’s activities, the CC-Log functionality being used and applicable legislation.
Where CC-LOG AS acts as an independent data controller, personal data may be processed where necessary to:
-
perform or administer a contract;
-
comply with a legal obligation;
-
pursue legitimate business interests;
-
maintain and protect the security of CC-Log;
-
prevent misuse or unauthorised access; or
-
communicate with customers and customer representatives.
Where processing is based on consent, the individual may withdraw that consent as provided by applicable law. Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.
8. SMS Safety and System Notifications
CC-Log may use mobile telephone numbers to send SMS messages as part of its account, safety and operational services.
SMS messages may include:
-
account verification and authentication codes;
-
account and system notifications;
-
safety notifications;
-
alarm alerts;
-
alarm verification requests;
-
travel safety notifications;
-
incident-related notifications;
-
emergency preparedness communications; and
-
other operational messages related to the use of CC-Log.
CC-Log SMS messages are intended for transactional, operational and safety-related purposes and are not intended for advertising or promotional marketing.
Where SMS consent is required, recipients are informed about the types of SMS messages they may receive before providing their consent.
Information relating to SMS opt-in may include the telephone number, date and time of opt-in, method of opt-in and the version of the applicable consent information.
Recipients may stop receiving SMS messages by replying STOP.
Recipients may obtain assistance by replying HELP or by contacting CC-LOG AS at post@cc-log.com.
Where supported, a recipient who has previously opted out may be able to resume SMS messages by replying START or UNSTOP.
Opting out of SMS prevents further SMS notifications from being delivered to that telephone number while the opt-out remains active. It does not necessarily affect other communication channels or other processing carried out by the relevant customer organisation.
The customer organisation remains responsible for determining whether alternative communication procedures are necessary where a user does not receive SMS notifications.
SMS consent and opt-in information
CC-LOG AS does not sell, rent or transfer SMS opt-in consent for marketing or promotional purposes.
The above excludes text messaging originator opt-in data and consent; this information will not be shared with any third parties.
SMS consent cannot be transferred or sold to another organisation for its own independent messaging purposes.
9. SMS and Telecommunications Service Providers
CC-LOG AS uses telecommunications and technology service providers to provide SMS functionality.
Twilio is used as a service provider for the transmission and delivery of certain SMS messages.
When an SMS is sent, information necessary to provide the communication service may be processed by Twilio, telecommunications carriers and other infrastructure providers involved in delivering the message. This may include:
-
telephone number;
-
message content;
-
sender and recipient information;
-
date and time;
-
message status;
-
delivery information; and
-
technical information required for message routing and delivery.
These providers process such information only to the extent necessary to provide their telecommunications, infrastructure, security and related services, subject to applicable contractual and legal requirements.
SMS opt-in consent itself is not sold or transferred to these providers for their own marketing or promotional purposes.
10. Storage and Cloud Services
CC-Log uses cloud-based infrastructure and other technology services to operate the platform and store or process data.
Personal data may therefore be processed by hosting, infrastructure, security, communication and other technology providers acting as subprocessors to CC-LOG AS.
CC-LOG AS requires service providers processing personal data on our behalf to provide appropriate protection for such data and to process it in accordance with applicable contractual and data protection requirements.
11. International Transfers of Personal Data
Some service providers used to operate CC-Log, including telecommunications and technology providers, may process personal data outside Norway or the European Economic Area (“EEA”).
Where personal data is transferred outside the EEA to a country that has not been recognised as providing an adequate level of data protection, CC-LOG AS will use an appropriate lawful transfer mechanism where required.
Such mechanisms may include:
-
an adequacy decision issued by the European Commission;
-
Standard Contractual Clauses approved by the European Commission;
-
Binding Corporate Rules; or
-
another transfer mechanism permitted under applicable data protection legislation.
Additional safeguards may be applied where necessary based on the circumstances of the transfer.
12. Data Retention
Personal data processed by CC-LOG AS on behalf of a customer is retained according to:
-
the customer’s instructions;
-
the applicable agreement with the customer;
-
the applicable Data Processing Agreement;
-
the operational requirements of the service; and
-
applicable legal requirements.
Customers are responsible for determining appropriate retention periods for personal data for which they are the data controller.
CC-LOG AS may retain limited information for longer where necessary to:
-
comply with legal obligations;
-
maintain appropriate accounting or contractual documentation;
-
resolve disputes;
-
investigate security incidents;
-
prevent misuse;
-
establish, exercise or defend legal claims; or
-
maintain technical and security records where legitimately required.
When a customer relationship ends, customer data will be deleted or returned in accordance with the applicable agreement and Data Processing Agreement, subject to applicable legal requirements.
Backup copies may remain for a limited period as part of normal backup and disaster recovery procedures before being overwritten or deleted.
13. Sharing of Personal Data
CC-LOG AS does not sell personal data.
Personal data may be made available where necessary to:
-
the organisation responsible for the relevant CC-Log account;
-
authorised users within that organisation;
-
service providers and subprocessors necessary to operate and secure CC-Log;
-
telecommunications providers necessary to deliver communications;
-
professional advisers where reasonably necessary;
-
public authorities, regulators or courts where disclosure is required by applicable law; or
-
another party where disclosure is necessary to establish, exercise or defend legal claims.
Access to personal data is limited according to role, authorisation, contractual obligations and operational need where applicable.
Service providers and subprocessors are not permitted to use personal data for unrelated purposes contrary to applicable contractual and legal requirements.
The above excludes text messaging originator opt-in data and consent; this information will not be shared with any third parties.
CC-LOG AS does not sell, rent, transfer or share SMS opt-in consent with third parties or affiliates for their own marketing or promotional purposes.
14. Security
CC-LOG AS takes appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Security measures may include, where appropriate:
-
access controls;
-
authentication mechanisms;
-
role-based permissions;
-
logging and monitoring;
-
security updates;
-
backup and recovery procedures;
-
encryption and secure communications;
-
supplier security requirements; and
-
other technical and organisational safeguards appropriate to the nature and risk of the processing.
Access to customer data by CC-LOG AS personnel is limited to situations where access is authorised and necessary for purposes such as technical support, maintenance, security or compliance.
No online or electronic service can guarantee absolute security. CC-LOG AS continuously works to maintain a level of security appropriate to the risks associated with the information processed through CC-Log.
15. Your Privacy Rights
Under the General Data Protection Regulation (“GDPR”), individuals may have rights including:
-
the right to receive information about how personal data is processed;
-
the right to access personal data;
-
the right to correct inaccurate or incomplete personal data;
-
the right to request deletion in certain circumstances;
-
the right to restrict processing in certain circumstances;
-
the right to object to certain processing;
-
the right to data portability where applicable;
-
the right to withdraw consent where processing is based on consent; and
-
the right to lodge a complaint with a competent data protection authority.
These rights are subject to the conditions and limitations provided by applicable law.
Where personal data is processed by CC-LOG AS on behalf of an employer or another organisation, requests concerning these rights should normally be directed to that organisation because it is the data controller.
CC-LOG AS will assist its customers in responding to data subject requests where required under applicable law and the relevant Data Processing Agreement.
Where CC-LOG AS acts as the data controller, requests may be submitted directly to CC-LOG AS.
Individuals in Norway may also lodge a complaint with Datatilsynet, the Norwegian Data Protection Authority.
16. Website, Cookies and Technical Information
When visiting the CC-Log website or using CC-Log services, certain technical information may be processed automatically.
This may include:
-
IP address;
-
browser information;
-
device information;
-
operating system;
-
timestamps;
-
security-related information;
-
login and authentication information; and
-
technical logs.
Such information may be necessary to operate, protect, troubleshoot and improve the service.
Where cookies or similar technologies are used, information about their use and any required choices or consent will be provided in accordance with applicable law.
17. Data Processing Agreements
Where CC-LOG AS processes personal data on behalf of a customer, the processing shall be governed by an appropriate Data Processing Agreement where required under Article 28 of the GDPR.
The Data Processing Agreement describes matters including:
-
the subject matter and duration of processing;
-
the nature and purpose of processing;
-
categories of personal data;
-
categories of data subjects;
-
confidentiality;
-
security measures;
-
use of subprocessors;
-
assistance with data subject rights;
-
personal data breaches;
-
deletion or return of data; and
-
the respective responsibilities of CC-LOG AS and the customer.
Customers requiring information about the applicable Data Processing Agreement may contact CC-LOG AS.
18. Subprocessors
CC-LOG AS may use third-party service providers and subprocessors where necessary to provide and operate CC-Log.
These may include providers of:
-
cloud hosting and infrastructure;
-
databases and data storage;
-
telecommunications and SMS services;
-
email services;
-
mapping and location technology;
-
security services;
-
monitoring and technical operations; and
-
other services necessary to operate the platform.
Subprocessors are selected and managed in accordance with applicable data protection requirements.
Where required, the use of subprocessors is governed by the applicable Data Processing Agreement between CC-LOG AS and the customer.
19. Personal Data Breaches
CC-LOG AS maintains procedures for identifying, assessing and responding to personal data breaches.
Where CC-LOG AS acts as a data processor and becomes aware of a personal data breach affecting personal data processed on behalf of a customer, CC-LOG AS will notify the relevant customer without undue delay in accordance with applicable law and the applicable Data Processing Agreement.
Where CC-LOG AS acts as data controller, CC-LOG AS will fulfil applicable notification and reporting obligations relating to personal data breaches.
20. Changes to This Privacy Policy
CC-LOG AS may update this Privacy Policy when our services, technology, suppliers, business operations or legal obligations change.
The latest version will be made available through the CC-Log website.
The date at the top of this Privacy Policy indicates when it was last updated.
Where appropriate, material changes may also be communicated to customers through relevant communication channels.
21. Contact
Questions regarding this Privacy Policy or CC-LOG AS’s processing of personal data may be directed to:
CC-LOG AS
Organisation number: 924 925 957
Norway
Email: post@cc-log.com
Where CC-LOG AS processes personal data on behalf of your employer or another organisation using CC-Log, privacy requests relating to that organisation’s processing should normally be directed to the organisation itself as the data controller.
CC-LOG AS will cooperate with its customers in responding to appropriate privacy requests in accordance with applicable data protection legislation.