EXECUTIA™ Back to EXECUTIA
Data Protection

Data Protection

Last updated: 14 September 2026

Privacy is part of execution integrity.

EXECUTIA is being developed around the principle that data governance should be defined before execution, not reconstructed afterwards.

Where EXECUTIA processes personal data, we aim to apply data minimisation, purpose limitation, controlled access, traceability and privacy by design.

Role of EXECUTIA AS as controller where applicable

EXECUTIA AS (org. no. 838 230 962), Lerkeveien 6B, 4314 Sandnes, Norway, is the data controller for personal data processed through executia.io and EXECUTIA LIFE unless otherwise stated for a specific product or engagement. Open Banking / Account Information Services used in LIFE are described in the Privacy Policy.

Privacy by design

We aim to consider privacy early in product and process design — including what data is needed, why it is needed, who can access it, and how long it should remain available.

Purpose limitation

Personal data should be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes.

Data minimisation

We aim to limit personal data to what is adequate, relevant and necessary for the intended purpose.

Access control

Where systems process personal data, access should be limited to people and services that need it for a defined operational purpose.

Traceability

Where relevant to EXECUTIA’s execution model, we aim for clear accountability for actions and decisions — including when personal data is involved — without overstating current certification or audit status.

Security

We aim to apply security measures appropriate to the risk and context of processing. EXECUTIA does not claim certifications, formal audits or compliance guarantees that it does not currently hold.

GDPR rights

Where the GDPR applies, individuals may have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent where processing is consent-based. Details are set out in our Privacy Policy.

Requests regarding personal data

Requests concerning personal data may be submitted through the channels on our Contact page. We may need to verify your identity before acting on a request.

Complaint rights

You may lodge a complaint with Datatilsynet (the Norwegian Data Protection Authority) or another competent supervisory authority if you believe personal data has been processed unlawfully.