This Privacy Policy explains how RKT Consulting AS collects, uses, stores and protects personal data when you create an account or use the RKT AI Readiness Assessment Platform.
RKT Consulting AS is responsible for the processing of personal data described in this Privacy Policy where it determines the purposes and means of processing.
Norway is subject to the GDPR through the EEA framework.
We may collect and process:
We do not require users to provide sensitive or confidential business information as part of the assessment.
We process information to:
Depending on the processing activity, we process personal data where necessary:
The European Commission recognises legitimate interests as a possible legal basis for activities such as fraud prevention and network and information security, subject to the required balancing of interests and rights.
The platform uses automated scoring and AI-assisted analysis to generate AI readiness insights, maturity observations and recommendations.
The assessment is designed as a decision-support tool and is not intended to make decisions that produce legal or similarly significant effects concerning an individual.
Please do not submit personal, confidential, classified, customer-identifiable, security-sensitive or regulated information in assessment responses or free-text fields.
Assessment questions are designed to evaluate organisational readiness and do not require sensitive personal information.
Assessment responses and generated report data are retained on the RKT AI Readiness Assessment platform for up to 24 hours after report generation to allow users to access and download their assessment results.
After this retention period, assessment responses and generated report data are automatically deleted from the RKT assessment platform.
The assessment may use authorized technology and AI service providers to process assessment data for scoring, analysis, and report generation. Where such service providers process data on our behalf, limited technical, security, abuse-monitoring, or processing records may be retained separately in accordance with the provider's applicable data retention practices, contractual obligations, and legal requirements.
RKT Consulting AS configures AI processing, where technically supported, to minimise application-level storage of assessment content. Data submitted through business API services is not intended to be used for third-party advertising or for training general-purpose AI models where the applicable service terms provide such protections.
Account and service-related information may be retained separately for as long as necessary to operate and administer the platform. Certain account, transaction, payment, security, and audit records may also be retained where necessary for legal and regulatory obligations, accounting and tax requirements, fraud prevention, security monitoring and incident investigation, and service administration and account management.
RKT Consulting AS applies the principle of storage limitation and retains information only for as long as necessary for the purpose for which it was collected or as required by applicable law.
We may use selected service providers to support:
Service providers may process information only for the purposes of providing services to RKT Consulting AS and subject to applicable contractual and data protection requirements.
Where personal data is transferred outside the EEA, appropriate transfer safeguards will be used where required under applicable data protection law.
Payments for premium assessment reports are processed through Stripe.
RKT Consulting AS does not intend to directly store or process full payment card details within the AI Readiness Assessment Platform.
Payment providers may process payment information in accordance with their own applicable privacy and security requirements.
We apply appropriate technical and organisational safeguards designed to protect information against unauthorised access, alteration, disclosure or loss.
Security measures may include secure application access, encrypted data transmission, controlled backend access, secure API integration, environment separation and restricted handling of application credentials.
No internet-based service can guarantee absolute security.
Subject to applicable data protection law, you may have rights including:
These are among the rights recognised under GDPR.
To exercise a privacy right, contact info @rktconsulting .no.
You may contact us if you have concerns regarding the processing of your personal data.
You also have the right to lodge a complaint with the competent data protection authority. In Norway, the supervisory authority is Datatilsynet.
We may update this Privacy Policy to reflect changes to the platform, processing activities, service providers or applicable legal requirements.
The current version and last updated date will be published on the platform.
For questions about this Privacy Policy, please contact: