Skip to content

Privacy policy

This Privacy Policy explains how Webnorly collects, uses, and protects personal data when you visit webnorly.com or contact us about WordPress and WooCommerce work. We keep data collection to what we actually need, and we do not sell your data to anyone.

Webnorly is operated by Mainul Hasan Tech Studio, a company registered in Norway under organization number 935 804 388, based in Oslo. For the purposes of the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act, we are the data controller for the personal data described below.

Last updated: 14 June 2026

What data we collect

Information you give us directly

When you use our contact form or email us, we collect the information you choose to provide. Through the contact form, this is:

  • Your name, so we know who we are speaking with
  • Your email address, so we can reply to you
  • Your website URL (optional), so we can diagnose the issue you describe
  • A description of your issue, so we understand what you need help with

If you contact us by email instead, we receive whatever information you include in your message. If you later become a client, we may also collect the information needed to carry out and invoice the work, such as billing details and any site access credentials you choose to share with us for the duration of an engagement.

Information collected automatically

When you visit the site, some data is collected automatically by the technologies we use:

  • Analytics data through Google Analytics 4, such as pages visited, approximate location, device and browser type, and how you arrived at the site. This helps us understand which content is useful and how the site is performing.
  • Advertising data through Google Ads, used to measure whether our advertising is effective and to understand which visits lead to enquiries.
  • Security and delivery data through Cloudflare, which serves and protects the site. Cloudflare processes technical information such as IP addresses to deliver pages, defend against attacks, and run the spam protection on our contact form.

How we use your data

We use the data we collect only for clear, limited purposes:

  • To respond to your enquiry and provide a free diagnosis
  • To carry out, manage, and invoice work you engage us for
  • To protect the site and our contact form from spam and abuse
  • To understand how the site is used so we can improve it
  • To measure the effectiveness of our advertising
  • To meet our legal and accounting obligations

We do not use your contact details to send marketing emails or newsletters unless you have explicitly asked us to, and we do not sell, rent, or trade your personal data to third parties.

Legal basis for processing

Under the GDPR, we rely on the following legal bases:

  • Consent for non-essential analytics and advertising cookies, which load only where consent applies, and for any optional communications you opt into.
  • Performance of a contract when we process the data needed to deliver work you have engaged us for.
  • Legitimate interests for responding to enquiries you send us, securing the site, and preventing spam and abuse, balanced against your rights.
  • Legal obligation where we are required to retain certain records, for example for tax and accounting purposes.

Cookies and tracking

Cookies are small files stored on your device. We use a small number of them:

  • Essential cookies that the site and its security layer (Cloudflare) need to function and to protect the contact form. These cannot be switched off without breaking core functionality.
  • Analytics cookies set by Google Analytics 4 to measure how the site is used.
  • Advertising cookies set by Google Ads to measure advertising effectiveness.

You can control or delete cookies through your browser settings, and where a consent mechanism is presented, you can decline non-essential cookies without losing access to the core site. Blocking essential cookies may prevent parts of the site, including the contact form, from working.

Who we share data with

We share data only with the service providers that help us run the site and our business, and only to the extent they need it to perform their service. These include:

  • Cloudflare, for hosting delivery, site security, and contact-form spam protection (Turnstile)
  • Google, for website analytics (Google Analytics 4) and advertising measurement (Google Ads)
  • Our hosting and email providers, which store the site and the messages you send us
  • Our accounting provider, where required to invoice and meet tax obligations

Each of these acts as a data processor on our behalf, or as an independent controller for their own infrastructure, and is bound by its own data protection obligations. We do not share your data with anyone for their own marketing.

International transfers

Some of our service providers, including Google and Cloudflare, are based outside the European Economic Area or process data on global infrastructure. Where data is transferred outside the EEA, it is protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an equivalent recognized transfer mechanism.

How long we keep your data

We keep personal data only as long as we need it for the purpose it was collected, or as long as the law requires:

  • Contact-form and email enquiries are kept for up to 24 months, so we can follow up and maintain a record of work discussed, after which they are deleted unless you have become a client.
  • Client and invoicing records are kept for as long as Norwegian accounting law requires.
  • Site access credentials you share for a piece of work are used only for that engagement and removed afterward. We do not retain standing access to your site once work is complete.

Your rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you
  • Correct data that is inaccurate or incomplete
  • Erase your data where there is no overriding reason for us to keep it
  • Restrict or object to how we process your data
  • Data portability, receiving your data in a portable format
  • Withdraw consent at any time, where processing is based on consent

To exercise any of these rights, email us at [email protected]. We will respond within the time the law allows. If you believe we have handled your data improperly, you also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).

How we protect your data

We take reasonable technical and organizational measures to protect your data, including serving the site over an encrypted connection, limiting who can access enquiry data, and using established providers for hosting and security. No method of transmission or storage is completely secure, but we work to protect your data in line with industry practice.

Children’s privacy

Our services are aimed at businesses and are not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, contact us and we will delete it.

Changes to this policy

We may update this policy from time to time to reflect changes in how we work or what the law requires. When we do, we will update the date at the top of this page. We encourage you to review it occasionally.

Contact us

If you have any questions about this Privacy Policy or how we handle your data, email us at [email protected]. Webnorly is operated by Mainul Hasan Tech Studio, organization number 935 804 388, based in Oslo, Norway.