Hopp til innhold
lerka

Privacy policy

Last updated: 10 August 2026 · Version: 1.0

In short

  • If you answer a commuter survey from us: we do not know who you are, and we cannot find out. We store no name, e-mail address, IP address or location. Your employer never sees your answer, only figures for groups of at least five people.
  • If you request a quote on this site: we use what you send to reply, and for nothing else. The request is handled as e-mail correspondence and is not added to any marketing database.
  • We do not track you. No tracking pixels, no advertising cookies, no profiling. The only cookie we use is the login for business customers.
  • Want something deleted? Write to personvern@lerka.app and we will do it.

1. Who is responsible

Cadence AS, Norwegian organisation number 912 024 652, is the controller for the personal data described here. Lerka is the service Cadence AS develops and delivers. Cadence AS is established in Norway, inside the EEA, so no separate EU representative under Article 27 GDPR is required.

Contact for privacy matters: personvern@lerka.app. We are happy to provide our full registered address on request; it also appears on invoices and in the Norwegian business registers.

The service is under establishment. Should the controller role later be transferred to another company in the same ownership structure, we will update this policy and notify everyone whose contact details we hold before the transfer takes place.

2. What this policy covers

This policy covers three situations. Find yours:

Your situationRead
You received a link to a commuter survey from your employer§3
You requested a quote or contacted us via lerka.app§4
You are a contact person at a customer or at a company we approach§5

Our Norwegian-language self-service products (the commuter calculator, the e-mail list and online ordering) are covered by the Norwegian privacy policy, which is the authoritative text for those services.

3. The commuter survey (anonymous)

3.1 What we collect

Only your answers to the survey questions: department (where your employer has defined groups of at least five people), number of office days, commuting distance in broad bands, mode of transport, winter habits, car access, parking, your biggest barrier to greener commuting, what could make you leave the car at home, and, only if you choose to answer, an approximate number of self-certified absence days in broad bands.

In addition we store which survey wave the answer belongs to (which identifies the employer and the wave, never you) and the date the answer arrived.

3.2 What we do not collect

We do not store, and have no access to:

  • names, e-mail addresses, phone numbers, employee numbers or any other identifiers
  • IP addresses, browser or device information
  • location data
  • time of day (only the date)
  • free text: the survey has no free-text fields, precisely so that no one can be identified through what they write

We have also switched off the routine logging of visitors' IP addresses on the survey pages. Such a log, combined with the time an answer arrived, could recreate exactly the link we promise does not exist.

We never receive employee lists from your employer. Your employer shares the survey link in its own channels, and we do not know who the link was sent to.

3.3 Why the answers are anonymous

The survey is designed so that an answer cannot be linked to an individual, neither by us nor by your employer. There is no identifier to match against, no free text, no technical log, and the background questions are so coarse that they do not single anyone out. All reporting covers groups of at least five people, and small groups are merged before anything is shown.

We also suppress combinations that could point to someone, for example the only person in a small department who lives more than 40 kilometres away. This applies not only in the report but also in the analysis behind it.

Our assessment is therefore that the answers are anonymous data, and that the GDPR does not apply to them. We still treat them with the same security and discipline as personal data, and we repeat the assessment whenever we change the survey.

One honest consequence you should know about: because we cannot link an answer to you, we also cannot find it again. We cannot give you access to, correct or delete your own answer afterwards. Participation is therefore entirely voluntary, and you decide what to answer, including "prefer not to say" where that option exists.

3.4 What your employer sees

Your employer receives a report with aggregate figures: modal split, distances, the parking picture, barriers and potential, always for groups of at least five people.

Your employer never sees individual answers, and never learns who answered or who did not. Reminders during the survey window therefore go generically to everyone, never to named individuals. That is a direct consequence of the survey being anonymous.

Our agreement with your employer expressly forbids using the results for personnel assessment, monitoring or follow-up of individual employees.

3.5 How long we keep it

The raw data (the individual answers) are deleted no later than 12 months after the survey window closes. After that, only the report and the aggregate figures remain, and they cannot be broken down into individual answers. Your employer can ask us to delete the raw data earlier at any time.

4. Quote requests and contact via lerka.app

4.1 The quote form

If you request a quote, we receive what you enter in the form: company name, country, number of employees, your name, your work e-mail address and an optional message.

  • Purpose: to reply with a quote and follow up your request. Nothing else.
  • Legal basis: our legitimate interest in responding to a business enquiry made in your professional role, on behalf of your company (Article 6(1)(f) GDPR).
  • How it is handled: the request is forwarded and answered as e-mail correspondence. It is not stored in a marketing database, and you are not added to any mailing list.
  • Retention: we delete the correspondence no later than 12 months after our last contact, and earlier if you ask.
  • You are not obliged to provide this information, but without a working e-mail address we cannot reply.

4.2 Visit statistics and cookies

We count how many times our pages are viewed: one counter per page per day, without being able to recognise you. The counter uses no cookies and stores no IP address, browser information or time of day, only "this page, this day, this many views". Survey pages are not counted at all. Beyond this we use no tracking pixels, no advertising networks and no marketing cookies, and our e-mails contain no tracking of whether you open them.

One more thing, and it concerns companies rather than you as a person: when we e-mail a company, the link carries that company's business register number. If someone clicks it, we store the register number together with the fact that a visit came from one of our links, so we can see whether an approach led anywhere. We do not store who clicked, when, from which IP address or from which browser. To make sure such a record cannot point to one specific person, we only store it for companies with at least 20 registered employees, and never for sole proprietorships.

One cookie exists: if you log in as a business customer to follow a survey, we set a necessary login cookie. It is used only to keep you logged in, never for tracking, and it expires after no more than seven days.

5. Contact persons at customers and prospects

5.1 Customers

If you are a contact person at a customer, we process your name, position, work e-mail address and work phone number in order to deliver the service and manage the customer relationship. The legal basis is the agreement with your company (Article 6(1)(b)) and our legitimate interest in having a working customer contact (Article 6(1)(f)). The data is deleted 12 months after the customer relationship ends, except what Norwegian bookkeeping law requires us to keep on invoices and vouchers for five years.

5.2 Companies we approach

If we contact a company we have no prior relationship with, we may have registered the name, role and work e-mail address of a contact person, collected from publicly accessible sources: public business registers or the company's own website.

  • Purpose: to present a relevant professional offer to the company.
  • Legal basis: legitimate interest (Article 6(1)(f)). We contact you in your professional role, about something that concerns your employer, and never privately.
  • Retention: deleted no later than 12 months after the contact sequence ends, and immediately if you ask.
  • You can always say no. One message is enough. We then register an opt-out that applies across all our approaches, including future ones. We never send more than three messages in one sequence.
  • Sole proprietorships are treated as private individuals: we do not send marketing e-mail without consent.

6. Your rights

Where we process personal data about you, you have the right to request access, rectification, erasure, restriction and data portability, and to object to processing based on legitimate interest. Where processing is based on consent, you can withdraw it at any time; this does not affect processing that has already taken place.

We do not use automated decision-making or profiling.

Write to personvern@lerka.app. We reply within 30 days.

Note the exception in §3.3: for anonymous survey answers there is no data about you to access or delete. That is the point of the anonymity.

If you believe we process data about you in breach of the rules, you can complain to the Norwegian Data Protection Authority, Datatilsynet (datatilsynet.no), or to the supervisory authority in the country where you live or work, for example IMY in Sweden. We would appreciate hearing from you first, so we can put things right.

7. Who processes data on our behalf

We use a small number of suppliers who process data for us, under data processing agreements and only on our instructions. We never sell data, and never share it for anyone else's marketing.

SupplierRoleProcesses
Microsoft (Azure)Database, hosting and website, region NorwaySurvey answers, customer data, reports, form submissions (self-service forms on the Norwegian site)
Google (Workspace)E-mail and documentsE-mail correspondence
ResendSending e-mail and reportsE-mail addresses, content
FikenAccounting and invoicingInvoice details
StripeCard payment for online ordersPayment details (we never see card numbers)

Survey answers, customer data and reports are stored in Norway (Azure, region Norway East), inside the EEA. Some supporting services (e-mail delivery, payment) have suppliers established outside the EEA; those transfers rely on the European Commission's Standard Contractual Clauses (SCC) and/or the EU–US Data Privacy Framework. You can ask us for a copy of the safeguards that apply. If we take new suppliers into use, the table is updated before they process anything, and you can request an up-to-date list at any time.

8. Security

Data is stored encrypted, with access control at the database level so that every user and every customer reaches only their own data. The anonymity rules in §3 are built into the database itself; they are technical barriers, not just routines: they cannot be overridden from the application or by anyone at the customer, and administrative access on our side is kept to a minimum and never used to read individual answers. Deletion happens through automated jobs, not by someone remembering to do it.

9. Changes

We update this policy when the service changes. The date at the top shows the current version. For changes that matter to you, we notify you directly where we have contact details.