Privacy Policy

Effective Date: 2026-09-01. Last updated: 2026-09-01.

1. Introduction

Halden Cartographic Systems, Inc. ("Halden", "we", "our", or "us") respects your privacy and is committed to protecting your personal information in accordance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and other applicable data protection laws. This Privacy Policy explains what personal information we collect, how we use it, with whom we share it, and the rights you have in relation to that information. By using our services you acknowledge that you have read and understood this Policy.

This Policy applies to all users of Halden's mapping, geodata, and route-planning services accessed through our website, mobile applications, and public application programming interfaces. It does not apply to third-party services that we do not control.

2. Data We Collect

2.1 Information you provide directly

When you create an account, contact support, or submit content through our services, you may provide information such as your name, email address, postal address, telephone number, payment card details, and any other information you choose to disclose.

2.2 Information collected automatically

We automatically collect certain information when you interact with our services, including your Internet Protocol (IP) address, device identifiers, browser type and version, operating system, referring URLs, page views, session duration, and approximate location derived from your IP address. We use cookies and similar technologies to collect this information; you can control cookies through your browser settings.

2.3 Location data

If you grant our applications permission to access precise location data, we will collect that data to provide our core navigation and routing features. You can revoke this permission at any time through your device settings.

2.4 Information from third parties

We may receive information about you from third parties such as identity providers, payment processors, and marketing partners in accordance with their own privacy notices.

3. How We Use Your Data

The legal bases on which we rely under the GDPR are: performance of a contract, our legitimate interests (including protecting our services from abuse), your consent (which you may withdraw at any time), and compliance with legal obligations.

4. Sharing and Disclosure

We do not sell your personal information. We share personal information only in the following circumstances:

5. Retention

We retain personal information only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. When personal information is no longer required, we take reasonable steps to securely delete or anonymize it. Typical retention periods are: account data — for the duration of the account plus 24 months; billing and tax records — 7 years; support communications — 24 months; security and audit logs — 12 months.

6. Your Rights

Depending on your jurisdiction, you may have the following rights in relation to the personal information we hold about you:

To exercise any of these rights, please contact us using the details in Section 10.

7. Security

We implement appropriate technical and organizational measures to protect personal information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit and at rest, network segmentation, access controls based on the principle of least privilege, background checks for personnel with access to sensitive systems, and regular security assessments performed by independent third parties. No method of transmission over the Internet or method of electronic storage is completely secure, however, and we cannot guarantee absolute security.

8. Children

Our services are not directed to children under the age of 16 and we do not knowingly collect personal information from children under that age. If we become aware that we have collected personal information from a child without verified parental consent, we will take steps to delete that information promptly.

9. International Transfers

Halden operates in multiple jurisdictions and personal information may be transferred to, stored, and processed in countries other than the country in which it was collected. Where personal information is transferred out of the European Economic Area, we rely on the European Commission's Standard Contractual Clauses and, where appropriate, supplementary technical and organizational measures to ensure an adequate level of protection.

10. Contact

If you have questions about this Privacy Policy or our privacy practices, or if you would like to exercise any of the rights described above, please contact our Data Protection Officer at: privacy@halden.example — postal address: Halden Cartographic Systems, Inc., 12 Nordstrom Alle, 1780 Halden, Norway. Certification ID: HRA-7734-QG-2196.