Privacy Policy
Privacy, Confidentiality and Professional Data Protection Policy
Effective date: 29 July 2026
Last updated: 29 July 2026
Policy summary. BGB-360 protects personal data and confidential business information entrusted to it through its website, communications and professional engagements. We do not sell personal data. We use information only for specified business, contractual, legal and security purposes; limit access on a need-to-know basis; require appropriate safeguards from service providers; and retain records only for justified periods.
This Policy is a public transparency notice. A signed engagement letter, confidentiality agreement, data-processing agreement or mandatory law may impose additional or more specific requirements. If there is a conflict, mandatory law prevails, followed by the applicable written agreement to the extent legally permitted.
1. Scope and entity responsible
This Policy applies to personal data processed by BGB-360 – Business Growth & Beyond (“BGB-360”, “we”, “us” or “our”) through www.bgb-360.com, contact forms, email, telephone, meetings, proposals, client onboarding and delivery of our advisory, accounting-support, outsourcing, ERP, learning and global-talent services. It also applies to prospective clients, client personnel, suppliers, professional partners, job or talent candidates, learners and other business contacts.
This Policy does not govern a third party’s independent processing, even where its website or service is linked from ours. A client may also issue its own privacy notice when BGB-360 processes data on that client’s instructions.
2. Controller and processor roles
BGB-360 acts as a data controller when it determines why and how personal data is processed—for example, website enquiries, business administration, client relationship management, invoicing, security and legal compliance. BGB-360 may act as a data processor or service provider when processing personal data solely on a client’s documented instructions, such as within outsourced accounting, payroll-support, ERP-support, recruitment or project records. In those cases, the client ordinarily remains the controller and the engagement terms or data-processing agreement governs the processing.
BGB-360 is an advisory and professional-services provider. References to accounting, audit preparation, tax support or compliance do not represent a claim that BGB-360 performs any statutory audit, reserved legal service or other regulated activity unless expressly agreed and lawfully authorized.
3. Data-protection and confidentiality principles
Where applicable, we process personal data according to principles of lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. We apply professional confidentiality to non-public client information regardless of whether that information identifies an individual.
Relevant legal frameworks may include the EU General Data Protection Regulation (“GDPR”), the GDPR as incorporated into the European Economic Area and Norwegian law, the UK GDPR and Data Protection Act 2018, and other national privacy, electronic-communications, employment, tax, accounting, anti-money-laundering or recordkeeping laws that apply to a particular person, engagement or processing activity. Naming a law does not mean it governs every BGB-360 activity or that this Policy creates rights beyond its territorial and material scope.
4. Categories of information we may process
| Category | Illustrative information |
|---|---|
| Identity and contact | Name, professional title, employer, address, email, telephone number, country and preferred contact method. |
| Business and engagement | Enquiries, proposals, contracts, instructions, meeting notes, correspondence, deliverables, approvals and relationship history. |
| Financial and accounting | Invoices, ledgers, journal entries, bank or payment information, transaction records, budgets, forecasts, expenses, payroll-support data, tax-support records and supporting documents supplied for an engagement. |
| Workforce and talent | CVs, qualifications, employment history, skills, availability, professional references, interview notes and recruitment communications. |
| Learning | Registration or participation details, course interests, attendance, assessments and certificates where a learning service is offered. |
| Compliance and risk | Company-registration information, beneficial ownership or identity-verification material where legally or contractually required, conflicts checks, sanctions-screening results and fraud-prevention records. |
| Technical and usage | IP address, browser and device data, timestamps, referring pages, security logs, cookie identifiers and interaction information. |
| Other information | Any information voluntarily included in messages or files. Please do not submit unnecessary sensitive, privileged, health, government-identifier, payment-card or criminal-record information through the public contact form. |
We may obtain information directly from you; from your employer, client or authorized representative; from service providers; from public company registers and professional sources; or from another lawful source relevant to an engagement. Where required, the responsible controller will provide any additional notice concerning indirectly collected data.
5. Purposes and lawful bases
Subject to applicable law, we process information for the following purposes and legal bases:
Where we process special-category or similarly sensitive personal data, we require an additional lawful condition and apply heightened safeguards. We do not ask clients or visitors to provide such data unless it is necessary and legally permitted.
6. Accounting, financial, tax and professional records
Professional engagements may involve confidential commercial information and personal data contained in accounting books, invoices, payroll-support files, employee or contractor records, tax-support documents, ERP extracts, budgets, forecasts, audit-preparation files and management reports. BGB-360 will process such material only within the authorized engagement scope, documented instructions and applicable law.
7. Confidentiality and professional secrecy
“Confidential Information” includes non-public commercial, financial, technical, operational, strategic, personnel and contractual information disclosed in connection with an enquiry or engagement. We use it only for the authorized purpose and do not disclose it except to authorized recipients, with the discloser’s permission, or where required or permitted by law.
Confidentiality does not ordinarily cover information that is lawfully public, already known without restriction, independently developed without use of the confidential material, or lawfully obtained from a third party without a confidentiality duty. If legally compelled to disclose information, we will—where lawful and practicable—limit the disclosure and notify the affected client before disclosure. Detailed obligations may be governed by a separate nondisclosure agreement or engagement letter.
8. Disclosure and service providers
We do not sell or rent personal data. We may disclose only what is reasonably necessary to:
Providers are expected to process information only for authorized purposes, protect it appropriately, notify relevant security events and assist with compliance as contractually required.
9. International and cross-border processing
BGB-360 serves international clients and may use personnel or providers in more than one country. Consequently, information may be accessed, stored or processed outside the country in which it was collected. Where cross-border transfer restrictions apply, we use a legally recognized mechanism appropriate to the circumstances, such as an adequacy decision, approved standard contractual clauses, the UK International Data Transfer Agreement or Addendum, or a permitted statutory derogation, together with supplementary technical and organizational measures where necessary.
A copy or description of the relevant transfer safeguard may be requested, subject to protection of confidential and security-sensitive provisions.
10. Information security and incident response
We apply risk-based administrative, technical and organizational safeguards designed to preserve confidentiality, integrity and availability. Depending on the service and risk, measures may include role-based access, least-privilege controls, authentication, secure transmission and storage, backups, logging, malware protection, provider due diligence, confidentiality undertakings, staff awareness, data minimisation, separation of client records and incident-response procedures.
No internet transmission or storage method is completely secure. If a personal-data breach occurs, we will investigate, contain and document it and will notify the responsible client, regulator or affected individuals when and within the period required by applicable law or contract.
11. Retention, archiving and deletion
We retain information only for as long as reasonably necessary for the original purpose and any compatible legal purpose. The period is determined by the nature and sensitivity of the data, engagement duration, client instructions, limitation periods, dispute or investigation risk, security needs and applicable accounting, tax, corporate, employment, professional or regulatory retention rules.
Specific schedules may be stated in an engagement agreement because legal retention periods vary by record type and jurisdiction.
12. Cookies, analytics and electronic communications
Our website may use strictly necessary cookies for security, navigation and essential functionality, and may use preference, measurement or analytics technologies where permitted. Where consent is legally required, non-essential technologies should not be activated before valid consent. Visitors can manage available choices through the website’s consent controls and browser settings. Blocking essential cookies may affect website functionality.
We send marketing communications only where permitted by applicable law. You may opt out through the method provided in the communication or by contacting us. Service, security, contractual and legal notices are not marketing and may still be sent where necessary.
13. Individual rights and requests
Depending on applicable law and our role, an individual may have rights to be informed; access personal data; correct inaccurate data; request deletion; restrict or object to processing; receive portable data; withdraw consent; and complain to a competent supervisory authority. Certain rights are conditional and may be limited by legal privilege, another person’s rights, controller instructions, statutory exemptions or mandatory recordkeeping.
Requests should be sent to corporate@bgb-360.com with the subject “Privacy Rights Request.” We may request proportionate identity verification and clarification. We will respond within the period prescribed by applicable law. Where BGB-360 acts only as a processor, we may direct the request to, or assist, the relevant client-controller.
EEA individuals may complain to the supervisory authority in their habitual residence, place of work or place of the alleged infringement. UK individuals may contact the UK Information Commissioner’s Office. We encourage you to contact us first so we can try to resolve the concern.
14. Automated decision-making and artificial intelligence
BGB-360 does not currently use the public website to make decisions producing legal or similarly significant effects solely by automated processing. If a future service introduces such processing, we will provide legally required information about its logic, significance, consequences and available human review.
Public or third-party generative-AI systems must not be used for confidential client material unless the use is authorized, contractually permitted, appropriately secured and consistent with applicable privacy and professional obligations.
15. Children and the future eBGB Portal
The current BGB-360 website and professional services are not directed to children, and we do not knowingly collect children’s personal data through the public contact form. The separate eBGB Portal is under development and not yet operational. Before any service involving minors launches, BGB-360 will publish service-specific privacy information and implement age-appropriate design, consent or authorization, safeguarding, access and communication controls as required by applicable law. This Policy does not represent that student registration is currently available.
16. Third-party sites, social media and public sources
Links to third-party websites and social-media pages are provided for convenience. Those parties control their own data practices, and their privacy notices apply. Information deliberately made public on professional networks or registers may be used for legitimate due diligence, relationship management or service delivery, but public availability does not remove applicable data-protection duties.
17. Accountability, changes and jurisdiction-specific notices
We maintain proportionate records, contractual controls and privacy-by-design practices appropriate to our size, role and processing risks. A data-protection impact assessment or similar review will be considered before high-risk processing. This Policy may be updated when our services, providers, technology or legal obligations change. Material changes will be identified through a revised date and, where required, an additional notice or request for consent.
Jurisdiction-specific terms or a client’s data-processing agreement may supplement this Policy. Nothing in this Policy waives a mandatory right or limits a statutory obligation that cannot lawfully be excluded.
18. Principal legal references
The following official sources are included for transparency and do not constitute legal advice or an assertion that every instrument applies to every visitor:
Accounting, tax, company, employment and anti-money-laundering requirements are applied according to the engagement, record type and jurisdiction. Because these requirements differ materially, this public Policy does not state a single universal retention period.
19. Privacy contact
Questions, complaints, data-subject requests and confidential privacy correspondence may be directed to:
BGB-360 – Business Growth & BeyondEmail: corporate@bgb-360.com
Phone: +47 909 94 280
Website: www.bgb-360.com/contact-us/
Please do not send passwords, full payment-card data, government identity documents, health records or other highly sensitive material by ordinary email unless BGB-360 has requested it and provided an appropriate secure method.