Legal

Privacy statement

Last updated 6 September 2026. This statement explains how Audun processes personal data when you visit our website, use our services or contact us.

1. Who we are

Audun Collection AS, organisation number 937 848 293, Møllergata 6, 0179 Oslo (“Audun”, “we”), is the controller of personal data used in our business. This means we determine the purposes and means of processing. You can contact us about privacy at hello@audun.co.

2. Who this statement applies to

This statement applies when you visit our website, receive a claim from us, use My Page or represent a business that is or is considering becoming an Audun customer. It also applies when you send us an enquiry.

3. Personal data we process

The data we process depends on your relationship with us. It may include:

  • your name, address, telephone number, email address and information needed to identify you,
  • information about claims, invoices, payments and payment agreements,
  • messages, correspondence and notes from conversations with us,
  • your employer, role and contact details when you represent a business, and
  • technical information, such as IP addresses and login events, to operate and secure our services.

If a case contains sensitive data, we limit processing to what is necessary and has a specific legal basis. Information needed for secure identification or processing a claim may be necessary for us to follow up the case or give you access to the service.

4. Where the data comes from

We receive information from you when you use our services or contact us. In collection cases, we also receive information from the creditor that referred the claim. Where necessary, we obtain information from public registers, address services and credit reference agencies. We also record information arising during case handling, such as payment status and conversation notes.

5. Why we use the data

We use personal data to check and follow up claims, contact the right person, process payments, suggest payment plans and respond to enquiries. We also use data to manage customer relationships and access, secure our services and document our work.

Collection activity normally relies on our and the creditor’s legitimate interest in pursuing a lawful overdue claim. Other legitimate interests include preventing errors and misuse, protecting data and establishing or defending legal claims. Statutory documentation is processed to meet legal obligations. If you are personally a party to a contract with us, processing may also be necessary to perform that contract.

Where processing requires consent, we ask for it separately. Consent can be withdrawn. Debt collection does not rely on consent and therefore does not stop when consent for another purpose is withdrawn.

6. Technology and human involvement

Audun uses automation and AI for tasks such as drafting messages, categorising replies, summarising information and suggesting follow-up. Technology helps us tailor communication and follow up cases. Objections and situations requiring judgement or personal support are handled by a case manager.

Follow-up takes account of the amount and due date, payments, deadlines, your replies, whether the claim is disputed and whether your circumstances require an adjustment. You can ask us to explain a specific assessment, give your views and request human assistance. Write to hello@audun.co.

7. Who we share data with

We share data where necessary to carry out the assignment or meet legal obligations. We limit sharing to what the recipient needs:

  • The creditor receives information about case status, payments and matters needed to clarify the claim.
  • Hosting, storage and IT security providers process data to operate and protect our services.
  • SMS, email, letter and digital mail providers process contact details and the content to be delivered.
  • Language model providers process information needed for the tasks described in section 6.
  • Payment, banking and identification services process data needed for payments, reconciliation and secure login.
  • Public registers and credit reference agencies receive information necessary for lawful enquiries.
  • Advisers, legal partners, courts and relevant authorities receive information where the case or the law requires it.

Providers processing data on our behalf are subject to data processing agreements. Other recipients, such as banks and public authorities, may be independent controllers. We do not sell personal data. Contact us to find out who has received your personal data.

8. Retention and security

We use access controls, encryption and logging to protect personal data. Access is limited to people who need the information for their work.

Retention depends on the purpose and the documentation in which the data appears:

  • Case information, communications and payment history are kept while a case is being handled, and afterwards for as long as needed for statutory documentation, complaints or establishing, exercising or defending legal claims. We consider whether the claim is settled or disputed and which limitation periods apply.
  • Accounting records are kept for the periods required by accounting law. Data in those records may therefore need to be retained after a case or customer relationship ends.
  • Business representatives’ contact details are used while needed for the customer relationship. Data in contracts, correspondence and accounting records follows the retention needs of those documents.
  • Login and security data is retained as needed for access, abuse prevention and investigating security incidents. An expired login or payment link does not mean the case records have been erased.

You can ask about the retention period for specific data. When you request erasure, we assess which data can be deleted and which must be retained because of legal obligations or legal claims.

Some providers may process data outside the EEA. Such transfers require a valid transfer mechanism, such as an adequacy decision or standard contractual clauses. Contact us for information about processing countries, the applicable mechanism and a copy of the relevant safeguards.

9. Cookies

Our website and login services use cookies and similar technologies. Read about their purposes and your choices in our cookie information.

10. Your rights

You can request access to your personal data and ask for correction, erasure or restriction where the conditions are met. You can object to processing based on legitimate interests. In some cases, you can receive your data in a format that can be transferred to another service.

The right to erasure is not absolute. For example, we may have to retain documentation. Contact hello@audun.co to exercise your rights. We may ask for information to verify your identity before granting access or making changes.

We respond to privacy requests without undue delay and normally within one month. For particularly complex requests or a large number of requests, the deadline may be extended by up to two further months. We will explain the extension within the first month.

Objecting to the use of personal data is different from disputing a claim. You can do both in the same message. If you believe a claim is incorrect, contact us as described in the payment terms.

11. Complaints and questions

Please contact us if you believe we have processed your personal data incorrectly. You also have the right to complain to Datatilsynet, the Norwegian Data Protection Authority.

12. Changes and further information

We update this statement when our processing or the rules change. The date at the top shows when it was last updated. Contact us for further information about processing in your case or customer relationship.

13. Contact

Audun Collection AS
Organisation number 937 848 293
Møllergata 6, 0179 Oslo
hello@audun.co