Privacy policy
Last updated 3 October 2026.
This policy explains which personal data Kantax processes, why, and what rights you have. It covers the website kantax.no and the Kantax service.
1. Who is responsible
Kantax is provided by Kantos AS (org. no. 837 544 432), Waldemar Thranes gate 3B, 0172 Oslo, Norway. Send privacy questions to kantax@kantos.ai.
2. Two roles
We are the controller for data about you when you visit the website, have an account with us, or are the contact person for a company that subscribes to Kantax.
We are a processor for the data our customers enter into Kantax about other people: employees, their own customers and suppliers, and bank transactions. The customer – the company – is the controller for that data, and we process it only on the customer’s behalf. If you work for, buy from or supply a company that uses Kantax, please contact that company first. We help them answer you.
3. What we process, why, and on what legal basis
Visiting the website
When you open a page, our servers receive your IP address, information about your browser and the page you ask for, as every website does. We use this to deliver the page and to keep the service secure. The legal basis is our legitimate interest in running a secure website (GDPR Article 6(1)(f)).
Your account and signing in
- If you sign up with email, we store your email address and password. The password is stored only as a cryptographic hash, never in plain text.
- If you sign in with BankID through ID-porten, we receive your name and national identity number (fødselsnummer). We use it to identify you securely and to connect you to payslips and employment contracts from your employer. If you are registered as an employee of a company that uses Kantax, we connect your account to that company. Accounts created with BankID get an internal email address that is never used for sending.
The legal basis is our agreement with you (Article 6(1)(b)). We process the national identity number because we have a legitimate need for secure identification (Norwegian Personal Data Act, section 12).
Subscription and payment
For subscribing companies we store the name, organisation number, address, contact details, billing email address, subscription status and trial period. Payment is handled by Stripe. Card details go straight to Stripe and never reach us. The legal basis is the agreement and our bookkeeping obligation for invoices and payments (Article 6(1)(b) and (c)).
Emails from the service
We send emails when you or your company asks us to – such as invitations, invoices, payslips and signing links – and notices about the subscription and the bank connection. For each email we store the recipient address, type and status. The legal basis is the agreement and our legitimate interest in being able to document what was sent.
Activity log
We keep a log of changes in each company’s account: who did what, and when. It can contain names and email addresses, for example of employees or invoice recipients. The legal basis is our and the customer’s legitimate interest in an audit trail.
Customer support
When you contact us, we use the information you give us to answer you. The legal basis is our legitimate interest in helping our customers.
Analytics and ad measurement – only with consent
- Analytics: Google Analytics shows us which pages are visited and how the website is used.
- Advertising measurement: OpenAI’s ad measurement shows us which of our ads in ChatGPT lead to sign-ups and subscriptions. See section 5.
The scripts for both load only on the public pages of kantax.no, never inside the service and never while you are signed in – and only if you have said yes. If you start a paid subscription after saying yes to “Advertising measurement”, we report it to OpenAI from our servers (see section 5). The legal basis is your consent (Article 6(1)(a) and section 3-15 of the Norwegian Electronic Communications Act). You can withdraw it at any time, as easily as you gave it.
Data we process on behalf of our customers
When a company keeps its books and payroll in Kantax, we process the following on its behalf, among other things:
- employees’ names, email addresses, national identity numbers, bank account numbers, salaries, tax deductions, pensions, terms of employment, payslips and the content of the A-melding (the monthly payroll report to the tax authorities);
- signing of employment contracts with BankID: name, national identity number, assurance level, time, IP address and browser information, as evidence of who signed;
- customers and suppliers, who may be private individuals: names, contact details, invoices and messages sent from the invoice page;
- receipts and other vouchers, which we store as files;
- bank transactions when the company connects its bank: account names, account numbers, balances, and transactions with the counterparty’s name and account.
The legal basis for this processing is the company’s, for example the employer’s obligations under Norwegian payroll reporting and bookkeeping law.
4. Cookies and local storage
We use only the cookies and local storage the service needs to work, unless you say yes to more. Nothing in the “Analytics” and “Advertising measurement” categories is loaded or stored before you choose. You can change or withdraw your choice with “Cookie settings” at the bottom of the website. When you withdraw consent, we delete the cookies and local storage it covered.
Strictly necessary (always on)
| Name | Purpose | Lifetime |
|---|---|---|
sb-…-auth-tokencookie | Keeps you signed in. Holds your login tokens and user details – for BankID users, including the national identity number. May be split into parts (.0, .1). | Until you sign out; at most 400 days |
sb-…-auth-token-code-verifiercookie | Verifies the emailed link when you sign up or reset your password. | Until the link is used |
kantax_localecookie | Remembers the language you chose. | 1 year |
idporten_pkce_verifieridporten_stateidporten_purposeidporten_sign_tokenidporten_view_tokenidporten_view_langidporten_nextcookie | Used while you sign in or sign with BankID. | 15 minutes |
kantax_payslip_grantcookie | Lets you open a payslip after you have signed in with BankID. | 15 minutes |
kantax_consentcookie | Remembers your cookie choice. | Up to 180 days (7 days in Safari) |
Analytics (only with consent)
| Name | Purpose | Lifetime |
|---|---|---|
_ga_ga_…cookie | Google Analytics: tells visitors apart and counts visits. | Up to 2 years |
Advertising measurement (only with consent)
| Name | Purpose | Lifetime |
|---|---|---|
__opprefcookie | Remembers which ChatGPT ad you came from. | 30 days, renewed on each new ad click |
__obrefcookie | A reference to your browser, so OpenAI can connect visits and sign-ups. | 365 days |
__oaiq_consentcookie | OpenAI’s own record of your consent. | 30 days |
oaiq_consentlocal storage | OpenAI’s own record of your consent. | No expiry; deleted when you withdraw consent |
oaiq_cs:…session storage | OpenAI’s measurement session in this tab. | Until the tab closes |
__oaiq_domain_probecookie | Lets OpenAI’s script find the right domain for its cookies. | 60 seconds |
__cf_bm_cfuvidcookie · bzrcdn.openai.com | Set by Cloudflare on OpenAI’s server when the script loads, to stop abuse. We can’t delete them. | From the session to 30 minutes |
5. Ad measurement with OpenAI
We advertise in ChatGPT. If you have said yes to “Advertising measurement”, we use OpenAI’s ad measurement on the public pages of kantax.no to see which ads lead people to sign up and become customers. OpenAI then receives:
- which public pages you view;
- that you have created an account, when you submit the sign-up form;
- that you have started a paid subscription, with plan, amount and currency – sent from our servers once the payment is confirmed;
- a reference to the ad click you came from, and a reference to your browser;
- your IP address and browser information;
- your email address in hashed form: the one you pay with, and the one you type into the sign-up form. A hash can’t be turned back into the email address, but OpenAI can compare it with email addresses it knows and so connect it to a ChatGPT account. It is therefore not anonymous.
So that we can report the subscription, when you start the payment we store the references to the ad click and your browser, your IP address and browser information with the payment at Stripe. This happens only if you have said yes to “Advertising measurement”.
OpenAI uses this data to measure how our ads perform. The ad measurement script is never loaded inside the service, never on pages that show payslips, invoices, contracts or invitations, and never while you are signed in.
6. AI features
- When you upload a voucher to AI Innboks (the AI inbox), the file is sent to OpenAI’s API, which reads the supplier, amounts, dates and other details. We store the answer with the voucher.
- Customers can connect AI assistants and their own integrations to Kantax through our API and MCP. They get access to the data the customer gives them access to. Answers that AI assistants get through MCP leave out national identity numbers and employees’ bank account numbers.
7. Who we share data with
These providers process personal data for us (processors):
| Provider | What | Where |
|---|---|---|
| Supabase | Database, sign-in and file storage | EU (Ireland); a US company |
| Vercel | Hosting the website and the service | EU (Ireland); a US company |
| Stripe | Subscription payments – with advertising consent, also its references | EU and US |
| OpenAI | Reading vouchers in AI Innboks, and ad measurement with consent | US |
| Google (Google Analytics) | Website analytics, with consent | US |
| Google (Google Workspace) | Our email, including messages to kantax@kantos.ai | Several countries, including the US |
| Twilio SendGrid, through Kantos AS’s email platform | Sending email | US |
| Enable Banking | Bank connection, when the company connects its bank | Finland |
These receive data because the service requires it, but process it under their own responsibility:
- the Norwegian Digitalisation Agency (ID-porten), when you sign in or sign with BankID;
- the Norwegian Tax Administration, also through Altinn, when a company submits an A-melding or VAT return or fetches tax cards;
- the Brønnøysund Register Centre, when you look up a company;
- recipients the company chooses itself, such as webhook addresses, AI assistants and integrations.
We never sell personal data.
8. Transfers outside the EEA
Supabase, Vercel, Stripe, OpenAI, Google and Twilio SendGrid are US companies. Even where data is stored in the EU, it may be processed in the United States, for example for operations and support. That applies wherever you live. These transfers rely on the EU–US Data Privacy Framework or on the European Commission’s standard contractual clauses.
9. How long we keep data
- We keep your account as long as it exists. You can ask us to delete it at kantax@kantos.ai.
- Accounting data – vouchers, invoices, payroll, A-meldinger and VAT – is kept as long as the company has an account with us. The Norwegian Bookkeeping Act requires accounting records to be kept for five years after the end of the financial year. That obligation is the company’s, and we keep the records for it.
- Invoices and payments for the subscription are kept for five years after the end of the financial year, as the Bookkeeping Act requires.
- If you said yes to “Advertising measurement” when you started a subscription, the ad measurement references, your IP address and browser information are kept with the payment at Stripe. They aren’t deleted automatically today; ask us to delete them at kantax@kantos.ai.
- Logs of emails and activity are kept as long as the account exists.
- Access granted to AI assistants (MCP) is deleted automatically when it expires.
- Cookies: see the table in section 4.
The service has no self-service deletion today. We delete data when you or the company asks, unless the law requires us to keep it.
10. Your rights
You have the right to access the data we hold about you, and to have it corrected or deleted. You can also ask us to restrict processing, receive your data in a machine-readable format, and object to processing based on our legitimate interest. You can withdraw consent at any time.
Email kantax@kantos.ai and we will answer within one month. If the request concerns data we process for a company (section 2), we pass it on to that company.
If you believe we process data in breach of the rules, you can complain to the Norwegian Data Protection Authority (Datatilsynet).
11. Security
- All traffic to and from Kantax is encrypted (HTTPS).
- The database and files are stored with Supabase in the EU (Ireland), and each company can access only its own data.
- Payslips sent by email are opened with BankID, and the PDF is also protected with the employee’s national identity number as its password. Employment contracts are signed with BankID.
12. Changes
We update this policy when the service changes. The date at the top shows when it last changed.