FIDESTRIP / LEGAL
Privacy Policy
Fidestrip is business software. This notice explains how Kalirox AS handles personal data, including Google sign-in, Stripe billing and customer workspace information. It is not a waiver of privacy rights or a request for blanket consent.
Effective date: 3 October 2026 · English version
1. Who we are
Fidestrip is provided by Kalirox AS, Norwegian organisation number 836 971 752, Tårnveien 14, 3047 Drammen, Norway. Contact info@fidestrip.com for privacy enquiries, data requests or security concerns. Identify the relevant workspace if known; do not send passwords, full card details or unnecessary sensitive records.
This notice covers visitors, business account holders, authorised users, billing contacts and people contacting us. Subscriptions are offered only for professional use. That restriction does not reduce the privacy rights of employees, contacts, travellers or other individuals.
2. Controller and processor responsibilities
Kalirox AS is a controller for its business relationships, account administration, billing, support, service security and legal compliance. For customer-controlled operational records, such as contacts, groups and reservations, the customer normally determines the purposes and Kalirox AS acts as its processor under documented instructions.
A data processing agreement (DPA) must be concluded before production personal data is uploaded. This notice does not replace it. A customer acting as a processor for another organisation must have authority to appoint us as a subprocessor. Customers must provide their own privacy information to affected people. Kalirox AS remains responsible for obligations applying to its own role.
3. Account and operational information
Google sign-in through Firebase Authentication verifies your Google identity. We process your Firebase user identifier, verified email address and authentication information, and retain the account, workspace membership, permissions and trial dates needed to provide access. Google and Firebase also process profile, device and connection information associated with their service. We do not receive your Google password.
Workspace records can contain company and contact names, contact details, guide names, group descriptions and sizes, hotels, rooms, reservation references, stay dates, room assignments, rates and text supplied by users. The actual categories depend on what the customer enters. Authorised workspace users can see records according to their permissions.
4. Sensitive information and children
Hajj or Umrah information may reveal religious beliefs, including by inference. The customer must establish both a lawful basis and, where necessary, a separate GDPR Article 9 condition before entering special-category data. Accepting business terms does not supply an individual's consent to that processing.
Use only information necessary for accommodation operations. Do not enter full card details, security codes, passwords, identity-document copies, detailed medical records or unnecessary sensitive information. Children's travel information requires an authorised organisation, a valid lawful basis and appropriate safeguards. Accounts are not offered directly to children. Contact us before a use requiring additional safeguards.
5. Stripe payments, billing and disputes
We use Stripe-hosted Checkout and the Stripe customer portal for subscription payments, billing management and invoices. To start checkout, we send Stripe your business name, registration number, country, account email, workspace reference, selected plan and terms version. Stripe collects payment-method details, billing address and tax information through its hosted services. Fidestrip's application does not receive or store full card numbers or card security codes.
We retain customer, checkout and subscription identifiers, the plan, payment-related status, billing-period dates, trial dates and the account, time and terms version associated with checkout acceptance. Stripe sends status updates so we can administer access and billing. We may access invoices and relevant transaction details in Stripe for support, refunds, accounting and payment disputes.
Stripe's role depends on the activity: it processes some information on our behalf and acts as an independent controller for activities it determines, including certain fraud-prevention, regulatory and payment-network functions. Its privacy notice explains those activities and international processing. Using Stripe does not transfer our responsibilities as software supplier or controller to Stripe.
To handle a refund or chargeback, we may share proportionate order, acceptance, access-history and correspondence evidence with Stripe, payment providers, banks and advisers. We do not routinely send guest or reservation contents to Stripe.
6. Contact messages, activity history and diagnostics
When you contact us, we process your name, company, email, message and information you choose to supply. Where the contact form is enabled, Cloudflare Turnstile checks connection and browser signals for abuse; verification includes an IP address. Cloudflare email services deliver the message to our support mailbox. Do not send guest lists or sensitive documents in a general enquiry.
Operational history records the user, time, affected record, outcome and selected before-and-after changes, and may contain personal data. Technical diagnostics include route templates, response status, duration, request identifiers and limited error details. Our browser diagnostics exclude form contents, passwords, tokens, full URLs and session replay. Hosting, network and authentication providers may separately process IP addresses and device information.
Where Azure Monitor is enabled, limited technical and business-event diagnostics are sent to Microsoft. Monitoring events exclude guest names, contact details, record contents and before-and-after values; separate workspace activity history remains in the application database. These controls do not mean that all diagnostic information is anonymous.
7. Purposes and lawful bases
For controller activities, we rely on legitimate interests under GDPR Article 6(1)(f) to administer relationships with business customers and their personnel, authenticate users, respond to enquiries, protect the service, investigate misuse and establish or defend legal claims. We assess these interests against individuals' rights. Where an individual is the contracting customer, such as a sole trader, Article 6(1)(b) may apply to requested pre-contractual steps and contract performance.
We use Article 6(1)(c) for applicable accounting, tax and other legal obligations. Where an optional activity requires consent, we request it separately and allow withdrawal. Acceptance by a business representative is not blanket privacy consent. For processing on instructions, the customer determines the lawful basis and any required special-category condition.
Required identity and billing information is necessary for an account or paid subscription; those services may be unavailable without it. We do not sell personal data or use customer workspace content for advertising.
8. Recipients and service providers
Information is available to authorised customer users and personnel who need it for their work. Providers include Google/Firebase for authentication, Stripe for billing and payments, Cloudflare for web delivery, security and, where enabled, contact verification and email delivery, and Microsoft Azure for application, database and monitoring infrastructure. Support correspondence also passes through the email providers used to send and receive it.
We may disclose necessary information to professional advisers, authorities where legally required, and parties to a corporate transaction with appropriate confidentiality and data-protection safeguards. Subprocessors handling customer operational information must be covered by the DPA's authorisation and change-notice arrangements. This general description does not replace the deployment-specific subprocessor list.
9. Locations and international transfers
Our selected Azure deployment region is Qatar Central. Where that deployment is used, application, database and monitoring processing can take place in Qatar, outside the European Economic Area (EEA). Cloudflare's network and Google, Microsoft and Stripe services can involve processing or support outside your country, including in the United States. Fidestrip does not promise that all data stays in Norway or the EEA.
Before production processing, the DPA and provider information must identify the applicable locations and transfer arrangements. Required transfers must rely on a valid adequacy decision or appropriate safeguards, such as the European Commission's standard contractual clauses, with assessment and supplementary measures where necessary. Accepting these terms alone is not a transfer safeguard. Contact us for applicable arrangements and copies of safeguards, subject to lawful redactions.
10. Retention, return and deletion
Account and membership information is retained while needed to provide and secure the account. Operational data is retained under the customer's documented instructions and DPA, including agreed return and deletion arrangements. Cancellation, trial expiry and read-only access do not themselves delete a workspace or promise indefinite storage. Contact us to arrange return or deletion.
Billing, transaction and acceptance records are retained for applicable accounting, tax, fraud-prevention and legal-claims requirements. Support correspondence is kept while needed for the enquiry and any related dispute. A specific legal hold may preserve relevant material, but does not justify indefinite retention of unrelated records. Stripe applies its own legal retention obligations to data it controls.
Technical logs, operational history and backups have different lifecycles. Their deployment-specific periods, backup expiry and deletion process must be documented in the DPA and retention schedule before production personal data is accepted. Restricted backups may retain deleted data until expiry, subject to legal requirements and protection against ordinary use. We do not promise immediate erasure from every backup or provider system.
11. Cookies, storage and automated checks
We use essential session and request-protection cookies and storage for language and onboarding preferences. Firebase uses temporary in-memory authentication state, cleared by the application after establishing its server session. Google and Stripe use their own browser mechanisms on their hosted services; Turnstile uses the mechanisms described by Cloudflare when verification is enabled.
Our application does not add advertising trackers or session-replay tools. Non-essential technologies requiring consent must not be enabled without the appropriate choice. Authentication, abuse and subscription checks control access; they are not decisions about eligibility for employment, credit or comparable services. Contact us to review a suspected access or billing error.
12. Security and incidents
We use authenticated sessions, workspace access checks, request protection and activity logging to protect information. Customers must manage users, secure Google accounts, minimise uploaded data and report misuse. No service can guarantee perfect security or availability; this does not exclude statutory security, confidentiality or breach-notification duties.
As processor, we notify the customer of a personal data breach without undue delay after becoming aware and provide the information and assistance required by law and the DPA. As controller, we assess and make required notifications to authorities and affected individuals.
13. Rights and complaints
Subject to applicable conditions, individuals may request access, correction, erasure, restriction, portability, or object to processing, including processing based on legitimate interests. Consent may be withdrawn without affecting the lawfulness of earlier processing. A business contract does not waive these rights.
Email info@fidestrip.com. We may seek proportionate identity and authority verification. We respond without undue delay and normally within one month; if a lawful extension is needed, we explain it within that period. Requests are normally free, subject to lawful exceptions. For customer-controlled data, contact the customer first; we help identify the responsible organisation and assist under the DPA.
You may complain to Datatilsynet, the Norwegian Data Protection Authority, or another competent authority, and use legal remedies. Business terms do not restrict mandatory data-subject rights, regulatory powers or legally required compensation.
14. Changes
We identify the revision on this page and provide appropriate notice of material changes. A revised notice does not retrospectively create consent, authorise an incompatible purpose or override a DPA. Where additional information, agreement or consent is required, we obtain it before the relevant change.
info@fidestrip.com · Kalirox AS · Stripe Privacy Policy · Datatilsynet