Privacy Notice for Summit EcoSystem™

Last updated August 12, 2026

This Privacy Notice explains how personal data is processed when you visit summitecosystem.com, send us an enquiry, register for Summit Growth Fund or use a password-protected area of the website.

1. Controller

Tronrud Ventures AS is the controller of personal data collected through the website.

Tronrud Ventures AS

Organisation number: 918 439 706

Fornebuveien 1

1366 Lysaker

Email: press@summitecosystem.com

Summit EcoSystem™ is a trademark and an interconnected ecosystem, not a separate legal entity.

2. Personal data we process

Enquiries and contact forms

When you contact us, we may process your name, email address, telephone number, company, how you found us, the content of your enquiry and subsequent correspondence.

The purpose is to respond to and follow up your enquiry. The legal basis is our legitimate interest in communicating with people who contact us of their own initiative, pursuant to Article 6(1)(f) of the General Data Protection Regulation (GDPR). Where the enquiry concerns entering into or performing a contract, the legal basis may be Article 6(1)(b).

Summit Growth Fund

When you register for Summit Growth Fund, we may process your name, email address, telephone number, company, how you found us, your description, the time of registration and evidence of your consent.

The personal data is used to administer the stakeholder and development panel and to contact you about relevant development tracks, tests, surveys, pilot projects, demonstrations, events, collaboration opportunities and information about relevant products or services.

The legal basis is consent, pursuant to GDPR Article 6(1)(a). Consent is voluntary and may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing already carried out.

Login and restricted access

For individuals who are given access to password-protected content, we may process their name, email address, access level, encrypted or hashed password information, login data and security logs.

The purpose is to administer access and protect restricted content. The legal basis is our legitimate interest in secure access management, pursuant to Article 6(1)(f), or performance of a contract where relevant.

Technical information

When the website is used, the following may be processed: IP address, time, requested page, browser and device information, error messages, security events and cookie preferences.

The purpose is to provide, secure and troubleshoot the website, and to document and respect cookie preferences. The legal basis is our legitimate interest in secure and stable operation, pursuant to Article 6(1)(f).

We do not use personal data for automated individual decision-making or profiling.

3. Providing personal data is voluntary

It is voluntary to send us an enquiry or register for Summit Growth Fund. Fields marked as mandatory are necessary for us to process the registration or respond to the enquiry.

Do not submit health information, national identification numbers or other special-category personal data through the website forms.

4. Retention and deletion

Personal data is not retained for longer than necessary:

  • General enquiries are normally deleted no later than 12 months after the last relevant contact.
  • Personal data in Summit Growth Fund is retained until consent is withdrawn, the panel is discontinued or 24 months have passed since the most recent active confirmation or participation.
  • Account information is normally deleted or anonymised within 90 days after access has ended.
  • Technical logs are normally retained for up to 30 days and never longer than 90 days, unless a specific security incident requires longer retention.
  • Evidence of consent may be retained for up to three years after the consent has been withdrawn or expired, in order to document compliance with applicable law.

Personal data may be retained for longer where this is necessary to comply with statutory record-keeping requirements or handle a specific legal claim.

5. Who we may share personal data with

Access is granted only to individuals and suppliers who need the personal data for the relevant purpose.

We may use:

  • Texicon AS for development, maintenance and technical administration
  • Railway Corporation for hosting and technical infrastructure
  • Google (Google Workspace) for email services
  • the relevant company within Summit EcoSystem™ where an enquiry specifically concerns that company

Processors must be bound by data processing agreements and may process personal data only on documented instructions.

The website uses Adobe Fonts. Adobe may receive the IP address in order to deliver the fonts, but states that the IP address is not stored as part of the font delivery service.

The website contains external links to Vimeo. No personal data is sent to Vimeo through the link itself before you choose to open it. Once you leave the website, Vimeo’s own privacy rules apply.

We do not sell personal data.

6. Transfers outside the EEA

Railway Corporation and Google are established in the United States, and certain technical suppliers may process personal data outside the EEA. Where this occurs, the transfer must be based on a valid transfer mechanism, such as an adequacy decision, the EU–US Data Privacy Framework or the European Commission’s Standard Contractual Clauses, together with any necessary supplementary measures.

7. Cookies and local storage

The website may use the following strictly necessary technologies:

  • acts_cms_cookie_consent: remembers whether optional cookies have been accepted or rejected. Retention period: 12 months.
  • acts_cms_consent_ts: records the time of the cookie choice. Retention period: 12 months.
  • Local storage for display preferences: remembers a technical display preference. Retained until browser data is deleted.
  • Login cookie (payload-token): is set only when an authorised user logs in and is used for secure session and access management. Retention period: 90 days, or until it is deleted on logout.

Strictly necessary cookies are used without consent because they are necessary for security, login or remembering your choices.

Any optional analytics or marketing cookies must not be activated until freely given, informed and explicit consent has been obtained. Rejecting must be as easy as accepting, and consent must be capable of being withdrawn through the cookie settings.

As at the date of this Notice, the website does not use active analytics or marketing cookies. This Notice and the consent solution must be updated before any such services are introduced.

8. Your rights

Depending on the processing, you may have the right to:

  • access the personal data we hold about you
  • rectification of inaccurate or incomplete personal data
  • erasure or restriction of processing
  • object to processing based on legitimate interests
  • data portability where the processing is based on consent or a contract
  • withdraw consent at any time

You may exercise your rights by contacting press@summitecosystem.com. We will respond without undue delay and normally no later than one month. Your rights may be limited where permitted by law.

You may lodge a complaint with Datatilsynet, the Norwegian Data Protection Authority, if you believe that your personal data is being processed in breach of applicable law: www.datatilsynet.no.

9. Information security

We use appropriate technical and organisational measures to protect personal data, including encrypted data transmission, access controls, secure authentication mechanisms and restricted administrative access.

10. Changes

This Notice will be updated if the processing, website functionality or suppliers change. Material changes will be communicated in an appropriate manner before they take effect.