NyhetValgt ut av Innovasjon Norges Økosystemprogram — vi tilbyr startups gratis kundemøter med store internasjonale selskaper. Registrer innen 15. august.Registrer →

Privacy Policy

David Goliath Ventures AS

Last updated: 28 June 2026

This privacy notice describes how David Goliath Ventures AS ("DGV", "we", "us", "our"), collects, uses and processes personal data. For information about our use of cookies please refer to our Cookie Policy.

1. Introduction

David Goliath Ventures AS ("David Goliath Ventures", "we", "our", or "us") is committed to protecting your privacy and processing personal data responsibly, securely, and in accordance with applicable Norwegian and European data protection legislation, including the Norwegian Personal Data Act (Personopplysningsloven) and the EU General Data Protection Regulation (GDPR), as incorporated into Norwegian law.

This Privacy Policy explains how we collect, use, store, share, and protect personal data when you interact with us through our website, services, events, startup programs, partnerships, investment-related activities, or other business activities.

2. Data Controller

David Goliath Ventures AS is the data controller for the personal data described in this Privacy Policy, unless otherwise stated in a specific agreement or notice.

3. Personal Data We Collect

Depending on your relationship with us, we may collect and process the following categories of personal data:

  • Contact information: name, company, job title, email address, telephone number, and country.
  • Business information: company information, startup profile, investment-related information, industry, innovation interests, partnership interests, and other business information you provide to us.
  • Communication information: emails, meeting notes, calendar invitations, event participation, feedback, survey responses, and other correspondence.
  • Website and technical information: IP address, browser type, device information, cookie identifiers, website usage data, and analytics data.

We do not intentionally collect special categories of personal data unless this is necessary for a specific purpose and permitted by law, or you have explicitly provided such information.

4. How We Use Personal Data

We may process personal data for the following purposes:

  • To deliver our services and manage business relationships.
  • To manage startup, scaleup, investment, and corporate innovation programs.
  • To facilitate introductions, meetings, and collaboration opportunities between companies, startups, investors, and partners.
  • To respond to enquiries and communicate with you.
  • To organise events, workshops, meetings, and networking activities.
  • To send newsletters, invitations, updates, and marketing communications where we have a valid legal basis, including consent where required.
  • To improve our website, services, programs, and internal processes.
  • To fulfil contractual obligations and comply with legal, accounting, and regulatory requirements.
  • To protect our rights, prevent misuse, and maintain information security.

5. Legal Basis for Processing

We process personal data only where we have a valid legal basis under GDPR. Depending on the circumstances, the legal basis may be:

  • Consent, where you have given clear permission for a specific purpose.
  • Performance of a contract, where processing is necessary to enter into or perform an agreement with you or your organisation.
  • Legal obligation, where processing is necessary to comply with applicable laws and regulatory requirements.
  • Legitimate interests, where processing is necessary for our business operations, provided that your rights and freedoms do not override those interests. Our legitimate interests may include maintaining business relationships, developing innovation programs, improving services, managing events, preventing misuse, and communicating with relevant business contacts.

6. Cookies and Website Analytics

Our website may use cookies and similar technologies to ensure website functionality, analyse website traffic, improve the user experience, remember preferences, and, where relevant, support marketing activities.

Non-essential cookies will only be used where legally permitted and, where required, after consent has been obtained. You may be able to manage cookie preferences through our website cookie banner or your browser settings.

7. Sharing of Personal Data

We may share personal data with trusted third parties where necessary for the purposes described in this Privacy Policy. These may include:

  • Startups, scaleups, investors, corporate partners, and other participants in our programs or collaboration activities.
  • IT, cloud, CRM, communication, analytics, and hosting service providers.
  • Event, marketing, and administrative service providers.
  • Professional advisers such as lawyers, accountants, auditors, and consultants.
  • Public authorities, courts, or regulators where required by law.

We do not sell personal data. Where third-party service providers process personal data on our behalf, we require appropriate data processing agreements and security measures.

8. International Transfers

Personal data may be processed or stored outside Norway or the European Economic Area (EEA) where our suppliers or partners operate internationally.

Where personal data is transferred outside the EEA, we will ensure that appropriate safeguards are in place, such as an adequacy decision, EU Standard Contractual Clauses, or other legally approved transfer mechanisms.

9. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including to provide services, maintain business relationships, comply with legal and accounting obligations, resolve disputes, and protect legal rights.

When personal data is no longer required, it will be deleted, anonymised, or securely archived in accordance with applicable law and internal routines.

10. Information Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure.

Access to personal data is limited to persons who need it for legitimate business purposes. In the event of a personal data breach, we will assess the risk and, where required, notify the Norwegian Data Protection Authority (Datatilsynet) and affected individuals in accordance with GDPR.

11. Your Rights

Subject to applicable law, you have the following rights regarding your personal data:

  • Right of access: to request information about and a copy of the personal data we process about you.
  • Right to rectification: to request correction of inaccurate or incomplete personal data.
  • Right to erasure: to request deletion of personal data in certain circumstances.
  • Right to restriction: to request that processing is restricted in certain circumstances.
  • Right to object: to object to processing based on legitimate interests and to object to direct marketing at any time.
  • Right to data portability: to receive certain personal data in a structured, commonly used, and machine-readable format.
  • Right to withdraw consent: where processing is based on consent, you may withdraw that consent at any time without affecting processing already carried out before withdrawal.
  • Right to lodge a complaint: you may lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) if you believe that our processing of personal data violates applicable law.

12. Automated Decision-Making

We do not normally make decisions about individuals based solely on automated processing that produce legal or similarly significant effects. If this changes, we will provide relevant information and safeguards as required by law.

13. Third-Party Services and Links

Our website, communications, or services may contain links to third-party websites, tools, or platforms. Their processing of personal data is governed by their own privacy policies, and we are not responsible for their privacy practices.

14. Children's Privacy

Our services are not directed at individuals under the age of 16, and we do not knowingly collect personal data from children.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect legal, technical, or business developments. The latest version should be made available on our website or provided upon request.

16. Contact and Company Information

Company

David Goliath Ventures AS

Organisation number

932 833 751

Address

Breidablikkveien 8, 1167 Oslo, Norway

Email

gustav@davidgoliath.no

Supervisory authority

Norwegian Data Protection Authority (Datatilsynet)

You may also contact Datatilsynet or read more about data protection rights at: www.datatilsynet.no