Privacy Policy for Bare Dykk
Last updated: July 2, 2026
How Bare Dykk AS processes personal data through our website, online store, and services.
This is an English translation provided for convenience. The Norwegian version is the legally binding version.
1.Who is the data controller?
Bare Dykk AS is the data controller for personal data processed through our websites, online store, contact forms, and services.
Bare Dykk AS
Organization number: 924 412 747
Registered business address: Bruhaugvegen 52, 7710 Sparbu
Contact address: Melgårdsvegen 27A, 7710 Sparbu
Email: info@baredykk.no · Phone: +47 458 02 787
Contact us if you have questions about how your personal data is processed or if you wish to exercise your privacy rights.
2.What this privacy policy covers
This policy covers the processing of personal data in connection with:
- Visits to baredykk.no
- Purchases in the online store
- Customer account
- Contact and inquiry forms
- Newsletters and marketing
- Courses and certification programs
- Guided dives and boat trips
- Accommodation and dive packages
- Rental of diving equipment
- Service, repair, and inspection
- Gas filling
- Customer service and complaints
- Social media and digital ads
3.Which data we process
Depending on how you use our services, we may process the following data:
Contact data
- Name
- Address
- Email address
- Phone number
- Country and language
Order and payment data
- Products and services you order
- Order number
- Price, payment, and payment status
- Delivery and billing address
- Shipping information and tracking number
- Return, warranty, and complaint information
Bare Dykk does not normally receive complete card details. Such data is processed by the payment provider you choose at checkout.
Account data
- Username
- Encrypted password
- Order history
- Saved addresses
- Account activity
Inquiries and customer dialogue
- Messages through the contact form
- Email and other correspondence
- Information you provide when requesting product guidance
- Photos, video, and documentation in service or complaint cases
Data about courses and diving activities
This may include, among other things:
- Certification level
- Number and type of dives
- Date of last dive
- Experience with drysuit, current, technical diving, or rebreather
- Rebreather model and equipment configuration
- Gas and cylinder data
- Rental and size information
- Course progress and certification documentation
- Travel and arrival information
- Emergency contact when this is necessary for the activity
We only ask for data that is relevant to planning, delivering, and documenting the service in question.
Technical data
When you use the website, we may receive:
- IP address
- Device type
- Operating system
- Browser type
- Time and pages visited
- Referring website
- Information from cookies and similar technology
- Technical security and error logging
Marketing data
- Consent to newsletters
- Interaction with email
- Choices in the cookie banner
- Ad and campaign information where you have given consent
4.Health data and medical forms
Diving and certain courses may require a medical self-declaration or documentation from a physician.
Health data is a specially protected category of personal data.
As a general rule, we do not ask for detailed health data through ordinary contact forms or regular email.
When medical information is necessary, it should as far as possible:
- Be collected through a separate and appropriate process
- Be limited to what is necessary
- Only be available to persons with a work-related need
- Be deleted when the purpose and any documentation requirements have been fulfilled
- Be processed with explicit consent or another valid legal basis under the data protection rules
Do not send medical records or detailed health data through the ordinary contact form unless this has been expressly agreed.
5.Why we process personal data
Processing purchases and delivering goods
We use data to:
- Register the order
- Carry out payment
- Ship the item
- Communicate about the delivery
- Handle returns and complaints
The legal basis is normally that the data is necessary to perform the contract with the customer.
Delivering courses, rental, and diving activities
We use data to:
- Assess whether the activity is suitable for the participant's certification and experience
- Plan groups, equipment, and gas
- Organize accommodation and transport
- Conduct courses and document progress
- Ensure operational planning and preparedness
- Administer rental and returns
The legal basis is normally the contract with the participant and Bare Dykk's legitimate interest in organizing the service responsibly. Special categories of data are only processed when there is a separate valid legal basis.
Customer service
We process data to:
- Answer questions
- Provide product guidance
- Handle service and warranty cases
- Follow up on complaints and disputes
The processing is based on the contract, legal obligations, or our legitimate interest in providing customer service and documenting the dialogue.
Accounting and legal obligations
We retain necessary transaction and accounting data in order to meet requirements under the bookkeeping, tax, and duty regulations. The legal basis is a legal obligation.
Security and abuse prevention
We may process technical data and logs to:
- Protect the website and customer accounts
- Detect abuse and fraud
- Troubleshoot technical problems
- Document security incidents
The processing is based on our legitimate interest in protecting our customers, the business, and our digital systems.
Newsletters
We send newsletters when you have consented to this or when another lawful basis exists. You can unsubscribe at any time through the link in the email or by contacting us. Withdrawing consent does not affect the lawfulness of processing that has already taken place.
Analytics and marketing
Non-essential cookies and similar technologies are used only when you have given valid consent. This may be used for:
- Visitor statistics
- Improvement of the website
- Measuring campaigns
- Personalized advertising
You can change or withdraw your consent through the cookie settings.
6.Where the data comes from
We mainly receive data directly from you when you:
- Complete a purchase
- Create an account
- Fill out a form
- Contact us
- Book a course or diving stay
- Rent or return equipment
- Sign up for the newsletter
We may also receive limited data from:
- Payment providers
- Carriers
- Course and certification organizations
- Login providers
- Analytics and marketing tools
- Partners who take part in delivering an ordered service
7.Google sign-in and other login services
If you choose to log in with Google or another external login service, we may receive data such as:
- Name
- Email address
- Profile identifier
- Profile picture, where applicable
Which data is shared is displayed by the login service before you approve the connection.
We use the data to create or link the customer account and to carry out login.
The external provider also processes data as an independent data controller under its own privacy terms.
8.Who we share personal data with
We do not sell personal data.
We may share necessary data with providers who help us deliver our services, including:
- Online store and operations providers
- Payment providers
- Accounting and finance systems
- Carriers and shipping companies
- Email and newsletter providers
- Cloud services and security providers
- Analytics and advertising providers when you have given consent
- Course and certification organizations
- Service workshops and suppliers in warranty or service cases
- Partners necessary for a booked stay or activity
- Public authorities when required by law
Providers who process data on our behalf must be governed by data processing agreements where this is required.
Some providers may be independent data controllers, for example payment and credit providers. Their own privacy policies apply to the processing for which they themselves determine the purpose.
9.Transfers outside the EEA
Certain technical, analytics, email, or advertising providers may process personal data outside Norway or the EEA.
When personal data is transferred to a country that has not been approved by the European Commission as providing an adequate level of protection, the transfer must be based on a valid transfer basis. This may include, among other things:
- The European Commission's standard contractual clauses
- A valid adequacy decision
- Other lawful transfer mechanisms
We also assess the need for supplementary security measures.
10.How long we retain the data
We do not keep personal data longer than necessary.
Orders and accounting
Accounting and transaction data is retained for as long as the bookkeeping and tax rules require, normally at least five years after the end of the accounting year.
Customer account
Account data is retained for as long as the account is active or until you request deletion, with the exception of data we must retain on another legal basis.
Customer service and complaints
Inquiries are retained for as long as necessary to follow up on the case and document any claims. Data may be kept longer if necessary due to an ongoing warranty, complaint, or dispute case.
Courses and certification
Data necessary for conducting courses and certification is retained for the period necessary to administer and document the course and to meet requirements from the certification organization.
Bookings and diving activities
Booking, participant, and equipment data is retained for as long as necessary to carry out the stay and handle any subsequent claims or documentation needs.
Health data
Health data must be deleted or anonymized when it is no longer necessary for the specific purpose, unless further retention is required or permitted by law.
Newsletters
Data related to newsletters is retained until you withdraw consent or we discontinue the service in question. We may keep limited documentation that consent was given or withdrawn if this is necessary to document compliance.
Cookies
The retention period for each cookie is stated in the cookie settings and the updated cookie overview on the website.
11.Cookies and similar technology
The website uses cookies and similar technology.
Essential cookies
Essential cookies are used for functions such as:
- Shopping cart
- Login
- Payment
- Security
- Language selection
- Storing privacy choices
These may be used without consent when they are strictly necessary for a service the user has requested.
Analytics, marketing, and other cookies
Cookies for analytics, marketing, personalization, and ad measurement are activated only after consent. The cookie banner must give you the ability to:
- Accept all
- Reject non-essential cookies
- Choose purposes or categories
- Change or withdraw consent later
It must be just as easy to refuse or withdraw consent as it is to give it.
An updated overview in the cookie settings shows:
- The name of the cookie
- Provider
- Purpose
- Category
- Retention period
12.Your rights
When the conditions in the data protection rules are met, you can request:
Access
You can obtain information about which personal data we process about you and receive a copy.
Rectification
You can ask us to correct inaccurate or incomplete data.
Erasure
You can request that personal data be deleted when we no longer have a valid basis for processing it. The right to erasure does not apply if we must retain the data due to legal requirements or in order to establish, exercise, or defend a legal claim.
Restriction
In certain cases, you can request that the processing be restricted while an objection or dispute is being assessed.
Data portability
For data processed automatically on the basis of consent or a contract, you may in certain cases have the right to receive the data in a structured and machine-readable format.
Objection
You can object to processing based on a balancing of interests. You can always object to direct marketing.
Withdraw consent
When the processing is based on consent, you can withdraw your consent at any time.
Complaint
You can lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) if you believe that the processing of your personal data is contrary to the regulations. We recommend that you contact us first, so that we have the opportunity to look into the matter.
13.Automated decisions
Bare Dykk does not normally make decisions based solely on automated processing that have legal effects or a similarly significant impact on the customer.
A payment or credit provider may carry out an independent credit or risk assessment when the customer chooses invoice or installment payment. The provider's own terms and privacy policy apply to this assessment.
14.Information security
We use technical and organizational measures to protect personal data against:
- Unauthorized access
- Loss
- Alteration
- Misuse
- Accidental disclosure
- Unlawful processing
The measures may include, among other things, access control, encrypted communication, backups, updating of systems, and limiting which employees have access.
No digital solution is entirely risk-free. If we discover a personal data breach, it is handled in accordance with applicable rules.
15.Links to other websites
The website may contain links to external websites and services.
Bare Dykk is not responsible for how these parties process personal data. Read the relevant provider's privacy policy before submitting any data.
16.Changes to this privacy policy
We may update this privacy policy when the services, providers, or regulations change.
The date of the last update is shown at the top.
In the event of significant changes, we may provide information on the website, through the customer account, or by email when relevant.
Contact us
Questions can be sent to:
Email: info@baredykk.no · Phone: +47 458 02 787
Please mark your inquiry "Privacy".
AI-based customer service chat
baredykk.no offers an AI-based chat assistant that helps with product questions, order status and general enquiries.
What data is processed: what you type in the chat. For order-status lookups, the assistant asks for your order number and the email address the order was placed with. A technical security cookie is also set to keep your chat session running. Do not share sensitive information such as card numbers, national ID numbers or health data – the assistant never asks for this.
Purpose and legal basis: to answer enquiries and provide customer service, based on our legitimate interest in offering efficient customer service (GDPR art. 6 (1) f).
Data processor: the conversation content is sent to Anthropic PBC (the “Claude” service), which generates the responses. Anthropic processes the content only to deliver the answer and does not use it to train its models. Transfer to the USA takes place under the EU Standard Contractual Clauses (SCC), governed by our data processing agreement with Anthropic.
Retention: conversations are stored for up to 30 days and then deleted automatically. Anonymous, aggregated statistics (such as number of conversations and language) may be retained.
Your rights: you may request access to, correction of or deletion of the data linked to a conversation. Provide the reference number (BD-XXXXX) the conversation gave you. Contact us at info@baredykk.no or +47 458 02 787.
Data controller: Bare Dykk AS.

Bruk av informasjonskapsler (cookies)