How we handle personal data in EGGS Design

In this privacy notice, you’ll find information about which personal data is collected, why it is collected, what it is used for and which lawful basis we rely on to process those data. Furthermore, you will find information on how to contact us and exercise your rights.

About EGGS Design

EGGS Design is an independent group of innovation consultancies, helping clients craft new products, services and business transformations. We work holistically to ensure that personal insights play well together with technology, brand and business.

While we embrace technology, we are not driven by it. We also respect the impact technology can have on individual rights such as privacy and free expression, so we strive to balance these interests in the work we perform for our clients.

EGGS Design processes personal data about our website visitors, our clients and our clients' employees and/or end-users to provide our services. We believe in cementing our relationships in trust and transparency, so privacy is, therefore, a central value in our company.

In this privacy notice, you’ll find information about which personal data is collected, why it is collected, what it is used for and which lawful basis we rely on to process those data. Furthermore, you will find information on how to contact us and exercise your rights.

1. Accountability and contact details

When processing your personal data for its own purposes and needs, EGGS Design acts as a data controller.

When carrying out user-insight projects, EGGS Design may act as a joint data controller with the client ordering the innovation project or as a data processor. See below section 4 for more information on insight projects.

Our contact information for all privacy-related matters is:

EGGS Design AS

Møllergata 4, 0179 Oslo

T. +47 404 78 154


2. What personal data do we process and why?

EGGS Design is required to process personal data to conduct its business activities, answer inquiries and maintain or create new business relationships.

  • We process personal data such as name, email, role and telephone number about prospective clients, to follow up on leads and establish new business connections. This is done under our legitimate commercial interests and in preparation for entering new contracts.

  • We process personal data about existing customers such as contact details to our contact point within the company, to administer our relationship, perform billing, answer inquiries and provide assistance. This is done under our need to fulfil our contractual and legal obligations, such as those connected to taxes and bookkeeping.

  • We process personal data to obtain insight into specific subjects. These insights are gained by sending questionnaires to a particular target group or interviewing the insight subjects. The personal data and the precise processing activities to be performed is dependent on the scope and subject of the project. We rely on explicit consent from the insight subjects for collecting and processing that data.

  • We process personal data such as CV, professional references and contact information if you’ve applied to a job with us. This is done in our legitimate interest to assess your competence and fulfil our business needs.

In these situations, your personal data is provided to us by you directly.

3. Personal data that is not collected directly from you

We may receive personal data about you indirectly if:

  • We have contacted your organisation, and your organisation provides us with your contact in its response. This is done under our legitimate interest to obtain information or establish a relationship with your organisation.

  • A company you are a customer, member or employee of provides us with your contact information so that we may contact you within the scope of an insight project we are conducting for them or for a third party they have an agreement or relationship with. Those companies, entities and organisations are themselves responsible for having a valid lawful basis for collecting your personal data and providing us with your contact information.

4. User-insight projects

EGGS Design provides its clients with research and insight into certain user-groups or subjects, including the health industry. As a result, personal data provided willingly by an insight interviewee will vary according to the particular project and may include so-called "special categories" of data such as personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, health or sex life history, sexual orientation, trade union membership or criminal history. This specific category data receive additional protection under the law, and EGGS Design has implemented a secure process to ensure its proper handling and deletion.

While a project is ongoing, we secure your personal data by pseudonymising it. This means we use an identifier such as "Interviewee #1" to refer to you rather than a personal trait like your name, age or telephone number. Once we have gathered sufficient insights, we aggregate your responses along with other project participants so that no single person may be identified by delivering our results to our customer.Once the project has been completed and the aggregated results produced, the material gathered from your participation (including any photos, audio recordings or other personal data) is promptly deleted or fully anonymised.

In cases where our customers solely determine the purpose, scope and focus group of a project, EGGS Design acts as a data processor. In these cases, our customer provides us with your contact information and remains responsible for the lawfulness of the purpose and legal basis for processing. For more information on how such a customer processes your data and how you may exercise your data subject rights, please contact the customer directly or, if you prefer, contact us as described below and we will notify them.

In cases where EGGS Design collaborates with a customer to jointly determine the project focus group and/or locates participants itself, we act as a joint data controller with our customer. In these cases, you will find information in this privacy notice about how your personal data is processed and how to exercise your data subject rights.

5. Who do we share your personal data with?

In conducting its business activities, EGGS Design may share your personal data with the following parties:

Other EGGS Subsidiaries within the EGGS Design

To maintain an overview of which customers and contacts have relationships with various entities within the EGGS Design

Public Authorities

In the event of legal action involving EGGS, EGGS may be required to provide personal information according to a court order or other statutory requirement.

6. Who processes your personal data on behalf of EGGS Design?

To process its data and perform its activities, EGGS Design AS relies on several companies to store and process personal data on our behalf. These companies are referred to as “data processors”, and our relationship with them is defined in a written data processing agreement that states the processors’ obligations and limitations under which they will process personal data. We may transfer the data we collect about you in countries other than the country in which the data was originally collected, including the United States, Canada or other destinations outside the European Economic Area (“EEA”). Those countries may not have the same data protection laws as the EEA. When we transfer your data to other countries, we will protect the data as described in this Privacy Policy and comply with applicable legal requirements providing adequate protection for the transfer of data to countries outside the EEA. For data sent outside EEA we use the Standard Contractual Clauses created by the European Data Protection Board as a part of the agreement with each processor.

EGGS Design utilises the following data processors to process your personal data under our specific instructions:


Purpose: Project management

Processing Location: USA

Legal Basis for Transfer Outside of EU/EEA: Standard Contractual Clauses


Purpose: Document storage

Processing Location: Western Europe

Legal Basis for Transfer Outside of EU/EEA: N/A


Purpose: Event registration

Processing Location: USA

Legal Basis for Transfer Outside of EU/EEA: Standard Contractual Clauses


Purpose: Site analytics and performance measurement of website

Processing Location: Western Europe, USA

Legal Basis for Transfer Outside of EU/EEA: Standard Contractual Clauses


Purpose: User engagement on social media

Processing Location: Canada

Legal Basis for Transfer Outside of EU/EEA: Adequacy Decision by European Commission in Commission Decision 2002/2/EC


Purpose: Office 365

Processing Location: Western Europe, USA

Legal Basis for Transfer Outside of EU/EEA: Standard Contractual Clauses -


Purpose: Project collaboration

Processing Location: USA

Legal Basis for Transfer Outside of EU/EEA: Standard Contractual Clauses


Purpose: Customer billing/ERP

Processing Location: Norway

Legal Basis for Transfer Outside of EU/EEA: N/A


Purpose: Marketing management

Processing Location: USA

Legal Basis for Transfer Outside of EU/EEA: Standard Contractual Clauses

7. Retention periods

To the extent permitted by applicable law, EGGS Design retains your personal information for as long as it is needed to fulfil the purposes for which we obtained it. We may in some cases keep it beyond that time if we process the same data under another lawful basis, stated in this Privacy Policy or at the point of collection, that permits us that.

Contacts of Partners, Vendors and Customers

We retain contact information of employees of our partners, vendors and customers for 2 years after our commercial relationship terminates unless the employee terminates their employment before, and we are informed to update the data, or we are required to retain it longer due to legal action.

Insight Project Data

We anonymise or delete all information regarding an insight project within 30 days of the project’s completion.

Data of Former EGGS Design Employees

EGGS Design retains information on its former employees as necessary to comply with other legal obligations such as applicable accounting and tax law. Certain information kept for accounting and tax reasons such as your salary history will be deleted no later than 5 years following the end of your employment, while limited information pertaining to your identification as a former employee, your role, dates of employment and information linked to your competence and/or responsibilities shall be retained in our systems.

8. Your data protection rights

You have the right to request us to confirm whether we are processing personal data about you. Also, you have the right to ask us to:

  • access to your personal data

  • rectify, supplement and update your personal information

  • delete or restrict the processing of your personal data under certain circumstances

  • object to processing activities carried out for marketing purposes, as well as to object to certain activities carried out to fulfil our legitimate purposes, under certain circumstances

  • have personal data that you have provided us directly ported to you or another company in a commonly readable file format

  • withdraw a consent you have given, at any time

You may exercise your rights by contacting us at Requests will typically be answered within 30 days. For more information about your data subject rights, visit the Norwegian Datatilsynet’s website.

9. Complaints

If you have queries or concerns, please contact us at, and we'll respond.

If you remain dissatisfied, you may file a complaint about the way we process your personal information to the Norwegian Datatilsynet, who is the supervisory authority for the processing of personal data by EGGS Design.

10. Visits to our website

When you visit our website, we process your IP-address, your cookies and user setting information, as well as information about the machine you’re using including device attributes like IP address, operating system software, device type and browser type to generate anonymous site analytics and performance measurement using Google Analytics.

Furthermore, we may collect information about your interaction with our website, including logs, crash reports, date and time, referrer URL of your request, and other information of relevance to uncover malfunction and ensure the security of our website and IT-infrastructure.

We use TLS-certificate (HTTP) to ensure the security of the communication between our websites and our visitors so that no one can read or change the information being exchanged.

These processing activities are performed based on our legitimate interests to improve our website and its usability, improve the quality of the information we provide and measure activity for site analytics and performance management, as well as ensure the security of our website.

We use cookies. For information on the cookies we use, and what data they collect, please check our cookie policy,

11. Changes to this notice

We periodically update or change this privacy notice as a consequence of changes to our business activities, our processing activities or changes in the law. We will post a notice on this website when such changes are made, so you may review what is new and inform yourself about our practices.

Oslo, Norway


We use cookies to ensure you get the best experience on our website. If you continue to click on this page, you accept the use of cookies. Read more about our cookie policy and our privacy policy.

Got it!