Skip to main content
Find&Close
Pricing FAQ About us Extension Help
Sign in Start free trial
Pricing FAQ About us Extension Help
Sign in Start free trial

Legal

Privacy notice

What we hold, where it came from, how long we keep it, and how to make us stop.

Version 1.0 · Last updated 25 July 2026 · FindAndClose AS, Norway

The short version

We collect business contact information that is already published — on Google Maps and on companies' own websites — and we make it searchable. We record where every single field came from, we do not keep it longer than 24 months, and you can ask us to remove your details at any time using the form linked below. We do not sell or process special-category data, and we do not knowingly hold data about consumers.

1. Who we are

FindAndClose AS ("we") is the data controller for the processing described here. Written enquiries and all data-protection requests: privacy@findandclose.com.

2. What we hold, and where it comes from

Two separate sets of data, held for different reasons.

2.1 Business records in our search index

Collected from public sources rather than from you. For each business we may hold: trading name, category, address and coordinates, telephone number, website address, email addresses published on that website, public social-media profile links, opening hours, review counts and ratings, detected website technologies, and company-register identifiers.

The sources are: Google Maps (name, category, address, coordinates, phone, rating), the business's own public website (email addresses, contact pages, social profiles), Overture Maps Foundation open data, and the Brønnøysund Register Centre (company form, registered managing director, insolvency status). Every field in every export names the URL or register it came from — that record is part of the product, not an internal note.

2.2 Account data about our customers

Given to us by you when you register: name, work email address, telephone number, company name, a hashed password, and how you heard about us. Plus, in use: session records, credit and export history, support correspondence, and a customer identifier held by our payment processor. We never see or store your card details.

3. Why we are allowed to do this

Most business contact information is not personal data at all — post@example.no identifies a company, not a person. Where a record does identify an individual (a named person's work address, or a sole trader whose business is legally themselves), we rely on legitimate interests under Article 6(1)(f) GDPR: enabling business-to-business contact between companies, using information those companies have themselves published for the purpose of being contacted.

We have carried out and documented the balancing assessment that this basis requires. The safeguards that make it proportionate are the ones described in this notice: publication-only sources, a 24-month retention limit, per-field provenance, an always-on suppression list, and a self-service objection route. You can object at any time and we will stop — see §7.

For account data, the basis is performance of our contract with you, and our legal obligation to keep accounting records.

4. What we deliberately do not do

  • We do not process special-category data. Business categories relating to health, religion, political activity and trade unions are excluded from our index by design.
  • We do not collect data that a person has restricted from public view.
  • We do not buy contact lists, and we do not sell our database.
  • We do not target consumers. The service is business-to-business only.

5. Who else processes it

We use a small number of providers, each under a data-processing agreement, each processing only what their function requires:

ProviderPurposeLocation
HetznerServers and database hostingGermany / Finland (EU)
CloudflareDNS, and storage of generated export filesEU
StripePayments and invoicingEU / USA
ResendAccount emails such as password resetsEU / USA
MillionVerifierChecking whether an address can receive mailEU
ChatwootCustomer support conversationsSelf-hosted, EU

Where a provider processes data outside the EEA, that transfer is covered by the European Commission's Standard Contractual Clauses.

6. How long we keep it

Business records: 24 months from the date we last confirmed them, after which they are re-verified or deleted. Account data: for as long as you have an account, then 12 months. Invoices and accounting records: 5 years, because Norwegian bookkeeping law requires it. Suppression entries: kept indefinitely, in irreversibly hashed form, because that is the only way to guarantee your objection survives our next data refresh.

7. Your rights, and how to actually use them

You have the right to obtain a copy of what we hold about you, to correct it, to have it erased, to object to our processing it, to have it restricted, and to receive it in a portable format.

Email privacy@findandclose.com with the email address, domain or telephone number concerned. We will reply with exactly what we hold and where each field came from, and remove it on request. We respond within 30 days, we do not charge, and we do not ask you to prove anything beyond control of the address.

A self-service version of this — search, see the provenance, remove it yourself, no email required — is being built and will replace the address above. We would rather tell you it is not ready than link you to a page that does not work.

If you are unhappy with how we have handled a request, you may complain to the Norwegian Data Protection Authority, Datatilsynet, or to the supervisory authority where you live.

8. Being told we hold your data

Because we collect business records from public sources rather than from the individual, Article 14 GDPR requires us to tell people we hold their information. At the scale of a national business index, writing to every record individually is not workable, so we do it in two ways: this notice is public and indexed, and we contractually require every customer to identify us as the source in their first message to any contact obtained here. If you have received such a message, write to the address in §7 and we will show you everything we hold.

9. Cookies

One cookie, and only after you sign in: a session token that keeps you logged in. It is HttpOnly, cannot be read by scripts, and expires. We use no advertising or tracking cookies, and our analytics collects no cookies and no personal data — which is why this site has no cookie banner. There is nothing to consent to.

10. Changes

If we change how we process personal data we will update this page and its version number, and email account holders where the change is material.

Status of this document. It is an accurate description of what our systems do, written by the people who built them, and it is published in good faith. It has not yet been reviewed by external counsel; that review is scheduled and this page will be re-issued afterwards. If you spot something here that does not match your experience of the service, tell us at privacy@findandclose.com — we would rather hear it than not.

Find&Close

The local leads generator for Google, Apple and Bing Maps. Nordic coverage, 4,000+ categories, one export away.

Public business data only · every field traceable to its source

Essential

Pricing FAQ About us Extension Help

Advanced

API

Resources

Local business lists Sample export

© 2026 FindAndClose — All rights reserved.

TermsPrivacy Policy