Come to visit
Strandveien 55,
1366 Lysaker – Oslo Norway
Org: 997 906 314
Last update: 27 July 2026
These Terms and Conditions apply to business customers and their authorised platform users. Survey respondents do not create platform accounts and are not bound by these Terms and Conditions.
1.1 These Terms and Conditions (“T&Cs”) constitute a binding agreement between InFact AS, organisation number 983 067 999, with registered office at Strandveien 55, 1366 Lysaker – Oslo, Norway (“InFact”, “we”, “us”, “our”), and the business or other legal entity that has entered into an agreement for use of the Service (“Customer”).
1.2 An “Authorised User” is an individual whom the Customer authorises to access and use the Service on its behalf. References to “you” include the Customer and, where relevant, its Authorised Users.
1.3 These T&Cs govern access to and use of the InFact platform and related services described in section 2 (the “Service”). They apply together with any order form, statement of work, subscription agreement, service-level agreement, data processing agreement (“DPA”), or other written agreement between InFact and the Customer.
1.4 By accessing or using the Service, an Authorised User confirms that they are authorised to act on behalf of the Customer and agree to use the Service in accordance with these T&Cs and applicable law.
1.5 The Service is intended for business use. Individuals cannot independently register for a platform account. A business contacts InFact, and InFact creates the Customer account and authorised user access based on the agreed business relationship.
1.6 Survey respondents receive a survey link and do not receive a platform account. General privacy information for respondents is provided in InFact’s Privacy Policy for Survey Respondents, available on the InFact website and through survey links where applicable.
1.7 If the Service is licensed, resold, or provided through a third-party service provider, separate commercial terms may apply between the Customer and that provider. InFact is not a party to such separate terms unless expressly stated in writing.
2.1 InFact provides a digital platform that may enable Customers to create, configure, operate, and manage landing pages, forms, surveys, campaigns, dashboards, reports, communication activities, integrations, and related data collection and analytics functions.
2.2 Depending on the agreed solution, the Service may include:
2.3 The specific features, capacity, support arrangements, service levels, fees, and subscription period are determined by the applicable written agreement or order between InFact and the Customer.
2.4 Where there is a conflict, the following order of precedence applies unless otherwise agreed in writing: the DPA for matters concerning processing of personal data; the applicable order form or statement of work; the service-level agreement; these T&Cs; and general information published on the website.
2.5 Fees, invoicing terms, taxes, usage charges, and payment deadlines are governed by the applicable commercial agreement or invoice. Unless otherwise agreed in writing or required by law, fees already paid are non-refundable.
2.6 InFact may add, change, or remove features where reasonably necessary to improve, secure, maintain, or develop the Service. InFact will provide reasonable notice of material changes that substantially reduce agreed core functionality, where practicable.
3.1 Customer accounts and Authorised User accounts are created by InFact following a request from the Customer or in accordance with the applicable agreement. The Customer must provide accurate and current business contact and user information required to administer access.
3.2 The Customer is responsible for:
3.3 Authorised Users must keep credentials confidential, use individual accounts, follow applicable authentication requirements, and must not share passwords or access credentials. InFact will never ask a user to disclose their password to InFact staff.
3.4 The Customer and Authorised Users must immediately notify InFact of suspected unauthorised access, credential compromise, security incidents, or misuse of the Service.
3.5 InFact may suspend, restrict, reset, or disable access where reasonably necessary to protect the Service, Customer Content, users, or third parties, or where access appears unauthorised or insecure.
3.6 Authorised Users may not impersonate another person, use another person’s account, or use an identity or account information that is misleading, unauthorised, offensive, or unlawful.
4.1 The Customer is responsible for its use of the Service and for all content, data, messages, files, configurations, survey questions, respondent lists, and other material uploaded, created, transmitted, stored, or otherwise processed through the Service by or on behalf of the Customer (“Customer Content”).
4.2 The Customer must ensure that its use of the Service and Customer Content:
4.3 The Service must not be used to:
4.4 The Customer is responsible for configuring surveys, forms, campaigns, access rights, recipients, exports, and integrations correctly, and for reviewing material settings before publication or distribution.
4.5 Unless otherwise agreed in writing, the Customer remains responsible for retaining appropriate copies or exports of Customer Content needed for its business, legal, or continuity requirements.
5.1 The Customer retains ownership of Customer Content and all intellectual property rights it holds in that content. Nothing in these T&Cs transfers ownership of Customer Content to InFact.
5.2 The Customer grants InFact and its approved subprocessors a non-exclusive, limited right to host, copy, transmit, display, transform, back up, and otherwise process Customer Content solely as necessary to provide, secure, support, maintain, and improve the Service in accordance with the applicable agreement and DPA.
5.3 The Customer represents that it has all rights and authority necessary to provide Customer Content to InFact and to permit its processing through the Service.
5.4 The Service, including its software, source code, design, structure, functionality, documentation, trademarks, logos, and related intellectual property, is owned by or licensed to InFact and is protected by applicable law.
5.5 Except as expressly permitted by law or in writing by InFact, the Customer and Authorised Users may not copy, reproduce, modify, adapt, distribute, sell, lease, sublicense, reverse engineer, decompile, derive source code from, or create competing products or services based on the Service.
5.6 Feedback, suggestions, and improvement requests may be used by InFact to improve its products and services. This does not give InFact any ownership rights in Customer Content or confidential Customer information.
6.1 Roles
6.1.1 InFact may process personal data in different roles depending on the context:
6.1.2 Where InFact acts as processor, the Customer is normally the controller and remains responsible for the lawfulness, fairness, transparency, accuracy, and permitted use of the personal data, including providing appropriate privacy information to respondents and other data subjects.
6.1.3 Processing by InFact as processor is governed by the applicable DPA. If these T&Cs conflict with the DPA on a personal-data processing matter, the DPA prevails.
6.2 Platform user and business contact data
6.2.1 For platform administration and the business relationship, InFact may process name, business email address, telephone number, employer, role, username, authentication and login information, support correspondence, billing and contract information, usage records, IP address, device and browser information, timestamps, audit data, and security event information.
6.2.2 InFact processes this information to create and administer accounts, provide and support the Service, manage the Customer relationship, communicate about operation and security, issue invoices, improve service quality, prevent misuse, investigate incidents, and comply with legal obligations.
6.2.3 The legal bases may include performance of a contract or steps connected to a contract, InFact’s legitimate interests in operating and securing the Service and maintaining business relationships, consent where required, and compliance with legal obligations.
6.2.4 InFact may send communications necessary for the operation, security, support, or administration of the Service. Limited non-essential B2B communications may be sent where permitted by law. Recipients may object to direct marketing at any time.
6.3 Customer and respondent data
6.3.1 The Customer must ensure that personal data uploaded to or collected through the Service is processed lawfully and only for defined purposes. The Customer is responsible for determining the lawful basis, providing required notices, handling data subject requests, and giving InFact lawful and documented instructions.
6.3.2 Survey respondents do not create accounts. They normally receive a link to a survey and can review InFact’s Privacy Policy for Survey Respondents through the website or survey link. The Customer must also provide any project-specific information required to identify the controller, explain the survey purpose, legal basis, data source, recipients, and project-specific retention.
6.3.3 Some surveys may involve special categories of personal data under GDPR Article 9, such as information about health, political opinions, religion, ethnicity, trade union membership, or sexual orientation. The Customer must not collect or process such information through the Service unless it is lawful, necessary for the agreed purpose, supported by an applicable Article 9 condition, covered by the relevant agreement and instructions, and protected by appropriate safeguards.
6.3.4 Where InFact acts as processor, it processes special category data only on documented instructions from the Customer and in accordance with the DPA. Appropriate safeguards may include data minimisation, access restrictions, confidentiality, pseudonymisation, encryption, and defined deletion periods.
6.4 Recipients, providers and transfers
6.4.1 InFact may use approved hosting, IT, communication, support, security, analytics, payment, professional-service, and other providers necessary to deliver and administer the Service. Providers processing personal data on InFact’s behalf are subject to written data processing and confidentiality obligations.
6.4.2 Where personal data is transferred outside the EEA, InFact will use an applicable transfer mechanism and appropriate safeguards, such as an adequacy decision, the EU Standard Contractual Clauses, and supplementary technical and organisational measures where required.
6.5 Retention
6.5.1 InFact retains personal data only for as long as necessary for the purpose for which it was collected, unless a longer period is required or permitted by law. Examples include:
6.6 Rights and contact details
6.6.1 Where InFact acts as controller, individuals may have rights to access, rectify, erase, restrict, object to, or receive certain personal data in a portable format, and to withdraw consent where processing is based on consent.
6.6.2 We normally respond without undue delay and within one month. We may request additional information where reasonably necessary to verify your identity.
6.6.3 Where InFact acts only as processor, requests concerning Customer-controlled data should normally be directed to the Customer as controller. InFact will assist the Customer as required by the DPA and applicable law.
Data Protection Officer: Iryna Lazorenko
Email: iryna@infact.no
6.6.4 Individuals may lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) or another competent supervisory authority.
6.7 Cookies
6.7.1 The platform may use cookies and similar technologies necessary for authentication, session handling, security, preferences, and operation of the Service. Non-essential cookies will be used only where the required consent has been obtained. Further information is available in InFact’s Cookie Policy.
7.1 InFact implements appropriate technical and organisational measures designed to protect the Service and personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, access, or misuse.
7.2 The Customer must implement appropriate security measures within its own environment, including access management, secure devices, strong authentication practices, timely removal of access, appropriate user training, and secure handling of exports and integrations.
7.3 Each party must protect the other party’s non-public business, technical, commercial, security, and personal information (“Confidential Information”) using at least reasonable care and may use it only for purposes connected to the agreement.
7.4 Confidentiality obligations do not apply to information that the receiving party can demonstrate was lawfully known without restriction, becomes public without breach, is independently developed, or is lawfully received from a third party. Disclosure required by law is permitted, subject to notice where legally allowed.
7.5 InFact may disclose Confidential Information to employees, contractors, professional advisers, and providers who need access to perform the agreement and who are subject to appropriate confidentiality obligations.
8.1 InFact will use reasonable care and skill in providing the Service. Unless a separate service-level agreement states otherwise, the Service is provided on an “as is” and “as available” basis.
8.2 InFact may perform maintenance, updates, security work, repairs, and technical changes. Parts of the Service may be temporarily unavailable during such work or due to circumstances outside InFact’s reasonable control.
8.3 Support channels, response targets, operating hours, and service levels are governed by the applicable agreement or support arrangement.
8.4 No online service can be guaranteed to be uninterrupted, completely secure, or error-free. InFact does not warrant that every defect will be corrected or that the Service will meet requirements not included in the agreed scope.
9.1 The Service may contain or connect to third-party websites, APIs, integrations, communication providers, sample providers, or other external services.
9.2 Third-party services may be governed by separate terms and privacy notices. InFact is not responsible for third-party content, availability, security, or processing outside InFact’s control, except to the extent expressly agreed or required by law.
9.3 The Customer is responsible for authorising and configuring Customer-selected integrations and for ensuring that data transferred to or from those integrations is lawful and secure.
10.1 The Customer may terminate the Service in accordance with the applicable agreement. Unless otherwise agreed, termination does not entitle the Customer to a refund of fees already paid.
10.2 InFact may suspend or terminate access, in whole or in part, if:
10.3 Where the circumstances allow, InFact will provide notice and a reasonable opportunity to remedy a breach before termination. Immediate suspension may be used where necessary to prevent harm, secure the Service, comply with law, or address serious misuse.
10.4 Upon termination, the Customer’s right to use the Service ends. Customer Content will be returned, made available for export, retained, or deleted in accordance with the applicable agreement, DPA, documented instructions, backup cycles, and legal retention requirements.
10.5 The Customer should arrange necessary exports before access ends. Any post-termination access or assistance may be subject to technical feasibility, security requirements, the applicable agreement, and additional fees.
10.6 Provisions that by their nature should survive termination remain in effect, including provisions relating to intellectual property, confidentiality, data protection, payment, liability, indemnity, governing law, and dispute resolution.
11.1 To the fullest extent permitted by law and except as expressly stated in a written agreement, InFact disclaims implied warranties, including merchantability, fitness for a particular purpose, title, and non-infringement.
11.2 The Customer is responsible for decisions, communications, survey design, interpretations, and actions based on Customer Content, reports, analytics, exports, or results generated through the Service.
11.3 To the fullest extent permitted by law, neither party is liable for indirect, incidental, special, punitive, or consequential loss, or for loss of profit, revenue, goodwill, anticipated savings, or business opportunity.
11.4 InFact is not liable for loss or corruption of Customer Content to the extent caused by the Customer, an Authorised User, a Customer-selected integration, failure to follow documentation or security requirements, or circumstances outside InFact’s reasonable control.
11.5 Unless a separate written agreement states otherwise, InFact’s total aggregate liability arising out of or in connection with the Service or these T&Cs will not exceed the fees paid or payable by the Customer for the affected Service during the twelve months preceding the event giving rise to the claim.
11.6 Nothing in these T&Cs excludes or limits liability that cannot lawfully be excluded or limited, including liability for fraud or wilful misconduct where applicable.
12.1 The Customer will indemnify and hold harmless InFact, its affiliates, officers, employees, and contractors from third-party claims, losses, liabilities, and reasonable costs arising from:
except to the extent the claim was caused by InFact’s breach of the applicable agreement or applicable law.
13.1 InFact may revise these T&Cs to reflect changes in the Service, law, security requirements, or business practices.
13.2 Updated T&Cs will be published or otherwise communicated to the Customer. Material changes will take effect from the stated effective date, with reasonable advance notice where practicable.
13.3 Continued use of the Service after updated T&Cs take effect constitutes acceptance of the updated terms. If the Customer does not accept a material change, it may stop using the Service and terminate in accordance with the applicable agreement.
14.1 These T&Cs and the applicable written agreements constitute the entire agreement concerning the Service and supersede earlier general terms relating to the same subject matter.
14.2 The Customer may not assign or transfer its rights or obligations without InFact’s prior written consent. InFact may assign the agreement in connection with a merger, acquisition, reorganisation, financing, or sale of all or substantially all relevant business assets.
14.3 If any provision is held invalid or unenforceable, the remaining provisions remain in effect, and the invalid provision will be interpreted or replaced to reflect its intended commercial effect as closely as legally possible.
14.4 A failure or delay in enforcing a provision does not waive that provision or any other right.
14.5 Nothing in these T&Cs creates a partnership, joint venture, agency, employment relationship, or fiduciary relationship between the parties.
14.6 Notices concerning the Service or agreement may be sent to the business email addresses registered for the Customer or stated in the applicable agreement. The Customer is responsible for keeping those details current.
15.1 These T&Cs and any dispute or claim arising out of or in connection with them are governed by Norwegian law.
15.2 The Norwegian courts have exclusive jurisdiction over disputes or claims arising out of or in connection with these T&Cs or the Service.
15.3 Oslo District Court (Oslo tingrett) is agreed as the sole venue.