Skip to content
Privacy & data

d2o Privacy Policy.

How d2o processes personal data in connection with its products and services, including the PMI platform.

Policy

Last updated: January 2026

1. Purpose and Scope

This Privacy Policy describes how d2o processes personal data in connection with its products and services, including the PMI platform. It applies to personal data relating to customers, end users, business partners, and website visitors.

This document supports the organization’s overall Privacy and Security governance framework.

2. Personal Data Collected

d2o processes only limited, non-sensitive personal data that is strictly necessary to provide and operate its services. This includes personal data processed directly by d2o as well as non-sensitive personal data processed within the PMI platform on behalf of customers.

The categories of personal data processed may include:

  • Name
  • Company or organization name
  • Job title or role
  • Email address
  • Username or employee identifier (where applicable)
  • Support communications and service-related inquiries
  • Payroll cost (where applicable)

No special categories of personal data are intentionally collected or processed by d2o. All personal data processed within PMI is encrypted in transit and at rest.

3. Cookies and Website Usage

d2o uses cookies on its websites to support core functionality, improve user experience, and analyze usage.

Cookies may include:

  • Essential cookies required for website functionality
  • Analytics cookies used to understand website usage and improve content
  • Preference cookies that remember user settings

Cookies do not directly identify individuals unless combined with information voluntarily provided by the user.

4. Legal Basis for Processing

Personal data is processed based on one or more of the following legal grounds:

  • Contractual necessity
  • Legitimate interests related to service delivery, security, and improvement
  • Compliance with legal obligations

5. Subcontractors and Data Access

Subcontractors may be engaged by d2o for development and operational support purposes only. These subcontractors are not designated as sub-processors of customer personal data and do not process personal data on behalf of d2o.

Any access to systems by subcontractors is:

  • Strictly limited to what is necessary
  • Time-bound and role-based
  • Logged and auditable

Customer personal data is not shared with subcontractors unless legally required or explicitly agreed with the customer.

6. International Data Transfers

Personal data is primarily stored within the European Economic Area (EEA). Where access from outside the EEA is required, appropriate safeguards are applied, including encryption and access controls, in line with GDPR and EDPB recommendations.

7. Data Subject Rights

Individuals have the right to request access to, correction of, or deletion of their personal data in accordance with GDPR. Requests should be submitted through established customer or contractual communication channels.

8. Data Retention

Personal data is retained only for as long as necessary to fulfill the purposes described in this policy or to meet legal and contractual requirements.

9. Security Measures

Appropriate technical and organizational measures are implemented to protect personal data against unauthorized access, loss, or disclosure.

10. Contact

Privacy-related inquiries may be directed to d2o through established customer or contractual communication channels.

Global Headquarters
Norway: +47 900 80 123
Florida, USA: +1 954 612 5200
www.d2o.com
PMI

The next advantage isn't more revenue. It's converting more of it.

See where your profit is leaking — and what closing the gap is worth for your portfolio.