Security

Boringly secure. On purpose.

Customer data is borrowed trust. That is why security in KORTA is not a feature we switch on but the way everything is built: European hosting, encryption everywhere, and data that stays yours.

Hosted in the EU

Your data lives in European data centers and never leaves them. GDPR is our default, not a checkbox, and no data is sent outside the EEA.

Encrypted everywhere

Encryption in transit and at rest, audited access, and daily backups with tested restores. Login links are single-use and hashed in the database.

Your customers, your data

We never sell, share or advertise on your customer data. Export everything in one click, at any time, and take it with you if you leave.

Questions about security and privacy

Is KORTA GDPR-compliant?
Yes. Consent is collected on joining, data is stored encrypted in the EU, and your customers can request access, export and deletion at any time. We only collect what the card needs to work.
Do I need a data processing agreement?
Yes. When you use KORTA you are the controller and we are the processor, and GDPR requires an agreement between us. Write to hei@korta.no and we will put it in place.
What data is stored about my customers?
The minimum: what the customer provides on joining, and the visits, stamps and rewards on their card. No location tracking, no cross-business profiling, no third-party ad data.
What happens to the data if I cancel?
You export everything in one click before you go, and we delete your data when you ask. No lock-in, no hostage data.

Keep reading

Your card is 4 minutes away.

Free for your first 100 customers. No hardware, no contract, no designer needed.