This site runs no advertising trackers and stores nothing on your device. Below is every piece of personal data Reconfig handles through reconfig.ai, why we hold it, and how to get a copy or have it deleted.
LAST UPDATED 25 August 2026
Reconfig AS is the data controller for personal data collected through reconfig.ai and reconfig.no. We decide what is collected and why, and we are the party you hold accountable.
Privacy questions go to the address above and reach a person who can answer them.
We collect three things. If you read one section, read this one.
| What | When | Legal basis |
|---|---|---|
| Contact details. Your name, work email, organization, and whatever you write in the message field | Only when you submit a form | Our legitimate interest in answering you, GDPR Article 6(1)(f) |
| Assessment answers. Your responses to the AI maturity questions, and the report we build from them | Only when you complete the assessment | Our legitimate interest in answering you, GDPR Article 6(1)(f) |
| Traffic data. Pages viewed, referring site, browser and device type, and your IP address | Every visit | Legitimate interest in understanding site usage, GDPR Article 6(1)(f) |
We do not buy personal data, sell it, or share it with advertising networks. We run no advertising or retargeting pixels on this site.
This policy covers the public pages of reconfig.ai and reconfig.no. Our product at app.reconfig.no, the interactive demo embedded on the challenge page, and the editor at /admin are separate applications with their own handling of data. Ask us if you need the detail for any of them.
Four forms on this site collect personal data: the contact form, the demo request, the executive paper download, and the operating model form. Each asks for a name, a work email, and an organization. The contact form and the operating model form also require a message, and the operating model form asks two further questions about your situation.
None of this is required of you. Nothing on the site is gated behind a form except the material each form offers, and choosing not to fill one in costs you nothing else.
Submitting any of them sends an email to our team inbox at [email protected], where a colleague reads it and replies. Our mail provider carries that message, and our web server writes a log line recording the submission, including your name and email address.
The assessment collects more than the other forms, so it gets its own section.
When you complete it, we hold your answers, your contact details, and the maturity report we produce. We email the report to you and store a record in our customer relationship system so the team can follow up on the result.
We send your answers to Anthropic's Claude models to draft the written commentary in your report and any follow-up email. That transfer includes your first name, your company name, the role and scope you typed in, and the full text of every question and answer. Anthropic acts as our processor, and its commercial terms forbid training models on the data.
The plan briefing email goes only to people who tick the box asking for it, GDPR Article 6(1)(a). Our assistant Reily drafts and sends it without a person approving it first, which the form says before you tick and the email repeats in its own signature. A colleague receives a copy of every message and can step in afterwards. Leave the box unticked and no briefing is sent.
The report is our view of your organization's operating model, offered as advice. It produces no legal or similarly significant effect, so the Article 22 right to human intervention does not arise. Ask us for a person at any time and you will get one.
We set no cookies and write nothing to your device, so there is nothing a banner could ask you to consent to. The one exception sits outside our control: our security layer may set a short-lived cookie when it screens a request that looks automated, and that kind of cookie is exempt because the site cannot stay secure without it.
We do measure traffic. We run PostHog on our own server at ph.reconfig.ai, which you can confirm in your browser's network tab. It keeps no identifier in your browser, so while you stay anonymous each visit is counted on its own and we cannot tell that today's visit and last week's came from the same person. We record pages viewed, the referring site, your browser and device type, and your IP address, which tells us roughly where traffic comes from. The data stays on infrastructure we control, and we never share it or combine it with data from other sites.
Submitting a form ends the anonymity. From that point we can connect the pages you viewed to you as a named person, in our analytics and in our CRM, so the colleague who replies knows the context. Tell us at [email protected] if you would rather we did not, and we will unlink and delete the record.
We honour the Global Privacy Control and Do Not Track signals: PostHog never loads and we record no analytics for that visit. Our web server still logs the request itself, which it must do to serve you the page.
Five suppliers run the site and carry our replies. Each is bound by a data processing agreement and may use the data only on our instructions.
| Supplier | What it handles | Location |
|---|---|---|
| Amazon Web Services. Hosting | The site, the form handler, and our analytics server | European Union |
| Cloudflare. Content delivery | Serves pages and filters malicious traffic. Sees IP addresses in transit | Global edge network |
| HubSpot. CRM | Assessment contact records and follow-up notes | United States |
| Anthropic. Language models | Drafts assessment commentary and follow-up text | United States |
| Email provider. Mail delivery | Carries form notifications and assessment reports | European Economic Area |
To find out which supplier handles a specific piece of your data, email [email protected] and we will name it.
We disclose personal data outside this list only where the law requires it, or to establish or defend a legal claim.
HubSpot and Anthropic process data in the United States under the European Commission's Standard Contractual Clauses, and HubSpot is additionally certified under the EU-US Data Privacy Framework. All storage of your data stays in the EEA. Cloudflare is the exception in transit: its global network terminates the connection near whoever is browsing, so a visitor outside the EEA is served from outside it.
To see the safeguards for a specific transfer, ask us at [email protected] and we will send you the relevant terms.
We keep personal data while it still serves the purpose we collected it for, and we review what we hold at least once a year and delete records where the conversation has clearly ended. For an enquiry that means as long as the relationship is live. For assessment answers it means as long as the result is still useful to you or to us.
Our web server deletes request logs after 30 days.
A legal duty to keep records for longer takes precedence, for example under accounting law. We then keep only what that duty covers.
Ask us at [email protected] what we hold about you and we will tell you, and delete it if you want that.
Under the GDPR you can ask us to do any of the following, and we will respond within 30 days.
Send any of these requests to [email protected]. We ask for enough information to confirm who you are, and we charge nothing.
Tell us first if something looks wrong, because we can usually fix it quickly. You also have the right to go straight to the supervisory authority, or to your own national authority if you live in another EEA country.
We update this page when what we do changes, and the date at the top shows when. Where a change materially affects data you have already given us, we contact you directly. Questions about anything here go to [email protected].