Privacy Policy
Last updated: 16 July 2026
Eksire AS ("Mynto") processes personal data to deliver our accounting service. This policy explains what we collect, why, and your rights.
What we collect
Identity verified via Vipps and BankID (name, phone number and a one-way hashed national ID — we never store the national ID in clear text), company data from the Brønnøysund Register, bank transactions via a secure bank connection, and the receipts and invoices you upload. If you use the payroll module, we process data about your company's employees: name, national ID, salary, tax card and employment details. We process these as a data processor on behalf of your company — see the Data Processing Agreement.
Why we process it
To keep your books, calculate VAT, run payroll, send invoices and alert you to deadlines — performance of our contract with you and legal obligations under Norwegian bookkeeping and accounting law. For your company's accounting data (information about employees, customers and suppliers), your company is the data controller and Mynto the data processor.
Email integration
If you choose to connect Gmail or Outlook, Mynto reads email solely to find receipts, invoices and other accounting documents. We store attachments and relevant metadata (sender, subject, date) for emails that relate to your accounts; other content is not stored. You can revoke access at any time in settings or with your email provider. Data from the email integration is never used for advertising or AI training, and data obtained via Google APIs is handled in accordance with the Google API Services User Data Policy, including the Limited Use requirements.
Use of artificial intelligence
Mynto uses an AI provider (Anthropic PBC, USA) to suggest postings, read documents and answer questions about your accounts. Transfers rely on the European Commission's standard contractual clauses (SCCs). The data is not used to train AI models, and is not retained by the provider beyond what is needed to produce the answer. Every AI suggestion requires your approval before anything is posted or filed.
National identity numbers are not sent to the AI provider. They are replaced with a placeholder before the text is sent, and restored on our side when the answer comes back.
To answer questions about your accounts, the assistant otherwise sees the same information an accountant would: bank transactions including the text supplied by the bank, customers and suppliers, and payroll data such as names, salary, position percentage and registered leave — including parental leave, which employers are required to report in the a-melding.
If you upload a file in the chat, the file is sent to the AI provider as-is so its contents can be read. Only upload documents you want the assistant to see.
Sharing and storage
Data is stored in the EU/EEA. A few providers are outside the EEA; those transfers rely on the European Commission's standard contractual clauses (SCCs). We share only with the processors needed to run the service, under data processing agreements — a complete, current list with purpose, location and transfer basis is at mynto.no/underdatabehandlere. We also share with the authorities (Altinn, the Tax Administration) when you approve a filing yourself. We never sell data.
Retention periods
Accounting records are retained for as long as the customer relationship lasts, in line with the Norwegian Bookkeeping Act (see the terms). When the customer relationship ends, accounting data is deleted 90 days after termination. Account details linked to your login are deleted when your account is closed, unless statutory retention requires otherwise.
Your rights
You may request access, rectification, erasure and portability, and lodge a complaint with the Norwegian Data Protection Authority. For data where your company is the controller (for example employee payroll data), requests must be directed to the company. Contact us at personvern@mynto.no.
Cookies and local storage
Mynto uses cookies and equivalent storage in your browser. Most of it is strictly necessary for the service to work and requires no consent: your login, your language choice, which company you last worked in, and which onboarding steps you have dismissed. If you pay your subscription by card, Stripe sets its own cookies to detect fraud. We use Sentry for error monitoring; it stores nothing in your browser.
Product analytics is the only thing that requires consent, and we ask for it separately inside the app. If you say yes, PostHog (EU) stores a pseudonymous id and records which pages you visit and where you click. We may also capture masked session recordings showing layout and clicks. All text and all input is masked — no amounts, names or national identity numbers leave your machine. You can change your choice at any time under Settings → Data.
If you say no — or simply don't answer — nothing is stored in your browser for this purpose. You are still counted as an anonymous visit: PostHog then derives an id on its own server from your IP address and browser type, using a salt that is replaced and deleted every night, so the count cannot be traced back to you. The basis for that anonymous counting is our legitimate interest in knowing how the service is used.
The marketing pages on mynto.no count visits in exactly the same anonymous way, whatever you have chosen. They use no tracking, no ad networks and no third parties beyond this.