Legal
Privacy Policy
This page explains how Ungt Steg handles personal data when you use our website, account features, and digital tools.
Last updated: 11 September 2026
1. Who we are
Ungt Steg provides digital tools, content, and support for young people moving toward work. This privacy policy explains what personal data we process, why we process it, and which rights you have.
Privacy questions can be sent to hei@ungtsteg.no.
2. Data we collect
We may process contact details such as name and email address, account information, content you add to CVs, cover letters, job matching or other tools, finalized interview-practice transcripts and feedback, technical device and usage information, and messages you send to us.
When you use voice interview practice, OpenAI processes the audio stream to conduct the conversation and create a transcript. Ungt Steg stores the finalized transcript, result, and any optional experience review, but does not store raw audio.
If you use the community, we process your posts, comments, and reactions, your event sign-ups, and any reports you submit. If you use direct messages, we store the messages between you and the person you are writing to.
If you are affiliated with an organisation, we store the time of your latest signed-in use of Ungt Steg. We store only the latest timestamp for this purpose, not a page history.
For Sarepta UngdomsJobb, we may also process contact details from course and interest sign-ups before an account exists, school, course or cohort, consent summaries, and dated attributed notes about contact and follow-up. The employer and partner register may contain contact people, phone, email, address, and linked jobs.
When you register for a Sarepta course, we process your name, email, phone number, selected course, registration or waitlist status, and attendance. You confirm that you are 16–30, but the course form does not store your date of birth. Necessary messages about the selected course are sent regardless of your marketing choice.
Please avoid entering sensitive information unless it is necessary for the service you ask us to provide.
3. How we use data
We use personal data to create and operate accounts, provide our tools, store documents and progress, respond to requests, improve the service, protect it from misuse, and meet legal obligations.
For organisation participants, we use the latest-use timestamp to show the organisation's active-user capacity. A participant is active for 90 days after their latest use. Inactivity does not end the organisation affiliation.
When you use AI-based features, text or audio you submit may be processed to provide the suggestions, summaries, job matching, interview conversation, or feedback you requested.
We may use completed interviews and voluntary experience reviews in aggregated analysis to compare conversation approaches and improve interview practice.
The community and messaging exist so you can share experiences, ask questions, and stay in touch with your adviser. Reported content is reviewed by moderators to keep the community safe.
4. Legal bases
Processing is usually necessary to provide a service you use, based on consent, based on our legitimate interest in securing and improving the service, or required to meet legal obligations.
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing already completed before consent was withdrawn.
Sarepta's optional course consent covers marketing about new courses, job opportunities and relevant offers by both email and SMS. It is separate from necessary course administration and from the platform-wide marketing choice on an Ungt Steg account. It can be withdrawn through the secure link in a course email.
5. Sharing, processors, and transfers outside the EEA
We do not sell personal data. We currently use these providers (processors): Supabase (database, sign-in, and file storage), Railway (hosting), OpenAI (AI for CVs, cover letters, job matching, and interview practice), Anthropic (an optional profile-summary provider when enabled), Resend (email delivery), GatewayAPI EU (sending and receiving SMS), and Sentry (error tracking). GatewayAPI processes phone numbers, SMS content, and delivery metadata when Sarepta's SMS feature is used. Those providers must process data only on our instructions.
If you are connected to an organisation through an access code, the advisers and administrators there see your name, email address, municipality, and how far you have come: whether you have finished onboarding, built a CV, started an application, generated a cover letter, practised an interview, and whether a job outcome has been recorded for you. They also see the time of your latest signed-in use, and they can write notes and labels about your follow-up. If the organisation posts a job, you may appear among its candidates with a short machine-generated explanation of why you fit.
The organisation does not see your actual content. Your CV text, cover letters, interview conversations, and private direct messages are available only to the people in that conversation. SMS sent or received through Sarepta's shared number is, however, visible to authorised Sarepta administrators so the team can follow up the request. At Ungt Steg, a limited number of named administrators can access account content when needed for support, troubleshooting, and security.
Before a Sarepta job application becomes visible to staff, you are told that your name, email, phone and application status will be available to Sarepta. If you decline, your own application row remains without becoming visible to Sarepta. For other jobs, your application and the contact details you provide are shared with the employer or organisation behind the listing.
We may also share data when needed to comply with law, enforce terms, or protect users, the service, or other legitimate interests.
Some of the providers above are US companies, so personal data may be transferred to and processed in the United States. GatewayAPI is used with its EU setup. Where a transfer outside the EEA occurs, it relies either on the EU-US Data Privacy Framework, which the European Commission has decided provides an adequate level of protection, or on the EU Standard Contractual Clauses. You can request a copy of the basis we rely on for an individual provider by contacting us.
We do not train our own AI models on your content.
6. Retention
We keep personal data for as long as needed for the purposes described in this policy, for example while you have an account with us or need access to stored documents.
For Sarepta UngdomsJobb, we automatically anonymize participant contacts 24 months after the latest meaningful contact or activity. Personal partner contacts and private clients are anonymized 36 months after the latest meaningful contact or after the latest linked job has ended. CRM notes follow the deadline of the contact they concern.
SMS content in Sarepta's shared message history follows the same deadline as the relevant contact: 24 months for participants and 36 months for personal partner contacts. SMS to named one-off recipients without a stored contact, and unresolved SMS threads, are anonymized no later than 12 months after the latest activity.
Sarepta course registrations are automatically anonymized 24 months after the latest meaningful course or contact activity. Name, email, phone number, secure management link, account and contact links, consent details, and person-linked attendance are removed. Courses, sessions and anonymous aggregates may remain for reporting. There is no manual review before anonymization.
Application data shared with Sarepta is anonymized six months after the job ends. Unresolved identity matches are anonymized after 90 days, and identifying audit and discrepancy data is anonymized after 12 months. Raw local Monday exports are anonymized after 90 days.
When Sarepta data is anonymized in Ungt Steg, names, contact fields, personal relationships, and personal free text are removed. Information about a company, school, or venue as an organisation may remain without personal contact fields. Anonymous statistics may remain when they cannot be linked to an individual.
This Sarepta retention applies to CRM and applicant copies used by Sarepta for follow-up. It does not delete your Ungt Steg account, CV, documents, messages, or other content you own in the service.
An organisation administrator may end an affiliation because it is incorrect, consent is withdrawn, the participant is transferred, or for another exceptional reason. This does not delete the account or participant-owned content. Account deletion is a separate process.
You can delete your account yourself from the account page. This removes your profile, documents, applications, interview sessions, and your community content, along with the files we have stored for you and the copy of your profile in the job-matching service.
You can also ask us to delete your account or specific data. Some data may need to be kept longer where law, security, documentation, or dispute handling requires it.
7. Your rights
You may request access, correction, deletion, restriction, portability, and objection to processing where the law gives you those rights.
You can contact us at hei@ungtsteg.no. You may also complain to the Norwegian Data Protection Authority if you believe we process personal data unlawfully.
8. Security and changes
We use technical and organizational measures to protect personal data against unauthorized access, loss, and misuse. No digital service can guarantee complete security.
We may update this privacy policy when the service or legal requirements change. The new version will be published on this page with an updated date.
9. Cookies and local storage
Necessary cookies are used for login and security, and to remember the choice you make in the consent banner. These are required for the service to work and cannot be switched off.
The latest signed-in use timestamp is necessary operational data for the organisation's active-user capacity. It is recorded independently of analytics consent and contains no page history.
With your consent we additionally use our own first-party analytics: a temporary session id is stored in your browser, and we record page views, device type, and performance measurements to understand how the service is used and improve it. You can decline this in the banner without losing any functionality.
We also use error tracking (Sentry) to catch technical failures so we can keep the service stable and secure. You can change your consent by clearing cookies in your browser; the banner will then appear again.