Amed by It Happens
Privacy notice
This notice explains how Amed handles account, workspace, and connected commerce data.
Last updated 1 September 2026
Who operates Amed
Amed is operated by SillySanta AS, trading as It Happens, organisation number 916 896 050 MVA, Lilletorget 1, 0184 Oslo, Norway. Questions and privacy requests can be sent to henrik@ithappens.no.
Data we handle
- Account details such as name, business email, preferred language, and authentication records.
- Workspace content such as chats, saved agents, dashboards, schedules, and audit records.
- Encrypted connection credentials and the commerce data requested from connected services, including Google Ads, Meta Ads, Shopify, Triple Whale, Inventory Planner, and the It Happens return portal.
- Technical and security data needed to operate the service, such as request, error, and usage logs.
Amed is designed for business analytics. Customers should not submit special-category personal data or use chat prompts to request personal customer profiles.
How and why we use it
We use the data to provide the contracted service, authenticate users, retrieve data the workspace has authorised, answer questions, run saved work, deliver requested outputs, prevent misuse, and support the service. Connected sources are read-only except for destinations that the user explicitly enables, such as writing a dashboard table to an Amed-created Google Sheet.
Service providers and international transfers
Amed uses hosting and database infrastructure in Heroku's EU region, SendGrid for transactional email, and Anthropic's API to generate answers. Prompts and the relevant results retrieved for a request can therefore be sent to Anthropic. These providers may process limited data outside Norway or the EEA under their contractual transfer safeguards.
We do not sell personal data or use Amed account data for third-party advertising.
Storage, access, and deletion
Workspace data is separated by customer. Connection secrets are encrypted before storage and are not shown to the language model. We retain data while the workspace is active and as needed for security, contractual, and legal obligations. Disconnecting a source removes its renewable credential from the Amed vault. See the data deletion instructions for full account or workspace deletion.
Your rights
Depending on the circumstances, you can request access, correction, deletion, restriction, or a copy of your personal data, and object to certain processing. You can also complain to Datatilsynet. A business customer may act as the controller for commerce data it connects to Amed; requests about that data may need to be handled through the customer organisation.