Trust is not a feature. It is how we operate.
Amesto processes personal and financial data for more than 2,500 businesses across the Nordics, UK, Europe and North America. The responsibility that comes with that scale is something we take seriously — in how we design our systems, how we train our people, and how we document our practices.
This Trust Center is not a marketing page. It is a transparent record of our security controls, our privacy practices, our compliance documentation, and our sustainability reporting. We believe that the clients who need to trust us most deserve the clearest picture of how we work.
Privacy
Our ambition is full transparency in how we process your personal data. Privacy statements available in English, Norwegian, Swedish and Danish.
Privacy policySecurity
Continuous vulnerability scanning, DDoS prevention, penetration testing and physical data centre protection. Security awareness built into every development process.
Security practicesCompliance
DPA documentation (versions 1.0–2.1, publicly downloadable), standard delivery terms for Norway, Sweden and Denmark, and AML/KYC compliance information.
Compliance documentationTrust notification
Amesto promises to always remain compliant with applicable legislation, as well as industry specific standards and requirements.
Report incident
Our sustainability report — transparent by design.
In 2019, Spabogruppen adopted the Triple Bottom Line framework with the goal of creating lasting value for people, the planet, and the company. Our aim was to ensure that sustainability became an integrated part of our business operations — not a side project — embedded from top management all the way through to our employees' everyday interactions with customers.
Building on this foundation, we established Amesto Footprint in 2022. Amesto Footprint develops digital solutions that make it easier for businesses to start their sustainability work — helping identify which laws and reporting requirements apply, and supporting the entire process from measurement and reporting to advisory and improvement initiatives.
The ESRS report for Spabogruppen is a natural continuation of this work. It provides a clear overview of key sustainability areas and helps us track progress and follow up on actions in a structured way. The report contributes to deeper insights, clearer priorities, and better decision-making — both internally and in dialogue with our stakeholders.
We care about data protection.
Privacy and data protection is a foundational consideration in building trust with our clients. Amesto has prepared a Privacy Policy to describe our practices regarding the personal information that may be collected — covering what we collect, how we use it, how long we retain it, and what rights you have as a data subject.
Our ambition is to be fully transparent in how we process personal data and in the choices you can make regarding it. Privacy statements are available in four languages — English, Norwegian, Swedish and Danish — to ensure our clients and their employees across the Nordic region can access the information in their own language.
If you have a question about how we handle your personal data, or want to invoke your data subject rights, you can use the Amesto Trust Notification form. For confidential matters, contact us at amestotrust@amesto.no — noting that sensitive information should not be sent over unsecured email.
Privacy policyBuilt to protect what you entrust to us.
Over the years, Amesto has established processes, methods and technologies and embraced proven standards to meet our customers' security, privacy and accessibility needs. The nature of threats is constantly changing — so security awareness is a natural part of our development process and we constantly strive to improve.
Our security controls include: continuous scanning for vulnerabilities, monitoring of intrusion attempts, abuse detection, DDoS attack prevention, frequent penetration testing and data analytics. For cloud solutions, we use vendor data centres that run around the clock and conform to recognised industry standards of physical security, reliability, protection against power outage and network outage.
If you have discovered a potential security incident involving Amesto systems or data, please use the Amesto Trust Notification form to report it as soon as possible. We take all reports seriously and respond promptly.
Security practices
Committed to applicable legislation — and beyond.
Amesto promises to always remain compliant with applicable legislation, as well as industry-specific standards and requirements. We also strive to evolve our services dynamically to meet modern standards and client requests relating to our legal obligations.
For Amesto AccountHouse, Data Processor Agreements (DPAs) are publicly documented and versioned — covering all sub-processors, system changes and legal updates. The current version is DPA 2.1 (April 2026). All prior versions from DPA 1.0 are available for download, giving our clients a complete audit trail of how our data processing arrangements have evolved.
Standard terms of delivery are in place for all Nordic markets: Norway (Regnskap Norge standards), Sweden (Srf konsulterna), and Denmark. Anti-money laundering (AML) and Know Your Customer (KYC) documentation is also publicly available for clients in regulated industries.
For industry-specific compliance enquiries, please contact the relevant Amesto business unit directly.
Compliance documentation and DPAsReport an incident or exercise your data rights.
If you — as a customer, employee or supplier of Amesto — have discovered a potential privacy or security incident, please submit our online Amesto Trust Notification form as soon as possible. Early reporting enables us to contain and remediate incidents quickly.
If you believe Amesto is processing your personal data, you may also invoke your data subject rights — including the right to access, correction, erasure and portability — by submitting the same form. Amesto responds to data subject requests where we are acting as a data controller. For cases where we are acting as a data processor on behalf of a client, please refer to that client's privacy notice.
For general Trust Centre enquiries or if you already have an open Amesto Trust case, please use the Amesto Trust Portal or contact amestotrust@amesto.no. Note: confidential information should not be sent via unsecured email.
Report an incidentQuestions about security, privacy or compliance?
Our Trust team is available to answer questions about how we handle data, our security practices, or our compliance documentation. Contact us directly or use the notification form for incident reports and data subject requests.