EVImport · Driftly AS
Data security
Updated · Version 2026-09-22
Payments for our products and services are made to EVImport / Driftly AS. Viva.com processes the payment. Vehicle purchase money is paid directly between exporter and dealer.
How EVImport controls access and handles information, and how to report a security issue. Driftly AS operates the service.
1. Access controls
Portals require login. Access follows company and role, including separate finance and administration rights. Support access is time-limited and recorded. Security-related actions and changes may be logged for review. Do not share credentials; remove access for former staff.
2. Communication and payments
The site uses HTTPS. Login-cookie settings limit access from browser scripts and cross-site use. Secret API credentials belong on the server, not in customer pages or public source code.
EVImport / Driftly AS is the supplier and payee for our deliveries. Viva handles card payment on its checkout; our forms do not request card numbers or CVC. Payment status is checked against the provider’s transaction rather than relying solely on a browser redirect. Vehicle settlement remains separate with the exporter.
3. Documents
Link documents to the correct order/VIN and restrict them to those who need them. Minimise personal information, and verify recipients and attachments. Do not put identity documents, payment secrets or sensitive personal data in ordinary customer messages without a specific arrangement.
4. Operations and incidents
Access controls, updates, logs and backups form part of secure operations. Restoration must account for integrity and prior deletion requests. Backups do not replace your company’s own contractual and accounting records.
Incidents require investigation, containment and assessment of notification to affected people and authorities under applicable rules. No online service can guarantee that all incidents or outages are prevented. This page is neither a certification nor a specific uptime agreement.
5. Report a concern
Contact support@evimport.no about unauthorised access, a wrong recipient, fraud or a suspected data leak. Include time, page/order and what you observed. Do not initially send passwords, full card data or other customers’ documents; we can arrange a suitable channel.
For suspected card misuse, also contact your bank or card issuer. We never ask for BankID passwords, one-time codes or CVC by email. Verify unexpected account changes through a known contact channel before paying.
