Both your web hosting and support account credentials are encrypted. I see you point not sending them to you when you setup the services, but you have to understand that we do offer services for a wide range of people. Some really want a copy of their login in their email that they have locally.
But I take your point about this and we will try to make that optional. It is optional when you setup email sub-accounts for the administrator.
If you are a layman, it does. But this quote is very restrictive in the interpretation by Post og Teletilsynet: "Tilbyder av elektronisk kommunikasjonsnett som anvendes til offentlig elektronisk kommunikasjonstjeneste og tilbyder av offentlig elektronisk kommunikasjonstjeneste er lagringspliktig."
What we dont do is offer "Tilbyder av elektronisk kommunikasjonsnett". That means we are outside. Then the rest is not relevant.
We have been in the courts about this and both Kripos (they wanted information) and the judge found that we are outside the scope of this.
It does, but they dont offer email or phone services. So they are also exempt. We use Blix: https://www.blix.com/
What you call a loophole, was no secret in the hearings about the new law. The government wanted this implemented mainly for the phone providers. They understood that foreign email providers like Gmail and Hotmail that most use in Norway, could not be under the law in any practical way, so they restricted who this is applicable to.
The way company law is set up in Norway, you cant as a board member do anything else than what is best for the company you are board member in. Doing something different would mean you could be held responsible. They could fire the board, but the next board have the same rules to go by.
Datalagringsdirektivet is not applicable for most providers in Norway, only the big carriers like Telenor, Telia-Sonera/Netcom and Tele2. The practical rule is that if you have a ASN-number (Data Center) and you provide the relevant services, then you need to follow it. The email service I work for, Runbox, is not. Probably not Jotta either.
Well, what you say is not correct. First of all the Data Retention Directive have to be valid for you. I work for the Norwegian email provider Runbox and the EU Data Retention Directive is not applicable for us. It is only valid for carriers that own their own infrastructure down to the data center, called "communication providers". We even have it confirmed by both Kripos (FBI-ish) and Post- og Teletilsynet (Norwegian Post and Telecommunication Authority). We have tried to explain a bit why here: http://www.runbox.com/why-runbox/email-privacy-offshore-emai...
But I take your point about this and we will try to make that optional. It is optional when you setup email sub-accounts for the administrator.