Privacy
What happens to what you leave here
Very little, and this page says all of it. There is no advertising, no analytics and no tracking on this site, and nothing on these pages asks your browser to contact anybody else.
Last reviewed
Who is responsible
Bergen Facilitation Collective is the data controller for the personal data described here. Responsibility sits with the board.
- Registered as
- forening/lag/innretning
- Organisation number
- 937 490 089
- Registered address
- c/o Vinje & Eriksen, Strandgaten 18, 5013 Bergen
- hei@bergen-fasiliterer.no
Write to us about anything on this page, including a request about your own data.
What our server records
The website itself records the method and the address of each request — that a page was asked for, and which one. It does not record your IP address or your browser's user-agent string: neither reaches the application at all.
The web server in front of it keeps short operational records of the kind any web server does, so that faults can be diagnosed and attacks blocked. These are kept briefly and are used for nothing else.
Our basis is legitimate interest under Article 6(1)(f): a website cannot be run securely with no operational record at all, and what is kept is the minimum that serves that.
How this site reports its own faults
This site keeps working when your connection does not, which means most of it runs in your browser. When that goes wrong — a page that stays empty, something that fails silently — the evidence is on your device and we never see it. So some visits send us a short technical record of how the page loaded.
To tie together the few messages one visit sends, we put a number in the page. It is new every time you open the site, it is not stored on your device, and it is not connected to anything else we hold. It is not a visitor identifier: it cannot tell one visit from the same person apart from a visit by somebody else.
About one visit in 4 sends a record of an ordinary, working page load. We need those to know what normal looks like — a page that took four seconds tells us nothing unless we know what four seconds means on the devices people actually use.
A visit where something did go wrong sends a record whether or not it was one of those, because those are the ones we cannot otherwise hear about.
A record contains, and contains only:
- which version of the site your browser was running
- the number described above
- which kind of page you were on — that it was an event page, say, or the search page: one choice out of about two dozen, never the address itself and never the name of what you were reading
- the sequence of what the page did as it started, as short lines of English written by the site itself
- how long each step took and how much data it moved — opening the browser database, reading it, fetching the content, building the search index
- the text of anything that failed, including where in our own code it failed
It contains no page views, no count of visitors, no address, no information about your device beyond the numbers above, and nothing that identifies you. The kind of page above is everything it says about where you were: it cannot tell us which event you were reading, what you typed into the search, or where you went next.
You do not have to take our word for any of this. Open the site's diagnostics page and it shows you exactly what your browser would send, in full:
Records are kept for 30 days and then deleted. The summary figures we keep longer carry no session number and describe no individual visit.
Turning JavaScript off in your browser stops this completely — nothing is sent, because the part that would send it never runs. If your browser sends the Global Privacy Control signal, we honour it and send nothing either, not even when something goes wrong. In that case there is a button on the diagnostics page below that sends one record, once, if you decide you would like us to see it.
Our basis is legitimate interest under Article 6(1)(f), as for the server records above: a site cannot be kept working for people whose problems it never hears about, and what is sent is the minimum that serves that.
What this site stores in your browser
More than the cookies, and it is worth explaining because it is unusual. This site is built to keep working when your connection does not, which means your browser holds its own copy of what it has read.
A copy of the site's content
Every event, offering and steward profile you are allowed to see, kept in a database in your browser so that pages open without waiting for the network. Alongside it, a note of what you had already seen, so the site can show you what has changed since.
A search index
So that searching happens on your device rather than by asking our server.
Your unsent writing, if you are a member
Anything you type into a form is saved in your browser as you go, and changes you make offline wait there until there is a connection. That is so a reload or a lost connection does not empty a form you spent an hour on.
The member list, if you are an administrator
An administrator's copy of the site includes the member list with email addresses, because the administration pages have to work offline like the rest of the site. If you administer this site, the membership list is on your device — which is a reason to keep that device locked.
All of it is a copy of what our server already holds, and you can remove it at any time by clearing this site's data in your browser settings. The site will still work; it will simply fetch things again.
If you are a member
We store your email address, the identity your sign-in provider gives us, whether your account is active, when it was created, and which roles you hold.
We store no password. Signing in happens through an external provider, so we never see one. Your session is held as a one-way hash of a token rather than as anything that could be used to sign in as you.
Changes to roles are recorded — which role, granted or revoked, by whom, and when — so that who can do what on this site is something the board can check afterwards.
Our basis is the performance of your membership agreement, Article 6(1)(b).
If you have a public profile
A steward's profile is public: the name they chose, the introduction they wrote in both languages, and a photograph if they uploaded one. All of it is written by the person it describes, and any of it can be changed or removed by them.
A photograph you upload is re-encoded before it is stored, so the information cameras and phones attach to a picture — including where it was taken — is not kept and is not published.
If you write to us
Your message arrives in a mailbox the collective reads, and stays there while there is a reason to keep it. There is no form on this site and no ticketing system behind it: it is email, read by people.
Our basis is legitimate interest — answering somebody who has written to us — or the performance of an agreement where one exists.
Who else can see any of this
- The collective's website administrator, who operates and maintains the site on the board's instructions under a written agreement, and may use the data for nothing else.
- netcup GmbH, in Germany, which provides one of the two servers the site runs on. The other is the association's own machine, in Norway.
- Your sign-in provider, if you are a member. Signing in sends you to them and back, so they know that you signed in to this site. We receive an identifier and your email address from them and nothing more.
- Substack, if you follow the newsletter link in the footer. The newsletter is published there rather than here, so what you do on Substack is between you and Substack — we hold no subscriber list.
We do not sell personal data and we share it with nobody else, unless we are required by law to.
Where it is kept
On two servers: the association's own machine in Norway, and a rented one in Germany. Backups are held under the association's own control. Our email is run by the association itself rather than by an external provider. Nothing described here is transferred outside the EEA — Norway and Germany are both in it.
Your rights
Under the GDPR you may:
- ask what personal data we hold about you and receive a copy
- have anything inaccurate corrected
- have data deleted, where we have no continuing reason to keep it
- object to our processing, or ask us to restrict it
- receive data you gave us in a portable form
- withdraw consent at any time, where consent is our basis
Write to us and we will answer within one month. If you think we are handling your data badly, please tell us first — we would rather fix it than have you go elsewhere unsatisfied.
Complaining to the authority
You can complain to the Norwegian Data Protection Authority, whether or not you have raised it with us:
DatatilsynetPostboks 458 Sentrum, 0105 Oslo
datatilsynet.no
When this page changes
If what we do with personal data changes, this page changes with it and the date above changes too. The date is checked against the text of this page by the site's own tests, so it cannot quietly fall behind what is written here. Where a change matters to members, we tell members directly.