Skip to content

Privacy Policy

This policy explains what personal data Diversify collects when you use diversify.no, why we collect it, how long we keep it, and the choices you have. We keep it in plain language on purpose.

Who we are

Diversify is a non-profit organisation registered in Norway (org. nr. 921 310 161) with its office in Oslo. For the purposes of the General Data Protection Regulation, Diversify is the data controller for the personal data described in this policy.

You can reach us at privacy@diversify.no for anything relating to your data, including access, correction and deletion requests.

What we collect

We collect only what a specific purpose requires, and we ask for it directly rather than buying or inferring it. In practice that falls into a small number of categories.

  • Contact details you give us — name and email address when you subscribe to the newsletter, register for an event, submit a comment, or write to us.
  • Event details — dietary needs or accessibility notes you choose to share when registering, used only for that event.
  • Programme applications — the information you enter when applying as a participant, mentor or intern.
  • Technical data — anonymised page-level usage statistics, and security data needed to keep forms working.

Why we are allowed to process it

Most of what we do rests on your consent: you subscribe, you register, you comment. You can withdraw that consent at any time, and doing so does not affect processing that already happened.

Some processing rests on our legitimate interest in running the organisation — answering an enquiry you sent us, keeping a record of a partnership, or protecting our forms from abuse. Where we rely on legitimate interest, we have weighed it against your privacy and can explain the reasoning if you ask.

Newsletter

Our newsletter goes out roughly once a month. We store your email address and the date you subscribed, and we record whether you confirmed the subscription.

If you never confirm, we delete the address after 30 days. Confirming is what starts the subscription, so an unconfirmed address is not on the list and does not stay on file.

Every email carries an unsubscribe link. Unsubscribing removes you from the sending list; we keep a minimal suppression record so you are not accidentally re-added.

Event registration

When you register for an event we collect your name, email address, and any notes you add about food or access needs. We use this to plan the event and to send you a confirmation and any practical updates.

Paid events are handled by a ticketing provider, which processes payment on its own terms. We do not receive or store card details.

Comments on articles

Comments on our Insights articles are moderated before they appear. Two different things happen to what you submit, and it is worth being precise about them.

What is published: the name you enter and the text of your comment appear publicly on the article page, and stay there indefinitely unless you or we remove them. Treat a comment as permanent and public, and please do not include anything you would not want indexed by a search engine.

What is kept privately: your email address is stored with the comment but never displayed. We use it only to contact you about moderation — for example, if we need to ask about something before publishing.

How to have a comment removed: email us from the address you used, or tell us the article and the name on the comment. We remove published comments on request, normally within five working days, and we do not require a reason.

Consulting and partner enquiries

If you contact us about consulting, funding or a partnership, we keep the correspondence and any documents you send for as long as the relationship is active, and afterwards for as long as we need them for accounting and reporting obligations.

Cookies and analytics

Analytics and marketing cookies stay switched off until you accept them in the consent banner. Rejecting them does not limit anything on the site. The details of each cookie, including how long it lasts, are set out separately in our Cookie Policy.

Who else sees your data

We use a small number of external service providers to host the site, send email and protect our forms. Each acts on our instructions under a data processing agreement, none of them may use your data for their own purposes, and each one only receives what it needs:

  • Sanity — stores the website's content and your form submissions. EU.
  • Vercel — hosts the website, and counts page views without cookies. It runs in the EU, in Stockholm; the company itself is US-based.
  • Google (Sheets API) — a working copy of form submissions, so we can read them without a login. US.
  • Resend — sends confirmation and notification emails. US.
  • MailerLite — sends the newsletter. EU.
  • Checkin.no — takes registrations for events where signing up happens on their site. A Norwegian company; the data sits on servers in Ireland. EU.
  • Cloudflare Turnstile — checks that you are not a bot when you submit a form or a comment. Global.
  • Google Analytics 4 — aggregate statistics about how the site is used, and only if you accept analytics cookies in the consent banner. US.

Some of these are US-based. Where personal data reaches them, the transfer is covered by the standard legal safeguards — the European Commission's standard contractual clauses, and where applicable the EU–US Data Privacy Framework.

We do not sell your data. We never have and we won't.

How long we keep things

Newsletter subscriptions are kept until you unsubscribe; an address that is never confirmed is deleted after 30 days. Event registrations are kept for the current programme year and then deleted, except where they form part of a funder report. Published comments remain until removed on request. Correspondence is kept for as long as it is useful and then deleted.

Your rights

Under the GDPR you can ask us for a copy of the data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict how we use it, object to processing based on legitimate interest, and ask to receive your data in a portable format.

Write to privacy@diversify.no and we will respond within one month. If you think we have handled your data badly, you can complain to the Norwegian Data Protection Authority (Datatilsynet).

Transfers outside the EEA

Some of our providers process data outside the European Economic Area. Where that happens, the transfer relies on the European Commission's standard contractual clauses or an equivalent safeguard.

Children

Some of our programmes involve participants under 18. Where that is the case, we ask a parent or guardian to register on the child's behalf and we collect the minimum needed to run the activity safely.

Changes to this policy

When we change this policy we update the date at the top of the page. If a change materially affects how we use data you have already given us, we will say so directly rather than relying on you noticing.

Questions, or want something removed?

Write to us and a person will answer. Include enough detail for us to find your data — for a comment, the page it sits on and the name you used.