Skip to the main content
Bergen Facilitation Collective

Privacy

What happens to what you leave here

Very little, and this page says all of it. There is no advertising, no analytics and no tracking on this site, and nothing on these pages asks your browser to contact anybody else.

Last reviewed

Who is responsible

Bergen Facilitation Collective is the data controller for the personal data described here. Responsibility sits with the board.

Registered as
forening/lag/innretning
Organisation number
937 490 089
Registered address
c/o Vinje & Eriksen, Strandgaten 18, 5013 Bergen
Email
hei@bergen-fasiliterer.no

Write to us about anything on this page, including a request about your own data.

What our server records

The website itself records the method and the address of each request — that a page was asked for, and which one. It does not record your IP address or your browser's user-agent string: neither reaches the application at all.

The web server in front of it keeps short operational records of the kind any web server does, so that faults can be diagnosed and attacks blocked. These are kept briefly and are used for nothing else.

Our basis is legitimate interest under Article 6(1)(f): a website cannot be run securely with no operational record at all, and what is kept is the minimum that serves that.

How this site reports its own faults

This site keeps working when your connection does not, which means most of it runs in your browser. When that goes wrong — a page that stays empty, something that fails silently — the evidence is on your device and we never see it. So some visits send us a short technical record of how the page loaded.

To tie together the few messages one visit sends, we put a number in the page. It is new every time you open the site, it is not stored on your device, and it is not connected to anything else we hold. It is not a visitor identifier: it cannot tell one visit from the same person apart from a visit by somebody else.

About one visit in 4 sends a record of an ordinary, working page load. We need those to know what normal looks like — a page that took four seconds tells us nothing unless we know what four seconds means on the devices people actually use.

A visit where something did go wrong sends a record whether or not it was one of those, because those are the ones we cannot otherwise hear about.

A record contains, and contains only:

It contains no page views, no count of visitors, no address, no information about your device beyond the numbers above, and nothing that identifies you. The kind of page above is everything it says about where you were: it cannot tell us which event you were reading, what you typed into the search, or where you went next.

You do not have to take our word for any of this. Open the site's diagnostics page and it shows you exactly what your browser would send, in full:

See what would be sent

Records are kept for 30 days and then deleted. The summary figures we keep longer carry no session number and describe no individual visit.

Turning JavaScript off in your browser stops this completely — nothing is sent, because the part that would send it never runs. If your browser sends the Global Privacy Control signal, we honour it and send nothing either, not even when something goes wrong. In that case there is a button on the diagnostics page below that sends one record, once, if you decide you would like us to see it.

Our basis is legitimate interest under Article 6(1)(f), as for the server records above: a site cannot be kept working for people whose problems it never hears about, and what is sent is the minimum that serves that.

Cookies

Four, and every one of them is needed for something you asked for. Three exist only after you sign in, so a visitor who only reads pages receives one — and only after choosing a language.

CookieWhat it is forHow long it lasts
langThe language you chose with the switcherOne year
bfc_sessionKeeps you signed in, if you are a member12 hours
bfc_auth_flowHolds a sign-in while it is in progress, so the answer coming back can be checked against the request that started it10 minutes
bfc_auth_noteCarries one message about a sign-in attempt to the page that shows itOne minute

Under ekomloven § 3-15 storage that is strictly necessary for a service you have asked for does not require consent, so there is no cookie banner on this site. We set nothing for advertising, analytics or social media.

What this site stores in your browser

More than the cookies, and it is worth explaining because it is unusual. This site is built to keep working when your connection does not, which means your browser holds its own copy of what it has read.

A copy of the site's content

Every event, offering and steward profile you are allowed to see, kept in a database in your browser so that pages open without waiting for the network. Alongside it, a note of what you had already seen, so the site can show you what has changed since.

A search index

So that searching happens on your device rather than by asking our server.

Your unsent writing, if you are a member

Anything you type into a form is saved in your browser as you go, and changes you make offline wait there until there is a connection. That is so a reload or a lost connection does not empty a form you spent an hour on.

The member list, if you are an administrator

An administrator's copy of the site includes the member list with email addresses, because the administration pages have to work offline like the rest of the site. If you administer this site, the membership list is on your device — which is a reason to keep that device locked.

All of it is a copy of what our server already holds, and you can remove it at any time by clearing this site's data in your browser settings. The site will still work; it will simply fetch things again.

If you are a member

We store your email address, the identity your sign-in provider gives us, whether your account is active, when it was created, and which roles you hold.

We store no password. Signing in happens through an external provider, so we never see one. Your session is held as a one-way hash of a token rather than as anything that could be used to sign in as you.

Changes to roles are recorded — which role, granted or revoked, by whom, and when — so that who can do what on this site is something the board can check afterwards.

Our basis is the performance of your membership agreement, Article 6(1)(b).

If you have a public profile

A steward's profile is public: the name they chose, the introduction they wrote in both languages, and a photograph if they uploaded one. All of it is written by the person it describes, and any of it can be changed or removed by them.

A photograph you upload is re-encoded before it is stored, so the information cameras and phones attach to a picture — including where it was taken — is not kept and is not published.

If you write to us

Your message arrives in a mailbox the collective reads, and stays there while there is a reason to keep it. There is no form on this site and no ticketing system behind it: it is email, read by people.

Our basis is legitimate interest — answering somebody who has written to us — or the performance of an agreement where one exists.

Who else can see any of this

We do not sell personal data and we share it with nobody else, unless we are required by law to.

Where it is kept

On two servers: the association's own machine in Norway, and a rented one in Germany. Backups are held under the association's own control. Our email is run by the association itself rather than by an external provider. Nothing described here is transferred outside the EEA — Norway and Germany are both in it.

Your rights

Under the GDPR you may:

Write to us and we will answer within one month. If you think we are handling your data badly, please tell us first — we would rather fix it than have you go elsewhere unsatisfied.

Complaining to the authority

You can complain to the Norwegian Data Protection Authority, whether or not you have raised it with us:

Datatilsynet
Postboks 458 Sentrum, 0105 Oslo
datatilsynet.no

When this page changes

If what we do with personal data changes, this page changes with it and the date above changes too. The date is checked against the text of this page by the site's own tests, so it cannot quietly fall behind what is written here. Where a change matters to members, we tell members directly.