PortalPrivacy Policy › Security & accountability log

The security & accountability log

This page explains, in plain language, exactly what our restricted security and accountability log records, why we keep it, who can see it, and how long we hold it. It sits alongside our Privacy Policy and expands on the "Security log" entry there. It is provided for transparency and is not legal advice.

What this log is for

To keep accounts and the portal safe, we keep a restricted log of security-relevant events. We use it only to protect accounts, to prevent and investigate abuse, to investigate incidents, and to defend legal claims. We never use it to build a profile of you, and we never use it for marketing or advertising.

What we record

Depending on the event, an entry may contain:

Your IP address
The full internet address your connection came from, at the time of the event.
Account acted on
The email address or account involved in the event.
Event
The time of the event, the type of event (for example a sign-in or a password reset), and its result.
Approximate location
The country or approximate city derived from the IP address. This is an estimate from the address alone; it is not GPS and not your exact location.

Why we are allowed to keep it (legal basis)

Our legal basis under the GDPR is our legitimate interests in operating the portal securely, preventing fraud and abuse, keeping an accountability record, and defending our rights. Because these records include a full IP address, we keep a written legitimate-interests assessment (LIA) that weighs this against your privacy and explains why what we keep, and for how long, is necessary and proportionate. That assessment is available on request.

Who can see it

Restricted to authorised administrators. Access is limited to a small number of authorised people, and only for as long as their role requires it.
Not shared. It is never shared with anyone else, except where the law requires it (for example a lawful request from an authority).
The exact rules stay private. The precise rules that flag a request as suspicious are not published, because doing so would only help someone trying to get around them. The categories of data and the purpose, however, are set out here.

How long we keep it

Event records: up to 270 days. The restricted security and accountability log is kept for up to 270 days and then deleted automatically, so that we can investigate incidents and defend legal claims within a realistic window.
Sign-in location records: 180 days. The more sensitive sign-in location records (IP address and approximate city) are kept for a shorter fixed period of 180 days and then deleted automatically.

Extra care for under-18s

Our account-security location check, which flags an unusual sign-in for a person to review, is never applied to members under 18. Their sign-ins are not logged in that way at all. For more on how we protect young members' data, see our Protecting young members' data page.

Your rights

You can ask us to access, correct or delete the personal data we hold about you, and to restrict or object to processing, at any time. To exercise any right, or to ask to see the legitimate-interests assessment described above, contact us at info@nordicdiplomacy.org. You can also complain to the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu, tietosuoja.fi) or your local supervisory authority.

Nordic Diplomacy Initiative. Guided by the North.