The security & accountability log
This page explains, in plain language, exactly what our restricted security and accountability log records, why we keep it, who can see it, and how long we hold it. It sits alongside our Privacy Policy and expands on the "Security log" entry there. It is provided for transparency and is not legal advice.
What this log is for
To keep accounts and the portal safe, we keep a restricted log of security-relevant events. We use it only to protect accounts, to prevent and investigate abuse, to investigate incidents, and to defend legal claims. We never use it to build a profile of you, and we never use it for marketing or advertising.
What we record
Depending on the event, an entry may contain:
Why we are allowed to keep it (legal basis)
Our legal basis under the GDPR is our legitimate interests in operating the portal securely, preventing fraud and abuse, keeping an accountability record, and defending our rights. Because these records include a full IP address, we keep a written legitimate-interests assessment (LIA) that weighs this against your privacy and explains why what we keep, and for how long, is necessary and proportionate. That assessment is available on request.
Who can see it
How long we keep it
Extra care for under-18s
Our account-security location check, which flags an unusual sign-in for a person to review, is never applied to members under 18. Their sign-ins are not logged in that way at all. For more on how we protect young members' data, see our Protecting young members' data page.
Your rights
You can ask us to access, correct or delete the personal data we hold about you, and to restrict or object to processing, at any time. To exercise any right, or to ask to see the legitimate-interests assessment described above, contact us at info@nordicdiplomacy.org. You can also complain to the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu, tietosuoja.fi) or your local supervisory authority.
Nordic Diplomacy Initiative. Guided by the North.