Portal › Privacy Policy

Privacy Policy

For the Nordic Diplomacy Initiative (nordicdiplomacy.org) and the conferences it runs, including NOMUN (Nordic Online Model United Nations). Last updated July 2026. This document explains in plain language what we collect and why. It is provided for transparency and is not legal advice.

1. Who we are and who controls your data

The Nordic Diplomacy Initiative ("NDI", "we", "us") is a standing, student led, non commercial initiative that designs, runs and archives Model UN activities. NOMUN is one of the conferences NDI runs; it is an activity of NDI, not a separate organisation. NDI is not yet a registered legal entity and operates on a non commercial basis with no revenue. Until a registered association is established, Ali Serbest, who currently leads NDI, acts as the data controller for the personal data processed through this portal and is responsible for the decisions described in this policy. The data controller can be contacted for all privacy, data and safeguarding matters at info@nordicdiplomacy.org. We aim to follow the EU General Data Protection Regulation (GDPR) and applicable data protection law.

No individual organiser, volunteer, chair or contributor is a separate controller of this data. People who help run NDI act only on NDI's documented instructions and only for as long as NDI authorises. They gain no personal ownership of, and no continuing right to, the accounts, records or personal data held here (see section 8).

2. What data we collect and why

We collect only what we need to run the event, we practise data minimisation, we do not sell personal data, and we do not use it for advertising.

Cookies and local storage. We use only what is strictly necessary to run the portal: a session cookie to keep you signed in, and small entries stored in your browser to remember your cookie and age confirmation so we do not ask again. We do not use advertising, analytics or cross site tracking cookies, so no separate cookie consent for tracking is needed.

2a. Detailed notes on each purpose (sub-policies)

Open any item below for the detail of what we collect for that purpose, why, the legal basis we rely on, and how long we keep it.

Account details (name, email, password)

What: your name, email address and a securely hashed password.

Why: to create your account, sign you in, and contact you about your account and applications.

Legal basis: performance of the arrangement to give you an account and run the conference you applied to.

How long: for as long as you hold an account; deleted when your account is deleted.

Age and residence (date of birth, country, citizenships)

What: date of birth, country of residence and, where you provide them, your citizenships and whether you would need a Schengen visa.

Why: to apply the correct age-of-consent rules for your country and to support conference logistics.

Legal basis: legal obligation (age-of-consent rules) and the arrangement to run the conference.

How long: for as long as you hold an account; deleted with your account.

Parent or guardian details (only for minors)

What: the name, relationship, email and phone of your parent or guardian.

Why: only collected when your age requires it, to obtain and record their authorisation and for urgent contact. Stored encrypted.

Legal basis: legal obligation under GDPR Article 8 (a child needs a guardian's authorisation).

How long: until you reach the digital age of consent (then removed automatically), or your account is deleted, whichever comes first.

Application content and MUN experience

What: the role and committee you apply for, your answers, country preferences, any committee or country later assigned, and the past conferences you list.

Why: to review applications and allocate places. Past-conference names are only checked online if you tick the optional verification box (see section 7a).

Legal basis: the arrangement to consider and run your participation; for a minor, backed by guardian authorisation.

How long: with the application; deleted when the application or your account is deleted.

Security log (full IP and event records)

What: full IP address, the email or account acted on, event time, type and result, and the country or approximate city derived from the IP.

Why: account security, preventing and investigating abuse, investigating incidents and defending legal claims. Never for profiling or marketing.

Legal basis: legitimate interests, backed by a written legitimate-interests assessment (available on request).

How long: the security/accountability log up to 270 days; the sign-in location log 180 days. Then deleted automatically.

Read the full detail on a dedicated page ›

Optional profile choices (photo, social links, visibility)

What: a profile photo, social links, and whether your profile is visible to other members.

Why: entirely optional and only if you choose them. Each is a separate, pre-unchecked choice; leaving them off does not affect your application.

Legal basis: your consent (and a guardian's, for a minor), which you can withdraw at any time.

How long: until you turn the choice off or your account is deleted. You can make your profile private at any time.

3. The legal bases we rely on

Under the GDPR we process your data on these bases: your consent (and, for a child below the digital age of consent, a parent or guardian's consent) to take part and to process the data an application needs; the performance of the arrangement between you and us to run the conference you signed up for; our legitimate interests in operating the portal securely, preventing fraud and abuse, keeping an accountability record, and defending our rights; and, where it applies, our need to comply with a legal obligation. Where we rely on consent you can withdraw it at any time, which does not affect processing already carried out.

4. Who can see your information

Most of your data is visible only to you and to a small number of authorised NDI organisers, and only for as long as their role requires. If you are accepted, certain details are shown to others to run the conference: your name and assigned country appear in your committee's country matrix to other accepted members of that committee, and your name, role and committee may appear on the conference participants list. A member profile page (photo, biography, social links and awards) is never open to the public internet: it can be seen only by signed in members whose own email address has been verified, and only if you have chosen to make your profile visible to members. You can make your profile private at any time. A member below the digital age of consent always has a private profile that other members cannot see, whatever the setting. Organisers' names and photos are shown on the conferences they run.

5. Minors and parental consent

The minimum age to take part is 14. Whether we need a parent or guardian's consent depends on the digital age of consent in your country of residence (generally between 13 and 16 across the EU and EEA). If you are below that age, we ask for a parent or guardian's details and obtain their consent before processing your application. Once you reach the age at which you can consent for yourself, guardian details are no longer required and are removed. We treat minors' data with particular care and do not publish a minor's image or full name without explicit guardian consent.

When a parent or guardian first gives consent, that consent covers both our processing of the young person's personal data on this platform and their participation in the specific conference applied for. If the same young person later applies to a further conference while still below the age of consent, we ask the parent or guardian again, but that later request is limited to consent for the new conference only, because consent for the platform has already been given. Each consent is specific, is recorded, and can be withdrawn at any time.

For a plain-language overview of the measures we take to protect young members' data, see our Protecting young members' data page.

6. Live sessions

Conference debate takes place in NDI's own online meeting rooms. Sessions are not recorded. We do not make video or audio recordings of live sessions, and participants are asked not to make their own. If this ever changes for a future event, we will update this policy and tell you, and where you are a minor tell your parent or guardian, in advance, and we will not record without the appropriate consent.

7. Where we process data, and service providers

We rely on a small number of providers to operate: our web host (Namecheap, Inc.), the optional conference-verification providers, and country and flag reference data loaded from a public source. Our web host necessarily has technical access to the data stored on its servers, as any host does, and processes it on our instructions under its terms. We share data with providers only as needed to deliver the service, never for marketing, and where a provider necessarily processes data outside the EEA we rely on an appropriate GDPR transfer safeguard, such as an adequacy decision or the European Commission's Standard Contractual Clauses. We keep a written inventory of every provider (legal entity, role, data-processing agreement, transfer safeguard and deletion terms), available on request from info@nordicdiplomacy.org.

Read the full list of providers and the data each receives ›

7a. Conference verification (AI assisted)

When you apply, you can optionally allow us to verify the past conferences you listed. It is entirely voluntary: if you leave the box unticked, nothing is sent and no check runs. If you allow it, only the conference name, its date and any public link are sent (never your name or any account detail) to Tavily Inc. (USA) and Google LLC's Gemini API (USA). The result is advisory only, and every decision about your application is made by a person, never automatically.

Read the full detail on conference verification ›

8. Organisers, volunteers and third party platforms

Because we are a volunteer run initiative, it matters who may touch your data and on what terms. Access to member data is granted by NDI to specific people for a specific role, is limited to what that role needs, and is withdrawn when the role ends. Anyone acting for NDI must handle personal data only on NDI's instructions and only while authorised. When a person's role ends, they must stop using the data, return or securely delete any copies, and may not retain, export, transfer or reuse it for their own purposes. Attempting to remove NDI's own access to its data, or taking member data outside NDI's control, is treated as a personal data breach and, where appropriate, reported and acted on.

Where a conference is listed or run through an external platform (for example a third party Model UN registration site), that platform operates under its own terms and privacy policy and is responsible for the security of the data it holds. We are not responsible for the practices of such platforms. If we stop using an external platform, we ask it to return and then delete the personal data of our participants, and we handle any dispute over that data as a data protection matter.

If your data is collected through an outside registration website, that website keeps its own copy under its own rules, and it is responsible for that copy. The official record always stays with NDI, on NDI's own systems. We do not hand control of that record, or of our own materials, to any outside service or to any person who helped run an event. If a service or a person claims to own or keep our records or materials only because those passed through an outside tool, we do not accept that claim, and we treat it as a data protection matter.

9. How long we keep data

We keep personal data only as long as needed for the purpose it was collected, then delete or anonymise it, and you can ask us to delete your account and associated data at any time. Key limits: the security and accountability log is kept up to 270 days, the sign-in location records 180 days, and unconfirmed or declined minor accounts are cleaned up automatically.

Read the full data-retention table ›

10. Your rights

Under the GDPR you can access your data, correct it, have it erased, restrict or object to processing, request portability, and withdraw consent at any time. You may also complain to the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu, tietosuoja.fi) or to your local supervisory authority. To exercise any right, contact info@nordicdiplomacy.org; we respond within the time the GDPR allows, normally within one month. We do not make decisions with legal or similarly significant effects about you, such as whether to accept an application, by automated means alone: a person is always involved.

11. Data security and breaches

We use reasonable technical and organisational measures to protect personal data, including hashed passwords, restricted and role based access, encrypted connections, activity logging and regular backups held outside the public web folder. No online service can be guaranteed perfectly secure, so we cannot promise absolute security, but we work to limit who can access data and for how long. If a personal data breach occurs, including one caused by misuse of authorised access, we follow our incident plan and, where the breach is likely to risk people's rights and freedoms, we notify the supervisory authority within 72 hours of becoming aware and inform affected people (and, for minors, their guardians) without undue delay.

12. Changes

We may update this policy as the service evolves. The current version is always available on this page, and significant changes will be highlighted where practical.

Nordic Diplomacy Initiative. Guided by the North.