Privacy Policy
For the Nordic Diplomacy Initiative (nordicdiplomacy.org) and the conferences it runs, including NOMUN (Nordic Online Model United Nations). Last updated July 2026. This document explains in plain language what we collect and why. It is provided for transparency and is not legal advice.
1. Who we are and who controls your data
The Nordic Diplomacy Initiative ("NDI", "we", "us") is a standing, student led, non commercial initiative that designs, runs and archives Model UN activities. NOMUN is one of the conferences NDI runs; it is an activity of NDI, not a separate organisation. NDI is not yet a registered legal entity and operates on a non commercial basis with no revenue. Until a registered association is established, Ali Serbest, who currently leads NDI, acts as the data controller for the personal data processed through this portal and is responsible for the decisions described in this policy. The data controller can be contacted for all privacy, data and safeguarding matters at info@nordicdiplomacy.org. We aim to follow the EU General Data Protection Regulation (GDPR) and applicable data protection law.
No individual organiser, volunteer, chair or contributor is a separate controller of this data. People who help run NDI act only on NDI's documented instructions and only for as long as NDI authorises. They gain no personal ownership of, and no continuing right to, the accounts, records or personal data held here (see section 8).
2. What data we collect and why
- Account details: your name, email address and a securely hashed password, to create and protect your account.
- Age and residence: date of birth, country of residence and, where you provide them, your citizenships and whether you would need a Schengen visa. We use these to apply the correct age of consent rules and to support conference logistics.
- Approximate location at sign up: we check the country your connection appears to come from against your stated country of residence, as a basic anti fraud measure. This check is automated, but it does not by itself decide anything about you; a person reviews every application. For this residence check we keep only a short advisory flag (for example "location looks like another country"), not your address, and we do not use it to build a marketing or advertising profile.
- Security log: to keep accounts and the portal safe we keep a restricted security and accountability log. Depending on the event it may contain your full IP address, the email address or account acted on, the time of the event, the type of event and its result, and the country or approximate city derived from the IP address. We use it only for account security, preventing and investigating abuse, investigating incidents and defending legal claims. It is never used to build a profile of you or for marketing, access is restricted to authorised administrators, and it is not shared with anyone else except where the law requires. The exact rules that flag a request as suspicious are not published, but the categories of data and the purpose are set out here. See section 9 for how long these records are kept and section 3 for the legal basis (legitimate interests, backed by a written assessment).
- Parent or guardian details (name, relationship, email, phone): collected only when your age requires consent, to obtain and record that consent and for urgent contact.
- Application content: the role and committee you apply for, your answers to application questions, your country preferences, and any committee or country later assigned to you, to review applications and allocate places.
- MUN experience: the past Model UN conferences you list in an application (conference name, date, your role there, the format and, if you add one, a public link). We use these to assess your application and, only if you tick the optional verification box, to check online that the conference exists (see "Conference verification" in section 7).
- Profile details you choose to add: photo, short biography, social links and awards. You control these and can make your profile private at any time.
- Communications and records: emails we send you (such as confirmations and decisions) and an administrative log of key account, application and organiser actions, kept for security, accountability and to show who did what.
- Event attendance record: if you are accepted, whether you checked in at the conference, when, and which organiser recorded it. We use this to run the event on the day, to confirm who was present, and to issue participation certificates.
We collect only what we need to run the event, we practise data minimisation, we do not sell personal data, and we do not use it for advertising.
Cookies and local storage. We use only what is strictly necessary to run the portal: a session cookie to keep you signed in, and small entries stored in your browser to remember your cookie and age confirmation so we do not ask again. We do not use advertising, analytics or cross site tracking cookies, so no separate cookie consent for tracking is needed.
2a. Detailed notes on each purpose (sub-policies)
Open any item below for the detail of what we collect for that purpose, why, the legal basis we rely on, and how long we keep it.
Account details (name, email, password)
What: your name, email address and a securely hashed password.
Why: to create your account, sign you in, and contact you about your account and applications.
Legal basis: performance of the arrangement to give you an account and run the conference you applied to.
How long: for as long as you hold an account; deleted when your account is deleted.
Age and residence (date of birth, country, citizenships)
What: date of birth, country of residence and, where you provide them, your citizenships and whether you would need a Schengen visa.
Why: to apply the correct age-of-consent rules for your country and to support conference logistics.
Legal basis: legal obligation (age-of-consent rules) and the arrangement to run the conference.
How long: for as long as you hold an account; deleted with your account.
Parent or guardian details (only for minors)
What: the name, relationship, email and phone of your parent or guardian.
Why: only collected when your age requires it, to obtain and record their authorisation and for urgent contact. Stored encrypted.
Legal basis: legal obligation under GDPR Article 8 (a child needs a guardian's authorisation).
How long: until you reach the digital age of consent (then removed automatically), or your account is deleted, whichever comes first.
Application content and MUN experience
What: the role and committee you apply for, your answers, country preferences, any committee or country later assigned, and the past conferences you list.
Why: to review applications and allocate places. Past-conference names are only checked online if you tick the optional verification box (see section 7a).
Legal basis: the arrangement to consider and run your participation; for a minor, backed by guardian authorisation.
How long: with the application; deleted when the application or your account is deleted.
Security log (full IP and event records)
What: full IP address, the email or account acted on, event time, type and result, and the country or approximate city derived from the IP.
Why: account security, preventing and investigating abuse, investigating incidents and defending legal claims. Never for profiling or marketing.
Legal basis: legitimate interests, backed by a written legitimate-interests assessment (available on request).
How long: the security/accountability log up to 270 days; the sign-in location log 180 days. Then deleted automatically.
Optional profile choices (photo, social links, visibility)
What: a profile photo, social links, and whether your profile is visible to other members.
Why: entirely optional and only if you choose them. Each is a separate, pre-unchecked choice; leaving them off does not affect your application.
Legal basis: your consent (and a guardian's, for a minor), which you can withdraw at any time.
How long: until you turn the choice off or your account is deleted. You can make your profile private at any time.
3. The legal bases we rely on
Under the GDPR we process your data on these bases: your consent (and, for a child below the digital age of consent, a parent or guardian's consent) to take part and to process the data an application needs; the performance of the arrangement between you and us to run the conference you signed up for; our legitimate interests in operating the portal securely, preventing fraud and abuse, keeping an accountability record, and defending our rights; and, where it applies, our need to comply with a legal obligation. Where we rely on consent you can withdraw it at any time, which does not affect processing already carried out.
4. Who can see your information
Most of your data is visible only to you and to a small number of authorised NDI organisers, and only for as long as their role requires. If you are accepted, certain details are shown to others to run the conference: your name and assigned country appear in your committee's country matrix to other accepted members of that committee, and your name, role and committee may appear on the conference participants list. A member profile page (photo, biography, social links and awards) is never open to the public internet: it can be seen only by signed in members whose own email address has been verified, and only if you have chosen to make your profile visible to members. You can make your profile private at any time. A member below the digital age of consent always has a private profile that other members cannot see, whatever the setting. Organisers' names and photos are shown on the conferences they run.
5. Minors and parental consent
The minimum age to take part is 14. Whether we need a parent or guardian's consent depends on the digital age of consent in your country of residence (generally between 13 and 16 across the EU and EEA). If you are below that age, we ask for a parent or guardian's details and obtain their consent before processing your application. Once you reach the age at which you can consent for yourself, guardian details are no longer required and are removed. We treat minors' data with particular care and do not publish a minor's image or full name without explicit guardian consent.
When a parent or guardian first gives consent, that consent covers both our processing of the young person's personal data on this platform and their participation in the specific conference applied for. If the same young person later applies to a further conference while still below the age of consent, we ask the parent or guardian again, but that later request is limited to consent for the new conference only, because consent for the platform has already been given. Each consent is specific, is recorded, and can be withdrawn at any time.
For a plain-language overview of the measures we take to protect young members' data, see our Protecting young members' data page.
6. Live sessions
Conference debate takes place in NDI's own online meeting rooms. Sessions are not recorded. We do not make video or audio recordings of live sessions, and participants are asked not to make their own. If this ever changes for a future event, we will update this policy and tell you, and where you are a minor tell your parent or guardian, in advance, and we will not record without the appropriate consent.
7. Where we process data, and service providers
We rely on a small number of providers to operate: our web host (Namecheap, Inc.), the optional conference-verification providers, and country and flag reference data loaded from a public source. Our web host necessarily has technical access to the data stored on its servers, as any host does, and processes it on our instructions under its terms. We share data with providers only as needed to deliver the service, never for marketing, and where a provider necessarily processes data outside the EEA we rely on an appropriate GDPR transfer safeguard, such as an adequacy decision or the European Commission's Standard Contractual Clauses. We keep a written inventory of every provider (legal entity, role, data-processing agreement, transfer safeguard and deletion terms), available on request from info@nordicdiplomacy.org.
Read the full list of providers and the data each receives ›
7a. Conference verification (AI assisted)
When you apply, you can optionally allow us to verify the past conferences you listed. It is entirely voluntary: if you leave the box unticked, nothing is sent and no check runs. If you allow it, only the conference name, its date and any public link are sent (never your name or any account detail) to Tavily Inc. (USA) and Google LLC's Gemini API (USA). The result is advisory only, and every decision about your application is made by a person, never automatically.
Read the full detail on conference verification ›
8. Organisers, volunteers and third party platforms
Because we are a volunteer run initiative, it matters who may touch your data and on what terms. Access to member data is granted by NDI to specific people for a specific role, is limited to what that role needs, and is withdrawn when the role ends. Anyone acting for NDI must handle personal data only on NDI's instructions and only while authorised. When a person's role ends, they must stop using the data, return or securely delete any copies, and may not retain, export, transfer or reuse it for their own purposes. Attempting to remove NDI's own access to its data, or taking member data outside NDI's control, is treated as a personal data breach and, where appropriate, reported and acted on.
Where a conference is listed or run through an external platform (for example a third party Model UN registration site), that platform operates under its own terms and privacy policy and is responsible for the security of the data it holds. We are not responsible for the practices of such platforms. If we stop using an external platform, we ask it to return and then delete the personal data of our participants, and we handle any dispute over that data as a data protection matter.
If your data is collected through an outside registration website, that website keeps its own copy under its own rules, and it is responsible for that copy. The official record always stays with NDI, on NDI's own systems. We do not hand control of that record, or of our own materials, to any outside service or to any person who helped run an event. If a service or a person claims to own or keep our records or materials only because those passed through an outside tool, we do not accept that claim, and we treat it as a data protection matter.
9. How long we keep data
We keep personal data only as long as needed for the purpose it was collected, then delete or anonymise it, and you can ask us to delete your account and associated data at any time. Key limits: the security and accountability log is kept up to 270 days, the sign-in location records 180 days, and unconfirmed or declined minor accounts are cleaned up automatically.
Read the full data-retention table ›
10. Your rights
Under the GDPR you can access your data, correct it, have it erased, restrict or object to processing, request portability, and withdraw consent at any time. You may also complain to the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu, tietosuoja.fi) or to your local supervisory authority. To exercise any right, contact info@nordicdiplomacy.org; we respond within the time the GDPR allows, normally within one month. We do not make decisions with legal or similarly significant effects about you, such as whether to accept an application, by automated means alone: a person is always involved.
11. Data security and breaches
We use reasonable technical and organisational measures to protect personal data, including hashed passwords, restricted and role based access, encrypted connections, activity logging and regular backups held outside the public web folder. No online service can be guaranteed perfectly secure, so we cannot promise absolute security, but we work to limit who can access data and for how long. If a personal data breach occurs, including one caused by misuse of authorised access, we follow our incident plan and, where the breach is likely to risk people's rights and freedoms, we notify the supervisory authority within 72 hours of becoming aware and inform affected people (and, for minors, their guardians) without undue delay.
12. Changes
We may update this policy as the service evolves. The current version is always available on this page, and significant changes will be highlighted where practical.
Nordic Diplomacy Initiative. Guided by the North.