Portal › Privacy Policy

Privacy Policy

For the Nordic Diplomacy Initiative (nordicdiplomacy.org) and the conferences it runs, including NOMUN (Nordic Online Model United Nations). Last updated July 2026. This document explains in plain language what we collect and why. It is provided for transparency and is not legal advice.

1. Who we are and who controls your data

The Nordic Diplomacy Initiative ("NDI", "we", "us") is a standing, student led, non commercial initiative that designs, runs and archives Model UN activities. NOMUN is one of the conferences NDI runs; it is an activity of NDI, not a separate organisation. NDI is the sole data controller for the personal data processed through this portal. We are based in Finland and aim to follow the EU General Data Protection Regulation (GDPR) and applicable Finnish data protection law. All privacy, data and safeguarding questions go to a single address: info@nordicdiplomacy.org.

No individual organiser, volunteer, chair or contributor is a separate controller of this data. People who help run NDI act only on NDI's documented instructions and only for as long as NDI authorises. They gain no personal ownership of, and no continuing right to, the accounts, records or personal data held here (see section 8).

2. What data we collect and why

We collect only what we need to run the event, we practise data minimisation, we do not sell personal data, and we do not use it for advertising.

Cookies and local storage. We use only what is strictly necessary to run the portal: a session cookie to keep you signed in, and small entries stored in your browser to remember your cookie and age confirmation so we do not ask again. We do not use advertising, analytics or cross site tracking cookies, so no separate cookie consent for tracking is needed.

3. The legal bases we rely on

Under the GDPR we process your data on these bases: your consent (and, for a child below the digital age of consent, a parent or guardian's consent) to take part and to process the data an application needs; the performance of the arrangement between you and us to run the conference you signed up for; our legitimate interests in operating the portal securely, preventing fraud and abuse, keeping an accountability record, and defending our rights; and, where it applies, our need to comply with a legal obligation. Where we rely on consent you can withdraw it at any time, which does not affect processing already carried out.

4. Who can see your information

Most of your data is visible only to you and to a small number of authorised NDI organisers, and only for as long as their role requires. If you are accepted, certain details are shown to others to run the conference: your name and assigned country appear in your committee's country matrix to other accepted members of that committee, and your name, role and committee may appear on the conference participants list. If you make your profile public, your photo, biography, social links and awards are visible to other signed in members and on your member page. You can make your profile private to limit this. Organisers' names and photos are shown on the conferences they run.

5. Minors and parental consent

The minimum age to take part is 14. Whether we need a parent or guardian's consent depends on the digital age of consent in your country of residence (generally between 13 and 16 across the EU and EEA). If you are below that age, we ask for a parent or guardian's details and obtain their consent before processing your application. Once you reach the age at which you can consent for yourself, guardian details are no longer required and are removed. We treat minors' data with particular care and do not publish a minor's image, full name or voice without explicit guardian consent.

When a parent or guardian first gives consent, that consent covers both our processing of the young person's personal data on this platform and their participation in the specific conference applied for. If the same young person later applies to a further conference while still below the age of consent, we ask the parent or guardian again, but that later request is limited to consent for the new conference only, because consent for the platform has already been given. Each consent is specific, is recorded, and can be withdrawn at any time.

For a plain-language overview of the measures we take to protect young members' data, see our Protecting young members' data page.

6. Live sessions and recordings

Conference debate takes place in NDI's own online meeting rooms. Sessions are recorded. Each recording is stored securely in NDI's systems for a strict maximum of 96 hours. If, within that 96-hour window, no legal matter arises and no authorised person present at the conference reports an incident (such as a breach of our Code of Conduct or unlawful conduct), the recording is deleted in full and automatically, including from backups. Within that window recordings are not browsed, published, or used for any general purpose. Access is limited to the narrow case of investigating a reported incident or meeting a legal obligation, and every access is logged. We tell you in advance, and where you are a minor we tell your parent or guardian, that sessions are recorded, why, how long we keep them, and who may access them. Our legal basis is your consent, and for a minor the consent of a parent or guardian; where the law allows we also rely on our legitimate interest in the safety and integrity of the event. Recording serves only participant safety, Code of Conduct enforcement, and legal compliance, never monitoring or profiling. You may ask about or object to this processing at any time.

7. Where we process data, and service providers

We rely on a small number of providers to operate: our web host (which stores the site and its database), our email provider (which sends service emails), and country and flag reference data loaded from a public source. We choose providers that process data within the EU or EEA where practicable. Where a provider necessarily processes data outside the EEA, we rely on an appropriate transfer safeguard recognised under the GDPR, such as an adequacy decision or the European Commission's Standard Contractual Clauses. We share data with providers only as needed to deliver the service, never for marketing, and we may disclose data where required by law or to protect someone's safety.

7a. Conference verification (AI assisted)

When you apply, you can optionally allow us to verify the past conferences you listed. This is entirely voluntary: if you leave the box unticked, your application is processed exactly the same way and no check is run.

8. Organisers, volunteers and third party platforms

Because we are a volunteer run initiative, it matters who may touch your data and on what terms. Access to member data is granted by NDI to specific people for a specific role, is limited to what that role needs, and is withdrawn when the role ends. Anyone acting for NDI must handle personal data only on NDI's instructions and only while authorised. When a person's role ends, they must stop using the data, return or securely delete any copies, and may not retain, export, transfer or reuse it for their own purposes. Attempting to remove NDI's own access to its data, or taking member data outside NDI's control, is treated as a personal data breach and, where appropriate, reported and acted on.

Where a conference is listed or run through an external platform (for example a third party Model UN registration site), that platform operates under its own terms and privacy policy and is responsible for the security of the data it holds. We are not responsible for the practices of such platforms. If we stop using an external platform, we ask it to return and then delete the personal data of our participants, and we handle any dispute over that data as a data protection matter.

If your data is collected through an outside registration website, that website keeps its own copy under its own rules, and it is responsible for that copy. The official record always stays with NDI, on NDI's own systems. We do not hand control of that record, or of our own materials, to any outside service or to any person who helped run an event. If a service or a person claims to own or keep our records or materials only because those passed through an outside tool, we do not accept that claim, and we treat it as a data protection matter.

9. How long we keep data

We keep personal data only as long as needed for the purpose it was collected, then delete or anonymise it. If a guardian declines consent, the related application data is removed. Security and accountability log entries are kept for a limited period so that we can investigate incidents, then cleared. You can ask us to delete your account and associated data at any time.

Two categories follow your membership rather than a fixed clock. Event attendance records (check in) are stored with the application they belong to and are deleted when that application or your account is deleted. Internal administrative notes are kept for as long as you are a member and are deleted together with your account. Deleting your account therefore removes both.

10. Your rights

Under the GDPR you can access your data, correct it, have it erased, restrict or object to processing, request portability, and withdraw consent at any time. You may also complain to the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu, tietosuoja.fi) or to your local supervisory authority. To exercise any right, contact info@nordicdiplomacy.org; we respond within the time the GDPR allows, normally within one month. We do not make decisions with legal or similarly significant effects about you, such as whether to accept an application, by automated means alone: a person is always involved.

11. Data security and breaches

We use reasonable technical and organisational measures to protect personal data, including hashed passwords, restricted and role based access, encrypted connections, activity logging and regular backups held outside the public web folder. No online service can be guaranteed perfectly secure, so we cannot promise absolute security, but we work to limit who can access data and for how long. If a personal data breach occurs, including one caused by misuse of authorised access, we follow our incident plan and, where the breach is likely to risk people's rights and freedoms, we notify the supervisory authority within 72 hours of becoming aware and inform affected people (and, for minors, their guardians) without undue delay.

12. Changes

We may update this policy as the service evolves. The current version is always available on this page, and significant changes will be highlighted where practical.

Nordic Diplomacy Initiative. Guided by the North.