Privacy policy
Version 2026-10 · Last updated 14 September 2026
Kordinert is a tool for the choirs and singers who use it. This policy explains what personal data is processed, why and on what legal basis, how long it is kept, who it is shared with, and the rights you have. It is written to be read, not to cover us.
Who we are
Kordinert is provided by Birget AS, org. no. 933 189 775, Oslo, Norway. You can reach us at support@kordinert.no.
We have no data protection officer. Privacy enquiries go to the same address and are answered by us.
Who is responsible for what
Responsibility is split in two, and the split decides who you should contact.
Your choir is the data controller for what it registers about its members: the member list and membership history, attendance and responses to activities, leaves of absence, notes, dues, posts and messages. Birget AS is the processor for those and handles them only on the choir’s instruction, under the data processing agreement the choir accepted when it was created.
Birget AS is itself the controller for your platform account (sign-in and profile), for billing the choir’s subscription, and for technical error logging.
If your request concerns data the choir is responsible for, we may forward it to the choir’s owner and tell you that we have. We never delete a choir’s data on our own initiative.
What data is processed
Depending on how your choir uses Kordinert, we process:
- Account data: name, email address, sign-in information and your chosen language.
- Profile data you or the choir add: phone number, birth date, address, pronoun, avatar and optionally an emergency contact.
- Membership history: voice group, status, admission, probation, leaves of absence, committees and roles in the choir.
- Activity: responses to rehearsals and concerts, and recorded attendance.
- Content: posts, comments, messages and files you share within the choir.
- Dues: charges, invoices and payments recorded by the choir’s board.
- Technical: push-notification tokens for the mobile app, your calendar feed address, strictly necessary cookies and operational logs.
What we use the data for, and on what basis
A choir’s member data is processed on the choir’s legitimate interest in running itself — keeping the member list, planning rehearsals and productions, recording attendance, sending messages and managing dues (GDPR Article 6(1)(f)).
Your contact details are visible to other members only if you have consented to it (Article 6(1)(a)). You can withdraw that consent at any time, and withdrawal does not affect the lawfulness of the processing before it.
Your platform account is processed to perform our agreement with you (Article 6(1)(b)). Billing and accounting are processed to meet a legal obligation (Article 6(1)(c), the Norwegian Bookkeeping Act). Error and security logs rest on our legitimate interest in a stable, safe service.
We do not use the data for marketing, we never sell it, and no decision about you is made automatically or by profiling.
Special categories of data
Membership of a church choir can reveal religious belief. Where it does, the processing rests on Article 9(2)(d), which allows a not-for-profit body with a religious aim to process data about its own members, and the data is not disclosed outside the choir without consent.
If you write health information into a leave request — illness, pregnancy, a family situation — it is processed on your explicit consent (Article 9(2)(a)). The reason text is deleted automatically six months after the leave ends, and it never travels in a notification.
Age
You must be at least 13 to have your own Kordinert account. If you are under 18, the choir records a guardian as your emergency contact. Children under 13 get no account: the choir registers them with a guardian as the contact person.
How long we keep data
The general rule is that data is kept for as long as you have an account and your choir uses the service. On top of that we delete automatically:
- An unused account: we send a warning email after 24 months without a sign-in and delete the account three months later. Signing in during those three months stops the deletion on its own.
- Your emergency contact: removed when your last active membership in any choir ends.
- Notes the choir’s leadership wrote about you: deleted 12 months after the membership ends.
- The reason text in a leave of absence: deleted six months after the leave ends.
- Read receipts on posts: deleted after 90 days.
- Notifications: archived 90 days after being read, and deleted 90 days after archiving. The send queue and digests are deleted 30 days after sending.
- Import files containing member lists: deleted 30 days after the import completes or was last touched.
- Push tokens from devices unseen for 90 days: deleted.
- Rejected and withdrawn applications to join a choir: deleted six months after the decision.
- Accounting material — invoices, payments and dues charges: kept for five years after the end of the financial year, as section 13 of the Norwegian Bookkeeping Act requires.
- Operational logs: 30 days. Audit trails of who did what: five years, with the actor pseudonymised if the account is deleted.
The choir’s own records
Messages have no automatic deletion deadline in this version, and a choir’s history — who sang, when, in which voice group, with what attendance — is the choir’s own archive and is kept for as long as the choir exists. If you delete your account, that history remains under the label “Former member”, without your name or contact details. That is why we pseudonymise rather than delete: the records are the choir’s as much as they are yours.
Deleting your account
You delete your account yourself under Min profil. We send an email confirmation, and the clock starts only once you open it: the account is deleted 14 days later. If you change your mind, cancel the deletion under Privacy in Min profil at any point within those 14 days. If you are the only owner of a choir you have to hand ownership over first — otherwise the choir is left with no-one who can administer it.
When the deletion runs, your sign-in is removed, your name and contact details are overwritten, your avatar is deleted, notes about you are deleted and leave reasons are emptied. You leave every choir you are a member of, your roles end, and your name is also removed from notifications sitting with other people. Posts and attachments you made stay without your name, because they are part of the choir’s and the other participants’ own conversation. If you want a specific post gone, you can delete it yourself at any time.
Some things remain: accounting material for five years because the Bookkeeping Act requires it, audit trails with you pseudonymised, and the choir’s pseudonymised history. This is stated in the answer you get.
Your rights
You have the right to access the data we hold about you, to have it corrected, to have it deleted, to have the processing restricted while a dispute is resolved, to object to processing based on legitimate interest, and to receive the data in a machine-readable format.
You can download a complete copy of your data yourself under Min profil — it spans every choir you belong to and includes your platform data. You edit your own profile, and the choir’s leadership can correct member data and history.
If you ask for restriction, the choir’s leadership sets a marker that hides you from the member overviews and stops notifications to and about you until the matter is settled.
Requests go to support@kordinert.no and are answered within one month. For a complex request we may extend by up to two further months, and we tell you within the first month if we do. You may complain to Datatilsynet (the Norwegian Data Protection Authority) at any time (https://www.datatilsynet.no/).
Where the data is stored and how it is secured
The database, the files and the sign-in run on our own infrastructure within the EU/EEA. Each choir is isolated with row-level security in the database: a query from one choir cannot reach another choir’s data, whatever the client asks for.
All traffic is encrypted. Internal access is limited to those who need it, and administrative actions are logged. We back up daily, keep the backups encrypted for 30 days, and hold one copy off the production machine.
Backups are not rewritten. When we delete something it leaves the live database immediately and falls out of the backups as they rotate within 30 days. If we ever have to restore from a backup, the deletions are re-applied afterwards.
Your avatar is one exception we want to be plain about: it sits at a public address. The address cannot be guessed and the images cannot be listed, but anyone holding the link can open the picture without signing in. If you would rather not have that, do not upload an avatar, or remove the one you uploaded.
Who we share with
We use a small number of vendors for well-defined tasks. All of them have a data processing agreement with us, and transfers outside the EEA rest on the EU Standard Contractual Clauses.
- Stripe (Ireland/USA) — card payment of the choir’s subscription. Stripe never sees member dues.
- Sentry (EU region, Frankfurt) — error logging. Personal data is scrubbed before an event is sent, IP addresses are not stored, session replay is off, and events are deleted after 90 days. The vendor is US-based, so the agreement rests on the EU Standard Contractual Clauses.
- Resend (USA) — outbound email: invitations, digests, dues invoices.
- Expo (USA) — delivery of push notifications to the mobile app.
- Anthropic (USA) — AI-assisted import of production plans and Kordinert’s MCP connector. Both are used only when the choir switches them on, and the traffic runs with no retention and no training on the content.
Services you connect yourself
If you subscribe to your calendar in Google Calendar, Apple Calendar or another app, that app fetches the activities and stores them in your own account there. That is outside our control, and you govern it by removing the subscription or rotating your calendar address under Min profil.
If you connect Kordinert to Claude, the answers to your queries also sit in your own Anthropic account. You govern them there.
If you download the app, Apple or Google holds the customer relationship for the download. We receive no personal data from them beyond what you enter in the app yourself.
Cookies
Kordinert sets only cookies that are strictly necessary to deliver the service you asked for: sign-in, security and language choice. Cookies of that kind need no consent under the Norwegian Electronic Communications Act, which is why the site has no consent banner.
We use no marketing or tracking cookies, no third-party analytics and no tracking pixels. The full list is in the cookie statement.
Changes to this policy
For material changes we give notice in the service and update the version number and date at the top. If we change something that affects what you agreed to, we ask you to accept again.