Skip to content
KordinertSign in
Privacy

Privacy policy

Version 2026-10 · Last updated 29 September 2026

Kordinert is a tool for the choirs and singers who use it. This policy explains what personal data is processed, why and on what legal basis, how long it is kept, who it is shared with, and the rights you have. It is written to be read, not to cover us.

Who we are

Kordinert is provided by Birget AS, org. no. 933 189 775, Voksenhagen 17, 0770 Oslo, Norway. You can reach us at support@kordinert.no.

We have no data protection officer. Privacy enquiries go to the same address and are answered by us.

Who is responsible for what

Responsibility is split in two, and the split decides who you should contact.

Your choir is the data controller for what it registers about its members: the member list and membership history, attendance and responses to activities, leaves of absence, notes, dues, posts and messages. Birget AS is the processor for those and handles them only on the choir’s instruction, under the data processing agreement the choir accepted when it was created.

Birget AS is itself the controller for your platform account (sign-in and profile), for billing the choir’s subscription, and for technical error logging.

If your request concerns data the choir is responsible for, we may forward it to the choir’s owner and tell you that we have. We never delete a choir’s data on our own initiative.

What data is processed

Depending on how your choir uses Kordinert, we process:

  • Account data: name, email address, sign-in information and your chosen language.
  • Profile data you or the choir add: phone number, birth date, address, pronoun, avatar and optionally an emergency contact.
  • Membership history: voice group, status, admission, probation, leaves of absence, committees and roles in the choir.
  • Activity: responses to rehearsals and concerts, and recorded attendance.
  • Content: posts, comments, messages and files you share within the choir.
  • Dues: charges, invoices and payments recorded by the choir’s board.
  • Technical: push-notification tokens for the mobile app, your calendar feed address, strictly necessary cookies and operational logs.

What we use the data for, and on what basis

A choir’s member data is processed on the choir’s legitimate interest in running itself — keeping the member list, planning rehearsals and productions, recording attendance, sending messages and managing dues (GDPR Article 6(1)(f)).

Your contact details are visible to other members only if you have consented to it (Article 6(1)(a)). You can withdraw that consent at any time, and withdrawal does not affect the lawfulness of the processing before it.

Your platform account is processed to perform our agreement with you (Article 6(1)(b)). Billing and accounting are processed to meet a legal obligation (Article 6(1)(c), the Norwegian Bookkeeping Act). Error and security logs rest on our legitimate interest in a stable, safe service.

We do not use the data for marketing, we never sell it, and no decision about you is made automatically or by profiling.

Special categories of data

Membership of a church choir can reveal religious belief. Where it does, the processing rests on Article 9(2)(d), which allows a not-for-profit body with a religious aim to process data about its own members, and the data is not disclosed outside the choir without consent.

If you write health information into a leave request — illness, pregnancy, a family situation — it is processed on your explicit consent (Article 9(2)(a)). The reason text is deleted automatically six months after the leave ends, and it never travels in a notification.

Age

You must be at least 13 to have your own Kordinert account. If you are under 18, the choir records a guardian as your emergency contact. Children under 13 get no account: the choir registers them with a guardian as the contact person.

How long we keep data

The general rule is that data is kept for as long as you have an account and your choir uses the service. On top of that we delete automatically:

  • An unused account: we send a warning email after 24 months without a sign-in and delete the account three months later. Signing in during those three months stops the deletion on its own.
  • Your emergency contact: removed when your last active membership in any choir ends.
  • Notes the choir’s leadership wrote about you: deleted 12 months after the membership ends.
  • The reason text in a leave of absence: deleted six months after the leave ends.
  • Read receipts on posts: deleted after 90 days.
  • Notifications: archived 90 days after being read, and deleted 90 days after archiving. The send queue and digests are deleted 30 days after sending.
  • Import files containing member lists: deleted 30 days after the import completes or was last touched.
  • Push tokens from devices unseen for 90 days: deleted.
  • Rejected and withdrawn applications to join a choir: deleted six months after the decision.
  • Accounting material — invoices, payments and dues charges: kept for five years after the end of the financial year, as section 13 of the Norwegian Bookkeeping Act requires.
  • Requests for a quote you send us from the pricing page: deleted from the support mailbox 12 months after they arrive.
  • Content you report to us from the wall: the email carrying your reason and your address is deleted from the support mailbox 12 months after it arrives. The post or comment itself is not copied into the email — support follows the link and reads it in the app.
  • Operational logs: 30 days. The sign-in log — who signed in when, and from which IP address: 90 days, because it is the log a question about a compromised account is answered from. Audit trails of who did what: five years, with the actor pseudonymised if the account is deleted.

The choir’s own records

Messages have no automatic deletion deadline in this version, and a choir’s history — who sang, when, in which voice group, with what attendance — is the choir’s own archive and is kept for as long as the choir exists. If you delete your account, that history remains under the label “Former member”, without your name or contact details. That is why we pseudonymise rather than delete: the records are the choir’s as much as they are yours.

Deleting your account

You delete your Kordinert account yourself, whether or not you are in a choir. Sign in at kordinert.no/konto and choose «Delete my account» under Privacy and account. In the Kordinert mobile app it is under More → Privacy and account or, if you are not in a choir, behind «Delete account» on the screen the app shows you. If you are in a choir, you also find it under Privacy in My profile on the web. We send an email confirmation, and the clock starts only once you open the link in it: the account is deleted 14 days later. If you change your mind, cancel the deletion in the same place at any point within those 14 days. If you are the only owner of a choir you have to hand ownership over first — otherwise the choir is left with no-one who can administer it.

When the deletion runs, your sign-in is removed, your name and contact details are overwritten, your avatar is deleted, notes about you are deleted and leave reasons are emptied. You leave every choir you are a member of, your roles end, and your name is also removed from notifications sitting with other people. Posts and attachments you made stay without your name, because they are part of the choir’s and the other participants’ own conversation. If you want a specific post gone, you can delete it yourself at any time. A message you had already removed is no longer part of the conversation — its text is deleted outright.

Some things remain: accounting material for five years because the Bookkeeping Act requires it, audit trails with you pseudonymised, and the choir’s pseudonymised history. This is stated in the answer you get.

Your rights

You have the right to access the data we hold about you, to have it corrected, to have it deleted, to have the processing restricted while a dispute is resolved, to object to processing based on legitimate interest, and to receive the data in a machine-readable format.

You can download a complete copy of your data yourself at kordinert.no/konto or under My profile — it spans every choir you belong to and includes your platform data. You edit your own profile, and the choir’s leadership can correct member data and history.

If you ask for restriction, the choir’s leadership sets a marker that hides you from the member overviews and stops notifications to and about you until the matter is settled.

Requests go to support@kordinert.no and are answered within one month. For a complex request we may extend by up to two further months, and we tell you within the first month if we do. You may complain to Datatilsynet (the Norwegian Data Protection Authority) at any time (https://www.datatilsynet.no/).

Where the data is stored and how it is secured

The database, the files and the sign-in are run by Supabase in Stockholm, Sweden. Personal data is stored in the EEA; Supabase is a US company, so our agreement with it rests on the EU Standard Contractual Clauses. Each choir is isolated with row-level security in the database: a query from one choir cannot reach another choir’s data, whatever the client asks for.

All traffic is encrypted. Internal access is limited to those who need it, and administrative actions are logged. Backups are taken daily and kept encrypted for at most 30 days — the backups are in Stockholm as well.

Backups are not rewritten. When we delete something it leaves the live database immediately and falls out of the backups as they rotate within 30 days. If we ever have to restore from a backup, the deletions are re-applied afterwards.

Your avatar is one exception we want to be plain about: it sits at a public address. The address cannot be guessed and the images cannot be listed, but anyone holding the link can open the picture without signing in. If you would rather not have that, do not upload an avatar, or remove the one you uploaded.

Who we share with

We use a small number of vendors for well-defined tasks. All of them have a data processing agreement with us, and transfers outside the EEA rest on the EU Standard Contractual Clauses.

  • Supabase (Stockholm, Sweden; the vendor is US-based) — the database, the files and the sign-in, and the storage of the backups. Supabase runs on the Amazon Web Services (AWS) data centre in Stockholm. Everything is stored in the EEA, and the agreement rests on the EU Standard Contractual Clauses.
  • Gigahost (Norway) — the server that delivers Kordinert in the browser. Gigahost stores no personal data, but requests and responses pass through the server in transit.
  • Fiken — invoicing and accounting for the choir’s subscription. Vipps MobilePay — recurring subscription payments when selected. Billing contact and necessary order information are shared; member dues are not included.
  • Sentry (EU region, Frankfurt) — error logging. Personal data is scrubbed before an event is sent, IP addresses are not stored, session replay is off, and events are deleted after 90 days. The vendor is US-based, so the agreement rests on the EU Standard Contractual Clauses.
  • Resend (USA) — outbound email: invitations, digests, dues invoices.
  • Expo (USA) — delivery of push notifications to the mobile app.
  • Anthropic (USA) — AI-assisted import of production plans. The feature starts off for every choir: text a leader pastes is sent only once the choir itself has switched it on under Settings → AI assistance. Every call is recorded in the choir’s own log, and the traffic runs with no retention and no training on the content.
  • Anthropic (USA) — Kordinert’s MCP connector. The choir does not switch this one on; the individual member does, by connecting their own AI client to Kordinert, and the connection sees only what that member may see. Here too the traffic runs with no retention and no training on the content.

Maps from OpenStreetMap

When a leader picks the place for activities, a small map of it is shown. The map is loaded directly from the OpenStreetMap Foundation in the United Kingdom, so your browser sends its IP address and ordinary browser details there while the map is shown. The OpenStreetMap Foundation is not our processor but responsible in its own right for what it receives, and the United Kingdom is covered by an EU adequacy decision. The map appears only where a leader picks a place for activities (the activity form and the new-season wizard), and only when the place has a map position.

The address search in those same places goes through our server to the Photon search service run by komoot GmbH in Germany, which searches the same OpenStreetMap data. What is sent is the search text as typed (it may be an address), the choir’s country and the language the page is shown in — nothing that identifies you.

Services you connect yourself

If you subscribe to your calendar in Google Calendar, Apple Calendar or another app, that app fetches the activities and stores them in your own account there. That is outside our control, and you govern it by removing the subscription or rotating your calendar address under My profile.

If you connect Kordinert to Claude, the answers to your queries also sit in your own Anthropic account. You govern them there.

If you download the app, Apple or Google holds the customer relationship for the download. We receive no personal data from them beyond what you enter in the app yourself.

Cookies

Kordinert sets only cookies that are strictly necessary to deliver the service you asked for: sign-in, security and language choice. Cookies of that kind need no consent under the Norwegian Electronic Communications Act, which is why the site has no consent banner.

We use no marketing or tracking cookies, no third-party analytics and no tracking pixels. The full list is in the cookie statement.

Changes to this policy

For material changes we give notice in the service and update the version number and date at the top. If we change something that affects what you agreed to, we ask you to accept again.