The Quiet Responsibility

PRIVACY

Privacy notice

This page is about the Tuesday Letter. The rest of the site needs no login, sets no cookies and carries no tracking – it is static pages, and there is no analytics tool to ask your consent for.

Who is responsible

Misha Tryndiuk, as a private individual. Questions about what is held on you go to hei@tauseansvaret.no, and I am the one who answers.

What is stored, and why

When you subscribe, what is kept is your email address, the language of the page you subscribed from, whether the subscription is confirmed, and the times of subscribing, confirming and – if it happens – leaving. Two random keys are stored alongside them: one for the confirmation link and one for the unsubscribe link, so that neither can be used as the other.

Your IP address is not stored – Cloudflare holds it briefly in its own network logs, but it never reaches the database. The time of the confirmation shows you completed the subscription yourself, and that is enough.

The address is used only to send you the Tuesday Letter. It is not sold, shared, lent out or used for anything else.

Legal basis

Consent, under GDPR article 6(1)(a). You give it by subscribing and confirming in the email that follows – without that confirmation no letter is ever sent.

For how long

If you leave, the row is marked as unsubscribed rather than deleted. GDPR article 7(1) requires me to be able to demonstrate that consent was given, and the row is the only evidence of it – deleting it destroys the record at exactly the point someone might dispute it. Norwegian marketing law §15 is why the consent had to be obtained in the first place. No letter is sent after you leave.

So an unsubscribed row stays until you ask for something else. A subscription you never confirm is the opposite case: no consent was ever given, so there is nothing to evidence – only an address I have no reason to hold. It is deleted automatically after 30 days. If you want it gone sooner, ask at the address above and I will remove it.

If you want everything deleted rather than merely unsubscribed, I will do that. The record of your consent goes with it, and that is your call to make, not mine.

Who else handles the address

All three are processors acting for me. None of them uses the address for anything of their own.

The database is pinned to Cloudflare’s EU jurisdiction, so the rows are stored and mirrored only in Europe – and they are read there too. The sending runs inside a Cloudflare object pinned to that same jurisdiction, and the pinning governs where the object runs, not only where it stores. The list is read where it sits.

Three qualifications belong with that, and they are worth saying plainly. The backup on GitHub in the United States stands ready if the sending fails, and on a morning it steps in it pulls the address and unsubscribe key of every confirmed subscriber over there. Subscribing, confirming and leaving are handled in the data centre nearest you, which may be outside the EEA. And Cloudflare documents no region for the service that delivers the mail itself, so the address may be processed outside the EEA there whatever happened before it. What holds, then, is that the sending happens in the EU – not that the address never leaves the EEA.

Those transfers rest on the EU standard contractual clauses, which both Cloudflare and GitHub are bound by. If you want a copy of the clauses as they apply here, ask at the address above.

Your rights

You have the right to see what is held on you, to have it corrected, to have it handed over, and to have it deleted. Write to hei@tauseansvaret.no and I will answer within a month. You do not have to give a reason.

Leaving needs no email at all: every letter carries an unsubscribe link, and it works in one click.

If you think something is wrong, you can complain to the Norwegian Data Protection Authority. I would rather hear it first, but that is not a condition.