Privacy policy

Privacy policy

Last updated: 16.september 2026

Overview

We respect your privacy and are committed to protecting the personal information you share with us. This Privacy Policy explains what information we collect, how we use it, and the choices you have regarding your data.


About me

IThis website is run by Tove Petterson, organisasjonsnummer 917436266, Valhallgata 5, 5531 Haugesund, Norway. I am the data controller for any personal information collected through this site. If you have a question about your data, or want it corrected or deleted, write to me at tovepetterson@me.com and I will handle it myself.


Cookies and similar tracking technologies

TO DO: Do not keep that as it stands. It describes a site that tracks visitors and personalises their experience. Yours currently does neither, as far as either of us knows, and a privacy policy that claims more data collection than you actually do is the wrong kind of wrong. It also fails the one thing this section legally has to do, which is tell people what is actually set.

Find out first. Open your published site in a private browsing window, then check what cookies are on it. In Chrome, click the icon left of the address bar, then Cookies and site data. You will most likely see a small number of systeme.io cookies for the session and the form handling, and nothing else. That is the answer you write down.

If that is all you find, write this:

This site uses a small number of cookies set by systeme.io, the platform the site is built on. They keep the site working and remember whether you have filled in a form. I do not use advertising cookies, I do not run tracking pixels, and I do not build profiles of visitors.

You can block or delete cookies in your browser settings. Forms on the site may stop working properly if you do.

Short, true, and it is worth more to a suspicious reader than any policy language, because almost nobody else can say it.

If you find Google Analytics, a Meta pixel, or anything from a third party, the section has to name each one, say what it does, and you need a cookie banner that asks for consent before those load. Analytics and advertising cookies are not strictly necessary, so under EU rules they require opt-in consent, not a notice.

The line to delete either way is "personalize your experience." It is meaningless, and in a privacy policy meaningless claims about personalisation invite exactly the question you do not want.

Tell me what you find in the cookie list and I will write the section to match.


How do I use your personal information?

How I use your personal information

I use what you give me to:

  • Reply to you when you write to me through the contact form.

  • Send you word when a workshop opens, if you have asked to be on the list.

  • Organise a workshop you have signed up for, which means knowing who is coming, what dive qualifications you hold, and anything you have told me about food.


How I protect your information

How I protect your information

Your details sit in systeme.io, the platform this site runs on, which handles the hosting and the security. The site runs over an encrypted connection, and my account is protected with a strong password and two-factor authentication.

I am the only person with access. Nothing is stored on paper, and I do not keep a copy on my own computer beyond what I need to run a workshop.

No system is completely secure. If anything ever happened that put your information at risk, I would tell you and report it as required.

Three notes.

Two-factor authentication. Only write that line if it is switched on. If it is not, turn it on in systeme.io before you publish the page. It takes two minutes and it is the single biggest thing protecting your list.

"I am the only person with access." This is the strongest sentence in the section and no large company can write it. It answers the real question a reader has, which is how many strangers can see their name.

The breach line. Under GDPR you are required to notify Datatilsynet within 72 hours of becoming aware of a breach that risks people's rights, and to tell affected people if the risk is high. Saying so plainly costs a sentence and shows you know the obligation exists.

One thing to check before you publish: whether you export your list to a spreadsheet, keep participant names in Notion, or have workshop signups sitting in your email. If so, the sentence about not keeping copies needs adjusting, because it has to be true.


Your privacy rights

You have the right to:

  • See the personal information I hold about you.

  • Have it corrected if it is wrong.

  • Have it deleted, unless I am required to keep it for accounting or legal reasons.

  • Ask me to stop using it, or to limit how I use it.

  • Get a copy of what you gave me in a form you can take elsewhere.

  • Withdraw your consent at any time, which for the mailing list means unsubscribing or telling me to take you off.

  • Complain to Datatilsynet, the Norwegian Data Protection Authority, if you think I have handled your information badly.

Write to me at tovepetterson@me.com and I will deal with it myself. You will hear back within a month, and usually a lot sooner than that.