Privacy policy
Last updated 28 August 2026
Kordinert is a tool for the choirs and singers who use it. This policy explains what personal data is processed, why, where it is stored, and the rights you have.
Who is responsible
Kordinert is provided by Birget AS (org. no. 933 189 775, Oslo, Norway). You can reach us at hei@kordinert.no.
For the data a choir registers about its members — member list, attendance, leaves, dues, messages — the choir is the data controller, and Birget AS is the processor acting on the choir’s behalf.
For your platform account (sign-in), billing of the choir’s subscription and technical error logging, Birget AS is itself the controller.
What data is processed
Depending on how your choir uses Kordinert, we process:
- Account data: name, email address and sign-in information.
- Profile data you or the choir add: phone, birth date, address, pronoun, avatar, and optionally an emergency contact.
- Membership history: voice group, status, admission, probation, leaves of absence and roles in the choir.
- Activity: RSVPs and attendance records.
- Content: posts, comments, messages and files shared within the choir.
- Dues: charges and payments recorded by the choir’s board.
- Technical: push-notification tokens for the mobile app, session cookies and operational logs.
What the data is used for
The data is used to deliver the service: maintaining the member list, planning rehearsals and productions, recording attendance, sending messages and notifications, and managing the choir’s dues. We do not use the data for marketing, and we never sell it.
Where the data is stored
The database and file storage are operated within the EU/EEA. Each choir is isolated with row-level security in the database — no choir can see another choir’s data. Choirs on the Ensemble plan can get their own tenant-isolated environment with a dedicated data processing agreement.
Sub-processors
We use a small number of sub-processors for well-defined tasks:
- Stripe — card payment of the choir’s subscription (not member dues).
- Resend — outbound email (invitations, digests).
- Expo — delivery of push notifications to the mobile app.
- Sentry — error logging, with personal data scrubbed before submission.
- Anthropic — AI-assisted import and AI assistant; used only when the choir itself uses the feature.
Cookies
Kordinert only uses cookies that are necessary for sign-in and security. We use no marketing or third-party tracking cookies, and no tracking analytics on the websites.
How long we keep data
Data is kept for as long as you have an account and your choir uses the service. The choir’s history (who sang, when, in which voice group) is part of the choir’s own records and may be retained by the choir in pseudonymised form after a membership ends. Accounting material is kept as long as the Norwegian Bookkeeping Act requires. Notifications are archived automatically 90 days after being read.
Your rights
You have the right to access, rectification, erasure, restriction and data portability under the GDPR. The choir can produce a complete access report for a member directly in the service, and you can edit your own profile data.
Requests for access or erasure go to hei@kordinert.no and are answered within one month. If the request concerns data your choir is the controller of, we may forward it to the choir’s board. You can also complain to Datatilsynet, the Norwegian Data Protection Authority.
Changes to this policy
For material changes we notify the choir in the service. The date at the top shows when the policy was last updated.