Privacy policy
What we process, on what legal basis, and how to exercise your rights.
Draft for legal review. The publisher is established in Norway and subject to the GDPR through Norwegian data protection law, while also processing data of readers in Brazil covered by the LGPD. Both apply in parallel.
1. Controller
Boreal Times AS, registered in Norway, based in Oslo. Privacy contact: privacidade@borealtimes.org.
2. What we process
Waiting list. Email address and sign-up date.
Subscribers. Name, email, subscription history and access records. Payment details are handled directly by Stripe — we neither receive nor store card numbers.
Browsing. IP address, device type and pages visited, in aggregate form, only with consent.
We process no special-category data and do not ask subscribers about their assets.
3. Purposes and legal bases
Performance of the contract: delivery, authentication, billing and support. Legal obligation: retention of records and tax documents for the periods required in Norway and, where applicable, Brazil. Legitimate interest: service security. Consent: audience measurement and promotional email, revocable at any time.
4. Processors and sharing
Stripe (payment and authentication), a transactional email provider, Cloudflare (hosting and protection) and Google Analytics where permitted. All act as processors under a data processing agreement. We do not sell personal data and do not pass the subscriber list to advertisers.
5. International transfers
Data may be processed outside Norway and outside Brazil. Where that happens we rely on standard contractual clauses and a transfer assessment consistent with the GDPR and the LGPD.
6. Retention
Waiting list: until conversion or removal. Subscription: for the life of the relationship and the accounting periods required afterwards in Norway. Access logs: six months.
7. Your rights
Access, rectification, erasure, restriction, objection, portability and withdrawal of consent. Requests go to privacidade@borealtimes.org and are answered within thirty days.
Complaints may be made to the Norwegian Data Protection Authority (Datatilsynet) or, for data subjects in Brazil, to the ANPD.
8. Security
Encrypted transport, sessions with no stored password, restricted access to the subscriber base and logging of administrative access. Incidents carrying material risk are reported to data subjects and to the competent authorities within statutory deadlines.
9. Protection of sources
Communications from journalistic sources are handled separately and never enter the subscriber or marketing base. Source confidentiality is protected under Norwegian law and, for Brazilian sources, by article 5, XIV of the Brazilian Constitution.