Privacy policy

NorskEnglish

Last updated: July 2026

Who is the data controller?

attester.no is a platform where volunteer organizations issue certificates to their volunteers. The organization issuing your certificate is the data controller for what you submit. attester.no operates the technical platform. Questions? Contact your organization, or hei@attester.no for technical matters.

What data is processed, and for how long?

When you fill in the form, your details (name, role, dates, etc.) are stored temporarily so the organization can review them and issue the certificate. Storage is strictly time-limited: your details are deleted automatically 24 hours after submission, whether or not the certificate has been issued. The window exists so the organization can regenerate the PDF if something went wrong.

What is stored permanently?

After issuance, only a cryptographic hash (a fingerprint) of the certificate contents is stored, along with the issuing organization, a timestamp, a template reference and a random ID. None of these can reveal who the certificate concerns or what was attested. The contents exist only on the PDF you received — and in its QR code.

Who has access?

Your submission (before deletion) is visible only to your organization’s administrators. The database is hosted at Nhost (EU region). If the organization has enabled email notifications, a message without personal data is sent to its administrators when a submission arrives.

Voluntary feedback

The rating you can leave after submitting is anonymous: it is stored without a user ID, without any link to your submission, and without an IP address. Please do not write personal data in the free-text field.

Administrator accounts

If you register an administrator account, your email address and name are stored with the authentication service (Nhost Auth) for as long as the account exists. When you issue a certificate, the fact that your account issued it is recorded (without the certificate contents). Contact hei@attester.no to delete the account.

Your rights

You have the right to access, rectification and erasure under the GDPR. In practice: your data exists in the system for at most a day — ask your organization to delete the submission if you change your mind before the certificate is issued. After issuance there is nothing left to delete on our side; you hold the certificate yourself, on paper.


See also the technical explanation of how the system works: How attester.no works

Back to the front page
Privacy policy – attester.no