Last updated: May 2026
Data controller
The data controller for information collected on slow-blues.com is KM TECH LABS — Kjell Mersland, reg. no. 934 044 029, Norway. The editor in charge and contact person for privacy matters is Kjell Mersland.
What information we collect
- Contact form: name, email address and the message content you send us.
- Newsletter: your email address, and which categories you've selected.
- Guestbook: name and message you choose to publish.
- Technical data: IP address and anonymized visit statistics for security and operations.
Legal basis and purpose
We process personal data on the following legal bases (cf. GDPR Art. 6):
- Consent (art. 6(1)(a)) — for newsletter and guestbook.
- Legitimate interest (art. 6(1)(f)) — to respond to inquiries via the contact form and maintain secure operations.
- Legal obligation (art. 6(1)(c)) — for bookkeeping and logging requirements.
Retention period
- Contact messages: deleted no later than 12 months after the last correspondence.
- Newsletter: stored until you unsubscribe.
- Guestbook: stored as long as the post is published (you can request deletion).
- Security logs: max 90 days.
Your rights
You have the right, at any time, to:
- Access to what information we hold about you.
- Correction of inaccurate information.
- Erasure ("the right to be forgotten").
- Data portability — provision in machine-readable format.
- Withdraw consent.
- File a complaint with the Norwegian Data Protection Authority (Datatilsynet) (datatilsynet.no).
Requests regarding your rights are sent via our contact form. We respond within 30 days.
Data processors
We use the following data processors, all with a data processing agreement (DPA) and GDPR-compliant processing:
- Cloudflare — hosting, database (D1) and security.
- MailerLite — newsletter delivery.
We do not transfer personal data to third countries without a valid transfer basis (SCCs or an adequacy decision).
Security
All data is transmitted encrypted via HTTPS/TLS. Access to the database is role-based and logged. In the event of a security breach affecting your rights, we notify the Data Protection Authority and affected users without undue delay (within 72 hours).
