For the complete documentation index, see /llms.txt. Markdown version of this page: /en/privacy.md.
Legal

Privacy notice

FM CyberSecurity AS processes personal data about visitors, customers, candidates and event attendees. This notice explains what we collect, why, and what rights you have.

Last updated 12 August 2026.

1. Data controller

FM CyberSecurity AS, Norwegian organisation number 934 418 840.
Henrik Ibsens gate 36, 0160 Oslo, Norway.
Privacy contact: [email protected].

2. What data we process

Contact form

Name, work email, and the message you write. We do not persist form submissions in a database. The message is forwarded by email to the named contact and lives on in our Microsoft 365 mailbox from there.

Event registration

Name, work email, company, role (optional), phone (optional). We also store the fact that you consented to the processing, whether you opted in to future invitations, the timestamp of the registration, and the IP address used by Cloudflare Turnstile for spam protection.

Job applications

The position you apply for, name, email, phone (optional), LinkedIn profile (optional) and your motivation text. We do not persist applications in a database. The application is forwarded by email to [email protected] and lives on in our Microsoft 365 mailbox from there. We only receive a CV if you choose to reply to the confirmation email with it attached. The IP address is used by Cloudflare Turnstile for spam protection.

Technical data

Standard Cloudflare server logs (IP address, user agent, timestamp). We do not use analytics cookies for our own statistics.

Marketing and ad measurement

We use Google Ads and LinkedIn to measure how our marketing performs. These tools set cookies and load scripts from Google and LinkedIn, but only if you accept in the consent box shown on your first visit. If you decline, or simply do not answer, nothing is loaded from Google or LinkedIn.

3. Purposes and lawful basis

  • Confirming and running the event you registered for. Lawful basis: contract (GDPR Art. 6(1)(b)).
  • Responding to enquiries from the contact form. Lawful basis: contract or legitimate interest (GDPR Art. 6(1)(b) or (f)).
  • Sending invitations to future FM events. Lawful basis: your consent (GDPR Art. 6(1)(a)). You tick the box yourself at registration.
  • Assessing job applications and running recruitment processes. Lawful basis: steps taken prior to entering into a contract (GDPR Art. 6(1)(b)).
  • Protecting the site from abuse, spam and automated attacks. Lawful basis: legitimate interest (GDPR Art. 6(1)(f)).
  • Measuring the effect of advertising on Google and LinkedIn. Lawful basis: your consent (GDPR Art. 6(1)(a)). You choose in the consent box, and you can change your mind at any time.

4. Recipients

We do not share attendee lists with third parties for their marketing. The following data processors have access to the extent necessary to deliver the service:

  • Cloudflare, Inc. (US and EU). Hosting, security, Workers KV storage, Turnstile bot protection. Data processing agreement in place.
  • Resend, Inc. (US). Sending confirmation and notification email. Data processing agreement in place.
  • Microsoft Ireland Operations Ltd. Microsoft 365 email and shared mailbox ([email protected]) where FM CyberSecurity staff receive enquiries.
  • Google Ireland Ltd. Ad measurement for Google Ads. Receives data only if you have consented to marketing cookies.
  • LinkedIn Ireland Unlimited Company. Ad measurement via the LinkedIn Insight Tag. Receives data only if you have consented to marketing cookies.

When an event is co-hosted with a technical partner (for example Tenable at FM Cyber Breakfast), we share the fact that we are running the event together. We do not share the attendee list with the partner unless you have consented to it.

5. Retention

  • Attendee lists in Cloudflare KV are deleted 30 days after the event.
  • Confirmation and notification emails in Resend follow Resend's default log retention (typically 30 days).
  • Marketing consents are stored until you withdraw the consent.
  • Enquiries in mailboxes are cleaned up per our internal policy, normally within 24 months.
  • Job applications and CVs are deleted from the mailbox no later than 6 months after the recruitment process closes, unless you consent to longer storage.
  • Cloudflare server logs are retained for 30 days.
  • Your marketing-consent choice is stored in your browser until you change or delete it. The lifetime of the Google and LinkedIn cookies is governed by their own notices.

6. Your rights

You have the right to:

  • Request access to the data we hold about you.
  • Ask us to correct mistakes.
  • Ask us to erase the data.
  • Ask us to temporarily stop processing, or object to processing based on legitimate interest.
  • Receive a machine-readable copy of your data (data portability).
  • Withdraw consents you have given, with effect going forward.

Send requests to [email protected]. We respond within 30 days.

You can change your marketing-cookie consent at any time: .

7. Complaints to the Norwegian Data Protection Authority

If you believe we are processing data incorrectly, you have the right to file a complaint with Datatilsynet, the Norwegian Data Protection Authority. See datatilsynet.no.

8. Changes

We may update this notice when our services or the regulations change. The latest update date appears at the top.

Questions or inquiry? [email protected] Contact us →