Privacy policy
The Vanguard ("we", "us") respects your privacy. This policy explains what personal data we collect, why, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act.
Data controller
The Vanguard is the data controller for personal data processed through this website. For any privacy-related request or question, contact us at mail@thevanguard.no.
What we collect and why
Job applications
When you apply for a position, we collect the information you provide: full name, email address, phone number, CV or resume file, any additional information you choose to share, confirmation that you are over 18, and your optional consent to keep your application on file for future consideration.
Purpose: reviewing applications and contacting
candidates.
Legal basis: steps taken at your request prior to
entering a contract (GDPR Art. 6(1)(b)); consent for extended
retention (Art. 6(1)(a)).
Newsletter
When you subscribe to our newsletter, we collect your name, email address, and your explicit consent. We use double opt-in: a confirmation email verifies that you own the address before we add you to the list.
Purpose: sending you the newsletter you signed up
for.
Legal basis: your consent (GDPR Art. 6(1)(a)). You
can withdraw consent at any time using the unsubscribe link in
every email.
How long we keep your data
- Applications without retention consent: deleted after the hiring round ends.
- Applications with retention consent: kept for up to six months from submission, then deleted.
- Newsletter subscribers: kept until you unsubscribe. On unsubscribe, we remove your address immediately.
- Server logs: operational logs (errors, request metadata) are retained for up to 30 days and do not include form content.
Who processes your data on our behalf
We use a small number of trusted service providers ("subprocessors") to run this website. We only share the data they need to perform their service, and each is bound by a data processing agreement and appropriate safeguards for any transfers outside the EU/EEA (typically EU Standard Contractual Clauses).
- Sanity — stores application data and site content. sanity.io/legal/privacy
- Resend — delivers newsletter and transactional emails. resend.com/legal/privacy-policy
- Vercel — hosts the website and runs our serverless functions. vercel.com/legal/privacy-policy
- Upstash — provides rate limiting using a hashed IP address (no profile, no cross-site tracking). upstash.com/trust/privacy
- Sentry — error monitoring. We have personally
identifiable information disabled (
sendDefaultPii: false) and do not record session replays. sentry.io/privacy
Cookies and tracking
We do not use cookies on this website. We do not run analytics, advertising trackers, social media pixels, or any behavioural tracking.
We do not sell or share your data with advertisers, data brokers, or any third party outside the subprocessors listed above.
Security
The site is served exclusively over HTTPS. API secrets are held server-side only. Uploaded files are validated for type and size. Passwords — where applicable — are never stored in plain text. Errors are reported to Sentry with personally identifiable information redacted.
Your rights
Under the GDPR, you have the right to:
- request access to the personal data we hold about you,
- ask us to correct inaccurate data,
- ask us to delete your data ("right to erasure"),
- restrict or object to processing,
- receive a copy of your data in a portable format,
- withdraw consent at any time (without affecting earlier processing).
To exercise any of these rights, email mail@thevanguard.no. We will respond within 30 days.
If you believe we have not handled your data properly, you may lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) at datatilsynet.no.
Changes to this policy
We may update this policy to reflect changes to our practices or to meet new legal requirements. The "last updated" date at the top of this page reflects the most recent change.