Privacy · GDPR
Privacy and data-protection notice
Last updated 12 August 2026
In short
The Passport Brief collects only the details you type into the signup or enquiry form — first name, work email, job title, and company — and uses them to send the weekly brief on the basis of your consent. No advertising or profiling cookies are used; optional audience measurement runs only if you switch it on, your data is never sold or shared with sponsors, and you can unsubscribe or ask for deletion at any time by emailing editor@readpassportbrief.com.
Who is the controller of your data?
The controller is Norvestio AS, Hektnerhagan 114, 2008 Fjerdingby, Norway, publisher of The Passport Brief, edited by Y. Lietzke. For any privacy question, data-subject request, or complaint, write to editor@readpassportbrief.com — requests are answered within one month, as required by Article 12 GDPR.
What data do we collect, and why?
Newsletter signup and free-resource requests: first name, work email, job title, and company. We use these to deliver the weekly brief and the requested resource, and to understand at a coarse level which roles and company types read it. Job title and company are contractual context only — they are never sold, rented, or shared with sponsors.
Sponsorship enquiries: name, work email, company, placement of interest, and your message. The enquiry form opens your own email client, so the message reaches us as ordinary business correspondence.
Server logs: our hosting provider processes IP address, user agent, and requested URL for a short period to serve pages and prevent abuse. These logs are not used to build profiles.
What is the legal basis for each purpose?
Sending the newsletter and free resources: your consent, Article 6(1)(a) GDPR. Consent is captured with an unticked checkbox and recorded with the signup.
Answering sponsorship or editorial enquiries: legitimate interests, Article 6(1)(f) GDPR — responding to a business enquiry you initiated.
Security logging and abuse prevention: legitimate interests, Article 6(1)(f) GDPR.
Who processes data on our behalf?
beehiiv, Inc. (United States) — newsletter delivery and subscriber management, acting as a processor under a data-processing agreement, with EU–US transfers covered by the EU Standard Contractual Clauses.
Our website hosting and edge-delivery provider — page delivery and short-term server logs, as a processor.
Web fonts are self-hosted: Playfair Display and Inter are served from our own domain, so no font or CDN request goes to Google or any other third party when you load a page.
Google Ireland Limited — Google Analytics 4, used for aggregated audience measurement. It is loaded only if you consent to the Audience measurement category; with consent withheld, no request reaches Google. Any transfer to the United States relies on the EU–US Data Privacy Framework and the Standard Contractual Clauses.
Payments for paid resources are processed by Stripe, which acts as a processor for the transaction and as controller for its own fraud-prevention purposes under its privacy notice. Downloads are served from our own member area: each file is generated on request and watermarked with the licensee’s name, organisation, email and licence reference so licences can be enforced — the legal basis is our legitimate interest in protecting the licensed work (Art. 6(1)(f) GDPR) and performance of the licence contract (Art. 6(1)(b)).
How long is data kept?
Subscriber records are kept for as long as you remain subscribed, and are deleted within 30 days of an unsubscribe or erasure request, except for a minimal suppression record kept so we do not email you again by mistake.
Enquiry correspondence is kept for up to 24 months after the last exchange. Server logs are kept for a short technical retention period by the hosting provider.
What are your rights under the GDPR?
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), and the right to withdraw consent at any time (Art. 7(3)). You are never subject to automated decision-making or profiling on this site.
To exercise any right, email editor@readpassportbrief.com. You also have the right to lodge a complaint with your national supervisory authority; for the controller that is the Norwegian Data Protection Authority (Datatilsynet), and EU/EEA readers may also complain to the authority in their own country.
Cookies and tracking
Only strictly necessary technical storage is used to render pages, secure the site, and remember your cookie choice. One optional category exists: Audience measurement, provided by Google Analytics 4 (Google Ireland Limited), which sets its own cookies and reports aggregated statistics on which pages and issues are read. It is switched off until you consent, is loaded on the legal basis of your consent (Art. 6(1)(a) GDPR and the ePrivacy Directive), uses IP anonymisation, and can be withdrawn at any time via “Cookie preferences” in the footer.
Newsletter emails may include open and click measurement provided by beehiiv, which you can avoid by unsubscribing or by disabling remote images in your mail client.
International transfers and security
Where a processor is outside the EEA, transfers rely on the EU Standard Contractual Clauses together with the processor's technical and organisational measures. Data in transit is encrypted with TLS; access to subscriber data is limited to the editor.
Children and changes to this notice
The brief is a business publication and is not directed at children under 16; we do not knowingly collect their data.
This notice may be updated as processors or purposes change. The current version is dated 12 August 2026; material changes will be announced in an issue of the brief.
Frequently asked questions about privacy
What personal data does The Passport Brief collect?
Only what you submit: first name, work email, job title, and company when you subscribe or request a free resource, and name, email, company, and message when you send a sponsorship enquiry. There is no advertising or profiling tracker on the site, and web fonts are self-hosted so no third party sees your page requests.
What is the legal basis for sending the newsletter?
Consent under Article 6(1)(a) GDPR, given by ticking the consent box on the signup form. You can withdraw it at any time using the unsubscribe link in every issue, without affecting the lawfulness of processing before withdrawal.
How do I unsubscribe or have my data deleted?
Use the one-click unsubscribe link in any issue, or email the editor. Unsubscribing stops all mailings; on request your subscriber record is deleted from the newsletter platform within 30 days.
Does the site use cookies or tracking?
Only strictly necessary storage runs by default. Google Analytics 4 is used for aggregated audience measurement, and it loads only after you switch on “Audience measurement” in the cookie banner or preferences dialog. Reject all, and no analytics request is ever made.