Privacy Policy

Last update: July 10, 2026

Who we are

This website, scisco.no (“the site”), is the personal professional website of Marisa Iversen. It shares research, writing, and information about human–AI collaboration, innovation, and technology strategy.

For the purposes of the EU/EEA General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act, the data controller for personal data processed through this site is Marisa Iversen. You can reach us through the contact form.

This policy explains what personal data we collect, why, how it is handled, and the rights you have.

What data we collect and why

When you use the contact form. If you fill in the contact form, we collect the information you provide — typically your name, email address, an optional company name, and your message. We use this solely to read and respond to your enquiry. We do not use it for marketing.

Server logs and security. Like most websites, our web server and our security plugin (Wordfence) automatically record technical information such as your IP address, browser type, and the pages requested. This is used to keep the site secure, prevent abuse, and diagnose problems.

Spam protection. The contact form uses Google reCAPTCHA to distinguish humans from automated spam. reCAPTCHA collects hardware and software information (such as device and application data) and sends it to Google for analysis. Your use of reCAPTCHA is subject to Google’s Privacy Policy and Terms of Service. (If the site later switches to a cookieless method such as a honeypot or Cloudflare Turnstile, this section will be updated.)

Email. Messages sent through the contact form are delivered to our inbox using Google Workspace (email hosted on Google’s infrastructure).

What we do NOT do. We do not use website analytics or advertising trackers, we do not sell or rent your data, and we do not publish email addresses on the site. Web fonts are self-hosted, so viewing the site does not send your data to a font provider.

Cookies

The site itself does not use cookies for tracking or analytics. Google reCAPTCHA may set cookies necessary for its spam-protection function. Any cookies set are limited to keeping the site secure and functional. You can control or delete cookies through your browser settings.

Legal basis for processing

We process your personal data on the following bases under the GDPR:

  • Consent / legitimate interest — to respond to enquiries you send us through the contact form.
  • Legitimate interest — to keep the site secure, prevent spam and abuse, and maintain reliable operation.

How long we keep your data

  • Contact-form messages are kept only as long as needed to handle your enquiry and any reasonable follow-up, after which they are deleted.
  • Server and security logs are kept for a limited period for security and troubleshooting, then removed or overwritten.

Who we share data with

We do not sell or share your personal data for marketing. Limited data is processed by service providers (“data processors”) that help us run the site:

  • Google (Google Workspace for email; Google reCAPTCHA for spam protection).
  • Google Cloud Platform (website hosting).
  • Plugins that support site operation and security (e.g. Wordfence, WP Mail SMTP, image optimisation).

Some of these providers are based in the United States. Where data is transferred outside the EU/EEA, it is protected by appropriate safeguards such as the EU Standard Contractual Clauses and the providers’ data-protection frameworks.

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • request correction of inaccurate data;
  • request erasure of your data (“right to be forgotten”);
  • restrict or object to certain processing;
  • request data portability; and
  • withdraw consent at any time, where processing is based on consent.

To exercise any of these rights, contact us through the contact form. We will respond within the time required by law.

You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no) if you believe your data has been handled unlawfully.

Changes to this policy

We may update this policy from time to time. The “last updated” date at the top shows when it was last revised. Material changes will be reflected on this page.

Contact

For any questions about this policy or your personal data, please use the contact form.