The company: how I run Alfen, where my data lives and on what legal basis
Alfen is my own test case, so here is how it is run: the philosophy behind it, how information moves through my systems, where each step physically runs, and the legal basis and data processing agreement behind it. Below you also find every tool I use in Alfen.
The philosophy behind Alfen
Alfen is named for my two children, Alfred and Ellen: the start of one name and the end of the other. In Danish, alfen means "the elf", a figure from old stories who knows more than is visible on the surface. Alfred carries the idea of wise counsel, Ellen the idea of light. Together they describe what I want to bring to a company: the judgement and clarity to see it as it actually is.
I use my own company as the test case. I cannot advise on how to run finance and operations unless I live up to the same principles myself, so Alfen runs on what I recommend, and this page shows how.
Follow the data from the top
This is what happens when you register for the library. The marker starts at you and moves down through each system. Use the controls to pause, step or show everything at once.
-
You
What travels here: A page request. If you register: name, email, company, position and your consent choices.
- Where it physically is
- Your own device and browser.
- What happens to it
- The public pages set no cookies and load nothing from third parties. The calculator runs in your browser, and what you type into it is never sent to me.
- Legal basis
- Public pages: I collect no personal data beyond what the host handles in the next step. Registration: contract, GDPR art. 6(1)(b), giving you the library you asked for.
- Data processing agreement
- No processor at this step
Not applicable
-
Cloudflare: hosting, delivery and DNS
What travels here: Your IP address and the technical details of the request. Registration details, the sign-in link and the session cookie pass through in transit.
- Where it physically is
- Cloudflare's global network. Cloudflare, Inc. is a US company. On my current plan I cannot restrict processing to the EU, so it may take place outside the EU/EEA.
- What happens to it
- Cloudflare keeps its own technical request records as my processor. My application stores nothing here and writes no personal data to function logs.
- Legal basis
- My legitimate interest in delivering and securing the site, art. 6(1)(f). Cloudflare acts as my processor under a data processing agreement and keeps its technical records for the period it sets.
- Data processing agreement
- Cloudflare data processing addendum
Version 6.4, accepted online 1 October 2026 - Note
- The site is delivered by Cloudflare, a US company, under standard contractual clauses. I plan to move it to a European host.
-
Sign-in functions (run on Cloudflare)
What travels here: The registration details, checked before anything is stored.
- Where it physically is
- The same Cloudflare network as the step before.
- What happens to it
- A hidden form field to catch bots, rate limits, and a rule for free-mail domains. For rate limits I keep only a keyed hash of your IP address, for 24 hours at most, and never join it to your registration.
- Legal basis
- Abuse protection: my legitimate interest in keeping the library secure, art. 6(1)(f).
- Data processing agreement
- Cloudflare data processing addendum
Same agreement as the step before
-
Supabase: the database
What travels here: Name, email, company, position, the time and version of the terms you accepted, a hashed one-time sign-in link, a hashed session and which library items you open.
- Where it physically is
- Frankfurt, Germany (AWS eu-central-1). Supabase Pte. Ltd. in Singapore is the processor and processes primarily in that region.
- What happens to it
- Kept for 24 months after your last activity, then deleted. Registrations never confirmed by the sign-in link are deleted after 30 days. Backups roll off within 7 days of a deletion.
- Legal basis
- Registration: contract, art. 6(1)(b). Company and position: my legitimate interest in understanding who uses the library, art. 6(1)(f). Library activity and proof of what you accepted: legitimate interest, art. 6(1)(f). Transfers rely on the EU standard contractual clauses.
- Data processing agreement
- Supabase data processing addendum
Version 1 of 1 August 2026, accepted online 2 October 2026
-
Google Workspace: email and booking
What travels here: The one-time sign-in link to your inbox, a plain alert to me about the registration, and, if you use the booking button, the name and email you enter on Google's booking page.
- Where it physically is
- Google, with the Europe data region for data at rest in certain core services. That setting does not govern where Google processes data.
- What happens to it
- The booking page is hosted by Google and receives your name and email. Calendar entries are kept for 24 months after my last contact with you. The sign-in email is sent from my own domain, with SPF, DKIM and DMARC set. The alert goes to my Workspace mailbox only.
- Legal basis
- Sign-in email: contract, art. 6(1)(b). Alert to me: same as registration. Booking page: my legitimate interest in handling your request for a meeting, art. 6(1)(f). Google acts as my processor under the Workspace data processing terms.
- Data processing agreement
- Google Cloud data processing addendum
Accepted in the Admin console 3 October 2026. Contracting party: Google Cloud EMEA Limited
-
PostHog: analytics, only if you accept
What travels here: A random ID that is linked to your lead record, the event name (item opened, calculator started, calculator completed), the library item and the language. No name, email, company or IP address, and nothing you type into the calculator. It is sent from my server, not from your browser.
- Where it physically is
- PostHog EU Cloud, hosted in Frankfurt, Germany.
- What happens to it
- Events are kept for 12 months in the active project. If you decline, or later withdraw, nothing is sent.
- Legal basis
- Your consent, art. 6(1)(a). You can withdraw it at any time in the library. Transfers rely on the standard contractual clauses that are part of the agreement.
- Data processing agreement
- PostHog data processing agreement
Signed by both parties 4 October 2026
- The library page then reaches you from the same Cloudflare function. The only cookie is alfen_session, set after you sign in.
Behind this website
| Tool | What it does | Where | Data | Vendor tier | Data processing agreement |
|---|---|---|---|---|---|
| Cloudflare | Hosting, delivery, DNS and the sign-in functions. | Global network, US company | IP address and request data; registration details in transit | Tier 3: exception, time-limited | Cloudflare data processing addendum Version 6.4, accepted online 1 October 2026 |
| Supabase | The database for registrations, consent proof, sessions and library activity. | Frankfurt, Germany | Name, email, company, position, consent proof, library activity | Tier 2: US company with EU data region | Supabase data processing addendum Version 1 of 1 August 2026, accepted online 2 October 2026 |
| Google Workspace (Gmail API and Calendar) | Sends the sign-in email, delivers the alert to me and hosts the booking page. | Europe data region for data at rest | Email address and name, booking details | Tier 2: US company with EU data region | Google Cloud data processing addendum Accepted in the Admin console 3 October 2026. Contracting party: Google Cloud EMEA Limited |
| Google Cloud (service account for sending) | Lets the website send mail from my domain. | Not applicable, no personal data is stored | None | Tier 2: US company with EU data region | Google Cloud data processing addendum Cloud terms accepted 4 October 2026. The Cloud Data Processing Addendum covers Google Cloud as well as Workspace. Contracting party: Google Cloud EMEA Limited. |
| PostHog | Counts which library items are opened, only with your consent. | EU Cloud, Frankfurt | Random ID linked to the lead record, event, item, language | Tier 2: US company with EU data region | PostHog data processing agreement Signed by both parties 4 October 2026 |
| GitHub | Stores the source code and builds the site. | US company | Source code, no personal data and no test data with real addresses | Not applicable | No processor No agreement needed, since no personal data is processed |
| one.com | Holds the registration of the domain alfenconsulting.dk. DNS runs at Cloudflare. | Domain registrar | The registrant's business contact details, no visitor data | Not applicable | No processor Domain registrar, no processing on my behalf. one.com handles the registrant details in its own right. |
How I run Alfen itself
Client data is only processed in tools under a signed data processing agreement. For client work the target is EU-hosted model access (AWS Bedrock in Frankfurt or Google Vertex in the EU), with the agreement signed before first use. General AI tools used for internal work never receive client data.
| Tool | What it does | Where | Data | Vendor tier | Data processing agreement |
|---|---|---|---|---|---|
| Google Workspace (Drive, Gmail, Calendar) | My mailbox, calendar, documents and the store for the instructions my AI agents run on. | Europe data region for data at rest in certain core services | My business email, documents and calendar | Tier 2: US company with EU data region | Google Cloud data processing addendum Accepted in the Admin console 3 October 2026. Contracting party: Google Cloud EMEA Limited |
| LedgerBee | Alfen's own accounting. | A Danish company. According to its agreement, processing mainly takes place within the EU/EEA. A few of its providers are US companies, listed in the agreement. | Alfen's books: invoices and counterparties | Tier 1: EU-native | LedgerBee data processing agreement Part of the terms, accepted online on 12 September 2026. The text in force then was last updated on 6 July 2026. The linked text is the current version, updated on 21 September 2026. |
| Pliant | Corporate cards for Alfen. | A European card provider (cards issued by Pliant Oy). Some of its own providers use servers outside the EU. | The cardholder's details and card transactions | Not applicable: Pliant is a controller in its own right | Pliant privacy policy for card issuing No processing agreement with me, since Pliant acts as controller. Its privacy policy applies. |
| EU-resident AI model hosting (planned) | Claude through Amazon Bedrock in Frankfurt or Google Vertex in the EU, where client data is involved. The model can be swapped to fit each client's residency rules. | Frankfurt or EU | Not in use yet | Tier 2: US company with EU data region | Data processing agreement Planned. I sign the agreement before any client data is used. |
Legal bases and retention
Each step above names its legal basis. The full list of bases and how long data is kept is in the privacy notice, so there is one version only.
Read the full privacy notice and the terms of use.