The company: how I run Alfen, where my data lives and on what legal basis

Alfen is my own test case, so here is how it is run: the philosophy behind it, how information moves through my systems, where each step physically runs, and the legal basis and data processing agreement behind it. Below you also find every tool I use in Alfen.

The philosophy behind Alfen

Alfen is named for my two children, Alfred and Ellen: the start of one name and the end of the other. In Danish, alfen means "the elf", a figure from old stories who knows more than is visible on the surface. Alfred carries the idea of wise counsel, Ellen the idea of light. Together they describe what I want to bring to a company: the judgement and clarity to see it as it actually is.

I use my own company as the test case. I cannot advise on how to run finance and operations unless I live up to the same principles myself, so Alfen runs on what I recommend, and this page shows how.

Follow the data from the top

This is what happens when you register for the library. The marker starts at you and moves down through each system. Use the controls to pause, step or show everything at once.

  1. You

    What travels here: A page request. If you register: name, email, company, position and your consent choices.

    Where it physically is
    Your own device and browser.
    What happens to it
    The public pages set no cookies and load nothing from third parties. The calculator runs in your browser, and what you type into it is never sent to me.
    Legal basis
    Public pages: I collect no personal data beyond what the host handles in the next step. Registration: contract, GDPR art. 6(1)(b), giving you the library you asked for.
    Data processing agreement
    No processor at this step
    Not applicable
  2. Cloudflare: hosting, delivery and DNS

    What travels here: Your IP address and the technical details of the request. Registration details, the sign-in link and the session cookie pass through in transit.

    Where it physically is
    Cloudflare's global network. Cloudflare, Inc. is a US company. On my current plan I cannot restrict processing to the EU, so it may take place outside the EU/EEA.
    What happens to it
    Cloudflare keeps its own technical request records as my processor. My application stores nothing here and writes no personal data to function logs.
    Legal basis
    My legitimate interest in delivering and securing the site, art. 6(1)(f). Cloudflare acts as my processor under a data processing agreement and keeps its technical records for the period it sets.
    Data processing agreement
    Cloudflare data processing addendum
    Version 6.4, accepted online 1 October 2026
    Note
    The site is delivered by Cloudflare, a US company, under standard contractual clauses. I plan to move it to a European host.
  3. Sign-in functions (run on Cloudflare)

    What travels here: The registration details, checked before anything is stored.

    Where it physically is
    The same Cloudflare network as the step before.
    What happens to it
    A hidden form field to catch bots, rate limits, and a rule for free-mail domains. For rate limits I keep only a keyed hash of your IP address, for 24 hours at most, and never join it to your registration.
    Legal basis
    Abuse protection: my legitimate interest in keeping the library secure, art. 6(1)(f).
    Data processing agreement
    Cloudflare data processing addendum
    Same agreement as the step before
  4. Supabase: the database

    What travels here: Name, email, company, position, the time and version of the terms you accepted, a hashed one-time sign-in link, a hashed session and which library items you open.

    Where it physically is
    Frankfurt, Germany (AWS eu-central-1). Supabase Pte. Ltd. in Singapore is the processor and processes primarily in that region.
    What happens to it
    Kept for 24 months after your last activity, then deleted. Registrations never confirmed by the sign-in link are deleted after 30 days. Backups roll off within 7 days of a deletion.
    Legal basis
    Registration: contract, art. 6(1)(b). Company and position: my legitimate interest in understanding who uses the library, art. 6(1)(f). Library activity and proof of what you accepted: legitimate interest, art. 6(1)(f). Transfers rely on the EU standard contractual clauses.
    Data processing agreement
    Supabase data processing addendum
    Version 1 of 1 August 2026, accepted online 2 October 2026
  5. Google Workspace: email and booking

    What travels here: The one-time sign-in link to your inbox, a plain alert to me about the registration, and, if you use the booking button, the name and email you enter on Google's booking page.

    Where it physically is
    Google, with the Europe data region for data at rest in certain core services. That setting does not govern where Google processes data.
    What happens to it
    The booking page is hosted by Google and receives your name and email. Calendar entries are kept for 24 months after my last contact with you. The sign-in email is sent from my own domain, with SPF, DKIM and DMARC set. The alert goes to my Workspace mailbox only.
    Legal basis
    Sign-in email: contract, art. 6(1)(b). Alert to me: same as registration. Booking page: my legitimate interest in handling your request for a meeting, art. 6(1)(f). Google acts as my processor under the Workspace data processing terms.
    Data processing agreement
    Google Cloud data processing addendum
    Accepted in the Admin console 3 October 2026. Contracting party: Google Cloud EMEA Limited
  6. PostHog: analytics, only if you accept

    What travels here: A random ID that is linked to your lead record, the event name (item opened, calculator started, calculator completed), the library item and the language. No name, email, company or IP address, and nothing you type into the calculator. It is sent from my server, not from your browser.

    Where it physically is
    PostHog EU Cloud, hosted in Frankfurt, Germany.
    What happens to it
    Events are kept for 12 months in the active project. If you decline, or later withdraw, nothing is sent.
    Legal basis
    Your consent, art. 6(1)(a). You can withdraw it at any time in the library. Transfers rely on the standard contractual clauses that are part of the agreement.
    Data processing agreement
    PostHog data processing agreement
    Signed by both parties 4 October 2026
  7. The library page then reaches you from the same Cloudflare function. The only cookie is alfen_session, set after you sign in.

Behind this website

How I run Alfen itself

Client data is only processed in tools under a signed data processing agreement. For client work the target is EU-hosted model access (AWS Bedrock in Frankfurt or Google Vertex in the EU), with the agreement signed before first use. General AI tools used for internal work never receive client data.

Legal bases and retention

Each step above names its legal basis. The full list of bases and how long data is kept is in the privacy notice, so there is one version only.

Read the full privacy notice and the terms of use.