Privacy and cookie notice
How I handle personal data on this site: who is responsible, what I process and why, how long I keep it, and what you can ask of me.
1. Who is responsible
Alfen Consulting ApS, CVR 46747445, C/o Martin Sørensen, Lejrevej 14, 2700 Brønshøj, Denmark, is the data controller for what is described here. In this notice “I” and “my” mean Alfen Consulting ApS, the company I run. Contact on privacy matters: finance@alfenconsulting.dk. I have no data protection officer, because none is required.
2. The public pages
The public pages of alfenconsulting.dk set no cookies and load nothing from third parties: no external fonts, analytics or embeds. My hosting provider, Cloudflare, necessarily receives your IP address when your browser requests a page and handles it for me. My own application writes no personal data to function logs. Cloudflare keeps its own technical request records (address, path and time) as my processor, and Cloudflare sets how long they are kept. Your one-time sign-in link appears in the address of one request and can therefore appear in those records; it works once and expires after 15 minutes.
I count page views and clicks on the booking button as totals. The daily counts I store contain no IP address or identifier. The company that delivers the site (Cloudflare) processes IP addresses technically to deliver and secure it, see section 3.
Counting visits and sign-up steps. I count distinct visits per day using a one-way, keyed hash of your IP address and browser details. The hash is kept for 24 hours, used only for counting, and then deleted. It is never joined to a registration and never sent to anyone else. I also record which website a visit came from (host name only, never the path or search terms) and campaign tags in the links you followed, and I keep anonymous daily totals of sign-up steps: form shown, submitted, mail sent and link used. I do this under my legitimate interest in understanding how the site is used (GDPR art. 6(1)(f)). You can object by writing to finance@alfenconsulting.dk.
Booking runs on a Google Calendar page hosted by Google. Google receives your IP address and the name and email you enter, and processes them for me under my data processing agreement with Google (Workspace, accepted 3 October 2026). The booking page rests on my legitimate interest in handling your request for a meeting (art. 6(1)(f)). Calendar entries are kept for 24 months after my last contact with you.
3. What I process, why, and on what basis
| Purpose | Data | Legal basis | Kept |
|---|---|---|---|
| Registration and access to the library | Name, email, company, the time and version of the terms you accepted, a one-time sign-in link | Contract: giving you the library you asked for (GDPR art. 6(1)(b)). For the company field: my legitimate interest in understanding who uses the library (art. 6(1)(f)) | 24 months after your last activity, then deleted. Registrations never confirmed by the sign-in link: 30 days |
| Position (job title) | Position, entered in the registration form | So I know who I am speaking with and can tailor my reply. Legitimate interest (art. 6(1)(f)) | Until the lead is deleted (24 months after last activity) |
| How you found the site (optional, from a list) | Your choice from a closed list, no free text | To see which channels work. Legitimate interest (art. 6(1)(f)) | Until the lead is deleted |
| Staying signed in | The session cookie alfen_session (section 5) |
Contract (art. 6(1)(b)); strictly necessary for sign-in | 24 hours from sign-in, or until you sign out |
| Activity in the library | Which items you open and which booking buttons you click inside the library, linked to your account | My legitimate interest in seeing what is useful, improving it, and knowing when someone may want to talk (art. 6(1)(f)). You may object at any time (section 9) | 24 months after your last activity |
| Abuse protection | A keyed hash of your IP address, used only for rate limits, kept in its own table and never joined to your registration | My legitimate interest in keeping the library secure (art. 6(1)(f)) | 24 hours at most. Apart from the technical logs in section 2, I do not store your raw IP address |
| Marketing emails | Name, email, company, your consent record | Your consent (art. 6(1)(a)), only if you tick the marketing box | Until you withdraw, or 24 months after your last activity |
| Proof of what you accepted or consented to | Email, timestamps, versions of the texts | My legitimate interest in being able to document it (art. 6(1)(f)) | A minimal record for up to 3 years after withdrawal or deletion |
| An alert to me about a new registration | I receive an alert with these details: name, email, company and position | Same as registration | Same as registration |
| Delivering and securing the site | IP address and technical request data, processed by Cloudflare | My legitimate interest in delivering and securing the site (art. 6(1)(f)) | For as long as Cloudflare keeps its technical request records, which Cloudflare sets |
I do not make decisions about you by automated means, and I build no profile beyond the activity described above. I do not sell personal data.
Marketing is optional. Access to the library never depends on it.
4. The business case calculator
The calculator runs in your browser. What you type into it is not sent to me and I do not store it. It stays on your device until you close or reload the page. Please do not enter personal data about named individuals, or confidential information you are not free to use. The result is indicative and is not advice.
Analytics in the library. If you accept, I record three events: when you open a library item, when you start the calculator and when you complete it (when you copy the summary), together with the language. These events are linked to your registration record through a random ID. PostHog never receives your name, email or company, and I never send what you enter in the calculator. I use it to understand which content is useful, not to follow up with you individually. My legal basis is your consent. PostHog, Inc. is my processor under a data processing agreement, see section 6. Events are kept for 12 months in the active project. You can withdraw consent at any time in the library, and you can ask for access, erasure or object at finance@alfenconsulting.dk. You can also complain to the Danish Data Protection Agency (Datatilsynet).
5. Cookies
| Name | Purpose | Duration | Type |
|---|---|---|---|
alfen_session |
Keeps you signed in after you use your sign-in link. HttpOnly, Secure, SameSite=Lax | 24 hours from sign-in, or until you sign out | Strictly necessary, first party |
This is the only cookie I set, and only after you sign in. It is strictly necessary for a service you asked for, so no cookie consent is required and I show no cookie banner. I use no advertising, analytics or third-party cookies, and nothing else is stored on your device.
6. Who receives your data
I use these providers as data processors, each under a data processing agreement:
- Supabase (database, Frankfurt, Germany)
- Cloudflare (hosting, delivery of the site and DNS; it also runs the sign-in functions, so the details you enter in the registration form, your sign-in link and your session cookie pass through Cloudflare in transit. I do not store them there)
- Google Workspace, EU region (sending sign-in emails from a no-reply sender and, if you opt in, marketing emails; my mailbox and the alerts I receive)
- PostHog, Inc. (analytics for the gated library, only if you accept analytics)
Cloudflare, Inc. (USA) hosts and delivers my website and runs the server functions behind the library sign-in. As my processor it processes your IP address and technical request data. When you register or sign in, your registration details (name, email, company and consent choices), your one-time sign-in link and your session cookie pass through Cloudflare in transit. The application stores nothing at Cloudflare, and registration details are stored only in my database. On my current plan I cannot restrict Cloudflare’s processing to the EU, so processing may take place outside the EU/EEA. Transfers to the USA rely on the EU Commission’s standard contractual clauses.
My database is stored with Supabase in Frankfurt, Germany. Supabase Pte. Ltd. (Singapore) is my processor, and transfers to Supabase rely on the EU Commission’s standard contractual clauses. Daily backups are kept for 7 days.
My Google Workspace account uses the Europe data region for data at rest in certain core services. This does not govern where Google processes data.
PostHog (PostHog Inc.) provides analytics for the gated library, as my processor under a data processing agreement signed 4 October 2026. Data is stored in the EU, in Frankfurt. Transfers to PostHog rely on the standard contractual clauses that are part of the agreement. Events are linked to your lead record and only recorded if you have accepted analytics.
Backups roll off within 7 days after deletion.
7. Providing your data
Name, email, company and position are required to register, so that I know who I am speaking with. Marketing consent and the question about how you found the site are optional.
8. Retention
See the table in section 3. I delete or anonymise a registration 24 months after your last activity. Analytics events are kept for 12 months in the active project. Aggregated counts that identify nobody may be kept longer.
9. Your rights
You can ask me for access to your data, correction, deletion, restriction and a portable copy. You can also object to processing that rests on my legitimate interest, such as activity in the library and abuse protection. You can withdraw marketing consent at any time through the unsubscribe link in any marketing email or by writing to finance@alfenconsulting.dk. Withdrawal does not affect earlier processing, and I reply within one month.
10. Complaints
You can complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, dt@datatilsynet.dk, www.datatilsynet.dk. I would be glad to try to resolve it with you first.
11. Changes
I version this notice. I announce material changes on the library sign-in page and, if you opted in to marketing, by email. Earlier versions are available on request.
Version 1.1, 8 October 2026: added distinct-visit count, referrer host, campaign tags and sign-up step totals.
Version 1.1, effective 8 October 2026