top of page

Privacy Policy for www.linnfoss.com

Effective date: 01-01-2026
Last updated: 20-03-2026

 

LINNFOSS ApS (“LINNFOSS”, “we”, “us”, “our”) respects your privacy and processes personal data in accordance with applicable data protection law, including the EU General Data Protection Regulation (“GDPR”) and applicable Danish data protection rules. The Danish Data Protection Agency is the relevant supervisory authority in Denmark.
 

This Privacy Policy explains how we collect, use, store, and protect personal data when you visit www.linnfoss.com, contact us, submit forms, or otherwise interact with our website.
 

1. Data Controller

LINNFOSS ApS is the data controller for the processing of personal data covered by this Privacy Policy.

Company name: LINNFOSS Consulting ApS
Address: Gunderuplundvej 13, 8370 Hadsten, Denmark
CVR/VAT no.: DK-33163983
Email: kli(at)linnfoss.com
Phone: +45 4116 677(null)
Website: www.linnfoss.com
 

If LINNFOSS has appointed a data protection contact person or Data Protection Officer, include:
Data protection contact: Kenneth Linnebjerg
 

2. What Personal Data We Collect

We may collect and process the following categories of personal data:
 

a. Information you provide directly

When you contact us through the website, email us, book a meeting, sign up for a newsletter, download material, or submit an inquiry, we may process:

• name
• company name
• job title
• email address
• phone number
• address details, if provided
• the content of your inquiry or message
• any other information you choose to submit
 

b. Information collected automatically

When you visit our website, we may collect technical and usage-related information, such as:

• IP address
• browser type and version
• device type
• operating system
• referring URLs
• pages visited
• date and time of access
• approximate geographic location derived from IP
• cookie identifiers and similar online identifiers
 

c. Marketing and analytics data

If enabled on the website, we may process information about:

• newsletter sign-up and consent status
• campaign source
• website behavior and engagement
• event registrations or downloads
• form submissions and lead generation activity
 

3. Purposes of Processing and Legal Basis

Under the GDPR, personal data processing must have a legal basis, and individuals must be informed about the purpose of the processing.
 

We process personal data for the following purposes:
 

a. To respond to inquiries and communicate with you

We process your contact details and message content so we can respond to your request, provide information, or follow up on your inquiry.

Legal basis:

• GDPR Article 6(1)(b), if the processing is necessary to take steps at your request before entering into a contract
• GDPR Article 6(1)(f), our legitimate interest in communicating with website visitors and business contacts
 

b. To provide requested materials or services

If you ask for a download, proposal, meeting, consultation, or other service-related interaction, we process the relevant personal data to deliver what you requested.

Legal basis:

• GDPR Article 6(1)(b)
• GDPR Article 6(1)(f), where relevant
 

c. To improve the website, security, and performance

We process technical usage data to operate, secure, troubleshoot, and improve the website.

Legal basis:

• GDPR Article 6(1)(f), our legitimate interest in operating a secure and functional website
 

d. To use cookies, analytics, and similar technologies

We may use cookies and similar technologies for necessary functions, preferences, analytics, and marketing. Danish guidance states that consent is required before setting non-essential cookies, and GDPR also applies where personal data is processed through such technologies.

Legal basis:

• Necessary cookies: GDPR Article 6(1)(f), legitimate interest in delivering core website functionality
• Analytics/marketing cookies: GDPR Article 6(1)(a), your consent, where required
 

e. To send newsletters or marketing communications

If you subscribe to our newsletter or otherwise consent to receive marketing, we may send you updates, insights, articles, invitations, or information about LINNFOSS services.

Legal basis:

• GDPR Article 6(1)(a), consent
• Where relevant under Danish marketing rules, only where valid consent has been obtained

You may withdraw your consent at any time.
 

f. To establish, exercise, or defend legal claims and comply with legal obligations

We may process personal data where necessary for bookkeeping, documentation, legal compliance, IT security, or dispute handling.
Legal basis:

• GDPR Article 6(1)(c), legal obligation
• GDPR Article 6(1)(f), legitimate interest
• GDPR Article 6(1)(b), where contractual necessity applies
 

4. Cookies and Similar Technologies

Our website may use cookies and similar technologies to:

• ensure technical functionality
• remember preferences
• analyze website traffic and performance
• measure campaign effectiveness
• support embedded content or third-party tools
 

Non-essential cookies should only be set after you have given consent through the cookie banner or consent management platform, in line with Danish guidance.

You can manage or withdraw your cookie consent at any time by contacting us.
 

5. Sources of Personal Data

We collect personal data:

• directly from you when you contact us or submit information through the website
• automatically through your use of the website
• in some cases, from third-party services integrated into the website, such as analytics, forms, scheduling, CRM, newsletter, or advertising platforms
 

6. Recipients and Data Processors

We may share personal data with trusted third parties where necessary to operate the website and our business, including:

• website hosting providers
• website developers and maintenance providers
• analytics providers
• CRM or marketing automation providers
• email and newsletter providers
• cloud storage and collaboration tools
• IT support and security providers
• professional advisers such as lawyers, auditors, or accountants
• public authorities where required by law
 

Where third parties process personal data on our behalf, they act as our data processors and are bound by appropriate data processing agreements as required by GDPR.
 

7. International Transfers

If personal data is transferred outside the EU/EEA, we will ensure that the transfer takes place on a lawful basis and with appropriate safeguards, such as:


• an adequacy decision by the European Commission, or
• the European Commission’s Standard Contractual Clauses, supplemented where necessary
 

[Web bureau note: confirm whether any tools on the site transfer data to the United States or other third countries, for example Google Analytics, Meta Pixel, HubSpot, Mailchimp, Calendly, embedded YouTube, reCAPTCHA, etc.]
 

8. Retention Periods

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required by law.

Typical retention periods may include:

• Contact inquiries: up to [12–24 months] after the last relevant communication
• Client/prospect correspondence: for as long as relevant to business dialogue and follow-up
• Newsletter data: until you withdraw consent or unsubscribe
• Analytics/cookie data: according to the cookie settings and provider configuration
• Accounting or contract-related data: as required by applicable law
 

Your web bureau should adjust these periods to match actual practice and systems used.
 

9. Your Rights

Under the GDPR, individuals have rights including the right to be informed, access, rectification, erasure, restriction, portability, objection, and not to be subject to certain solely automated decisions.
 

Subject to the applicable conditions, you have the right to:

• request access to the personal data we process about you
• request correction of inaccurate or incomplete data
• request deletion of your personal data
• request restriction of processing
• object to processing based on legitimate interests
• withdraw consent at any time where processing is based on consent
• request data portability where applicable
• lodge a complaint with the relevant supervisory authority
 

If you wish to exercise your rights, please contact us using the contact details in section 1.
 

10. Complaints

If you are dissatisfied with how we process your personal data, you may contact us first. You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet). Datatilsynet is the independent authority supervising compliance with personal data rules in Denmark.
 

11. Data Security

We take appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
 

The GDPR requires appropriate security measures and breach handling where risks arise.
 

These measures may include:

• access control
• encrypted connections (HTTPS)
• role-based access limitation
• secure hosting and backups
• monitoring and maintenance
• contractual controls with suppliers and processors
 

12. Third-Party Websites and Embedded Content

Our website may contain links to third-party websites or embedded services. We are not responsible for the privacy practices of third-party websites or services. We encourage you to read their privacy notices separately.
 

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect legal, technical, or operational changes.
The latest version will always be available on www.linnfoss.com with the updated effective date shown at the top.
 

14. Contact

If you have any questions about this Privacy Policy or our processing of personal data, please contact:

LINNFOSS Consulting ApS
Gunderuplundvej 13, DK8370 Hadsten
kli(at)linnfoss.com
+45 4116 677(null)
www.linnfoss.com

bottom of page