Privacy Policy
Last updated: 25 August 2026
This policy explains what ThinkTech ApS ("we", "us") does with personal data on this website. It is written to describe what the site actually does, not what a website of this kind typically does.
Data controller: ThinkTech ApS, CVR 44998459, Aarhus, Denmark. Contact: hello@thnktech.dk.
Cookies
This website sets two cookies. Both are strictly necessary for the site to work, and neither is used to track you:
- Session cookie — keeps your session while you browse, including your language choice and the token that protects forms against cross-site request forgery. Expires when your session ends.
- XSRF-TOKEN — the readable half of that same form protection. Expires when your session ends.
That is the complete list. We set no analytics cookie, no advertising cookie and no preference cookie, and no third party sets a cookie through this site.
This is why there is no cookie banner. Consent is required for cookies that are not strictly necessary. We do not use any, so there is nothing to ask you about. We removed our banner by removing the tracking that made one necessary — not by deciding to stop asking.
How we measure traffic
We do want to know which pages are read. We do it on our own server, without cookies and without sending anything to a third party. For each page request we store:
- the page requested, the time, the response status and size
- a one-way keyed hash of your IP address — never the address itself. The key is secret and the hash is re-salted every day, so the same visitor is not traceable from one day to the next
- your browser's user-agent string and the country your request came from
- the page that referred you, if any
This tells us that a page was read; it cannot tell us who read it, and it cannot follow you to any other website. We do not use Google Analytics, Google Tag Manager, Meta Pixel, Hotjar or any comparable service. We do not build visitor profiles and we do not advertise to you.
Legal basis: our legitimate interest in understanding whether our own website works (GDPR Art. 6(1)(f)). Retention: 26 months.
Security logging
We log requests that our bot defences act on — blocked crawlers, rate-limited traffic, and clients falsely claiming to be a search engine. These entries hold the same fields as above, including the keyed IP hash, plus the rule that fired.
Legal basis: our legitimate interest in keeping the site available and secure (GDPR Art. 6(1)(f)). Retention: 26 months.
When you contact us
If you submit a form, we store what you typed, together with your IP address and user-agent string so we can tell genuine enquiries from automated spam. We use it to answer you and, where a project follows, to carry out the work.
Legal basis: steps taken at your request before a contract, or our legitimate interest in responding to enquiries (GDPR Art. 6(1)(b) and (f)). Retention: enquiries are kept for as long as the business relationship makes them relevant, and accounting records for the five years Danish bookkeeping law requires.
Email we send you is delivered through Brevo, and we receive delivery events — sent, delivered, opened, bounced — so we can tell whether a message arrived. These events include your email address. We do not use them to score, segment or profile you.
Who processes data for us
- Hetzner Online GmbH (Nuremberg, Germany) — hosts the server. All website data lives here, inside the EU.
- Brevo (France) — sends our email, inside the EU.
- Slack Technologies (United States) — receives our internal operational notifications, which include the recipient address of an email delivery event. This is a transfer outside the EU/EEA, made under the EU–US Data Privacy Framework and standard contractual clauses.
We do not sell personal data, and we do not share it for anyone else's marketing.
Your rights
Under the GDPR you may ask us to:
- Access — give you a copy of the personal data we hold about you
- Rectify — correct data that is wrong or incomplete
- Erase — delete your data, where we have no overriding obligation to keep it
- Port — hand your data over in a machine-readable format
- Restrict — pause our processing while a dispute is resolved
- Object — object to processing we base on legitimate interest
Write to hello@thnktech.dk and we will respond within one month. Requests are handled by hand — there is no self-service export, and we would rather say so than imply a button exists.
One practical limit worth stating plainly: our traffic and security logs identify no one, so we cannot find "your" rows in them and cannot action an access or erasure request against them. That is a consequence of collecting less, not a refusal.
If you think we have handled your data badly, you can complain to the Danish Data Protection Agency, Datatilsynet.
Changes to this policy
If what we collect changes, this page changes with it, and the date at the top moves. Should we ever reintroduce a service that needs consent, a consent flow returns at the same time — the two are not separable.