[Legal] / GDPR

Privacy policy.

This policy describes how algoritma handles personal data I receive by email, through my booking system and during spot calls. It is written in plain language, not legalese.

The essentials (short version)
  • No cookies: the site sets no cookies and uses cookieless, anonymous visit statistics. There is no banner to deal with.
  • Only what you give me: I only collect data you send me yourself: your name, email and what you write.
  • Never shared: your data is never sold or passed on to third parties for marketing.
  • AI tools: your personal data is never loaded into external AI services without your permission.
  • Your rights: access, rectification and erasure. Write to martin@algoritma.dk.

The full policy, including legal bases and retention periods, follows below.

Data controller

Martin Nørmark Hansen, sole proprietorship trading under the brand algoritma.

Address: to be updated upon company registration.

Contact: martin@algoritma.dk

CVR: to be updated once the company is registered.

What data I collect

I only collect data you give me yourself, plus cookieless, anonymous visit statistics that cannot be traced to you as a person.

When you write or book: your name, email address, phone number (if provided), company name and whatever you describe in your enquiry.

During a spot call: notes about your company's digital product, any screen shares and what we agree to look at.

During prototype and build: any data you explicitly give me access to (export files, API keys, demo accounts). These are stored encrypted and deleted at the end of the project unless otherwise agreed.

The free demo form: the website address you enter and the email address the demo should be sent to. The email address is used solely to send the demo and any follow-up on it, and is not added to newsletters or the like. For the demo I only retrieve publicly available information from the website you enter (for example a product catalogue), no personal data. Unless you ask otherwise, the enquiry is deleted after a maximum of 12 months.

Third parties and sub-processors

algoritma uses the following third-party services. All are GDPR compliant and covered by data processing agreements (DPAs). Transfers outside the EU take place on the basis of the EU's standard contractual clauses (SCCs), cf. GDPR Art. 46.

Google Workspace: email, calendar and document storage. Google LLC, USA. Data storage region: EU. Transfer basis: SCCs + Google's DPA.

Anthropic Claude (commercial plan): AI development tool for coding assistance and analysis in the work process. Anthropic PBC, USA. Data is never used for model training under commercial terms. Only anonymised / non-personally identifiable data is processed. Transfer basis: SCCs + Anthropic's DPA.

GitHub: code repository and version control. GitHub Inc. (Microsoft), USA. Transfer basis: SCCs + GitHub's DPA.

Cloudflare: processes form submissions from the website (free demo and contact) on their way to my inbox. Cloudflare Inc., USA. Transfer basis: SCCs + Cloudflare's DPA.

Resend: email delivery service that forwards form messages to my mail. Resend Inc., USA. Transfer basis: SCCs + Resend's DPA.

algoritma never loads personal data about you or your company's customers into external AI services without your written permission. The list of sub-processors may be updated. Material changes are notified in accordance with the section "Changes" below.

Cookies and web statistics

The site sets no cookies and therefore needs no cookie banner. To understand how the site is used (page views, traffic sources, device type) I use Cloudflare Web Analytics, which is cookieless and does not use fingerprinting. Only aggregated figures are collected, which cannot be traced to you as a person, and your IP address is not stored. Data is not passed on to third parties for marketing.

If you sign in to the dashboard (customers), your browser stores a technical login session (in the browser's local storage, not a cookie) so you stay signed in. It is strictly necessary for login to work and is not used for statistics or marketing.

What I do not do

  • I never sell or share data with third parties for marketing purposes.
  • There is no ad tracking, Facebook pixel or Google Ads on the site.
  • I set no cookies and use no cookie-based tracking.
  • I do not train AI models on your data without explicit, written permission.

Where data is stored

Email: Google Workspace (EU region), where my martin@algoritma.dk inbox is hosted.

Booking: Google Calendar (EU region) when you book a spot call.

Working files during a build: encrypted local disk plus encrypted cloud backup. Client data is isolated per project.

All data processors I use are GDPR compliant and have their own DPAs available.

How long data is kept

General email correspondence: kept for as long as there is an active dialogue, then for a maximum of 12 months. You can always request deletion.

Project-related correspondence: kept for 3 years after the end of the project. This is necessary in order to document agreements and deliverables within the Danish limitation period (section 3 of the Danish Limitation Act). It is then deleted.

Booking data: deleted automatically after the meeting has taken place, except for the calendar appointment itself.

Client data during a project: personal data in project material is deleted at project completion plus a 30-day bug-fix period. The contractual basis, scope description and delivery confirmation are kept for 3 years (the limitation period), after which these are also deleted unless otherwise agreed.

Invoices and bookkeeping: kept for 5 years as required by the Danish Bookkeeping Act.

Legal basis

I process your data on the basis of:

Consent (GDPR Art. 6(1)(a)): when you contact me or book a call yourself.

Contract (GDPR Art. 6(1)(b)): when we have an agreement for a prototype or build.

Legal obligation (GDPR Art. 6(1)(c)): for bookkeeping and tax purposes.

Your rights

You have the right to:

  • Access the data I hold about you
  • Have incorrect data rectified
  • Have your data erased (except for data subject to bookkeeping obligations)
  • Have the processing restricted
  • Receive your data in a common format (data portability)
  • Complain to the Danish Data Protection Agency (Datatilsynet) if you believe I am processing your data unlawfully: datatilsynet.dk

Requests concerning your rights are answered within 30 days. Write to martin@algoritma.dk with the subject "GDPR request".

Changes

This policy may be updated when processes or systems change. Material changes are notified by email to active clients.

Last updated: 2026-05-05