Skip to main content

Privacy Policy

Last Updated: February 18, 2026

1. Introduction and Data Controller Identity

This Privacy Policy explains how F.J. Holding ApS ("we," "us," or "our") collects, uses, stores, and protects your personal data when you visit our website or use our educational services. We are committed to processing personal data lawfully, fairly, and transparently in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Danish Data Protection Act (Databeskyttelsesloven).

Data Controller:

This Privacy Policy is effective as of February 18, 2026. By using our website, you acknowledge that you have read and understood this Privacy Policy. If you have questions regarding your personal data, contact us using the details above.

2. Personal Data We Collect

We collect the following categories of personal data, depending on how you interact with our website and services:

Identity and Contact Data: Full name, email address, phone number, and any other contact information you provide through our inquiry and registration forms.

Form Content: Messages, programme selection preferences, learning goals, professional background information, and any other details you include in inquiry or registration submissions.

Technical Data: IP address, browser type and version, device type and operating system, screen resolution, language preferences, and time zone setting. This data is collected automatically when you visit our website.

Usage Data: Pages visited, time spent on pages, click paths, referral source (the website you came from), navigation behaviour, and scroll depth. This helps us understand how visitors interact with our content.

Cookies and Identifiers: First-party and third-party cookies, pixel tags, and similar tracking technologies as detailed in Section 4 below and in our Cookie Policy.

Conversion Events: Submission confirmations, form interactions, and button clicks related to programme inquiries.

We do not collect special-category data (health information, religious beliefs, political opinions, trade union membership, genetic or biometric data), financial account details (bank account numbers, credit card numbers), or government identification numbers unless explicitly required for a specific service and only with your explicit consent.

3. Why We Process Your Data and Legal Basis

Under GDPR Article 6, we process your personal data on the following legal bases:

Contact and Inquiry Forms — Art. 6(1)(b) Performance of Contract and Art. 6(1)(a) Consent: When you submit an inquiry or registration request, we process your data to respond to your request, provide programme information, facilitate enrolment, and deliver educational services. Your consent is also obtained through the form's consent checkbox.

Analytics — Art. 6(1)(a) Consent: With your explicit consent (provided through our cookie consent mechanism), we use analytics tools to understand website usage patterns, improve content relevance, and optimise the learning experience.

Marketing and Remarketing — Art. 6(1)(a) Consent: With your explicit consent, we may use marketing cookies and pixel technologies for remarketing, conversion tracking, and creating custom or lookalike audiences on advertising platforms.

Security and Fraud Prevention — Art. 6(1)(f) Legitimate Interest: We process technical data to protect our website against unauthorized access, spam submissions, malicious attacks, and to maintain the security and integrity of our systems. Our legitimate interest is the safe operation of our digital infrastructure.

Legal and Tax Obligations — Art. 6(1)(c) Legal Obligation: We may retain certain data where required by Danish tax law, accounting regulations, or other applicable legal requirements.

Automated Decision-Making (Art. 22): We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on individuals.

4. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies, organised into three categories. Full details, including individual cookie names and retention periods, are available in our Cookie Policy.

Essential Cookies (No Consent Required — Always Active):

  • _site_session: Maintains session continuity during your visit. First-party. Retention: session.
  • cookie_consent: Stores your cookie consent preferences. First-party. Retention: 12 months.
  • CSRF protection tokens where applicable.

Analytics Cookies (Consent Required):

  • Google Analytics 4 with IP anonymisation enabled. Data retention: 14 months.
  • _ga: GA4 user identifier. Third-party. Retention: 2 years.
  • _ga_XXXXXXXXXX: GA4 session state (where XXXXXXXXXX is the 10-character GA4 measurement ID). Third-party. Retention: 2 years.

Marketing Cookies (Consent Required):

  • _gcl_au: Google Ads conversion linker. Third-party. Retention: 90 days.
  • _fbp: Meta Pixel browser identifier. Third-party. Retention: 90 days.
  • _fbc: Meta Pixel click identifier (set when a user arrives via a Facebook click). Third-party. Retention: 90 days.

Beyond browser cookies, our site may use pixel tags (gtag.js, Meta Pixel), server-side event tracking via Meta Conversion API or Google server-side GTM (using hashed identifiers), and device identifiers derived from IP address and User-Agent string combinations.

5. Consent for Users in the EEA and United Kingdom

Users located in the European Economic Area (EEA) and the United Kingdom receive a consent notice when they first visit our website, in compliance with GDPR and UK GDPR. Marketing and analytics cookies activate only after explicit, informed, freely given consent is provided (Art. 6(1)(a)).

Your consent choice is recorded in the cookie_consent browser cookie, which is retained for 12 months. You may withdraw your consent at any time by clicking "Manage Cookie Preferences" in the website footer or by clearing your browser cookies. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.

Essential cookies do not require consent and are always active, as they are strictly necessary for the website to function.

6. Sharing With Advertising and Service Partners

We share certain data with the following categories of service providers to operate our website and deliver advertising:

Google LLC (GA4, Google Ads, Google Tag Manager, Remarketing): Cookie identifiers, usage data, conversion events, and remarketing list membership. Google's privacy policy: policies.google.com/privacy.

Meta Platforms, Inc. (Meta Pixel, Custom Audiences, Lookalike Audiences, Conversion API): Page views, conversion events, audience membership, and hashed identifiers (email, phone — where applicable and with consent). Meta's privacy policy: facebook.com/privacy/policy.

Cloudflare, Inc. (CDN and Security): IP-based threat detection and content delivery optimisation. Cloudflare's privacy policy: cloudflare.com/privacypolicy.

We do not sell personal data. These providers process data on our behalf or as joint controllers and may not use data collected from our site for their own independent commercial purposes beyond what is described in their respective privacy policies.

7. International Data Transfers

Some of our service providers (notably Google LLC and Meta Platforms, Inc.) are based in the United States. When personal data is transferred outside the EEA or the United Kingdom, we rely on the following safeguards:

  • EU-US Data Privacy Framework (DPF): Primary transfer mechanism, in effect since July 2023. Both Google and Meta are certified under the DPF.
  • UK Extension to the Data Privacy Framework: For transfers originating from the United Kingdom.
  • Swiss-US Data Privacy Framework: For transfers involving Swiss data subjects.
  • Standard Contractual Clauses (SCCs): EU Commission Decision 2021/914 — used as a fallback mechanism where the DPF does not apply or is insufficient.
  • UK International Data Transfer Agreement (IDTA): Fallback for UK-originating transfers.

We continuously monitor the legal landscape around international data transfers and will update our transfer mechanisms if regulatory changes require it.

8. Data Retention

We retain personal data only for as long as necessary for the purposes described in this policy, or as required by law. Specific retention periods:

  • Contact and inquiry form submissions: 2 years from the date of last interaction.
  • Analytics data: 14 months (Google Analytics 4 data retention setting).
  • Marketing cookies: As per individual cookie lifetimes (90 days for _gcl_au, _fbp, _fbc; up to 2 years for _ga).
  • Email correspondence: Duration of the client or educational relationship plus 1 year.
  • Server logs: 90 days.
  • Cookie consent records: 3 years (for audit and compliance purposes).
  • Legal and tax records: As required by Danish law, typically 5 to 10 years for accounting and invoice records under the Danish Bookkeeping Act (Bogføringsloven).

When data is no longer needed, it is securely deleted or anonymised so that it can no longer be associated with an identifiable individual.

9. Your Rights Under GDPR and UK GDPR

If you are located in the EEA or the United Kingdom, you have the following rights regarding your personal data:

  • Right of Access (Art. 15): You have the right to request a copy of the personal data we hold about you and information about how it is processed.
  • Right to Rectification (Art. 16): You may request that we correct inaccurate or incomplete personal data.
  • Right to Erasure (Art. 17): You may request the deletion of your personal data where there is no compelling reason for its continued processing.
  • Right to Restriction of Processing (Art. 18): You may request that we temporarily restrict processing of your data in certain circumstances.
  • Right to Data Portability (Art. 20): You may request to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
  • Right to Object (Art. 21): You may object to processing based on legitimate interests, including direct marketing.
  • Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
  • Right to Lodge a Complaint (Art. 77): You have the right to lodge a complaint with a supervisory authority.

How to exercise your rights: Send an email to [email protected] with the subject line "Privacy Rights Request." We will respond within 30 days of receiving your request. This period may be extended by up to 60 additional days for complex or multiple requests, in which case we will inform you of the extension and the reasons for the delay within the initial 30-day period.

Lead Supervisory Authority: As F.J. Holding ApS is established in Denmark, our lead supervisory authority is the Danish Data Protection Agency (Datatilsynet):

  • Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark
  • Website: datatilsynet.dk

For participants in other EU/EEA member states, you may also contact your local supervisory authority. UK residents may contact the Information Commissioner's Office (ICO) at ico.org.uk.

10. Children's Privacy

Our website and educational services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that personal data has been collected from a child under 16 without verifiable parental consent, we will take steps to delete that data promptly. If you believe we may have inadvertently collected information from a child under 16, please contact us immediately at [email protected].

11. Do Not Track Signals

This website does not respond to Do Not Track (DNT) browser signals. There is currently no universally accepted standard for how websites should respond to DNT signals. Third-party providers integrated with our site may have their own DNT handling policies, which are described in their respective privacy policies linked in Section 6.

12. Account and Data Deletion

You may request the deletion of your personal data at any time by emailing [email protected] with the subject line "Data Deletion Request." Upon verifying your identity, we will complete the deletion within 30 days.

Please note that we may retain limited data where required by law (for example, accounting records under Danish bookkeeping requirements). In such cases, the retained data will be kept only for the legally required period, access will be restricted, and it will be securely deleted once the retention obligation expires.

13. Business Transfers

In the event of a merger, acquisition, asset sale, financing arrangement, or insolvency, personal data held by F.J. Holding ApS may be transferred to a successor entity as part of the business assets. If such a transfer materially changes how your data is used, we will notify users via a prominent notice on our website before the transfer takes effect or as soon as practicable thereafter. The successor entity will be bound by the terms of this Privacy Policy until a revised policy is communicated to you.

14. California Residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with specific rights regarding your personal information.

Categories of personal information disclosed in the past 12 months:

  • Identifiers (name, email address, IP address, device identifiers) → disclosed to service providers and advertising partners.
  • Internet or network activity (browsing history, page interactions, referral data) → disclosed to analytics and advertising providers.
  • Inferences (interests, preferences derived from browsing behaviour) → disclosed to advertising partners for audience creation.

We do not sell personal information as defined by the CCPA. We do share personal information for cross-context behavioural advertising purposes. California residents may opt out of this sharing through our cookie preferences panel accessible from the website footer.

Your California rights:

  • Right to Know: Request details about the personal information we collect, use, disclose, and share.
  • Right to Delete: Request deletion of your personal information, subject to certain legal exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out: Opt out of the sale or sharing of personal information for cross-context behavioural advertising.
  • Right to Non-Discrimination: You will not receive discriminatory treatment for exercising your privacy rights.

To submit a request, email [email protected] with the subject line "California Privacy Request." Identity verification is required before processing. Authorized agents may submit requests on your behalf with written proof of authorization.

15. Virginia Residents (VCDPA)

If you are a Virginia resident, the Virginia Consumer Data Protection Act (VCDPA) grants you the following rights:

  • Right to Access: Confirm whether we are processing your personal data and access that data.
  • Right to Correct: Correct inaccuracies in your personal data.
  • Right to Delete: Request deletion of your personal data.
  • Right to Data Portability: Obtain a copy of your data in a portable, readily usable format.
  • Right to Opt-Out: Opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects.

We do not sell personal data or engage in profiling that produces legal or similarly significant effects. To submit a request, email [email protected] with the subject line "Virginia Privacy Request."

Appeals: If we decline your privacy request, you may appeal by emailing us with the subject line "Appeal of Refusal — Privacy Request." We will respond to your appeal within 60 days. If the appeal is unresolved, you may contact the Virginia Attorney General's office.

16. Nevada Residents

Nevada residents may submit a verified opt-out request by emailing [email protected] with the subject line "Nevada Do Not Sell Request." We do not currently sell personal information as defined under Nevada Revised Statutes Chapter 603A.

17. Canadian Privacy Considerations

As F.J. Holding ApS provides educational services to participants throughout Canada, we are mindful of the Personal Information Protection and Electronic Documents Act (PIPEDA) and substantially similar provincial privacy legislation. Where PIPEDA applies to our processing of personal data of Canadian residents, we comply with the following principles:

  • Accountability: F.J. Holding ApS is responsible for personal information under its control and has designated a privacy contact point ([email protected]).
  • Consent: We obtain meaningful consent for the collection, use, and disclosure of personal information. Consent may be withdrawn at any time.
  • Limiting Collection: We collect only the personal information necessary for the purposes identified in this Privacy Policy.
  • Accuracy: We take reasonable steps to ensure personal information is accurate, complete, and up to date.
  • Safeguards: Personal information is protected by security safeguards appropriate to the sensitivity of the information.
  • Openness: This Privacy Policy is publicly available and describes our policies and practices relating to personal information management.
  • Individual Access: Upon request, you will be informed of the existence, use, and disclosure of your personal information and given access to it within 30 days.

Canadian residents may file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca if they believe their personal information has been handled improperly.

18. Security Measures

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • SSL/TLS encryption for all data transmitted between your browser and our servers.
  • Access controls limiting personal data access to authorised personnel only.
  • Regular security reviews and updates to our hosting infrastructure.
  • Server-side input validation and anti-spam protections on all forms.
  • Secure data storage with encryption at rest where applicable.

While we take reasonable precautions to protect your data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, but we continuously review and improve our security practices.

19. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. Material changes will be announced via a prominent banner on our homepage at least 14 days before the changes take effect. The "Last Updated" date at the top of this page will be revised with each update. We encourage you to review this policy periodically.

20. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, you may contact us using the following details:

For privacy-specific inquiries, please use the subject line "Privacy Inquiry" to help us route your request efficiently. We aim to respond to all privacy-related inquiries within 5 business days.