Privacy · GDPR · Denmark

How we handle your data.

Varn Industries is a defence company with a small website and a small inbox. We hold the minimum amount of personal data we can get away with, we hold it under European law, and we are direct about what we do with it. This page is the long version.

Controller and supervisory authority

  • Data controller
    privacy@varnindustries.com

    Varn Industries ApS · Copenhagen, Denmark. Our DPO function is held by the founder until headcount makes a dedicated hire sensible.

  • Supervisory authority
    Datatilsynet

    The Danish Data Protection Agency. You can complain about us to them — directly and without telling us first.

  • Last revised
    2026.05.23

    Version v0.1. Material changes are noted in the changelog at the bottom of this page.

In one screen

What this page actually says.

The legally precise version is below. If you only have a minute, read these four lines — they are accurate.

  1. 01

    We do not run third-party analytics on the public site. No Google Analytics. No Meta pixel. No session-replay heatmaps.

  2. 02

    We do not sell, rent, or share personal data with advertisers. Ever. The business does not need it and the cost of doing so is not worth what it would buy.

  3. 03

    We process under EU and Danish law. All routine processing happens inside the EEA. Anything that briefly leaves it is named on this page.

  4. 04

    If you write to us, a small named team reads the email. If you ask us to delete what we hold on you, we delete it.

What we collect · 08

Categories, purpose, legal basis, retention.

One row per kind of personal data we ever touch through the public site or our inboxes. If you see a category about Varn somewhere else, check it against this table first.

  • D-01
    Category

    Inbound email

    Your name, email address, signature block, the words you sent us.

    Purpose & basis

    To read your message and write back.

    Legitimate interest (Art. 6(1)(f)) — answering a message you sent us.

    Retention

    24 months from last reply, then archived or deleted.

  • D-02
    Category

    Briefing list (newsletter)

    Email address you typed into the briefing dialog. No name required.

    Purpose & basis

    To send the very occasional Varn briefing dispatch.

    Consent (Art. 6(1)(a)) — given when you submit the form. Withdraw at any time.

    Retention

    Until you unsubscribe. One-click unsubscribe in every dispatch.

  • D-03
    Category

    Recruiting · CVs and applications

    CV, cover letter, links you sent, anything you put in the form.

    Purpose & basis

    To consider you for a role and to talk to you about it.

    Steps prior to a contract (Art. 6(1)(b)) and consent for unsolicited material.

    Retention

    12 months after the role closes, unless you ask us to delete sooner.

  • D-04
    Category

    Server logs (hosting)

    IP address, user-agent string, timestamp, requested URL. Standard web-server fields.

    Purpose & basis

    Security, abuse handling, uptime diagnostics. Not analytics.

    Legitimate interest (Art. 6(1)(f)) — keeping the site standing up.

    Retention

    30 days rolling, then purged at the edge.

  • D-05
    Category

    Strictly necessary cookies

    Session id used by the briefing dialog. No tracking cookies.

    Purpose & basis

    To make the site work. Not measurement.

    Strictly necessary — outside the consent requirement of the ePrivacy regime.

    Retention

    Session-scoped. Cleared when you close the browser.

  • D-06
    Category

    Press desk · attributed quotes

    Your name, outlet, byline, and anything you put on the record with us.

    Purpose & basis

    To attribute correctly and to track what we have said to whom.

    Legitimate interest (Art. 6(1)(f)) — accurate press handling.

    Retention

    Kept on file. Published quotes are public record.

  • D-07
    Category

    Vendor and supplier contacts

    Business email, name, role, company. The fields on a business card.

    Purpose & basis

    To run the company — invoicing, contracts, scheduling.

    Contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)).

    Retention

    For the life of the relationship, plus statutory retention for accounting.

  • D-08
    Category

    What we do not collect

    Location data, device fingerprints, social graph, cross-site behaviour.

    Purpose & basis

    Listed for absence of doubt. We do not gather any of this.

    Not applicable.

    Retention

    Not applicable.

Where data goes · 04

Sub-processors, named in full.

Every party that ever touches personal data on our behalf, with the legal mechanism for any transfer outside the EEA. Updated when we add or remove a vendor.

  1. S-01

    Vercel

    EU edge regions by routing preference.

    Web hosting and edge delivery for varnindustries.com.

    Transfer

    Control-plane in the United States. Covered by EU Standard Contractual Clauses (SCCs) and the EU–US Data Privacy Framework.

    Notes

    Sees IP and request metadata. No form-submission storage.

  2. S-02

    Fastmail

    Primary infrastructure in Australia, secondary in the United States.

    Mailbox provider for the @varnindustries.com inboxes.

    Transfer

    Transfer outside the EEA. Covered by SCCs in their data processing addendum.

    Notes

    Holds email at rest. We will revisit this choice as the company grows.

  3. S-03

    Cloudflare

    Global anycast network with EU points of presence.

    DNS, edge protection, and TLS termination for varnindustries.com.

    Transfer

    Transfer outside the EEA possible at the edge. Covered by SCCs.

    Notes

    Sees request metadata in transit. No persistent personal-data storage on our behalf.

  4. S-04

    In-house tooling

    EU only.

    Recruiting, supplier records, CRM-equivalent — kept on internal systems.

    Transfer

    None.

    Notes

    We will name a third-party recruiter or CRM here the day we adopt one.

Your rights · GDPR Art. 15 – 22

What you can ask, and how we answer.

Eight rights on the left. Four operating commitments on the right. Both sides are binding on us.

You can ask us toin writing
  1. R-01
    Access

    Ask for a copy of what we hold on you. We will return it as plain text or PDF, your call.

  2. R-02
    Rectification

    Tell us when something we hold on you is wrong. We will correct it.

  3. R-03
    Erasure

    Ask us to delete what we hold on you. We will, unless a legal duty (e.g. accounting law) requires us to keep something specific. We will tell you which.

  4. R-04
    Restriction

    Ask us to stop processing while a dispute is open. We will park the data and confirm.

  5. R-05
    Portability

    Ask for what you gave us in a machine-readable form. We will deliver JSON or CSV by default.

  6. R-06
    Objection

    Object to any processing we run under legitimate interest. We will reassess and either stop or explain why we believe we may continue.

  7. R-07
    Withdraw consent

    Where processing rests on consent (e.g. the briefing list), you can withdraw it at any time. One click in the email, or a one-line message to us.

  8. R-08
    Complain

    You can lodge a complaint with Datatilsynet (datatilsynet.dk) without going through us first. We would prefer you write to us — but it is your call.

How we respondbinding
  1. 01

    We reply to every rights request within 30 days. Usually inside one week.

  2. 02

    We will verify it is you before we hand over personal data. No security theatre, just enough to be sure.

  3. 03

    We do not charge for rights requests. We may charge for repeated or manifestly unfounded ones, in line with Art. 12(5).

  4. 04

    If we refuse a request in part, we will tell you which part, and why, and how to appeal it.

Send rights requests to privacy@varnindustries.com. Title the email with the right you are exercising — it gets us there faster.

Cookies & device storage

No banner. Because there is nothing to ask permission for.

We do not set tracking cookies on the public site. There is therefore no consent banner — the ePrivacy regime only requires one for storage that is not strictly necessary.

  • Set on the public site

    Session id · strictly necessary

    Issued by the briefing dialog to remember that you submitted a form during the same browser session. First party. Cleared when you close the tab.

  • Not set on the public site

    Analytics, ads, profiling, fingerprinting

    Listed for absence of doubt. We do not use Google Analytics, the Meta pixel, LinkedIn Insight, Hotjar, FullStory, or any equivalent.

If we ever introduce non-essential storage, this section will change first and a consent surface will appear before anything is stored. We do not believe we are quietly collecting more than this — and if we are, we have a bug, which we want to know about.

Security & breach posture

The fewer rooms, the fewer doors.

Operational security around classified or programme data is its own discipline and is not covered here. This section covers the everyday handling of personal data on varnindustries.com and in the company inboxes.

  • 01
    Hold less than we must

    The strongest data protection is the data we never collected. Every form on the site asks for fewer fields than feels reasonable. That is the point.

  • 02
    Encryption in transit and at rest

    TLS 1.3 across the public site. At-rest encryption on inbox and storage providers, by them, on managed keys.

  • 03
    Access on a need basis

    Inboxes are accessed by named people. The list is short. It grows only when a hire makes it necessary.

  • 04
    Breach notification

    If a breach is likely to result in a risk to your rights, we will notify Datatilsynet inside 72 hours of becoming aware (Art. 33) and notify affected individuals directly (Art. 34) — by email, in plain language, with what happened and what we are doing about it.

Suspect a vulnerability on the site or in our handling? Write to privacy@varnindustries.com with a description and a way to reach you. We acknowledge inside 48 hours.

Changelog · 01

When this page changes, we log it.

Material changes — new processors, new categories of data, new legal bases — get a row. Typos do not. If a change affects you, we will email the briefing list before it goes live.

  1. C-012026.05.23

    Initial publication. Version 0.1 of this notice — drafted on the day the public site went live.

Code
Effective
Summary

Empty rows reserved for future entries. We would rather show you that the log is short than pretend it is full.

Privacy contact

Write to the inbox that reads itself.

For anything on this page — a rights request, a security report, a question about a vendor we have named, or a correction to a fact we have published — privacy@varnindustries.com is the address. Routed to a named human, not a triage queue.

If you would rather take it up with the regulator directly, that is Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby. You do not need our permission, and we do not need to be told first.

Document · privacy.varnindustries.comv0.1Revised 2026.05.23