How we handle your data.
Varn Industries is a defence company with a small website and a small inbox. We hold the minimum amount of personal data we can get away with, we hold it under European law, and we are direct about what we do with it. This page is the long version.
Controller and supervisory authority
- Data controllerprivacy@varnindustries.com
Varn Industries ApS · Copenhagen, Denmark. Our DPO function is held by the founder until headcount makes a dedicated hire sensible.
- Supervisory authorityDatatilsynet
The Danish Data Protection Agency. You can complain about us to them — directly and without telling us first.
- Last revised2026.05.23
Version v0.1. Material changes are noted in the changelog at the bottom of this page.
What this page actually says.
The legally precise version is below. If you only have a minute, read these four lines — they are accurate.
- 01
We do not run third-party analytics on the public site. No Google Analytics. No Meta pixel. No session-replay heatmaps.
- 02
We do not sell, rent, or share personal data with advertisers. Ever. The business does not need it and the cost of doing so is not worth what it would buy.
- 03
We process under EU and Danish law. All routine processing happens inside the EEA. Anything that briefly leaves it is named on this page.
- 04
If you write to us, a small named team reads the email. If you ask us to delete what we hold on you, we delete it.
Categories, purpose, legal basis, retention.
One row per kind of personal data we ever touch through the public site or our inboxes. If you see a category about Varn somewhere else, check it against this table first.
- D-01Category
Inbound email
Your name, email address, signature block, the words you sent us.
Purpose & basisTo read your message and write back.
Legitimate interest (Art. 6(1)(f)) — answering a message you sent us.
Retention24 months from last reply, then archived or deleted.
- D-02Category
Briefing list (newsletter)
Email address you typed into the briefing dialog. No name required.
Purpose & basisTo send the very occasional Varn briefing dispatch.
Consent (Art. 6(1)(a)) — given when you submit the form. Withdraw at any time.
RetentionUntil you unsubscribe. One-click unsubscribe in every dispatch.
- D-03Category
Recruiting · CVs and applications
CV, cover letter, links you sent, anything you put in the form.
Purpose & basisTo consider you for a role and to talk to you about it.
Steps prior to a contract (Art. 6(1)(b)) and consent for unsolicited material.
Retention12 months after the role closes, unless you ask us to delete sooner.
- D-04Category
Server logs (hosting)
IP address, user-agent string, timestamp, requested URL. Standard web-server fields.
Purpose & basisSecurity, abuse handling, uptime diagnostics. Not analytics.
Legitimate interest (Art. 6(1)(f)) — keeping the site standing up.
Retention30 days rolling, then purged at the edge.
- D-05Category
Strictly necessary cookies
Session id used by the briefing dialog. No tracking cookies.
Purpose & basisTo make the site work. Not measurement.
Strictly necessary — outside the consent requirement of the ePrivacy regime.
RetentionSession-scoped. Cleared when you close the browser.
- D-06Category
Press desk · attributed quotes
Your name, outlet, byline, and anything you put on the record with us.
Purpose & basisTo attribute correctly and to track what we have said to whom.
Legitimate interest (Art. 6(1)(f)) — accurate press handling.
RetentionKept on file. Published quotes are public record.
- D-07Category
Vendor and supplier contacts
Business email, name, role, company. The fields on a business card.
Purpose & basisTo run the company — invoicing, contracts, scheduling.
Contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)).
RetentionFor the life of the relationship, plus statutory retention for accounting.
- D-08Category
What we do not collect
Location data, device fingerprints, social graph, cross-site behaviour.
Purpose & basisListed for absence of doubt. We do not gather any of this.
Not applicable.
RetentionNot applicable.
Sub-processors, named in full.
Every party that ever touches personal data on our behalf, with the legal mechanism for any transfer outside the EEA. Updated when we add or remove a vendor.
- S-01
Vercel
EU edge regions by routing preference.Web hosting and edge delivery for varnindustries.com.
TransferControl-plane in the United States. Covered by EU Standard Contractual Clauses (SCCs) and the EU–US Data Privacy Framework.
NotesSees IP and request metadata. No form-submission storage.
- S-02
Fastmail
Primary infrastructure in Australia, secondary in the United States.Mailbox provider for the @varnindustries.com inboxes.
TransferTransfer outside the EEA. Covered by SCCs in their data processing addendum.
NotesHolds email at rest. We will revisit this choice as the company grows.
- S-03
Cloudflare
Global anycast network with EU points of presence.DNS, edge protection, and TLS termination for varnindustries.com.
TransferTransfer outside the EEA possible at the edge. Covered by SCCs.
NotesSees request metadata in transit. No persistent personal-data storage on our behalf.
- S-04
In-house tooling
EU only.Recruiting, supplier records, CRM-equivalent — kept on internal systems.
TransferNone.
NotesWe will name a third-party recruiter or CRM here the day we adopt one.
What you can ask, and how we answer.
Eight rights on the left. Four operating commitments on the right. Both sides are binding on us.
- R-01Access
Ask for a copy of what we hold on you. We will return it as plain text or PDF, your call.
- R-02Rectification
Tell us when something we hold on you is wrong. We will correct it.
- R-03Erasure
Ask us to delete what we hold on you. We will, unless a legal duty (e.g. accounting law) requires us to keep something specific. We will tell you which.
- R-04Restriction
Ask us to stop processing while a dispute is open. We will park the data and confirm.
- R-05Portability
Ask for what you gave us in a machine-readable form. We will deliver JSON or CSV by default.
- R-06Objection
Object to any processing we run under legitimate interest. We will reassess and either stop or explain why we believe we may continue.
- R-07Withdraw consent
Where processing rests on consent (e.g. the briefing list), you can withdraw it at any time. One click in the email, or a one-line message to us.
- R-08Complain
You can lodge a complaint with Datatilsynet (datatilsynet.dk) without going through us first. We would prefer you write to us — but it is your call.
- 01
We reply to every rights request within 30 days. Usually inside one week.
- 02
We will verify it is you before we hand over personal data. No security theatre, just enough to be sure.
- 03
We do not charge for rights requests. We may charge for repeated or manifestly unfounded ones, in line with Art. 12(5).
- 04
If we refuse a request in part, we will tell you which part, and why, and how to appeal it.
Send rights requests to privacy@varnindustries.com. Title the email with the right you are exercising — it gets us there faster.
No banner. Because there is nothing to ask permission for.
We do not set tracking cookies on the public site. There is therefore no consent banner — the ePrivacy regime only requires one for storage that is not strictly necessary.
- Set on the public site
Session id · strictly necessary
Issued by the briefing dialog to remember that you submitted a form during the same browser session. First party. Cleared when you close the tab.
- Not set on the public site
Analytics, ads, profiling, fingerprinting
Listed for absence of doubt. We do not use Google Analytics, the Meta pixel, LinkedIn Insight, Hotjar, FullStory, or any equivalent.
If we ever introduce non-essential storage, this section will change first and a consent surface will appear before anything is stored. We do not believe we are quietly collecting more than this — and if we are, we have a bug, which we want to know about.
The fewer rooms, the fewer doors.
Operational security around classified or programme data is its own discipline and is not covered here. This section covers the everyday handling of personal data on varnindustries.com and in the company inboxes.
- 01Hold less than we must
The strongest data protection is the data we never collected. Every form on the site asks for fewer fields than feels reasonable. That is the point.
- 02Encryption in transit and at rest
TLS 1.3 across the public site. At-rest encryption on inbox and storage providers, by them, on managed keys.
- 03Access on a need basis
Inboxes are accessed by named people. The list is short. It grows only when a hire makes it necessary.
- 04Breach notification
If a breach is likely to result in a risk to your rights, we will notify Datatilsynet inside 72 hours of becoming aware (Art. 33) and notify affected individuals directly (Art. 34) — by email, in plain language, with what happened and what we are doing about it.
Suspect a vulnerability on the site or in our handling? Write to privacy@varnindustries.com with a description and a way to reach you. We acknowledge inside 48 hours.
When this page changes, we log it.
Material changes — new processors, new categories of data, new legal bases — get a row. Typos do not. If a change affects you, we will email the briefing list before it goes live.
- C-012026.05.23
Initial publication. Version 0.1 of this notice — drafted on the day the public site went live.
Empty rows reserved for future entries. We would rather show you that the log is short than pretend it is full.
Write to the inbox that reads itself.
For anything on this page — a rights request, a security report, a question about a vendor we have named, or a correction to a fact we have published — privacy@varnindustries.com is the address. Routed to a named human, not a triage queue.
If you would rather take it up with the regulator directly, that is Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby. You do not need our permission, and we do not need to be told first.