This policy explains what personal data this website and my consultancy collect, why, how long it is kept, and what rights you have under the EU General Data Protection Regulation (GDPR) and the Danish Data Protection Act.
Who is responsible for your data
The data controller is:
Relations Security ApS (registered as Agnoletti Security ApS)
CVR 42576786
Copenhagen, Denmark
Data protection contact: dataprotection@relationssec.net
General contact: relationsec.net/contact/
The business is run by Klaus Agnoletti. There is no separate data protection officer, because the company is not required to appoint one. Privacy requests go to the address above and are handled by me personally.
No cookie banner, and why
This site sets no cookies for analytics, advertising or tracking, which is why you were not asked to consent to any. The full reasoning is on the No cookies page. Two exceptions are worth naming plainly:
- If you choose to opt out of analytics, a single functional cookie named
analytics_optoutis stored in your browser so that your visits are excluded. It contains no identifier and is set only if you ask for it. - If you log in to the site as an administrator, WordPress sets session cookies. This affects me, not visitors.
What data is collected, and on what legal basis
1. Website analytics
The site runs two cookieless analytics tools:
- Plausible Analytics, self-hosted by me at
p.relationsec.net, so the data stays on infrastructure I control inside the EU. - PostHog, on PostHog’s EU cloud region, configured without cookies.
Both record aggregate, non-identifying information: page URL, referrer, approximate country, browser and device type, screen size, and events such as outbound-link clicks and file downloads. IP addresses are used transiently to derive country and are not stored in a form that identifies you. No cross-site profile is built and nothing is sold or shared for advertising.
Legal basis: legitimate interest (GDPR Article 6(1)(f)) in understanding whether the site works, since the processing is aggregate and cookieless and does not require consent under the ePrivacy rules.
2. Contact form and email
The contact form on relationsec.net/contact/ collects the name, email address and message you submit. Submissions are emailed to me and stored in the site database. The form is protected against automated abuse by Altcha, a privacy-preserving proof-of-work challenge that runs in your browser and does not profile you.
Outbound email from the site is delivered through Google Workspace, so email you send me is processed and stored by Google as my mail provider.
Legal basis: legitimate interest, and where the message concerns a possible engagement, steps taken prior to entering a contract (Article 6(1)(b)).
3. Booking a meeting
The contact page links to a Google Calendar appointment page. If you use it, you are submitting your details to Google, and Google’s own terms and privacy policy apply to that booking. Nothing is collected by this site in that step. The link is marked as external for exactly that reason.
4. Server logs
The site is hosted with Simply.com (unoeuro) on servers in Denmark. Standard web server logs record IP address, timestamp, requested URL, response status and user agent. These are used for security, abuse handling and troubleshooting, and are retained for a short period under the host’s own log rotation.
Legal basis: legitimate interest in the security and availability of the service.
5. Client and prospect data in the course of consultancy
When you engage me for security consulting, advisory work, workshops or training, I process the contact and business information needed to deliver and invoice the work: names, work email addresses, phone numbers, job titles, company details, and correspondence. Where an engagement gives me access to your systems, logs or documents, that data is processed strictly on your instructions as a data processor under a written data processing agreement, not for my own purposes.
Legal basis: performance of a contract (Article 6(1)(b)) and, for bookkeeping records, legal obligation (Article 6(1)(c)) under the Danish Bookkeeping Act.
6. Enable Banking API (internal finance tooling)
Relations Security ApS uses the Enable Banking API to read its own company bank account information for internal bookkeeping and payment automation. This processing covers the company’s own financial data only. It involves no personal data belonging to website visitors, clients or workshop participants, and no such data is sent to Enable Banking.
Who your data is shared with
I do not sell personal data and I do not share it for advertising. Data is shared only with service providers acting on my behalf, each under a data processing agreement:
- Simply.com (unoeuro), Denmark: website and email hosting
- Google Ireland Ltd: Google Workspace email, and Google Calendar if you book a meeting
- PostHog: analytics, EU cloud region
- Altcha: form abuse protection, EU-hosted
- Visma e-conomic: accounting and invoicing
- Enable Banking: company bank data for internal finance tooling
Plausible Analytics is self-hosted, so no third party is involved in that processing. Data may also be disclosed to my accountant and auditor where required for bookkeeping, or to public authorities where I am legally obliged to do so.
Transfers outside the EU and EEA
Processing is kept inside the EU or EEA wherever I have the choice, which is why hosting is Danish, analytics is self-hosted or EU-region, and form protection is EU-hosted. Where a provider is US-linked, in practice Google and PostHog, transfers rely on the EU-US Data Privacy Framework and, where applicable, the European Commission’s Standard Contractual Clauses.
How long data is kept
- Contact form submissions and related correspondence: up to 3 years from last contact, then deleted, unless an engagement follows.
- Client engagement records and correspondence: for the duration of the engagement plus 5 years, to cover the statutory bookkeeping retention period.
- Accounting records: 5 years from the end of the financial year, as required by the Danish Bookkeeping Act.
- Analytics data: aggregate and non-identifying, retained as long as it is useful for trend analysis.
- Server logs: short-term, per the hosting provider’s rotation policy.
Your rights
Under the GDPR you have the right to:
- be told what data I hold about you and get a copy of it (Article 15)
- have inaccurate data corrected (Article 16)
- have data erased where there is no lawful reason to keep it (Article 17)
- have processing restricted while a dispute is resolved (Article 18)
- receive data you provided in a portable, machine-readable form (Article 20)
- object to processing based on legitimate interest (Article 21)
- withdraw consent at any time, where processing is based on consent
There is no automated decision-making or profiling on this site.
To exercise any of these rights, write to dataprotection@relationssec.net. I will respond within one month. I may ask you to confirm your identity first, so that I do not hand your data to someone else.
Complaints
If you are not satisfied with how I have handled your data, you can complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, datatilsynet.dk. You are welcome to raise it with me first, since most things are faster to fix directly.
Security
Security is what I do for a living, so I will spare you the boilerplate assurances and name the substance: the site is served over HTTPS only, administrative access requires two-factor authentication, the platform and plugins are kept patched, backups are taken, and client material is handled on systems I control rather than scattered across consumer cloud services. If you believe you have found a vulnerability in this site, please tell me at klaus@relationssec.net.
Changes to this policy
If this policy changes materially, the revised version is published here with a new date below. Last updated 24-08-2026.