NULDAG
Legal

Privacy policy

Last updated: 13 May 2026

1. Data controller

NULDAG ApS is the data controller for the processing of personal data described in this privacy policy.

NULDAG ApS
CVR no.: 46450604
Address:
C/O LegalDesk.dk ApS
Njalsgade 21F, 2.
2300 Copenhagen S
Denmark
E-mail: kontakt@nuldag.dk

Data protection enquiries may be sent to the e-mail address above.

NULDAG ApS has not appointed a data protection officer for the processing described in this policy. If we later appoint a data protection officer, we will update this policy with the relevant contact details.

2. What this policy covers

This privacy policy applies to visits to NULDAG's website, nuldag.dk, and to enquiries sent to NULDAG ApS using the contact details shown on the website.

The policy does not necessarily apply to the processing of information as part of customer deliveries, penetration tests, incident response, security advisory services, processing of customer log data or other consultancy services. Such processing is governed by the relevant customer agreements, data processing agreements, confidentiality agreements and any separate privacy notices.

3. Visits to the website

NULDAG's website is a static HTML website. The website has no user login, web forms, comments, database functionality, analytics, advertising, advertising pixels or social plugins.

When you visit the website, it is technically necessary for your browser and our server to exchange ordinary network information in order to deliver the page you have requested. This may include:

IP address, the time of the request, the requested page or file, HTTP/TLS technical information, and browser or user-agent information to the extent sent by your browser.

This information is used only to deliver the website and maintain the technical communication between your browser and the server. The web server is configured so that access logs and other visit logs are not written to disk. NULDAG ApS therefore does not retain server logs of ordinary website visits.

No third-party runtime services or content

Purpose: To deliver the static website, ensure technical functionality and make the website available to visitors.
Legal basis: GDPR Article 6(1)(f), concerning legitimate interests. Our legitimate interest is to operate and provide a public corporate website. The processing is very limited, technically necessary, short-lived and does not involve storage, tracking or profiling of visitors.

4. Cookies and similar technologies

NULDAG ApS does not use cookies on the website.

We also do not use analytics, tracking pixels, advertising tools, fingerprinting, social media plugins or similar technologies to identify, recognise or track visitors.

Because the website does not use cookies or equivalent tracking technologies, we do not display a cookie banner and do not obtain cookie consent.

If we later change the website so that it uses cookies, analytics, third-party content or similar technologies, we will update this policy and obtain consent where required.

5. If you contact us

If you contact NULDAG ApS, we process the personal data you provide to us. This may, for example, include your name, e-mail address, telephone number, company, position, the content of your message, meeting details and any attachments.

We ask you not to send confidential information, passwords, tokens, CPR numbers, sensitive personal data, customer data, security logs or vulnerability details by ordinary e-mail unless we have agreed an appropriate secure communication channel in advance.

If you send confidential or sensitive information to us unsolicited, we process it only to the extent necessary to handle the enquiry, establish a secure channel, comply with a legal obligation or protect our rights or the rights of others.

Purpose: To respond to your enquiry, communicate with you, hold meetings, submit offers, enter into or perform agreements and document relevant business correspondence.
Legal basis: GDPR Article 6(1)(b), if the enquiry concerns a possible or existing agreement; GDPR Article 6(1)(f), if the processing is based on our legitimate interest in responding to enquiries and operating our business; and GDPR Article 6(1)(c), if we are legally required to retain or process the information.

6. Recipients and data processors

NULDAG ApS does not sell personal data and does not disclose information about website visitors for marketing purposes.

In connection with operating the website, we use the following provider:

DigitalOcean, LLC, USA, as cloud and hosting provider and data processor for the VPS on which the website is hosted.

The server is located in DigitalOcean's FRA1 region in Frankfurt, Germany. NULDAG ApS has configured the web server so that ordinary visit data is not logged to disk on the VPS.

If you contact us by e-mail, your information will also be processed by our e-mail provider:

Proton AG, Switzerland, as e-mail provider and data processor for e-mail communication with NULDAG ApS.

NULDAG ApS uses Proton AG to receive, send and store e-mails. This means that personal data you send to us by e-mail may be processed by Proton AG as part of providing the e-mail service.

We may also share information with advisers, accountants, lawyers, public authorities, courts or other recipients where necessary to comply with legislation, handle claims or protect our rights.

7. Transfers to countries outside the EU/EEA

The website is hosted on a VPS in DigitalOcean's FRA1 region in Frankfurt, Germany. Because the hosting provider is DigitalOcean, LLC in the USA, personal data processed in connection with hosting may in some cases be transferred to or accessed from the USA or other countries outside the EU/EEA, for example in connection with operations, security, support, troubleshooting or the use of sub-processors.

For such transfers, DigitalOcean's applicable data protection terms and transfer mechanisms are used. DigitalOcean's Data Processing Agreement states that transfers to countries without an adequacy decision take place on the basis of DigitalOcean's certification under the EU-U.S. Data Privacy Framework, where relevant, and otherwise on the basis of the European Commission's Standard Contractual Clauses or other lawful transfer mechanisms.

If you contact us by e-mail, the information included in the e-mail correspondence may be transferred to or processed in Switzerland by our e-mail provider, Proton AG. Switzerland is not a member of the EU/EEA, but the European Commission has decided that Switzerland ensures an adequate level of protection for personal data. Transfers to Switzerland may therefore take place on the basis of GDPR Article 45 without additional transfer safeguards.

If DigitalOcean, Proton AG or other providers use sub-processors or make onward transfers to countries outside the EU/EEA, Switzerland or other countries with an adequacy decision, this takes place in accordance with the relevant data protection terms and appropriate transfer mechanisms, including, where relevant, the European Commission's Standard Contractual Clauses, the EU-U.S. Data Privacy Framework or other lawful transfer mechanisms.

8. Retention and deletion

For ordinary visits to the website, NULDAG ApS does not retain server logs of the visit. The technical information necessary to deliver the page is processed only temporarily as part of network communication and is not saved as a visit log by us.

Enquiries that do not result in a customer relationship or an agreement are generally deleted no later than 12 months after the latest contact, unless there is a sound reason for retaining them longer.

Correspondence and information relating to a customer, supplier or collaboration relationship are retained for as long as necessary for the relationship and thereafter for as long as necessary for documentation, bookkeeping, handling claims or compliance with legislation. Accounting records are retained for 5 years from the end of the financial year to which the records relate.

Information may be retained for longer where necessary to establish, exercise or defend legal claims.

9. Your rights

Under data protection law, you have a number of rights. These rights apply subject to the limitations and conditions that follow from the law.

You may request access to the information we process about you. You may request that inaccurate information be corrected. In certain cases, you may request deletion or restriction of processing. In certain cases, you may object to processing based on legitimate interests. In certain cases, you may request data portability.

If, exceptionally, we process information on the basis of consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

If you wish to exercise your rights, you can contact us using the contact details in section 1, including at kontakt@nuldag.dk. We may ask you for information necessary to confirm your identity and process your request. We will respond without undue delay and normally no later than within one month.

10. Complaints to the Danish Data Protection Agency

You have the right to lodge a complaint with the Danish Data Protection Agency if you believe that NULDAG ApS processes your personal data in breach of data protection law.

The Danish Data Protection Agency can be contacted at:

Danish Data Protection Agency
Carl Jacobsens Vej 35
2500 Valby
Telephone: +45 33 19 32 00
E-mail: dt@datatilsynet.dk

11. Automated decisions and profiling

NULDAG ApS does not use personal data from the website for automated decision-making or profiling.

12. Security

NULDAG ApS has designed the website according to the principle of data minimisation. The website is static, does not use cookies, does not use analytics, does not use tracking and does not retain web server logs of ordinary visits.

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse and alteration. The measures depend on the nature of the processing and may include access restrictions, system updates and limits on the information collected and retained.

13. Changes

We will update this privacy policy if we change the website's functionality, begin to use cookies, analytics, external third-party services, web forms, a CDN, reverse proxy, WAF or other technology that changes the processing of personal data.

The version in force at any given time is published on the website.