Legal
Privacy Policy
How Stake Holding ApS handles personal data under Regulation (EU) 2016/679. Last updated 27 August 2026.
The short version
- We collect personal data in exactly two places: the corporate advisory enquiry form and the general contact form. Nowhere else.
- This site runs no analytics, no advertising pixel, no tag manager, no chat widget and no third-party fonts. Nothing is loaded from another company’s server.
- We do not sell personal data, and we do not disclose it to third parties for their own purposes.
- There is no mandatory consent tick-box on our forms, because consent is not the basis we rely on for answering enquiries.
- Everything runs on one server operated by Hostinger International Limited in the United Kingdom — outside the EEA, under the Commission's UK adequacy decision. Section 6 explains it.
1. Who is responsible for your data
The data controller is Stake Holding ApS, a private limited company registered in Denmark under CVR number 40320148, EU VAT DK40320148, with its registered office at c/o Atina Regnskab & Revision ApS, Kongelundsvej 50 A, st. tv., 2300 København S, Denmark.
For any question about this policy or to exercise your rights, write to contact@stakeholding.net or to the postal address above. We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR; enquiries are handled by the company’s director.
2. What we collect, why, and on what basis
This is the complete inventory. Every field below exists on a live form and in our database, and there are no others.
2.1 Corporate advisory enquiry form
All five fields are required, because each is needed to understand and answer an enquiry. The lawful basis for all of them is Article 6(1)(b) GDPR — processing necessary for steps taken at your request before entering into a contract.
| Field | Why it is necessary | Basis |
|---|---|---|
| company_name | Identifies the organisation making the enquiry. | 6(1)(b) |
| contact_email | The address we reply to. Without it we cannot answer. | 6(1)(b) |
| service_division | Routes the enquiry to the correct division. | 6(1)(b) |
| facility_scale | Determines whether the work is something we can take on. | 6(1)(b) |
| message | The substance of what you are asking us. | 6(1)(b) |
| consent_given | Records whether you ticked the optional marketing box. Not required to submit. | 6(1)(a) |
On the marketing box. It is unchecked by default, the form submits whether or not you tick it, and ticking it is the only processing on this site that rests on consent under Article 6(1)(a). You may withdraw it at any time by emailing us, and withdrawal has no effect on how we handle your enquiry. We do not operate a mailing list at present, so in practice the field records a permission we are not yet using.
2.2 General contact form
This form is open to businesses and individuals alike, including for press questions, complaints and data-protection requests. Because those are not pre-contractual steps, the basis is Article 6(1)(f) GDPR — our legitimate interest in reading and answering correspondence addressed to us. We consider this interest not to be overridden by your rights, because you chose to write to us and the data is used only to reply.
| Field | Required? | Purpose and basis |
|---|---|---|
| sender_name | Required | To address you correctly. 6(1)(f). |
| sender_email | Required | The address we reply to. 6(1)(f). |
| phone | Optional | Used only if you would rather be called than written to. 6(1)(f), for that narrower interest. Leaving it blank changes nothing, and you may object under Article 21. |
| subject | Required | Routes the message internally. 6(1)(f). |
| message | Required | The substance of your message. 6(1)(f). |
2.3 Technical data
Our web server writes an access log containing the IP address, timestamp, requested path, response status, referrer and user-agent of each request. This is necessary to operate the service securely and to investigate abuse, under Article 6(1)(f). Access logs are retained for 30 days and then deleted.
Both forms also carry a hidden anti-spam field. If it is filled in — which only an automated submission would do — the request is discarded. No personal data is stored in that case.
3. What we do not do
- We do not sell or rent personal data. There is no circumstance in which we would.
- We do not disclose personal data to third parties for those third parties’ own purposes. (We do use processors acting on our instructions — see section 5. Controller-to-processor is still a transfer, so we say so rather than promising that data never leaves us.)
- We do not profile you, score you, or make automated decisions about you.
- We run no analytics, advertising, remarketing or social-media pixels on this website at all.
- We load no fonts, scripts, stylesheets or images from another company’s servers. Our Content-Security-Policy enforces this, so if anyone ever adds a third-party script, the page breaks instead of this paragraph quietly becoming false.
4. How long we keep it
- Enquiries and messages: 24 months from our last exchange with you, then deleted.
- Where an engagement follows: correspondence forming part of the accounting record is kept for five years from the end of the financial year it relates to, as the Danish Bookkeeping Act (bogføringsloven) requires.
- Server access logs: 30 days.
- Your cookie choice: stored in your own browser until you clear it or it reaches 12 months.
5. Processors we engage
A processor is a company that handles data on our instructions and for no purpose of its own. Each is engaged under a written agreement meeting Article 28 GDPR.
- Hosting provider — operates the server this website and its database run on. Currently Hostinger International Limited, in United Kingdom.
- Email provider — carries mail sent to and from our domain. The domain’s mail is currently routed to Hostinger’s mail service, as the domain’s public MX records show. Automated outbound mail from the website itself is not yet enabled; form submissions are stored in our database and read there.
We use no customer-relationship platform, no marketing automation, no analytics vendor, no content delivery network and no third-party form service. If that ever changes, this section changes with it.
6. Where your data is processed, and transfers outside the EEA
This website, its API and its database all run on a single virtual server operated by Hostinger International Limited, located in the United Kingdom. Form submissions are written to a database on that same machine, which is not reachable from the internet.
The United Kingdom is outside the European Economic Area. Sending your data to our server is therefore a transfer to a third country under Chapter V of the GDPR, and we are required to tell you on what basis it happens.
The basis is an adequacy decision, not standard contractual clauses. On 19 December 2025 the European Commission decided, under Article 45 GDPR, that the United Kingdom ensures an adequate level of data protection. That decision runs until 27 December 2031 unless it is renewed or withdrawn earlier. In practice it means your data receives essentially equivalent protection in the UK to the protection it has in the EU, and no additional safeguard or derogation is required for the transfer.
If that adequacy decision lapses or is withdrawn, we will either move the site to an EEA-hosted server or put an Article 46 safeguard in place, and we will update this section when we do.
How we established this. We did not take it from a geo-IP database, because those routinely disagree with one another. The location was measured from inside the server itself: the RIPE registry records the address block to Hostinger International Limited in GB, and round-trip times from the machine to fixed city anchors put London at 6.5 ms against 12 ms for Amsterdam and 18 ms for Frankfurt. We do not name a city, because the measurement does not establish one.
7. Cookies and local storage
This site sets no cookies of its own. It stores one item in your browser’s local storage — your answer to the cookie banner — so that we do not ask you the same question repeatedly. Storage that is strictly necessary to provide a service you requested is exempt from the consent requirement in Article 5(3) of the ePrivacy Directive; remembering that you said no is such a case.
The full list of keys, their purpose and their lifetime is in the Cookie Policy.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Article 15);
- have inaccurate data corrected (Article 16);
- have data erased where the conditions are met (Article 17);
- restrict processing in certain circumstances (Article 18);
- receive data you gave us in a structured, machine-readable format (Article 20);
- object to processing based on our legitimate interests, including the optional telephone field on the contact form (Article 21);
- withdraw consent to marketing at any time, without affecting anything else (Article 7(3)).
Write to contact@stakeholding.net. We will respond within one month, as Article 12(3) requires. There is no charge.
If you are not satisfied, you may complain to the Danish Data Protection Agency: Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark — datatilsynet.dk. You may also complain to the supervisory authority in your own EU country of residence.
9. Security
The site is served over HTTPS. Form submissions are validated and parameter-bound on the server before they reach the database, submissions are rate-limited by IP, and database credentials are held outside the web root. Access to stored enquiries is limited to the company’s director.
No system is perfectly secure, and we are not going to claim otherwise. If you believe you have found a vulnerability in this site, please write to contact@stakeholding.net and we will acknowledge it.
10. Changes to this policy
We update this policy when what we do changes — not on a schedule. The date at the top reflects the last substantive change. Where a change materially affects how we handle data you have already given us, we will say so prominently rather than quietly amending the text.