Privacy Policy
Last updated: 18 February 2026
This Privacy Policy explains how personal data may be processed when you visit kristofferknudsen.dk (the “Website”).
1) Controller (who is responsible)
This Website is a personal portfolio website operated by:
Kristoffer Knudsen
Email: [email protected]
2) What this Website is for
The Website is a portfolio and career-focused site where visitors can view projects, read about my background, and find ways to contact me (email, LinkedIn, GitHub).
There is no specific intended target group, and the Website is not aimed at children.
3) What data may be processed
When you visit the Website, certain data may be processed automatically as part of normal website operation and security:
A) Technical and usage data
This can include:
- IP address
- Date and time of access
- Pages visited and request URLs
- Browser and device information (e.g., user-agent)
- Referrer information (where you came from)
- Basic performance/security events (e.g., blocked requests)
B) Communication data (only if you contact me)
If you contact me via email or through a third-party platform (e.g., LinkedIn), I will process the information you choose to share, typically:
- Your email address or profile identifier
- The content of your message
- Any information you include in your message
Note: The Website does not have a contact form, user accounts, comments, or newsletter sign-ups.
4) Cookies
I do not intentionally use cookies for advertising or marketing.
However, some services used to deliver and protect the Website (see Section 5) may use cookies or similar technologies depending on their configuration and your browser. If that happens, it is typically for security, performance, or basic measurement—not marketing.
5) Services and third parties used
The Website uses the following third-party services to operate securely and efficiently:
A) Cloudflare (CDN, security, firewall rules, analytics)
The Website uses Cloudflare for content delivery, performance, and security (including firewall rules). Cloudflare may process technical data such as IP address, request metadata, and security-related events to deliver and protect the Website.
I also use Cloudflare Analytics to understand general traffic patterns (e.g., page views, popular pages). I do not use this for advertising or profiling.
B) Google Fonts (external font loading)
The Website loads fonts from Google Fonts. This means your browser may connect to Google servers (e.g., fonts.googleapis.com / fonts.gstatic.com) and share technical data such as your IP address and browser information as part of loading fonts.
C) Links to third-party platforms (LinkedIn, GitHub)
The Website contains normal links to platforms like LinkedIn and GitHub. If you click those links, you leave this Website and their own privacy policies apply. I do not control how those platforms process your data.
6) Legal bases for processing (GDPR)
I process personal data based on the following legal grounds:
Legitimate interests (GDPR Art. 6(1)(f))
To operate, secure, and improve the Website (e.g., preventing abuse, ensuring uptime, understanding general usage).
Consent (GDPR Art. 6(1)(a))
Only where it is required and applicable. Currently, I do not run marketing tracking or profiling that relies on consent-based cookies.
7) Data retention (how long data is kept)
I keep data only as long as necessary for the purposes described:
Server/security logs (Nginx / infrastructure logs): retained for a limited period according to standard server configuration and operational needs (security troubleshooting, abuse prevention, reliability).
Cloudflare-related logs/analytics: retained according to Cloudflare’s configuration and retention practices.
Messages you send me: retained as long as necessary to respond and maintain any relevant follow-up, and then deleted or archived at my discretion.
Backups
My hosting provider maintains backups of the VPS. Backup retention and deletion are handled by the hosting provider’s backup system.
8) International data transfers
Some service providers used for delivery and analytics may process data in countries outside the EU/EEA (depending on where their infrastructure and operations are located). This can include transfers to jurisdictions with different data protection standards.
If you want more detail, you should review the privacy documentation of those providers:
- Cloudflare
- Google (Google Fonts)
9) Security measures
I take reasonable technical measures to protect the Website and reduce risk, including:
- HTTPS encryption
- Cloudflare firewall rules and security protections
- Restricted administrative access (only me)
No system is 100% secure, but I continuously aim to keep the setup sensible and hardened for a personal portfolio site.
10) Your rights
If you are in the EU/EEA, you have rights under the GDPR, including:
- Access to your personal data
- Correction of inaccurate data
- Deletion (in certain cases)
- Restriction of processing (in certain cases)
- Objection to processing based on legitimate interests (in certain cases)
- Data portability (where applicable)
To exercise your rights, contact me at [email protected].
11) Complaints
If you believe your data has been processed unlawfully, you can file a complaint with your local supervisory authority. In Denmark, this is Datatilsynet.
12) Changes to this policy
I may update this Privacy Policy from time to time. The latest version will always be available at:
/privacy-policy