Privacy Policy

Last updated: 18 February 2026

This Privacy Policy explains how personal data may be processed when you visit kristofferknudsen.dk (the “Website”).

1) Controller (who is responsible)

This Website is a personal portfolio website operated by:

Kristoffer Knudsen
Email: [email protected]

2) What this Website is for

The Website is a portfolio and career-focused site where visitors can view projects, read about my background, and find ways to contact me (email, LinkedIn, GitHub).

There is no specific intended target group, and the Website is not aimed at children.

3) What data may be processed

When you visit the Website, certain data may be processed automatically as part of normal website operation and security:

A) Technical and usage data

This can include:

B) Communication data (only if you contact me)

If you contact me via email or through a third-party platform (e.g., LinkedIn), I will process the information you choose to share, typically:

Note: The Website does not have a contact form, user accounts, comments, or newsletter sign-ups.

4) Cookies

I do not intentionally use cookies for advertising or marketing.

However, some services used to deliver and protect the Website (see Section 5) may use cookies or similar technologies depending on their configuration and your browser. If that happens, it is typically for security, performance, or basic measurement—not marketing.

5) Services and third parties used

The Website uses the following third-party services to operate securely and efficiently:

A) Cloudflare (CDN, security, firewall rules, analytics)

The Website uses Cloudflare for content delivery, performance, and security (including firewall rules). Cloudflare may process technical data such as IP address, request metadata, and security-related events to deliver and protect the Website.

I also use Cloudflare Analytics to understand general traffic patterns (e.g., page views, popular pages). I do not use this for advertising or profiling.

B) Google Fonts (external font loading)

The Website loads fonts from Google Fonts. This means your browser may connect to Google servers (e.g., fonts.googleapis.com / fonts.gstatic.com) and share technical data such as your IP address and browser information as part of loading fonts.

C) Links to third-party platforms (LinkedIn, GitHub)

The Website contains normal links to platforms like LinkedIn and GitHub. If you click those links, you leave this Website and their own privacy policies apply. I do not control how those platforms process your data.

6) Legal bases for processing (GDPR)

I process personal data based on the following legal grounds:

Legitimate interests (GDPR Art. 6(1)(f))
To operate, secure, and improve the Website (e.g., preventing abuse, ensuring uptime, understanding general usage).

Consent (GDPR Art. 6(1)(a))
Only where it is required and applicable. Currently, I do not run marketing tracking or profiling that relies on consent-based cookies.

7) Data retention (how long data is kept)

I keep data only as long as necessary for the purposes described:

Server/security logs (Nginx / infrastructure logs): retained for a limited period according to standard server configuration and operational needs (security troubleshooting, abuse prevention, reliability).

Cloudflare-related logs/analytics: retained according to Cloudflare’s configuration and retention practices.

Messages you send me: retained as long as necessary to respond and maintain any relevant follow-up, and then deleted or archived at my discretion.

Backups

My hosting provider maintains backups of the VPS. Backup retention and deletion are handled by the hosting provider’s backup system.

8) International data transfers

Some service providers used for delivery and analytics may process data in countries outside the EU/EEA (depending on where their infrastructure and operations are located). This can include transfers to jurisdictions with different data protection standards.

If you want more detail, you should review the privacy documentation of those providers:

9) Security measures

I take reasonable technical measures to protect the Website and reduce risk, including:

No system is 100% secure, but I continuously aim to keep the setup sensible and hardened for a personal portfolio site.

10) Your rights

If you are in the EU/EEA, you have rights under the GDPR, including:

To exercise your rights, contact me at [email protected].

11) Complaints

If you believe your data has been processed unlawfully, you can file a complaint with your local supervisory authority. In Denmark, this is Datatilsynet.

12) Changes to this policy

I may update this Privacy Policy from time to time. The latest version will always be available at:

/privacy-policy