Legal · Last updated 11 August 2026

Privacy policy

This policy describes how Black Team ApS handles personal data when you visit blackteam.dk or get in touch with us. It is written to match what the site actually does — not what a template usually describes.

In short

The site collects nothing on its own

blackteam.dk is a static website. There are no user accounts, no tracking and no third parties who learn that you were here. We process only what you choose to write or say to us.

  • We set no cookies and use no analytics or tracking tools.
  • The typefaces are served from our own domain, so your IP address is never passed on to Google Fonts or anyone else.
  • There are no embedded maps, videos, chat widgets or social feeds on the site.
  • The contact form sends nothing by itself — it opens your own mail programme with the text filled in.
  • We never sell, rent out or exchange personal data.

Data and legal basis

What we process — and on what legal basis

We never ask for special category data, national ID numbers or payment card details through this site. If you send them anyway, we delete them.

  1. 01

    Contact form and email

    Name, company, email, phone, subject and the content of the message

    The information is used solely to answer the enquiry and, where relevant, to prepare a quote. The legal basis is our legitimate interest in being able to respond to enquiries and run a business, under Article 6(1)(f) of the General Data Protection Regulation. If the enquiry leads to an agreement, the data is processed as part of entering into and performing that agreement, under Article 6(1)(b).

  2. 02

    Contact by telephone

    Number, name and whatever notes the conversation gives rise to

    We do not record calls. If you ring us, the number and a short note may be kept so that we can follow up. The legal basis is the same as above.

  3. 03

    Technical log data held by our hosting provider

    IP address, time, page requested, browser type

    Every web server records this as part of ordinary operation, troubleshooting and security. We do not use log data to follow visitors, we produce no statistics from it and we do not combine it with other information. The legal basis is our legitimate interest in secure and stable operation, under Article 6(1)(f).

Retention and sharing

How long, and who sees it

Retention

Enquiries that do not lead to an engagement are deleted no later than 12 months after the last correspondence. If you become a client, we keep the correspondence for as long as the client relationship lasts, and after that only for as long as it is necessary to document the agreement. Accounting records are kept for five years from the end of the financial year they relate to, as required by the Danish Bookkeeping Act.

Disclosure

We do not pass personal data to third parties for marketing purposes — and we never sell it. Two suppliers process data on our behalf as data processors: our email provider and the host of this website. They may not use the data for their own purposes. Beyond that, we disclose data only where the law requires it.

Security

The site is served over HTTPS. Correspondence and material from engagements are treated confidentially and kept separate from ordinary post, and access is limited to those who need it. Never put drawings, access arrangements or known weaknesses in an ordinary email — we agree a secure channel once we have spoken.

Your rights

What you can require — and how

Under the General Data Protection Regulation, data subjects have a number of rights in relation to us. Write to info@blackteam.dk and we will normally reply within a month. Exercising these rights is free of charge.

  • Access. You can be told what data we process about you, and receive a copy.
  • Rectification. If something is wrong or incomplete, we correct it.
  • Erasure. You can ask to have data deleted once we no longer have a legitimate reason to hold it.
  • Restriction. In certain cases you can ask us to restrict processing while an objection is being handled.
  • Objection. You can object to processing carried out on the basis of our legitimate interest.
  • Data portability. In certain cases you can receive your data in a common, machine-readable format.

We do not currently obtain consent for anything, because we do nothing that requires it. Should that change, consent can always be withdrawn, without affecting the lawfulness of processing carried out up to that point.

Next step

Test the assumptions.
Find the way in.

A short conversation is enough to establish whether a Security Assessment or a full penetration test suits you best. It costs nothing and commits you to nothing.