Website privacy · Effective 4 October 2026
Clear about what happens.
How Techbase handles information when you visit this website or get in touch.
Who is responsible
The data controller is techbase, a sole proprietorship operated by Dan Larsen, CVR 21663948, C/O Dan Larsen, Gråspurvevej 15, 3. 2, 2400 København NV, Denmark.
For questions or privacy requests, email info@techba.se or use the website form.
When you contact us
We use the email address, selected topic and message you provide to understand your enquiry and reply. The form sends these details through Mailjet to our fixed recipient, info@techba.se. Our inbox and replies use Google Workspace. Please include only information needed for your enquiry.
The website does not keep a contact-message database or save messages to disk. It sends messages directly, with no queue or automatic retry. There are no attachments, automatic replies or marketing messages, and email open and click tracking are disabled. A sending confirmation means Mailjet accepted the message, not that it has reached the inbox.
Keeping the website safe
Your IP address is processed to serve the website and limit contact-form abuse. The form uses bounded, temporary IP-based buckets in server memory; these reset when the server restarts. The IP address is not included in the contact email. Application contact-error logs contain failure categories and status codes, not message contents or email addresses.
Operational statistics
We collect server request counts, response status and error counts, totals for known routes, response durations and coarse client categories such as browser or bot. These help us understand reliability and investigate problems, including contact-form failures. Unknown paths are grouped into a single unmatched category.
These statistics do not store raw IP addresses, raw browser identification strings (User-Agent), query strings, cookies, request headers, contact messages or email addresses. These server statistics are separate from the frontend statistics described below. We do not use advertising or third-party analytics.
Aggregate statistics are retained without a scheduled age-based deletion period. A separate recent-problem history contains at most 200 sanitized problem requests; newer problems replace older entries when that limit is reached. This is a count limit, not a promise to delete entries after a fixed number of days.
Separately, we keep a filtered sample of recent client-error paths (400–499 responses) in server memory to diagnose broken links and common probes. Each observation contains only a filtered pathname, HTTP method, response status and time. Ordinary pathnames stay readable to help distinguish broken links and scanner requests. Identifier-shaped segments (such as numbers, email addresses, UUIDs and long tokens) and suffixes after sensitive contexts such as auth, password reset or verification are redacted. Encoded or malformed paths are rejected. These filters cannot recognize every possible secret in an arbitrary pathname. We do not collect query strings, fragments, IP addresses, User-Agent, headers, cookies, referrers or contact content in this sample. Access is restricted to global administrators using a password session.
This memory sample holds at most 200 observations from the last seven days. Expired entries are removed on reads and writes and by periodic cleanup every minute. All observations are cleared when the server restarts. Collection begins after this update; earlier unmatched paths cannot be recovered. Existing housekeeping and /assets/ exclusions also apply, and the sample endpoint itself is excluded. This sample is separate from the persistent aggregates and recent-problem history described above and does not change their retention.
Cookieless frontend statistics
A self-hosted frontend tracker counts views of our public pages, clicks on the ten homepage project rows, and contact forms accepted for delivery. These are observations, not counts of unique people or sessions. Private, sign-in, administration and unknown pages are excluded, and query strings and fragments are never analytics dimensions.
We store daily page and registered-event totals and reduced external referrer origins, such as https://example.com, without the referring path, query or fragment. External origins have a fixed daily limit; additional origins are grouped as “Other”. Project clicks use only a fixed project label. An accepted contact form records only the event and the constant area “contact”, never your email, message, selected topic or provider data.
The tracker creates no analytics identity, cookies or browser storage. Raw IP addresses, browser identification strings and individual page or event records are not stored in analytics. IP addresses are used temporarily in memory to bound ingestion requests. Collection is best effort, so blocked requests or capacity limits can leave counts incomplete.
Frontend statistics are kept for a rolling 90-day UTC window. Cleanup runs on startup and at least once each UTC day while the worker runs, retrying after failures. Only global administrators using an operator password session can read the report. This retention is separate from server statistics and the recent 4xx sample above.
Operator accounts and essential cookies
Private operator accounts provide access to administration, server statistics and frontend statistics. There is no public signup. Operator email addresses, password hashes and session records support this access. Only global administrators can view these statistics.
Ordinary anonymous visits do not set cookies. Signing in sets an essential session cookie, protected with Secure, HttpOnly and SameSite safeguards in production. It is used for authentication, not visitor tracking. Sessions expire after seven days. Logout invalidates the current session; changing a password invalidates other sessions, while operator password recovery invalidates all sessions. Authentication records have no separate scheduled age-based deletion policy.
Why we use this information
Our legitimate interests are answering enquiries, understanding public-page and project interest, monitoring service reliability, and keeping the website, operator access and contact service secure (GDPR Article 6(1)(f)). When you ask about entering a contract, we also process the information needed to take steps at your request before that contract (Article 6(1)(b)). Where records must be kept to meet a legal obligation, Article 6(1)(c) applies.
How long we keep correspondence
We delete contact-form messages and replies within 12 months after the conversation is resolved, unless they are needed for a contract or a legal obligation. Dan manages this deletion in the mailbox; it is not an automated website deletion job. Records kept for a contract or legal obligation are retained only for as long as that purpose requires.
This commitment covers our handling of correspondence. Email providers also process delivery records and backups under their own terms; we do not promise a specific provider backup or transaction-log deletion period.
Providers and international processing
Mailjet provides email delivery and Google Workspace provides the mailbox. Their processing may involve locations outside the EU/EEA. Their published data-processing terms describe subprocessors and applicable international-transfer safeguards, including standard contractual clauses: Mailjet data-processing terms and Google Workspace data-processing terms. These links do not imply that our data is stored in a particular region.
Your rights
You can request access to, correction or deletion of your personal data, and restriction of its use. You can object to processing based on legitimate interests. Where applicable, you can request a portable copy of information processed for a contract. These rights depend on the circumstances; contact us using the details above so we can help and verify the request appropriately.
You can also complain to Datatilsynet, the Danish Data Protection Agency.
A Minor Idea is separate
This policy covers the website and website correspondence. A Minor Idea is available as a free TestFlight beta. Its separate privacy policy, effective 6 October 2026, explains on-device music, optional diagnostic sharing, consent, and report deletion. App support and privacy requests go to support@techba.se.
A diagnostic report quoted in website correspondence remains subject to the app policy’s deadline: the report and accompanying email, including the sender address, are deleted when no longer needed and no later than 12 months after receipt, or earlier on request. A later support resolution does not extend that deadline.
A Minor Idea privacy policy →