Privacy Policy for pastwp.com

Last updated: 17 September 2026

Items in [brackets] are being finalised and will be replaced before this page is published.

1. Controller

BestSecurity ApS, CVR 38821148, Denmark, is the data controller for personal data collected on pastwp.com. PastWP is a brand of BestSecurity ApS. Contact: hello@pastwp.com [confirm].

2. What we collect and why

Contact and quote requests. Name, company, e-mail, phone and what you write to us. Purpose: answering you and preparing an offer. Legal basis: steps prior to entering a contract (GDPR art. 6(1)(b)). Kept for [12] months after last contact, or for the duration of the customer relationship plus the period required by the Danish Bookkeeping Act (5 years from the end of the financial year).

Customer account and billing. Contact details, invoicing details, correspondence. Purpose: delivering the service and invoicing. Legal basis: contract (art. 6(1)(b)) and legal obligation (art. 6(1)(c), bookkeeping). Kept for 5 years after the end of the financial year in which the relationship ended.

Website analytics. [Tool name, e.g. Plausible / Matomo / GA4] with [IP anonymised / no cookies]. Purpose: understanding how the site is used. Legal basis: consent (art. 6(1)(a)) where cookies or similar are set, otherwise legitimate interest (art. 6(1)(f)) in a working website. [Delete the option that does not apply.]

Server logs. IP address, browser, pages requested, timestamps, kept for [30] days for security. Legal basis: legitimate interest (art. 6(1)(f)) in a secure service.

We do not sell personal data and we do not use it for profiling.

3. Recipients

Hosting and e-mail providers acting as our processors under data processing agreements, all within the EU/EEA unless stated here: [list providers and countries]. Accountants and legal advisers where necessary. Public authorities where required by law.

4. Transfers outside the EU/EEA

[None. / Where a provider is outside the EU/EEA, transfer is based on the EU-US Data Privacy Framework or the EU Standard Contractual Clauses. List them here.]

5. Your rights

You can ask for access, rectification, erasure, restriction, data portability and object to processing based on legitimate interest. Where processing is based on consent you can withdraw it at any time. Write to hello@pastwp.com. You can complain to Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, www.datatilsynet.dk.

6. Customer websites

For websites we build and host for customers, the customer is the data controller and BestSecurity ApS is the data processor. Data collected on those sites is governed by the customer's own privacy policy and our Data Processing Agreement with the customer.

7. Cookies

[If the site sets non-essential cookies: describe them, the consent banner and how to change the choice. If the site sets no cookies or only strictly necessary ones: say so in one sentence.]

8. Changes

We update this policy when our processing changes. The date at the top shows the current version.