Skip to main content

Home / Privacy Policy

Privacy Policy

Last Updated: March 14, 2026

1. Introduction & Controller Identity

This Privacy Policy explains how Fj-Holding ApS (“we”, “us”, “our”) collects, uses, and protects personal data when you visit our website and when you contact us about our business and professional development education programmes. This policy also describes the choices available to you, including cookie preferences, and the rights you may have under applicable data protection laws.

Data controller (GDPR): Fj-Holding ApS, Hesselskovvej 73, 8620 Kjellerup, Denmark. You can reach us at [email protected].

We do not appoint a Data Protection Officer (DPO) for routine operations. If you have a privacy question, you can contact us using the email above and we will route the enquiry to the appropriate person.

This website and our programmes are designed for learners and organisations across Canada. Our registered office and corporate administration are based in Denmark, and we follow GDPR-aligned practices for the handling of enquiry data.

2. Personal Data We Collect

We collect personal data in a limited, purpose-driven way. The specific data we collect depends on how you interact with the website and whether you submit a request for information or an enrolment enquiry.

  • Identity and contact data: name, email address, phone number, and any organisation name you include in your message.
  • Enquiry and form content: your message, programme selection, scheduling constraints, and any details you choose to provide about learning goals or organisational context.
  • Technical data: IP address, browser type and version, device and operating system information, language settings, and approximate location derived from IP (country/region-level).
  • Usage data: pages visited, time spent on pages, referrer information, and click paths on the site (where analytics is enabled by consent).
  • Cookies and identifiers: first-party cookies used for session continuity and consent storage, and third-party identifiers when analytics and marketing cookies are enabled by consent (see Section 4).
  • Conversion events: events that help us understand whether a visitor submitted a form or reached a thank-you page (when analytics and/or marketing cookies are enabled by consent).

We do not intentionally collect special-category data (such as health information, political opinions, religious beliefs), financial account details, or government identification numbers through this website. Please avoid including sensitive information in your message. If sensitive data is included voluntarily, we will handle it with additional care and limit access as described in this policy.

3. Why We Process Data & Legal Basis (GDPR Art. 6)

We process personal data only when we have a lawful basis. The purposes and bases below are typical for a lead-generation and consultation-request website used to coordinate educational participation.

3.1 Responding to enquiries and programme requests

When you submit a form or contact us, we process the information to respond, recommend a programme track, clarify scope and timing, and provide the information you requested. Lawful basis: GDPR Art. 6(1)(b) (steps prior to entering into a contract) and, where applicable, Art. 6(1)(a) (consent) when you provide information voluntarily and consent to be contacted.

3.2 Analytics and website improvement

If you consent, we may use analytics to understand how visitors use the site, which pages are most helpful, and where content can be improved. We use this information in aggregate to improve navigation, clarity, and performance. Lawful basis: GDPR Art. 6(1)(a) (consent).

3.3 Marketing and advertising measurement

If you consent, we may use marketing cookies and related technologies to measure advertising performance, understand attribution, and build audiences for relevant messaging. This can include remarketing and lookalike audiences created from website interactions. Lawful basis: GDPR Art. 6(1)(a) (consent).

3.4 Security, abuse prevention, and service integrity

We process certain technical data (such as IP address and log data) to protect the website, prevent fraud, reduce spam, and investigate suspicious activity. This includes rate limiting and filtering that helps keep forms usable for legitimate enquiries. Lawful basis: GDPR Art. 6(1)(f) (legitimate interests in securing the website and preventing abuse).

3.5 Legal compliance

In limited circumstances we may process personal data to meet legal obligations, such as responding to lawful requests or maintaining records required by applicable law. Lawful basis: GDPR Art. 6(1)(c) (legal obligation).

3.6 Automated decision-making (GDPR Art. 22)

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects. Any programme guidance we provide is based on the information you share and is reviewed by a human.

4. Cookies & Tracking Technologies

Cookies are small text files stored on your device. We also use similar technologies such as pixel tags and, in some cases, server-side event forwarding to help measure website usage and advertising performance. Cookie categories on this site match the choices you can make in the cookie banner and preferences panel.

4.1 Essential cookies (always active)

Essential cookies are required for the site to function. They include session continuity and your cookie preference storage. Essential cookies do not require consent. Typical retention ranges from session-only to 12 months depending on the cookie’s purpose.

4.2 Analytics cookies (consent required)

With your consent, we may use Google Analytics 4 (GA4) to understand usage and improve the site. GA4 uses cookie identifiers such as _ga and _ga_XXXXXXXXXX. We configure analytics to follow privacy-oriented settings where available, including IP anonymization and limited data retention. Analytics data retention is set to 14 months.

4.3 Marketing cookies (consent required)

With your consent, we may use marketing technologies to measure advertising performance and show relevant messaging. Common cookies include _gcl_au (Google Ads conversion linker) and Meta Pixel identifiers such as _fbp and _fbc (when a click ID exists). These cookies may be used for remarketing, conversion attribution, and audience building. Cookie lifetimes typically range around 90 days, depending on the provider.

4.4 Beyond cookies

Some measurement is performed using pixel tags or event APIs. Where used, such systems may collect device and browser signals (for example IP address and User-Agent) to measure conversions and improve delivery of advertising. Where identifiers are transferred in a server-side context, they may be hashed before transfer where applicable.

You can read more in our Cookies Policy. You can also change your preferences at any time via “Manage cookie preferences” in the footer.

5. Consent (EEA/UK)

Users in the EEA and UK receive a consent notice under GDPR and UK GDPR. Analytics and marketing cookies activate only after explicit, informed, freely given consent (GDPR Art. 6(1)(a)). Your choice is recorded in the cookie_consent browser cookie (12 months).

You can withdraw or modify consent at any time by using “Manage cookie preferences” in the footer or by clearing cookies in your browser. Withdrawal does not affect the lawfulness of processing based on consent before it was withdrawn.

6. Sharing With Advertising & Service Partners

We share data only as necessary to operate the website, respond to enquiries, and (where consented) measure analytics and advertising. We do not sell personal data.

We do not permit these providers to use site data for their own independent commercial purposes. Providers may process limited information as needed to provide their services, and they may act as processors or independent controllers depending on the service and configuration.

7. International Transfers

We are established in Denmark, and some service providers may process data outside the EEA/UK, including in the United States. Where transfers occur, we rely on appropriate safeguards. These may include:

  • EU–US Data Privacy Framework (where applicable), including the UK Extension to the DPF and the Swiss–US DPF.
  • Standard Contractual Clauses (EU 2021/914) as a fallback mechanism.
  • UK International Data Transfer Addendum (IDTA) as a fallback mechanism.

If you want additional information about safeguards used for a particular transfer, contact us at [email protected].

8. Retention

We keep personal data only as long as necessary for the purposes described in this policy:

  • Contact submissions and programme enquiries: up to 2 years from the last interaction.
  • Analytics data: 14 months (where enabled by consent).
  • Marketing cookies: according to the cookie lifetime set by the provider (often around 90 days) and your consent settings.
  • Email correspondence: for the duration of the relationship plus 1 year, unless a longer period is required for legal reasons.
  • Server and security logs: typically 90 days unless a longer retention is necessary to investigate incidents.
  • Cookie consent record: up to 3 years for audit and compliance evidence.
  • Legal or tax records: retained as required by law (commonly 6–10 years for certain records, where applicable).

When retention periods end, we delete or anonymize data in a reasonable timeframe, taking into account backup cycles and security needs.

9. Your Rights (GDPR & UK GDPR)

If GDPR or UK GDPR applies to your data, you may have rights including:

  • Right of access (Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure (Art. 17)
  • Right to restriction of processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object (Art. 21)
  • Right to withdraw consent at any time (Art. 7(3))
  • Right to lodge a complaint with a supervisory authority (Art. 77)

To exercise your rights, email [email protected]. We typically respond within 30 days. For complex requests, this period may be extended by up to 60 additional days, in which case we will explain why.

Supervisory authority references: EU guidance: https://edpb.europa.eu. Denmark: The Danish Data Protection Agency (Datatilsynet): https://www.datatilsynet.dk. UK: ICO: https://ico.org.uk.

10. Children

This website is not directed at individuals under 16. We do not knowingly collect personal data from minors. If we learn that we have collected personal data from a child under 16 without verifiable parental consent, we will delete it promptly.

11. Do Not Track

This website does not respond to “Do Not Track” (DNT) browser signals. Some third-party providers may have their own handling of DNT and similar signals.

12. Data Deletion Requests

You can request deletion of your data by emailing [email protected] with the subject line “Data Deletion Request”. We may need to verify your identity to protect against unauthorized deletion requests. We aim to complete deletion within 30 days, unless a longer period is necessary for complex cases or lawful retention requirements.

In some cases we may need to retain limited information (for example, consent records or security logs) where required by law or for legitimate interests such as fraud prevention.

13. Business Transfers

If Fj-Holding ApS is involved in a merger, acquisition, financing, reorganization, asset sale, or insolvency, personal data may be transferred to a successor entity or other party as part of that transaction. If such a transfer materially changes how personal data is used, we will provide notice on the website.

14. California (CCPA / CPRA)

If you are a California resident, you may have rights under the California Consumer Privacy Act, as amended by the CPRA, including the right to know, delete, correct, and opt out of sale or sharing of personal information.

In the past 12 months, the categories of personal information we may have collected include: identifiers (such as name, email address, IP address, and cookie IDs), internet or network activity (such as pages viewed and interactions), and inferences (such as interests based on page interactions, when marketing cookies are enabled by consent).

We do not sell personal information as defined by the CCPA. We may share information for cross-context behavioral advertising when marketing cookies are enabled. California residents may opt out of sharing for targeted advertising via the cookie preferences panel (“Manage cookie preferences”) in the footer.

To submit a request, email [email protected] with the subject line “California Privacy Request”. We will verify your identity before fulfilling the request. Authorized agents may submit requests with written proof of authorization.

15. Virginia (VCDPA)

If you are a Virginia resident, you may have rights under the Virginia Consumer Data Protection Act, including the right to access, correct, delete, and obtain a copy of personal data, and to opt out of targeted advertising.

We do not sell personal data. We do not engage in profiling that produces legal or similarly significant effects.

To submit a request, email [email protected] with the subject line “Virginia Privacy Request”. If you believe a request was denied in error, you may appeal by emailing with the subject “Appeal of Refusal — Privacy Request”. We will respond to appeals within 60 days. If unresolved, you may contact the Virginia Attorney General.

16. Nevada

Nevada residents may submit a verified opt-out request by emailing [email protected] with the subject line “Nevada Do Not Sell Request”. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.

17. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service providers. Material changes will be announced via a notice on the website at least 14 days before taking effect. The “Last Updated” date at the top indicates when this policy was last revised.

18. Contact

If you have questions about this Privacy Policy or our data practices, contact:

Fj-Holding ApS
Hesselskovvej 73
8620 Kjellerup, Denmark
Email: [email protected]
Phone: +45 86 88 50 24

If you prefer postal contact, you may write to the address above. For map directions, use: Hesselskovvej 73, 8620 Kjellerup, Denmark.