Privacy Policy
Effective date: April 15, 2026
Last updated: April 15, 2026
1. Who we are
Campfire Security ApS, CVR 44318563, a company incorporated under Danish law with registered address at Søndre Jernbanevej 32, 3400 Hillerød, Denmark (“we,” “us,” or “our”), acts as the data controller for the purposes of applicable data protection laws, including the General Data Protection Regulation (EU) (the “GDPR”).
- Email: security@campfiresecurity.dk
- Postal Address: Søndre Jernbanevej 32, 3400 Hillerød, Denmark
- Visit and use the websites campfiresecurity.dk, campfiresecurity.com, campsec.dk, campsec.com, heledanmarkhacker.dk and all subdomains thereof (collectively, the “Websites”),
- Are signed up for and use our services, including our cybersecurity training platform, courses, laboratories, capture-the-flag exercises, and related educational services,
- Are signed up for our newsletter, or
- Interacting with us.
2. Definitions
Where this Privacy Policy uses the terms defined in the GDPR, those terms shall have the same meaning as in the GDPR.
3. Purpose of this Privacy Policy
The purpose of this Privacy Policy is to inform you how we handle your personal data in a lawful, fair and transparent manner in accordance with the General Data Protection Regulation (GDPR). The Privacy Policy outlines the types of personal data we collect, how it is used, the lawful basis for processing it and your rights as a data subject.
This Privacy Policy aims to fulfill our obligation under Articles 12-14 GDPR to provide clear, concise and transparent information about our data processing activities.
4. The data we collect
We collect and process the following categories of personal data in accordance with the principle of data minimization:
| Data Category | Specific Data Elements |
|---|---|
| A. Identity & Account Data | Full name, username, email address, account credentials, user identification numbers |
| B. Contact Information | Email address, postal address, telephone number, communication preferences |
| C. Profile & Social Data | Profile information, social media links, professional details, company affiliation |
| D. Learning & Progress Data | Course completion status, learning progress metrics, assessment scores, certificates awarded, experience points |
| E. Seat/License/Team Data | License assignments, team memberships, organizational hierarchies, seat allocations |
| F. Payment & Billing Data | Billing address, payment method tokens, transaction history, invoice records |
| G. Technical & Usage Data | Including but not limited to IP addresses, browser information, device identifiers, log files, behavioral data and usage patterns, data on interaction (clicks etc.) with email and services, session data, timestamps, approximate location, |
| H. Security Tokens | Authentication tokens, session identifiers, security credentials, multi-factor authentication data |
| I. Customer services data | Information provided when you contact us |
| J. Customer survey data | Information provided when responding to customer surveys, filing reviews or otherwise providing feedback on the services |
| K. AI Interaction Data | Chat messages, prompts, session logs |
Payment card details are processed exclusively by our third-party payment processor and are not stored on our systems, except where explicitly provided to us during direct communications.
Users should not include personal data in prompts submitted to the AI Mentor unless strictly necessary for the relevant learning context. This includes names, social security numbers, health data, credentials, account information, and other personally identifiable information. Data submitted to the AI Mentor is processed by Microsoft through Azure AI Foundry to generate responses and support abuse monitoring and platform safety. Such data may be retained for up to 30 days in accordance with Microsoft’s platform policies and is encrypted at rest. We only transmit the user’s prompt and limited contextual information necessary to support the AI Mentor.
4.4.1 Automatic redaction of personal data is not currently applied, as some course exercises may contain fictional personal data as part of the learning scenario, and redaction would materially reduce the functionality and service quality of the AI Mentor.
5. How we use your data
We process your personal data for the purposes and under the lawful bases specified in Section 6, which include:
- 5.1.1 Service Provision and Account Management (SAM)
- 5.1.2 Business Operations (BO)
- 5.1.3 Analytics and Improvement (AI)
- 5.1.4 Legal Compliance (LC)
6. Why we process your data (lawful basis and purposes)
| Processing Purpose | Data Categories (Section 4.2) | Lawful Basis (Article 6 GDPR) | Legitimate Interest Assessment | Purpose Category (Section 5.1) |
|---|---|---|---|---|
| Create and maintain user accounts | A, B, H | (b) Contract performance | N/A | SAM |
| Authenticate users and secure platform | A, H, G | (b) Contract performance; (f) Legitimate interests | Necessary for security; expected by users; minimal privacy intrusion | SAM |
| Deliver training services | A, D, E, G | (b) Contract performance | N/A | SAM |
| Track learning progress and award credentials | A, D | (b) Contract performance | N/A | SAM |
| Report learning progress to employers | A (identifier only), D, E | (f) Legitimate interests | Necessary for employers to assess usage of the services, if usage is mandated by a contract with the employer | BO |
| Manage licenses, billing, and invoicing | A, E, F | (b) Contract performance; (c) Legal obligation | N/A | BO |
| Send mandatory service communications | A, B | (b) Contract performance | N/A | BO |
| Send voluntary service communications | A, B, D | (f) Legitimate interests | Increases your value of the services; no marketing; opt-out offered | BO |
| Send personalized marketing communications | A, B, C, D, G | (a) Consent; | N/A | BO |
| Provide user support and troubleshooting | A, B, G, D, I | (b) Contract performance; (f) Legitimate interests | Necessary for issue resolution; restricted staff access | BO |
| Conduct platform analytics and improvement | G (aggregated), D | (f) Legitimate interests | Data aggregated/pseudonymized; no direct marketing; user expectation of service improvement | AI |
| Ensure security and prevent fraud | G, H | (f) Legitimate interests | Essential for safety; minimal, justified privacy impact. | AI |
| Comply with legal obligations | A, F, B (minimal) | (c) Legal obligation | N/A | LC |
| Provide contextual learner support through the AI Mentor | K, and limited relevant contextual learning data | (f) Legitimate interests | Necessary to help users progress in assigned course material and receive contextual support within the learning service. | SAM |
| Detect misuse, harmful prompts, and improve AI safety controls | K, G | (f) Legitimate interests | Necessary to protect platform security, prevent abuse, and maintain safe and reliable AI responses. | AI |
When you use the AI Mentor, we process your prompts and limited relevant contextual data in order to provide contextual learner support within the learning service. We do not use user prompts or responses to train or fine-tune the underlying AI model unless a separate and explicit legal basis has been established for that purpose. At present, quality improvement is limited to controlled refinement of system prompts, response constraints, and safety mechanisms.
6.2.1 We have a legitimate interest in processing limited AI Mentor data in order to detect abuse, investigate malicious or harmful prompts, maintain platform safety, and improve the quality of the AI Mentor through controlled refinement of system prompts, response constraints, and safety mechanisms. Such processing is limited to what is necessary for these purposes and does not include training or fine-tuning the underlying AI model unless a separate and explicit legal basis has been established for that purpose.
7. How we collect your data
| Collection Method | Description |
|---|---|
| Direct provision from you | When you register for an account, place orders, or voluntarily provide information |
| Direct provision from your employer | As part of our contract with your employer |
| Automated collection | Through cookies, log files, and similar technologies during website usage |
| Communications | When you contact us for support, feedback, or other communications |
| Third-party Integration | Through authorized integrations with third-party services |
9. How we store and secure your data
| Security Domain | Implemented Measures | Standards Compliance |
|---|---|---|
| Encryption | AES-256 encryption at rest, TLS 1.2/1.3 in transit, Azure-managed encryption keys | FIPS 140-2 Level 2 |
| Access Controls | Role-based access control (RBAC), multi-factor authentication, principle of least privilege | Internal security framework |
| Infrastructure Security | Distributed denial-of-service protection, intrusion detection, network segmentation | CIS18 IG1 |
| Backup and Recovery | Bi-weekly encrypted backups, 5-year retention, tested disaster recovery procedures | Automated integrity verification |
| Monitoring | Continuous security monitoring, vulnerability scanning, penetration testing | Annual third-party security assessments |
10. Data retention & deletion
| Data Category | Retention Period | Deletion Method | Legal/Business Justification |
|---|---|---|---|
| Technical logs and session data | 90 days | Automated purging | Security monitoring requirements |
| Active user accounts | Duration of service relationship plus 2 years | Secure deletion protocols | Service provision and support |
| Inactive user accounts | 2 years from last login | Scheduled deletion with 30-day notice | Business continuity, potential service resumption |
| Billing and financial records | Current year plus 5 years | Encrypted archival, then secure deletion | Danish Bookkeeping Act compliance |
| Marketing communication data | Until consent withdrawal or 12 months with no marketing communication or 3 years of user inactivity. We may, however, retain documentation for your consent for a period of up to 5 years following withdrawal or expiry of the consent. The legal basis is our legitimate interest in being able to document a prior consent | Immediate removal from active lists | Marketing law compliance |
| AI Mentor data | 30 days | Automated, handled by third party processor | Abuse monitoring and controlled quality improvements |
12. Your data protection rights & how to exercise them
| Right | Description | Limitations | Exercise Method | Response Time |
|---|---|---|---|---|
| Access (Article 15) | Obtain confirmation of processing and copies of your data | May be restricted for others' rights and freedoms | Email request with identity verification | 1 month (extendable to 3 months for complex requests) |
| Rectification (Article 16) | Correct inaccurate or incomplete data | Must not adversely affect others' rights | Email request with corrected information | 1 month |
| Erasure (Article 17) | Request deletion of your data | Limited by legal obligations and legitimate interests | Written request with specific grounds | 1 month |
| Restriction (Article 18) | Limit processing of your data | Available in specific circumstances only | Email request with justification | 1 month |
| Objection (Article 21) | Object to processing based on legitimate interests | Must be balanced against our legitimate interests unless related to direct marketing | Email request with specific objections | 1 month |
| Portability (Article 20) | Receive your data in structured format | Limited to data provided by you under contract/consent | Email request specifying data scope | 1 month |
| Withdraw Consent | Withdraw consent where processing is consent-based | Does not affect lawfulness of prior processing | Email request or unsubscribe mechanisms | Promptly |
To exercise these rights, contact us at security@campfiresecurity.dk with sufficient information to verify your identity and specify your request.
13. AI Mentor usage
This section provides additional information on the practical use and limitations of the AI Mentor.
When you use the AI Mentor, you are interacting with an AI-based support tool powered by AI-models deployed through Microsoft Azure AI Foundry. The AI Mentor is designed to provide contextual learner support within Campfire’s training services by helping you progress in assigned course material when you are unable to proceed on your own. In order to generate responses, the AI Mentor processes your prompt together with limited relevant contextual information, which may include information about the current course step, challenge data and relevant lab context.
The AI Mentor is intended as a learning support tool only. It is not designed to provide full solutions, perform assessment or grading, detect cheating or provide cybersecurity guidance to be used in real-world situations. The AI Mentor may produce incorrect, incomplete, or misleading responses. You should not rely on the AI Mentor as a sole source of truth and should use own judgment when applying its guidance.
Campfire will restrict and/or disable access to the AI Mentor in cases of suspected misuse, abuse, or other use contrary to the intended purpose of the service. If you experience any issues or have concerns regarding the responses provided, you may contact Campfire Security support at the following contact point: support@campfiresecurity.dk.
You may not provide personal data when interacting with the AI Mentor, unless the information is regarding fictional individuals or companies within the current course material. This includes, but is not limited to, names, social security numbers, health data, credentials, account information, and other personally identifiable information.
Further information on how personal data is processed in connection with the AI Mentor is provided in Sections 4.4 and 6.
The AI Mentor is provided to support users in progressing through course steps by offering guidance based on user-submitted prompts. Users are encouraged to provide clear and relevant context, including prior attempts and encountered issues, to improve response quality.
Users should, where possible, attempt to solve course steps independently before using the AI Mentor.
14. Children's privacy
Parents or guardians who believe we may have collected information from a child under 15 should contact us immediately at security@campfiresecurity.dk.
15. Automated decision-making
16. Data breach notification
- The nature of the breach and categories of data affected
- The likely consequences of the breach
- Measures taken or proposed to address the breach
- Contact information for further inquiries
17. Changes to this Privacy Policy
- Email notification to registered users
- Updated effective date at the top of this Privacy Policy
18. External websites & links
19. Contact information and complaints
- Email: security@campfiresecurity.dk
- Postal Address: Søndre Jernbanevej 32, 3400 Hillerød, Denmark
datatilsynet.dk if you believe we have not handled your personal data in accordance with applicable law.
Document Control:
- Version: 1.5
- Effective Date: April 15, 2026
- Next Review Date: April 15, 2027
- Approved By: Manager group
- Document Classification: Public
This Privacy Policy has been prepared in compliance with the General Data Protection Regulation (EU) 2016/679, the Danish Data Protection Act, and other applicable privacy laws.