Privacy Policy

Effective date: January 8, 2026

Last updated: January 8, 2026

1. Who we are

1.1

Campfire Security ApS, CVR 44318563, a company incorporated under Danish law with registered address at Søndre Jernbanevej 32, 3400 Hillerød, Denmark (“we,” “us,” or “our”), acts as the data controller for the purposes of applicable data protection laws, including the General Data Protection Regulation (EU) (the “GDPR”).

1.2Our contact details are as follows:
1.3This Privacy Policy (the “Privacy Policy”) describes how we will process your personal data when you:
  • Visit and use the websites campfiresecurity.dk, campfiresecurity.com, campsec.dk, campsec.com and all subdomains thereof (collectively, the “Websites”),
  • Are signed up for and use our services, including our cybersecurity training platform, courses, laboratories, capture-the-flag exercises, and related educational services,
  • Are signed up for our newsletter, or
  • Interacting with us.

2. Definitions

Where this Privacy Policy uses the terms defined in the GDPR, those terms shall have the same meaning as in the GDPR.

3. Purpose of this Privacy Policy

3.1

The purpose of this Privacy Policy is to inform you how we handle your personal data in a lawful, fair and transparent manner in accordance with the General Data Protection Regulation (GDPR). The Privacy Policy outlines the types of personal data we collect, how it is used, the lawful basis for processing it and your rights as a data subject.

3.2

This Privacy Policy aims to fulfill our obligation under Articles 12-14 GDPR to provide clear, concise and transparent information about our data processing activities.

4. The data we collect

4.1

We collect and process the following categories of personal data in accordance with the principle of data minimization:

4.2Data Categories:
Data CategorySpecific Data Elements
A. Identity & Account DataFull name, username, email address, account credentials, user identification numbers
B. Contact InformationEmail address, postal address, telephone number, communication preferences
C. Profile & Social DataProfile information, social media links, professional details, company affiliation
D. Learning & Progress DataCourse completion status, learning progress metrics, assessment scores, certificates awarded, experience points
E. Seat/License/Team DataLicense assignments, team memberships, organizational hierarchies, seat allocations
F. Payment & Billing DataBilling address, payment method tokens, transaction history, invoice records
G. Technical & Usage DataIncluding but not limited to IP addresses, browser information, device identifiers, log files, behavioral data and usage patterns, data on interaction (clicks etc.) with email and services, session data, timestamps, approximate location,
H. Security TokensAuthentication tokens, session identifiers, security credentials, multi-factor authentication data
I. Customer services dataInformation provided when you contact us
J. Customer survey dataInformation provided when responding to customer surveys, filing reviews or otherwise providing feedback on the services
4.3

Payment card details are processed exclusively by our third-party payment processor and are not stored on our systems, except where explicitly provided to us during direct communications.

5. How we use your data

5.1

We process your personal data for the purposes and under the lawful bases specified in Section 6, which include:

  • 5.1.1 Service Provision and Account Management (SAM)
  • 5.1.2 Business Operations (BO)
  • 5.1.3 Analytics and Improvement (AI)
  • 5.1.4 Legal Compliance (LC)

6. Why we process your data (lawful basis and purposes)

6.1We process your personal data based on the following lawful bases under Article 6 of the GDPR:
Processing PurposeData Categories (Section 4.2)Lawful Basis (Article 6 GDPR)Legitimate Interest AssessmentPurpose Category (Section 5.1)
Create and maintain user accountsA, B, H(b) Contract performanceN/ASAM
Authenticate users and secure platformA, H, G(b) Contract performance; (f) Legitimate interestsNecessary for security; expected by users; minimal privacy intrusionSAM
Deliver training servicesA, D, E, G(b) Contract performanceN/ASAM
Track learning progress and award credentialsA, D(b) Contract performanceN/ASAM
Report learning progress to employersA (identifier only), D, E(f) Legitimate interestsNecessary for employers to assess usage of the services, if usage is mandated by a contract with the employerBO
Manage licenses, billing, and invoicingA, E, F(b) Contract performance; (c) Legal obligationN/ABO
Send mandatory service communicationsA, B(b) Contract performanceN/ABO
Send voluntary service communicationsA, B, D(f) Legitimate interestsIncreases your value of the services; no marketing; opt-out offeredBO
Send personalized marketing communicationsA, B, C, D, G(a) Consent;N/ABO
Provide user support and troubleshootingA, B, G, D, I(b) Contract performance; (f) Legitimate interestsNecessary for issue resolution; restricted staff accessBO
Conduct platform analytics and improvementG (aggregated), D(f) Legitimate interestsData aggregated/pseudonymized; no direct marketing; user expectation of service improvementAI
Ensure security and prevent fraudG, H(f) Legitimate interestsEssential for safety; minimal, justified privacy impact.AI
Comply with legal obligationsA, F, B (minimal)(c) Legal obligationN/ALC

7. How we collect your data

7.1We collect personal data through the following methods:
Collection MethodDescription
Direct provision from youWhen you register for an account, place orders, or voluntarily provide information
Direct provision from your employerAs part of our contract with your employer
Automated collectionThrough cookies, log files, and similar technologies during website usage
CommunicationsWhen you contact us for support, feedback, or other communications
Third-party IntegrationThrough authorized integrations with third-party services

8. How your data is shared and transferred to third countries

8.1

We may share your personal data with the following categories of recipients:

8.2Third-Party Processors

We engage the following processors under appropriate data processing agreements and – to the extent personal data is transferred outside the European Economic Area – apply appropriate safeguards in accordance with Chapter V of the GDPR:

ProcessorService CategoryData SharedLocationTransfer Mechanism
Stripe, Inc.Payment processingPayment details, transaction data, billing informationUnited StatesEU-US Data Privacy Framework (adequacy decision under Article 45(1) GDPR)
Microsoft CorporationCloud infrastructureAll platform data at restEuropean Union (West Europe)N/A
Google LLCAnalytics and cloud servicesPseudonymized usage data, server logsEuropean Union/United StatesEU-US Data Privacy Framework (adequacy decision under Article 45(1) GDPR)
HubSpot, Inc.CRM, marketing automation, lead managementEmail addresses, names, contact details, interaction data, campaign engagement metricsUnited StatesEU-US Data Privacy Framework (adequacy decision under Article 45(1) GDPR)
Hetzner Online GmbHEU cloud hostingSession data, lab environment identifiersGermany (EEA)N/A
The Rocket Science Group LLC (Mailchimp)Email marketingEmail addresses, names, subscription dataUnited StatesEU-US Data Privacy Framework (adequacy decision under Article 45(1) GDPR)
Mailgun Technologies, Inc.Transactional emailEmail addresses, message metadataUnited StatesStandard Contractual Clauses under Article 46(1) GDPR
Usercentrics A/S (Cookiebot)Cookie consent managementConsent preferences, anonymized identifiersDenmark (EEA)N/A

We conduct transfer impact assessments where required and implement supplementary measures to ensure adequate protection. Please contact us at security@campfiresecurity.dk, if you wish to obtain a copy of the standard contractual clauses.

8.3Other Recipients

We may also share personal data with:

  • Employers or Organizations: Where you access our services through an organizational license, we may share learning progress data with your employer or organization, usage data and statistics
  • Legal Authorities: Where required by law, court order, or regulatory request
  • Professional Advisers: Including lawyers, auditors, and consultants under appropriate confidentiality obligations
  • Other users: Depending on your use of the services, your username may be visible to other users, including on leaderboards and in capture-the-flag exercises.

9. How we store and secure your data

9.1Data Storage Location: Your personal data is primarily stored within the European Economic Area, with our primary hosting infrastructure located in Microsoft Azure's West Europe region.
9.2Security Measures: We implement appropriate technical and organizational measures pursuant to Article 32 GDPR:
Security DomainImplemented MeasuresStandards Compliance
EncryptionAES-256 encryption at rest, TLS 1.2/1.3 in transit, Azure-managed encryption keysFIPS 140-2 Level 2
Access ControlsRole-based access control (RBAC), multi-factor authentication, principle of least privilegeInternal security framework
Infrastructure SecurityDistributed denial-of-service protection, intrusion detection, network segmentationCIS18 IG1
Backup and RecoveryBi-weekly encrypted backups, 5-year retention, tested disaster recovery proceduresAutomated integrity verification
MonitoringContinuous security monitoring, vulnerability scanning, penetration testingAnnual third-party security assessments

10. Data retention & deletion

10.1We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law:
Data CategoryRetention PeriodDeletion MethodLegal/Business Justification
Technical logs and session data90 daysAutomated purgingSecurity monitoring requirements
Active user accountsDuration of service relationship plus 2 yearsSecure deletion protocolsService provision and support
Inactive user accounts2 years from last loginScheduled deletion with 30-day noticeBusiness continuity, potential service resumption
Billing and financial recordsCurrent year plus 5 yearsEncrypted archival, then secure deletionDanish Bookkeeping Act compliance
Marketing communication dataUntil consent withdrawal or 12 months with no marketing communication or 3 years of user inactivity. We may, however, retain documentation for your consent for a period of up to 5 years following withdrawal or expiry of the consent. The legal basis is our legitimate interest in being able to document a prior consentImmediate removal from active listsMarketing law compliance
10.2Upon expiration of the retention period, personal data will be securely deleted or anonymized in accordance with industry best practices.

11. Cookies and similar technologies

11.1Our Websites use cookies and similar tracking technologies. The legal basis for cookie processing is set forth in our Cookie Policy, which forms part of this Privacy Policy.
11.2Cookie Categories:
Cookie TypePurposeLegal BasisRetentionUser Control
Strictly NecessaryEssential website functionality, security, load balancingArticle 6(1)(f) - Legitimate interestsSession to 1 yearCannot be disabled
Functional/PreferenceRemember user preferences, language settingsArticle 6(1)(a) - Consent1 day to 1 yearOnly used subject to consent
AnalyticsWebsite usage analysis, performance monitoringArticle 6(1)(a) - ConsentUp to 2 yearsOnly used subject to consent
MarketingTargeted advertising, conversion trackingArticle 6(1)(a) - Consent3 months to 2 yearsOnly used subject to consent
11.3Detailed Cookie Inventory and Declaration:
11.4Cookie Management: You may manage cookie preferences through our cookie consent banner or your browser settings. Disabling certain cookies may affect website functionality. Your current consent applies to the following domains: app.campfiresecurity.dk, campfiresecurity.dk.

12. Your data protection rights & how to exercise them

12.1Under the GDPR, you have the following rights regarding your personal data:
RightDescriptionLimitationsExercise MethodResponse Time
Access (Article 15)Obtain confirmation of processing and copies of your dataMay be restricted for others' rights and freedomsEmail request with identity verification1 month (extendable to 3 months for complex requests)
Rectification (Article 16)Correct inaccurate or incomplete dataMust not adversely affect others' rightsEmail request with corrected information1 month
Erasure (Article 17)Request deletion of your dataLimited by legal obligations and legitimate interestsWritten request with specific grounds1 month
Restriction (Article 18)Limit processing of your dataAvailable in specific circumstances onlyEmail request with justification1 month
Objection (Article 21)Object to processing based on legitimate interestsMust be balanced against our legitimate interests unless related to direct marketingEmail request with specific objections1 month
Portability (Article 20)Receive your data in structured formatLimited to data provided by you under contract/consentEmail request specifying data scope1 month
Withdraw ConsentWithdraw consent where processing is consent-basedDoes not affect lawfulness of prior processingEmail request or unsubscribe mechanismsPromptly
12.2

To exercise these rights, contact us at security@campfiresecurity.dk with sufficient information to verify your identity and specify your request.

12.3We may request additional information to verify your identity and will respond within the timeframes specified by law.

13. Children's privacy

13.1Our Services are intended for individuals aged 15 years and older. Campfire Security does not, to the extent of our capability, process personal data about children under 15 years of age.
13.2If we become aware that we have collected personal data from a child under 15, we will take steps to delete such information promptly.
13.3

Parents or guardians who believe we may have collected information from a child under 15 should contact us immediately at security@campfiresecurity.dk.

14. Automated decision-making

14.1We do not engage in automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.
14.2Any automated processing we conduct is limited to technical operations necessary for service provision and does not result in decisions that significantly affect your legal rights or interests.

15. Data breach notification

15.1In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
15.2Such notification will include:
  • The nature of the breach and categories of data affected
  • The likely consequences of the breach
  • Measures taken or proposed to address the breach
  • Contact information for further inquiries

16. Changes to this Privacy Policy

16.1We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
16.2Material changes will be communicated by:
  • Email notification to registered users
  • Updated effective date at the top of this Privacy Policy
16.3Your continued use of our services after the effective date constitutes acceptance of the revised Privacy Policy.

18. Contact information and complaints

18.1Data Controller Contact:
18.2Supervisory Authority: You have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) at

datatilsynet.dk if you believe we have not handled your personal data in accordance with applicable law.

18.3Response Times: We aim to respond to all privacy-related inquiries within 72 hours and formal data subject requests within one month as required by law.

Document Control:

  • Version: 1.5
  • Effective Date: January 8, 2026
  • Next Review Date: January 8, 2027
  • Approved By: Manager group
  • Document Classification: Public

This Privacy Policy has been prepared in compliance with the General Data Protection Regulation (EU) 2016/679, the Danish Data Protection Act, and other applicable privacy laws.