Who is responsible
The data controller for everything described here is:
- Trading name
- CopenhagenWebsiteCompany
- Legal form
- Enkeltmandsvirksomhed (sole proprietorship)
- CVR number
- 46406168
- Address
- Carlsvej 1a, 2840 Holte, Denmark
- professionalspanishteachers@gmail.com
- Phone
- +45 52 70 40 77
For anything about your data, write to professionalspanishteachers@gmail.com. There is no Data Protection Officer — this is a one-person business, and the person who answers is the controller.
What we collect, and why
Your email address
Collected at checkout. It is how you sign in and how your access link reaches you. Legal basis: performance of the contract (GDPR Art 6(1)(b)).
Your purchase
Amount, currency, country of purchase, tax amount, the Stripe identifiers for the payment, and the time and version of the withdrawal-right waiver you accepted. Legal bases: contract for the purchase itself, and legal obligation (Art 6(1)(c)) for the parts that are accounting and consumer-law records.
We never see your card number. It goes from your browser to Stripe and never touches our servers.
What you write in the book
Your notes and reading position. Stored so they follow you between devices — that is the whole point of the product. Legal basis: contract. We do not read it for any other purpose, we do not sell it, and we do not use it to train machine-learning models.
Sign-in sessions
One strictly-necessary cookie holding a session identifier, plus the hashed tokens behind your magic sign-in links. Legal basis: contract.
Cookies
One cookie, flor_session, which keeps you signed in. It is strictly necessary, it holds no advertising identifier, and it is not shared with anyone. There is no analytics, no tracking pixel and no third-party script on this site — which is why you are not being asked to dismiss a consent banner. If that ever changes, you will be asked properly, before anything is set.
The confirmation emails carry no open-tracking pixel and no click tracking. The link in the email is the real link.
Who else processes your data
These are our processors. Each is bound by a data processing agreement and processes only on our instructions.
- Stripe Payments Europe, Ltd.
- Payment processing, tax calculation, refunds and disputes. Ireland (EU), with group transfers to the United States. Transfer basis: EU Standard Contractual Clauses / EU–US Data Privacy Framework.
- Supabase
- The database holding your account, purchase, notes and reading position. EU region (Frankfurt). Transfer basis: Processing within the EEA.
- Cloudflare R2
- Storage and delivery of the book's page images. No personal data.. Cloudflare's global network; no jurisdiction restriction set. Transfer basis: EU Standard Contractual Clauses.
- Resend
- Sending your access link and purchase confirmation. EU region (eu-west-1). Transfer basis: EU Standard Contractual Clauses.
- Netlify
- Hosting the website itself. United States (Ohio), company in the United States. Transfer basis: EU Standard Contractual Clauses / EU–US Data Privacy Framework.
How long we keep it
- Purchase and invoice records: 5 years, as required by the Danish Bookkeeping Act (bogføringsloven). We cannot delete these on request.
- Your account and everything you wrote in the book: for as long as your access lasts, and until you ask us to delete it.
- Sign-in sessions and magic-link tokens: deleted automatically once they expire.
Your rights
Under the GDPR you can ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, and ask for it in a portable form. Send one email to professionalspanishteachers@gmail.com and you will get a real answer within 30 days. There is no form and no fee.
Deleting your account also deletes everything you wrote in the book, and that cannot be undone — we will offer you an export first. The accounting records above have to stay.
If you are not satisfied with how we handle it, you can complain to the Danish Data Protection Agency, Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, or to the supervisory authority in the EU country where you live.
Security
Data is held in EU regions, encrypted in transit and at rest by our processors. Access to the production database is limited to the controller. If a breach ever affects your data and is likely to be a risk to you, you will be told directly — not through a notice on a page you will never visit.