Skip to content
MI6 Holding

Legal

Privacy Policy

We measure as little as possible, by default anonymously, and never with cookies. This page documents what that means in practice, what your rights are, and how to reach us.

Last updated: 29 June 2026

1. Data controller

MI6 Holding ApS (CVR 43716344), registered in Denmark, is the data controller for this website.

Contact: [email protected]

2. What we collect

When you visit this site, your browser makes a standard HTTP request that includes an IP address, a user-agent string, and the page you asked for. Our hosting provider records these in short-lived server logs for operational and security purposes (rate limiting, abuse detection, error diagnosis). These logs are not used for marketing or profiling.

We run a self-hosted, cookieless analytics service (Rybbit, operated by BondIT ApS at stats.bondit.dk) in two tiers:

  • Anonymous measurement — always on. Page counts, referring page, and country (derived from IP, but the IP itself is not stored). No cookies, no fingerprinting, no personal identifiers, no third-party requests.
  • Performance & error diagnostics — only with your consent. Core Web Vitals (LCP, INP, CLS) and JavaScript errors, so we know quickly when something on the site is broken. Still no cookies and no personal data — only technical signals about how the page rendered in your browser.

If you email us at [email protected], we keep that correspondence as long as we need it to handle your enquiry.

We do not set tracking cookies, embed third-party widgets, load third-party fonts at runtime, run advertising tags, or share data with anyone outside our processors (the analytics service above and our hosting provider).

3. Legal basis

Where we process personal data — typically only the email you choose to send us, plus operational server logs — we rely on our legitimate interest under Article 6(1)(f) GDPR in operating a public corporate website and responding to enquiries.

4. Cookies

This site sets no cookies. Both measurement tiers above run without cookies or any client-side persistent identifier. Your choice on the consent banner is remembered in your browser’s local storage — not as a cookie, and never transmitted to us — so the banner does not return on every visit. Anonymous declines re-prompt after 30 days; an accept persists until you change it via “Cookie settings” in the footer.

If a browser developer-tools panel ever shows a cookie set by this site, that is a bug — please tell us.

5. Retention

Server logs are typically kept for up to 30 days for security and operational diagnostics, then rotated. Email correspondence is kept only as long as we need it to handle your enquiry, and then archived or deleted in line with normal record-keeping.

6. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, object to, and port any personal data we hold about you. Email [email protected] and we will respond within a reasonable time (one month at the outer edge, as the GDPR requires).

You also have the right to lodge a complaint with the Danish Data Protection Authority (Datatilsynet, datatilsynet.dk ).

7. Security

All traffic to this site is served over TLS. We apply standard HTTP security headers (Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, X-Frame-Options) and follow appropriate technical and organisational measures for the very small volume of personal data we ever hold.

8. How to withdraw consent

You can change your mind at any time. The footer at the bottom of every page has a Cookie settings link. Clicking it clears your stored choice and re-opens the consent banner so you can choose again. Declines re-prompt after 30 days; accepts persist until you change them.

Withdrawing consent is — as the GDPR requires — as straightforward as giving it.

9. Changes

We update this page when our practices change. The “Last updated” date at the top of the page reflects the most recent revision.