Who is responsible
RIXX.DK is the data controller for rixx.dk. Contact: mikael@mrieck.com. If you have appointed a data protection officer, add that name and address here.
What this page is
This page is a starter privacy notice for visitors in the EU/EEA, the United Kingdom, the United States, Brazil and other countries. It is written to cover the transparency rules we can reasonably cover in a template: GDPR Articles 13–14 and 15–22, the UK GDPR, PECR, the ePrivacy Directive, CCPA/CPRA (including Global Privacy Control), and LGPD. It is not legal advice. Delete what you do not do. Add what you do. Have counsel review it before you go live.
Whose data we process
We process data about website visitors, people who write to us, customers and suppliers, and people whose data appears in content you send us. Children: this site is not directed at children under 16 in the EEA/UK or under 13 in the United States. We do not knowingly collect their data. If you believe we have, write to mikael@mrieck.com and we will delete it.
Categories of data
Depending on how you use the site we may process: technical data (IP address, browser, device, pages viewed, approximate location from IP, server logs); data you send in forms (name, email, phone, message, account or order details); communications; payment references if you buy something (card data is handled by the payment provider, not stored by us unless you say otherwise here); and data from cookies, local storage and pixels you have accepted, as listed in Cookie declaration.
Purposes and legal bases
EU/EEA and UK — we rely on: consent (optional cookies, newsletters, some forms); contract (to deliver a purchase or a request you make); legal obligation (bookkeeping, consumer and tax rules); and legitimate interests (running and securing the site, preventing abuse, answering enquiries, and basic audience measurement where the law allows it without consent). You can object to legitimate-interest processing. We do not use automated decision-making that produces legal or similarly significant effects. If you later do, describe it here, including the logic and your right to human review.
Cookies and similar technologies
Under the ePrivacy Directive and UK PECR, we do not set non-essential cookies or similar technologies (local storage, pixels, SDKs) before you say yes. Reject and accept are equally easy. Nothing is pre-ticked. Necessary cookies that are strictly required to provide a service you asked for may run without consent. The live list, purposes, providers and lifetimes are in Cookie declaration. You can change or withdraw your choice at any time:
Recipients
We share data with providers who process it for us, for example hosting, email, security, payment, analytics and advertising tools you actually use. Name them here (legal name, country, what they receive). We do not sell personal information for money. In the US sense of “sale” or “sharing” for targeted advertising, optional marketing cookies may count as sharing until you opt out. We honour Global Privacy Control as an opt-out of sale/sharing and marketing cookies.
International transfers
If we transfer personal data out of the EU/EEA or the UK, we do so only where the destination has an adequacy decision or we use another lawful tool such as the European Commission’s Standard Contractual Clauses (and the UK addendum where required), plus a transfer assessment. Name the countries and tools here.
How long we keep data
We keep data only as long as needed for the purpose, or as long as the law requires (for example accounting records). Server logs are typically kept for a short security window. Cookie choices last 180 days, then we ask again. Form messages are kept only as long as the conversation requires. Replace these defaults with your real retention schedule.
Security
We use appropriate technical and organisational measures: HTTPS, access control, least-privilege admin accounts, updates, and backups. No method is perfectly secure. Say here if you have extra measures (SSO, 2FA, a processor agreement set).
Your rights in the EU/EEA and the UK
You can request access, correction, erasure, restriction and portability, and you can object to processing based on legitimate interests. You can withdraw consent at any time without affecting processing already carried out. We answer without undue delay and within one month (extendable as the law allows). You can complain to your supervisory authority (in the UK: the ICO, ico.org.uk). You may also complain in the country where you live or work.
United States (CCPA/CPRA and similar state laws)
If you are a consumer in California or another US state with a similar law, you may have the right to know, access, correct and delete personal information, to opt out of sale, sharing and targeted advertising, to limit use of sensitive personal information, and to non-discrimination for exercising those rights. You may use an authorised agent. We treat a Global Privacy Control signal as an opt-out of sale/sharing and of marketing cookies. To use these rights, write to mikael@mrieck.com.
Brazil (LGPD)
If LGPD applies, you may confirm processing, access, correct, anonymise, block or delete data that is unnecessary or non-compliant, request portability, information about sharing, information about the possibility of denying consent and the consequences, and withdraw consent. Contact mikael@mrieck.com. You may also contact the ANPD.
Contact and complaints
Write to RIXX.DK at mikael@mrieck.com. Supervisory authority: your supervisory authority (in the UK: the ICO, ico.org.uk).
Changes
We update this page when our processing changes. A new policy version can make the cookie banner ask again. Last updated: September 21, 2026.
Starter notice only. Not legal advice. Fill in processors, transfers, retention and any extra activities (accounts, webshop, newsletter, job applications) before you rely on it.

Råsted Kirkevej 9,7570 Vemb
+45 36991313
info@rixx.dk
