Privacy Policy
How Sport in Denmark collects, uses, and protects your personal data. Last updated: 2 June 2026.
1 Who we are
Sport in Denmark ("we", "us", "the platform") is a Danish initiative taken by 7 sports federations that helps international citizens discover and join local sports clubs in Denmark. Our platform is operated from Denmark and the website is available at sportindenmark.dk.
For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller for personal data processed through the platform.
2 Data we collect
Account information
- Name, email address, password (stored as a salted one-way hash — never in plain text)
- City of residence, preferred language, profile photo (optional)
- Date you joined and your role (member, club administrator, federation administrator, etc.)
Bookings and activities
- Trial sessions you book and the clubs/teams you book with
- Events you register for
- Volunteer roles you apply for
- Buddy profile and messages exchanged via our matching feature (if you opt in)
Club administrator data
If you administer a club, federation, or company on the platform, we additionally process the content you publish (team descriptions, photos, FAQs, events, volunteer postings, marketing materials you generate, etc.).
Technical data
- IP address, browser type and version, operating system, screen size
- Pages you visit on the platform and timestamps (kept in server logs)
- Session cookie that keeps you logged in
- If you submit a bug report: page URL, browser, viewport, timezone, and any recent in-browser JavaScript errors — used solely to reproduce and fix the issue
We do not collect bank or credit card numbers, government IDs (CPR), health data, or political/religious data. The platform does not currently process payments.
3 How we use your data
- To create and maintain your account and let you log in
- To register you for trial sessions, events, and volunteer roles, and to communicate those bookings to the relevant club
- To send transactional emails (booking confirmations, password resets, important account notices)
- To send the platform newsletter, if you have opted in (you can unsubscribe at any time using the link in every email)
- To improve the platform, debug issues, and prevent abuse
- To comply with legal obligations
We do not sell your personal data, and we do not use it for targeted advertising.
4 Legal basis (GDPR Art. 6)
| Purpose | Legal basis |
|---|
| Creating and operating your account | Performance of a contract (Art. 6(1)(b)) |
| Booking trials and events with clubs | Performance of a contract (Art. 6(1)(b)) |
| Sending transactional emails | Performance of a contract (Art. 6(1)(b)) |
| Newsletter and marketing emails | Your consent (Art. 6(1)(a)) — withdrawable at any time |
| Analytics cookies (Google Analytics) | Your consent (Art. 6(1)(a)) |
| Marketing pixels (Meta, LinkedIn, TikTok) | Your consent (Art. 6(1)(a)) |
| Security, fraud prevention, logging | Legitimate interest (Art. 6(1)(f)) |
| Compliance with Danish/EU law | Legal obligation (Art. 6(1)(c)) |
5 Sharing and third parties
We share the minimum data necessary with:
- Sports clubs and federations on the platform — when you book a trial, register for an event, or apply to volunteer, the relevant club receives your name and the booking details so they can welcome you. Clubs cannot see contact information until you allow them to, as well as members of other clubs.
- Email delivery providers — to send transactional emails and (if you opt in) newsletters.
- Hosting and infrastructure providers — to operate the servers and databases that run the platform.
- Public authorities — if required by Danish or EU law (e.g. court order, regulatory request).
- Analytics and advertising providers — we use Google Analytics (Google Ireland Ltd.) and social-media tracking pixels (e.g. Meta/Facebook, LinkedIn, TikTok) to measure how the platform is used and to evaluate the performance of campaigns. These providers receive technical identifiers, your IP address (truncated where supported), and page-interaction data. They act as independent or joint controllers for their part of the processing; details are in their respective privacy policies. These cookies and pixels only load after you give consent through our cookie banner.
All processors are bound by data-processing agreements and are required to handle your data in accordance with GDPR.
6 Cookies and tracking technologies
We use cookies and similar technologies (pixels, local storage) for three purposes:
Strictly necessary (always active)
These are required for the platform to work. They cannot be turned off.
| Cookie | Purpose | Lifetime |
|---|
| Session cookie | Keeps you logged in. | Session |
| Bug reporting | Enables user bug report when activated | 1 year |
| WordPress front-end cookies | Page caching and content rendering on the public website. | Varies — typically session to 1 year |
| Consent cookie | Remembers your cookie-banner choices. | Up to 12 months |
Analytics (only with your consent)
We use Google Analytics 4 (Google Ireland Ltd.) to understand how visitors find and use the platform, which pages are popular, and where the experience can be improved. We use IP-anonymisation and do not enable Google Signals or advertising features within Analytics by default.
| Cookie | Purpose | Lifetime |
|---|
_ga | Distinguishes unique users. | 2 years |
_ga_* | Persists session state for GA4. | 2 years |
_gid | Distinguishes users (24 h window). | 24 hours |
_gat | Throttles request rate. | 1 minute |
Marketing / social-media pixels (only with your consent)
To measure the performance of our campaigns on social media and to show relevant content to people who might benefit from the platform, we use tracking pixels from:
- Meta (Facebook / Instagram) — Meta Pixel (up to 90 days).
- LinkedIn — Insight Tag (up to 2 years).
- TikTok — TikTok Pixel (up to 13 months).
These pixels share technical identifiers and page-interaction data with the respective providers. They are only loaded if you accept the "Marketing" category in our cookie banner. Where applicable, Meta and Sport in Denmark act as joint controllers under GDPR Art. 26 for the data collected by the Meta Pixel.
Managing your choices
When you first visit the platform, a cookie banner asks you to accept or reject each non-essential category. You can change or withdraw your choices at any time by clicking "Cookie settings" in the footer. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
You can also block cookies entirely in your browser settings, or use browser-level tracking-prevention features.
7 Data retention
- Account data: kept while your account is active. You can delete your account at any time from Profile → Delete account; we then permanently erase your profile, bookings, buddy profile, and personal messages.
- Bookings and registrations: kept for up to 24 months after the event for record-keeping, after which they are anonymised or deleted.
- Email logs and server logs: typically up to 12 months, then deleted.
- Bug reports: kept until the issue is resolved, and then up to 12 months for quality assurance.
8 Your rights
Under the GDPR you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate or incomplete data
- Erasure — ask us to delete your data ("right to be forgotten")
- Restriction — ask us to limit how we use your data
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interest
- Withdraw consent — for anything we do on the basis of your consent (e.g. newsletter)
To exercise any of these rights, email us (see Contact us). We respond within 30 days.
You also have the right to lodge a complaint with the Danish Data Protection Authority (Datatilsynet) at datatilsynet.dk.
9 Security
We protect your data with industry-standard measures, including:
- TLS/HTTPS encryption for all traffic between your browser and our servers
- Salted one-way password hashing — we cannot read your password
- Role-based access controls — administrators can only see data for the clubs and federations they belong to
- Server-side input validation and protection against common web attacks (SQL injection, XSS, CSRF)
- Regular software updates and security reviews
No method of transmission over the Internet is 100% secure. If we ever experience a breach affecting your personal data, we will notify you and the Danish Data Protection Authority as required by GDPR Art. 33–34.
10 Children
Sport in Denmark is intended for users aged 16 and over. We do not knowingly collect personal data from children under 16 without verified parental or guardian consent. If a parent or guardian becomes aware that their child has provided us with personal data without consent, please contact us and we will delete it.
11 International data transfers
Our servers are hosted within the European Union. However, some of our analytics and marketing providers (Google, Meta, LinkedIn, TikTok) may transfer data to the United States. These transfers are protected by appropriate safeguards, including the EU–U.S. Data Privacy Framework (where the provider is certified) and/or the European Commission's Standard Contractual Clauses (SCCs), with supplementary technical and organisational measures where applicable.
12 Changes to this policy
We may update this policy from time to time to reflect changes in the platform or in the law. The "Last updated" date at the top will always show the current version. For material changes that affect your rights, we will notify registered users by email.
13 Contact us
If you have any questions about this policy or about how we handle your personal data, please contact us:
If you would like to delete your account directly, log in and go to Profile → Delete account.