GDPR

Privacy Policy

Last updated: 2026-08-23

Data Controller

We are the data controller for the processing of the personal data that we process about our members and business partners. You will find our contact information below.

The association Neptun
Møllevejen 93
5960 Marstal
Denmark

CVR no.: 43797336

It is not a requirement that our company has an external DPO, but if you have questions about the processing of your personal data, you can contact us via the contact form.

Treatment Activities

As data controller cf. GDPR, we have the following processing activities.

Visit Website

When you visit our website, we use cookies in order for the website to function, which you can read more about in our cookie policy (see below).

Communication With Potential Members

When you have questions about our site, or want to hear more about our services, you can contact us via:

  • Contact form
  • Email
  • Telephone

Through this, we will process your personal data so that we can enter into a dialogue with you, e.g. answer questions about our services. We only process the information that you give us in connection with our communication.

We will typically process the following general information: name, email, telephone number.

Our authority to process this personal data is the data protection regulation’s article 6, paragraph 1 liter f.

We delete our communication with you when it is clear whether you want our services or not.

Members

We need to communicate with our members to ensure that the service is delivered correctly. Through this, we can process information about name, address, services, special agreements, payment information and the like.

The authority to process this personal data is the data protection regulation’s article 6, subsection 1 liter b.

When the service has been delivered and any outstanding issues have been completed, we will immediately delete the personal data.

Newsletter

We have a newsletter that you can sign up for voluntarily, and you can always unsubscribe from this again.

The purpose of the newsletter is to send registered e-mails with new information from the company, which may deal with new content on the website, advertising of our services.

We will only send you emails if you have given your active consent. It initially requires that you enter your email address, to which we will subsequently send an email so that you can confirm the registration. This ensures that you have actually signed up for the newsletter yourself.

Our authority to process your personal data in connection with the newsletter is the data protection regulation, article 6, paragraph 1 letter a.

We will process your personal data as long as you are still registered for the newsletter. By unsubscribing, we will also stop sending this to you. If we have not sent you a newsletter for 1 year, your consent will expire as a result of our inaction.

If you unsubscribe from the newsletter, we will store your now previous consent for 2 years after it was last used due to statute of limitations, cf. Consumer Ombudsman’s Spam Guide section 11.3.

Bookkeeping

We must save all accounting documents cf. the Accounting Act. This means that we store invoices and similar attachments for accounting purposes. This may include general personal data such as name, address, service description.

We store this information for a minimum of 5 years after the current financial year has ended.

Job Applications

We gladly accept job applications in order to assess whether they match an employment need in our company.

If you send us your job application, our authority to process your personal data is the data protection regulation’s article 6, paragraph 1 liter f.

If you have sent an unsolicited application, HR will immediately assess whether your application is relevant, and then delete your information again if there is no match.

If you have sent an application for an advertised job, we will dispose of your application in the event that you are not hired, and immediately after the right candidate has been found for the job.

Data Processors

Few can handle everything by themselves, and the same applies to us. We therefore have business partners and use suppliers, some of whom may be data processors.

External suppliers can, for example, provide systems to organize our work, services, consultancy, IT hosting or marketing.

ServiceProviderPurposeLocation
HostingScaleway (SCW)Hosting of brigantineneptun.comEU (France)
Web analyticsGoogle AnalyticsTraffic analysis on brigantineneptun.comEU/USA*
FormsFillout.com (Restly, Inc.)Application, contact and newsletter forms embedded on the websiteUSA*
PaymentsStripe Payments Europe, Ltd.Membership and donation payments via Stripe’s hosted checkout pagesEU (Ireland)/USA*
Data storageGoogle Drive (Google LLC)General data storageEU/USA*
EmailHetzner Online GmbHEmail serverEU (Germany)
BookingSirvoyBooking system for guests etc.EU
Vessel trackingPredictWindLive position map on /ais (loads only when you click)New Zealand**
Vessel trackingVesselFinderFallback AIS map on /ais (loads only when you click)EU (Bulgaria)
Social mediaInstagram (Meta Platforms)Embedded Instagram posts (load only when you click)EU/USA*
VideoYouTube (Google LLC)Video player in privacy-enhanced mode (sets cookies only if you press play)EU/USA*
MapOpenStreetMap FoundationLocation map on the contact pageUnited Kingdom***
RemarketingGoogle Ads (Conversion Tracking)Advertising and remarketing on GoogleEU/USA*
RemarketingMeta Platforms (Facebook Pixel)Advertising and remarketing on Facebook/InstagramEU/USA*
RemarketingLinkedIn (Insight Tag)Advertising and remarketing on LinkedInEU/USA*

* Third-country transfers (Google, Meta, LinkedIn, Fillout and Stripe): Google LLC, Meta Platforms, LinkedIn Corporation, Fillout.com (Restly, Inc.) and Stripe, Inc. are certified under the EU-U.S. Data Privacy Framework (DPF), which the European Commission has approved as providing an adequate level of protection (adequacy decision of 10 July 2023).

** PredictWind: PredictWind is based in New Zealand, which is covered by a European Commission adequacy decision. The map loads only when you actively click to open it.

*** OpenStreetMap Foundation: Based in the United Kingdom, which is covered by a European Commission adequacy decision.

It is our responsibility to ensure that your personal data is processed properly. That is why we make high demands on our business partners, and our partners must guarantee that your personal data is protected.

Dissemination Of Personal Data

We do not pass on your personal data to third parties for their own purposes, with one exception: if you consent to marketing cookies, the remarketing partners listed in the table above (Meta, LinkedIn and Google) receive data about your visit and use it as independent data controllers for advertising. Withdrawing your consent via “Cookie settings” in the footer stops this sharing.

Profiling And Automated Decisions

We do not make automated decisions with legal or similarly significant effects for you (GDPR Article 22). If you consent to marketing cookies, our remarketing partners build advertising audience profiles based on your visit; this is the only profiling connected to the website, and it stops when you withdraw your consent.

Third Country Transfers

We generally use data processors in the EU/EEA, or who store data in the EU/EEA.

In some cases this is not possible, and here data processors outside the EU/EEA can be used if these can provide your personal data with adequate protection, cf. the table and footnotes above.

Treatment Safety

We keep the processing of personal data secure by having appropriate technical and organizational measures in place. We have made risk assessments of our processing of personal data, and have subsequently introduced appropriate measures to increase processing security.

The Rights Of The Data Subjects

According to the data protection regulation, you have a number of rights in relation to our processing of information about you.

Right To See Information (Right Of Access)

You have the right to gain insight into the information that we process about you.

Right To Rectification

You have the right to have incorrect information about yourself corrected.

Right To Erasure

In special cases, you have the right to have information about you deleted before the time of our normal general deletion occurs.

Right To Restriction Of Processing

In certain cases, you have the right to have the processing of your personal data restricted.

Right To Object

In certain cases, you have the right to object to our otherwise lawful processing of your personal data.

Right To Transmit Information (Data Portability)

In certain cases, you have the right to receive your personal data in a structured, commonly used and machine-readable format.

You can read more about your rights in the Data Protection Authority’s guidance at www.datatilsynet.dk.

When our processing of your personal data is based on your consent, you have the right to withdraw your consent.

Complaint To The Danish Data Protection Authority

You have the right to lodge a complaint with the Danish Data Protection Authority if you are dissatisfied with the way we process your personal data.

Stripe Payment

Membership subscriptions and donations are paid through Stripe’s hosted checkout pages. Your card details are entered directly with Stripe and never touch our website or our systems; we receive only a confirmation of the payment and the information needed to administer your membership until the subscription is terminated or ends.

The website uses “cookies”, which are text files that are saved on your computer, mobile phone etc. accordingly for the purpose of recognizing it, remembering settings, performing statistics and targeting ads. Cookies cannot contain harmful code such as virus.

Cookies on brigantineneptun.com

Cookie nameProviderTypeLifetimePurpose
cookie-consentForeningen NeptunNecessary12 monthsRemembers your cookie choice (stored in browser localStorage)
cookie-consent-metaForeningen NeptunNecessary12 monthsTimestamp and version of your cookie choice
_gaGoogle AnalyticsStatistics2 yearsDistinguishes between unique visitors
_ga_*Google AnalyticsStatistics2 yearsPersists session state (GA4)
_gidGoogle AnalyticsStatistics24 hoursDistinguishes between users and records page views
_gcl_auGoogle Ads (Conversion Tracking)Marketing3 monthsStores conversion data from Google Ads
_gcl_lsGoogle Ads (Conversion Tracking)Marketing3 monthsConversion data from Google Ads (localStorage mirror)
_fbpMeta Platforms (Facebook Pixel)Marketing3 monthsIdentifies browsers for Facebook advertising
_fbcMeta Platforms (Facebook Pixel)Marketing2 yearsStores click ID from Facebook ads
lastExternalReferrerMeta Platforms (Facebook Pixel)MarketingUntil deletedMost recent external referrer for Facebook advertising
lastExternalReferrerTimeMeta Platforms (Facebook Pixel)MarketingUntil deletedTimestamp of the most recent external referral (Facebook advertising)
li_sugrLinkedIn (Insight Tag)Marketing3 monthsIdentifies browsers for LinkedIn advertising
UserMatchHistoryLinkedIn (Insight Tag)Marketing30 daysLinkedIn Ads optimisation
bcookieLinkedIn (Insight Tag)Marketing1 yearBrowser ID for the LinkedIn Insight Tag
lidcLinkedIn (Insight Tag)Marketing24 hoursRouting for the LinkedIn Insight Tag

The table covers both cookies proper and equivalent storage technologies (e.g. browser localStorage), which the Danish Cookie Executive Order treats alike. Names marked with \* cover a family of keys whose suffix varies.

Statistics and marketing cookies are only activated after your active consent via our cookie banner. You can change or withdraw your consent at any time via the “Cookie settings” link in the footer of every page.

Embedded third-party content (the live position maps, Instagram posts and the newsletter signup in the footer) loads only when you actively click to open it — nothing is set beforehand.

  • Necessary cookies: Section 3(2) of the Danish Cookie Executive Order (exempt from consent requirement).
  • Statistics cookies: GDPR Article 6(1)(a) (consent), cf. Section 3(1) of the Danish Cookie Executive Order.
  • Marketing cookies: GDPR Article 6(1)(a) (consent), cf. Section 3(1) of the Danish Cookie Executive Order. Used for remarketing and advertising on Facebook, Instagram and LinkedIn.

How to delete cookies that have already been set

Withdrawing your consent via the cookie banner stops us from setting new cookies, but it does not automatically remove those already stored in your browser. You delete those yourself:

  • Open your browser’s settings and find the privacy section (typically “Privacy and security” or “Clear browsing data”).
  • Choose to delete cookies and site data for brigantineneptun.com, or for all websites. “Site data” also covers localStorage, which this policy treats on equal footing with cookies.
  • The exact steps vary between browsers (Chrome, Safari, Firefox, Edge); search for “delete cookies” in your browser’s own help function for step-by-step instructions.

Note: deleting cookies also deletes your saved cookie choice, and the banner will appear again on your next visit.