Privacy

A site that sells GDPR audits should be able to account for its own data handling on one page, without a cookie banner and without asking you to trust it. This is that page.

Denne siden finnes også på norsk.

Who is responsible

FTRCRP, Thomas A. Kleppestø, Skiptvet, Norway. Contact: HAL0zum@proton.me, or encrypted to our PGP key.

What this site does not do

No cookies are set. No third-party scripts or fonts are loaded: every asset on this site comes from this domain. No advertising, no tracking pixels, no social embeds, no consent banner, because there is nothing to consent to. You can verify all of it from your browser’s network tab, which is the only assurance worth anything.

What is collected

Reading a page. Our analytics are a self-hosted GoatCounter instance running on our own server at stats.ftrcrp.org. It is cookieless, it does not build a profile, it does not follow you between sites, and the data does not leave our infrastructure. It records the page you viewed, the referring page, a coarse browser and country, and a derived value used to count a visit once rather than twice. No third party receives it because there is no third party involved.

Hosting. The site is served from Microsoft Azure Static Web Apps. Like any web host, Azure processes the request needed to deliver a page, including your IP address, under its own operator role.

Sending the contact form. The fields you fill in: name, organisation if you give one, email address, which service your enquiry concerns, your message, and which page and language you sent it from. That is all, and none of it is optional-but-collected-anyway.

The form has one hidden field labelled “Website” that real visitors never see. It exists to catch automated spam. If you are reading without stylesheets and can see it, leave it empty. Anything typed there is treated as a bot and discarded.

Email. Replies come from a Proton Mail mailbox. Your message and our correspondence sit in it for as long as the matter is live.

Who processes it

What Processor Where
Analytics None, self-hosted by us Our own server
Hosting Microsoft Azure EU/EEA region
Contact form delivery Basin (usebasin.com) See the note below
Email Proton Mail Switzerland

On Basin, stated plainly rather than reassuringly. Basin receives what you type into the form and forwards it to our mailbox. We have not yet established in writing where Basin processes and stores submissions, nor a data processing agreement with them under Article 28. That is an open item on our side, not a settled one, and we would rather say so here than imply a paper trail we cannot show you. If you would prefer your first contact not to pass through a third party at all, email us directly, or encrypt to our PGP key. That route involves Proton and nobody else.

Why we are allowed to hold it

Analytics: legitimate interest in knowing whether anything we publish is read, served by the least invasive method we could find. Contact enquiries: your own request, and where it leads to work, the performance of that engagement. Nothing here is used for advertising or sold, ever, to anyone.

How long it is kept

Enquiries are kept while the matter is live and for as long as we may reasonably need to refer back to it. Analytics are aggregate and retained indefinitely in that aggregate form. We are still fixing exact retention periods and will state them here as numbers once they are decided rather than leave a vague sentence standing in for a policy.

What you can ask for

You have the right to know what we hold about you, to have it corrected, to have it deleted, to receive a copy, and to object to our processing. Ask by email and you will get an answer from a person, not a ticket number. There is no charge and no form to fill in.

If you think we have handled your data badly, you can complain to the Norwegian Data Protection Authority, Datatilsynet, and you do not need to raise it with us first.

When we hold data about someone who is not you

Some of our work involves personal data about people who never contacted us: OSINT, investigations, breach analysis. We take that work only when authorised, we use public sources only, we collect what the question requires and not more, and we do not publish personal details that are not necessary to the finding. Where our published investigations concern named people, our editorial standards apply.

Changes

Material changes will be dated here. This page was last reviewed on 22 September 2026.

AI disclosure

This article uses AI tools for research and generation with a human in the loop. Drafts are reviewed, edited, and signed off by a named natural person before publication. Editorial responsibility: Thomas A. Kleppestø.

Tools used: draft, review.