Privacy policy for staehrgroup.com
Last updated: 8 September 2026
1. Data controller
Henning Stæhr A/S is the data controller for the processing of the personal data collected when you visit staehrgroup.com.
Henning Stæhr A/S
Grusbakken 14
2820 Gentofte
Denmark
Company reg. (CVR) no. 43224913
E-mail: gdpr@staehrgroup.com
We have not appointed a data protection officer. If you have questions about this policy or about our processing of your personal data, or if you wish to exercise your rights, you are always welcome to write to us at gdpr@staehrgroup.com.
2. What this policy covers
This policy describes how we process personal data about visitors to staehrgroup.com — the data that arises technically when you use the website, and the data you send us yourself if you contact one of our departments.
Processing of personal data in other contexts — for example in customer and supplier relationships, in recruitment or in employment — is not covered by this policy.
3. What we do not do
We want to be clear about what the website does not do, because it defines the scope of the rest of this policy:
- We do not use web analytics or statistics tools, and we do not track your movement from page to page. Technical server log files are kept, however, as described in section 5.
- We do not use advertising, remarketing, tracking pixels or any other marketing tracking.
- There is no web shop, no payments and no customer accounts.
- We do not send newsletters from the site.
- There is no contact form on the website. You can contact us at the e-mail addresses we publish, as described in section 4.
- There are no embedded videos, maps or social media feeds. The consent banner is, however, loaded from an external supplier, as described in section 6.2.
- You cannot create a user profile. The only user accounts are our own editorial accounts in the site administration.
- We do not sell on or disclose data to third parties for their own purposes.
4. When you write to us
On the website we publish e-mail addresses you can write to. If you choose to do so, your e-mail is sent directly from your own mail programme to that address. The website does not itself collect or forward your message.
What data we process
We process the data you provide yourself — typically your name, your e-mail address, possibly a telephone number and company, and the content of your message.
Purpose
We use the data to receive, answer and handle your enquiry, and to be able to follow up on it where necessary.
Legal basis
The processing is based on our legitimate interest in maintaining a dialogue with customers, retailers, suppliers and others who contact the company, and in being able to document the course of an enquiry, cf. Article 6(1)(f) of the General Data Protection Regulation. We consider that this interest is not overridden by your interests, in part because you decide yourself what you send, and because the data is not used for anything other than replying to you.
If you are yourself a party to an agreement with us, or if the data is needed in order to take steps at your request prior to an agreement, the processing is based on Article 6(1)(b). If you write on behalf of a company, Article 6(1)(f) continues to apply to your own contact details.
If you would like further information about the balancing of interests we have carried out, you can request it at gdpr@staehrgroup.com.
Voluntary
Contacting us is voluntary, and you decide yourself what information you give. We ask you not to send sensitive personal data, personal identification numbers or confidential information in an ordinary e-mail — please call us instead if an enquiry requires it.
Retention
We retain enquiries for up to 12 months after the matter has been closed, after which they are deleted. If the enquiry leads to a customer or supplier relationship, or there is another reason for continued retention — for example documentation of a complaint — the data is retained for as long as is necessary for that purpose. If an enquiry forms part of our accounting records, it is retained for 5 years from the end of the financial year to which the records relate, cf. the Danish Bookkeeping Act.
5. Server log files
When you visit the website, our hosting provider automatically records a number of technical details in the server log files: your IP address, the time of the visit, which pages and files were retrieved, response codes, and information about your browser and operating system.
The purpose is solely troubleshooting and operational security — keeping the website running and protecting it against misuse and attack. The basis is our legitimate interest in operating a stable and secure website and in being able to detect and investigate technical faults and attacks, cf. Article 6(1)(f).
The log files are retained by the hosting provider for as long as is necessary for troubleshooting and operational security, and are then deleted automatically. They are not used to map your behaviour, for profiling or for marketing.
6. Cookies
6.1 Which cookies we use
The website only uses cookies that are necessary in order to deliver the pages and functions you ask for. There are no statistics or marketing cookies.
If you simply open a page and do nothing else, no cookies are set. They are set only when there is a reason for it.
| Cookie | Purpose | When it is set |
|---|---|---|
| Consent cookie from Usercentrics | Remembers and documents your choice, so that the consent banner is not shown again on every page view | When you respond to the consent banner |
| Technical cache cookie | Ensures that you are served the correct version of a page from the server cache | Only in particular situations, for example when a page must be delivered in a specific variant |
The lifetime of each cookie is shown in the cookie settings on the website under the «Details» tab. We refer you there rather than repeating it here, so that the information is always current.
The language is determined by the address you visit — the Danish version is at staehrgroup.com and the English at staehrgroup.com/en/. No cookie is therefore used to remember a language choice.
Because the cookies are necessary in order to deliver a service you have expressly requested, they do not require your consent, cf. section 4 of the Danish Executive Order on Cookies. The storage and reading of the cookies is based on our legitimate interest in being able to deliver a functioning website, cf. Article 6(1)(f) of the General Data Protection Regulation.
6.2 The consent banner
We use a consent solution from Usercentrics to provide information about cookies and to record and document your choice. Your choice, the time of the choice and a consent ID are recorded. Because the banner is loaded from Usercentrics’ servers, your IP address is technically known to Usercentrics when the banner loads.
The recording is carried out in order to be able to document your choice to the supervisory authority, cf. Article 6(1)(c) read together with Article 5(2) of the General Data Protection Regulation. The retention period is shown in the cookie settings on the website.
You can open the cookie settings at any time to view or change your choice.
6.3 How to disable cookies in your browser
You can always block or delete cookies in your browser settings. As the site’s cookies are technical, this may mean that the consent banner is shown again on every visit.
7. Who we share data with
We use the following data processors, who process data on our behalf and on our instructions. A data processing agreement has been concluded with each of them.
| Data processor | Role | Location |
|---|---|---|
| A/S ScanNet, CVR 29 41 20 06 | Hosting of website and database, including server log files | Denmark |
| Microsoft (Microsoft 365) | Mail hosting — receipt and storage of the e-mails you send us | EU/EEA |
| Usercentrics GmbH | Consent solution — recording of consent choice, time and consent ID | Germany |
| OnTheGoSystems Limited (WPML) | Translation tool — machine translation of the website’s public texts | See section 8 |
| WP Media (Imagify) | Optimisation of image files for the website | France |
In addition, data may be disclosed where we are legally obliged to do so, or where it is necessary in order to establish, exercise or defend a legal claim.
8. Transfers to countries outside the EU/EEA
The website and database are hosted in Denmark. Consent data is processed in Germany, and image optimisation takes place in France. All three are within the EU/EEA.
For machine translation of the website’s texts we use a translation tool from a supplier outside the EU/EEA. What is sent for translation is the website’s publicly available text — no information about visitors is sent.
Where personal data is transferred to a country outside the EU/EEA, this takes place on the basis of the European Commission’s standard contractual clauses or another valid transfer mechanism. You can obtain a copy of the safeguards a transfer relies on by writing to gdpr@staehrgroup.com.
9. Security
We have implemented appropriate technical and organisational security measures to protect your data against accidental or unlawful loss, alteration, unauthorised access and misuse. These include an encrypted connection (HTTPS) on the website, two-factor authentication and named access to the site administration, access control so that only relevant staff can see enquiries, and ongoing updating of the website’s platform and plugins.
10. Your rights
Under the General Data Protection Regulation you have a number of rights in relation to us:
- Access. You can be told what data we process about you, and obtain a copy of it.
- Rectification. You can have inaccurate data about you corrected.
- Erasure. In certain cases you can have data about you deleted before our ordinary deletion date.
- Restriction. In certain cases you can have the processing restricted, so that we only store the data going forward.
- Data portability. In certain cases you can have the data you have given us provided in a structured, commonly used and machine-readable format.
- Withdrawal of consent. If you have given consent to a processing activity, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew your consent.
You can exercise your rights by writing to gdpr@staehrgroup.com. We will respond within one month. If the enquiry is complex, the deadline may be extended by up to two months, in which case we will inform you within the first month.
There may be conditions or limitations attached to the individual rights. You can read more in the guidance from the Danish Data Protection Agency at www.datatilsynet.dk.
10.1 In particular about your right to object
You have the right at any time, on grounds relating to your particular situation, to object to our processing of your personal data where the processing is based on our legitimate interest. This applies both to the enquiries you send us and to the data in the server log files.
If you object, we may no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims. You object by writing to gdpr@staehrgroup.com.
11. Automated decision-making
We do not use automated decision-making or profiling that has legal effect for you or similarly significantly affects you.
12. Complaints to the supervisory authority
If you are dissatisfied with the way we process your personal data, we would like to hear from you first at gdpr@staehrgroup.com. You also have the right to lodge a complaint with the Danish Data Protection Agency:
Datatilsynet
Carl Jacobsens Vej 35
2500 Valby
Denmark
Telephone: +45 33 19 32 00
E-mail: dt@datatilsynet.dk
www.datatilsynet.dk
13. Changes to this policy
We update this policy when our processing of personal data changes, or when legislation or practice gives cause to do so. The version in force at any time is available on this page, and the date of the most recent update appears at the top.
