Skip to main content

Privacy Policy

Last Updated: March 8, 2026

1. Introduction & Controller Identity

This Privacy Policy explains how Fj ApS (“we”, “us”, or “our”) collects, uses, and protects personal data when you visit our website at fjaps.com (the “Site”), request information about our educational programs, or otherwise contact us. Fj ApS provides digital skills education and professional development services for participants across Canada, while the company is established in Denmark.

For the purposes of the EU General Data Protection Regulation (“GDPR”), Fj ApS is the data controller responsible for the processing described in this policy.

We do not appoint a Data Protection Officer (DPO) for the activities described here. If you have a privacy question, contact us using the email address above.

2. Personal Data We Collect

We collect personal data that you choose to provide and data that is collected automatically when you use the Site. The specific fields depend on how you interact with us (for example, whether you submit the contact form or only browse pages).

Categories of personal data we may collect include:

  • Identity and contact details: name, email address, phone number, organization name (if provided).
  • Form content: message text, program interests, schedule preferences, and other details you include in your inquiry.
  • Technical data: IP address, browser type and version, device type, operating system, language settings, time zone, and approximate location derived from IP.
  • Usage data: pages viewed, time spent on pages, referrer/source, click paths, and interaction events (for example, a form open or form submit).
  • Cookies and identifiers: cookie IDs and preference signals stored in your browser (see Section 4 and our Cookies Policy at /cookie-policy/).
  • Conversion events: whether an inquiry was sent successfully and which page or campaign source preceded the event (where permitted by consent).

We do not intentionally collect special-category data (such as health information, religious beliefs, or political opinions), financial account details, or government identification numbers through our standard forms. Please avoid including sensitive personal data in your message.

3. Why We Process Personal Data & Legal Basis (GDPR Art. 6)

We process personal data only when we have a valid legal basis under the GDPR. The table below explains the main purposes and the applicable legal bases. In practice, the same interaction may involve multiple bases. For example, an inquiry may be processed to respond to your request (contract steps) and to keep the Site secure (legitimate interests).

  • Responding to contact and enrollment requests: to review your inquiry, answer questions, and provide program details. Legal basis: Art. 6(1)(b) (steps prior to entering a contract) and Art. 6(1)(a) (consent where required, such as explicit consent checkbox on the form).
  • Site analytics and performance: to understand which pages are useful, improve navigation, and maintain content quality. Legal basis: Art. 6(1)(a) (consent).
  • Marketing and remarketing: to measure advertising performance and show relevant ads to people who have interacted with our Site (where enabled). Legal basis: Art. 6(1)(a) (consent).
  • Security and fraud prevention: to protect the Site, prevent abuse of forms, and investigate suspicious activity. Legal basis: Art. 6(1)(f) (legitimate interests).
  • Compliance with legal obligations: to meet applicable legal, regulatory, or tax requirements. Legal basis: Art. 6(1)(c) (legal obligation).

Automated decision-making (GDPR Art. 22): We do not engage in automated decision-making or profiling that produces legal or similarly significant effects for you.

4. Cookies & Tracking

Cookies are small text files stored on your device. We also use similar technologies, such as pixel tags and local storage, to support essential functions and (with consent) measure performance and marketing effectiveness. You can learn more in our Cookies Policy at /cookie-policy/.

We group cookies and related tracking into the categories below. These categories match our cookie preference panel:

Essential cookies (always active)

Essential cookies are required for core site functions, such as session continuity and storing your cookie choices. These do not require consent because they are necessary to provide the service you request when you use the Site.

  • _site_session (session): helps maintain basic site continuity and security.
  • cookie_consent (up to 12 months): stores your consent preferences for analytics and marketing cookies.
  • Security controls such as CSRF protection where applicable.

Retention for essential cookies ranges from the browser session to 12 months depending on the purpose.

Analytics cookies (consent required)

If you consent to analytics, we may use Google Analytics 4 (“GA4”) to understand how visitors use the Site. Where configured, IP anonymization is applied. Analytics helps us measure which content is read, which navigation patterns are common, and whether pages load reliably.

  • Examples include _ga (2 years) and _ga_XXXXXXXXXX (2 years).
  • Analytics data retention is typically set to 14 months.

Marketing cookies (consent required)

If you consent to marketing, we may use marketing cookies and pixels to measure advertising performance and to build audiences for remarketing and lookalike targeting. These tools help us understand which campaigns lead to inquiries, without promising or implying any specific outcomes from education participation.

  • Google Ads: for example _gcl_au (typically 90 days).
  • Meta: for example _fbp and _fbc (typically 90 days where set).

Beyond cookies, some advertising systems may use pixel tags and server-side event forwarding (for example, conversion events) when enabled and consented. When server-side approaches are used, identifiers may be hashed before transfer where supported by the provider.

5. Consent (EEA/UK)

Users in the EEA and the UK receive a consent notice under GDPR/UK GDPR rules. Analytics and marketing cookies activate only after explicit, informed, freely given consent (GDPR Art. 6(1)(a)). Your consent choice is recorded in the cookie_consent cookie (stored up to 12 months).

You can withdraw consent at any time by using the “Manage cookie preferences” link in the footer or by clearing cookies in your browser. Withdrawal does not affect the lawfulness of processing that occurred before you withdrew consent.

6. Sharing With Advertising & Service Partners

We share personal data only as needed to operate the Site, respond to inquiries, and (where consented) measure and improve marketing effectiveness. We do not sell personal data.

Categories of partners may include:

We do not permit these providers to use Site data for their own independent commercial purposes. They process data under their own terms as service providers and, in some cases, as independent controllers for their platform operations.

7. International Transfers

Fj ApS is established in Denmark. Some of our partners may process data outside the EEA/UK, including in the United States. When personal data is transferred internationally, we rely on appropriate safeguards, which may include:

  • The EU-U.S. Data Privacy Framework (DPF) where applicable (primary safeguard for certified organisations), including the UK Extension where relevant.
  • Standard Contractual Clauses (SCCs) (EU 2021/914) as a fallback mechanism.
  • UK International Data Transfer Agreement (IDTA) as a fallback mechanism for UK transfers.

If you want more detail on the safeguards used for a specific transfer, contact us at [email protected].

8. Retention

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer period is required by law. Typical retention periods are:

  • Contact submissions: up to 2 years from the last interaction, to provide continuity if you return with related questions.
  • Email correspondence: for the duration of the relationship, plus up to 1 year as a practical reference period.
  • Server/security logs: typically up to 90 days, unless a longer period is needed to investigate abuse or security incidents.
  • Analytics data: typically 14 months (subject to configuration).
  • Marketing cookies: per the cookie lifetime (often 90 days) unless you withdraw consent earlier.
  • Cookie consent record: up to 3 years for audit purposes (where applicable), while the browser cookie storing your choice is typically up to 12 months.
  • Legal/tax records: retained as required by applicable law.

9. Your Rights (GDPR & UK GDPR)

If GDPR applies to your personal data, you may have the following rights, subject to conditions and exceptions in the law:

  • Right of access (Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure (Art. 17)
  • Right to restriction of processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object (Art. 21)
  • Right to withdraw consent at any time (Art. 7(3))
  • Right to lodge a complaint with a supervisory authority (Art. 77)

To exercise your rights, email [email protected]. We may request information to verify your identity. We aim to respond within 30 days, and may extend by up to 60 days for complex requests.

Supervisory authorities:

10. Children

This Site is not directed at individuals under 16. We do not knowingly collect personal data from minors. If you believe a child under 16 has provided personal data to us without verifiable parental consent, contact us at [email protected] and we will delete the information promptly.

11. Do Not Track

Some browsers offer a “Do Not Track” (DNT) signal. This Site does not respond to DNT signals. Third-party providers may have their own DNT handling policies.

12. Data Deletion Requests

You can request deletion of personal data by emailing us with the subject line “Data Deletion Request” at [email protected]. We may need to verify your identity before completing the request. If we must retain certain data to comply with legal obligations or to establish, exercise, or defend legal claims, we will limit processing and retain only what is required.

13. Business Transfers

If Fj ApS is involved in a merger, acquisition, asset sale, financing, reorganisation, insolvency, or similar event, personal data may be transferred to a successor or affiliated entity as part of that transaction. If such a transfer materially changes how personal data is used, we will provide notice on the Site.

14. California (CCPA/CPRA)

Fj ApS provides educational programs to participants across Canada, and the Site may also be accessed from the United States. This section describes rights for California residents under the California Consumer Privacy Act (as amended by the CPRA), where applicable.

In the past 12 months, we may have collected the following categories of personal information:

  • Identifiers: name, email, IP address, cookie IDs.
  • Internet/network activity: browsing interactions and usage signals on our Site.
  • Inferences: interests or preferences inferred from site usage for advertising (only if marketing consent is given where required).

We do not sell personal information as defined by the CCPA. We may share personal information for cross-context behavioral advertising when marketing cookies are enabled. California residents can opt out by using the cookie preferences panel accessible from the footer.

California rights may include: the right to know, delete, correct, opt out of sale/sharing, and the right to non-discrimination. To submit a request, email [email protected] with the subject “California Privacy Request”. We will take steps to verify your identity. Authorized agents must provide evidence of authorization.

15. Virginia (VCDPA)

If the Virginia Consumer Data Protection Act (VCDPA) applies, Virginia residents may have rights to access, correct, delete, obtain a copy (portability), and opt out of targeted advertising. We do not sell personal data or engage in profiling that produces legal or similarly significant effects.

To submit a request, email [email protected] with the subject “Virginia Privacy Request”. If we deny a request, you can appeal by emailing with the subject “Appeal of Refusal — Privacy Request”. We aim to respond to appeals within 60 days.

16. Nevada

Nevada residents may submit a verified opt-out request by emailing [email protected] with the subject “Nevada Do Not Sell Request”. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.

17. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes to the Site, our practices, or legal requirements. If changes are material, we will post a notice on the Site at least 14 days before the changes take effect. The “Last Updated” date at the top of this page indicates when the policy was most recently revised.

18. Contact

For privacy questions, requests, or concerns, contact: