How we handle your data.
GDPR-compliant. We collect the minimum data needed to serve you, store it only as long as required, never sell it, and you have a clear right to access, correct, or delete it at any time.
1. Controller
The controller for personal data processing on this website (under Art. 4 (7) GDPR) is:
ImpactWorks
Christian Schulze
2900 Hellerup, Denmark
CVR-Nr.: 46021444
Email: christian.schulze@impactworks.online
2. Data we collect
2.1 Server logs (automatic)
When you visit any page on impactworks.online, the hosting infrastructure (Vercel) automatically records non-personal technical data: anonymized IP address, browser type and version, device type, referring URL, timestamp, and the page requested. This is required for security and to deliver the page. The data is kept for a maximum of 30 days.
2.2 AI Readiness Assessment submissions
When you complete the AI Readiness Assessment and choose to receive your results by email, we collect:
- Your name
- Your email address
- Your company name
- Your assessment answers and computed scores
- Submission timestamp
Submissions are stored in the Wix Forms / CRM backend (see section 4 on Wix). They are used to deliver your results, and to allow us to follow up if you wish to discuss them.
2.3 Discovery call bookings
When you book a discovery call via the Cal.eu link, that booking and any data you provide (name, email, optional message) is handled by Cal.eu under their privacy policy. We receive a notification of the booking and the data you submitted.
2.4 Email contact
When you email us directly, we process the email content and your email address for the purpose of replying. Email exchanges are kept for as long as the business relationship requires, typically no longer than 24 months after the last contact.
2.5 Cookies and local storage
This site uses strictly necessary technical cookies (e.g. session cookies on the Wix Blog subdomain) and one first-party analytics identifier stored in your browser’s local storage (PostHog, see section 2.6). We do not use advertising cookies or third-party tracking cookies. The PostHog identifier is anonymous and does not contain your name, email, or any direct identifier. You can clear your browser site data for impactworks.online at any time to remove it.
2.6 Website analytics (PostHog)
We use PostHog (EU region) for first-party website analytics, to understand how visitors use the site and to improve it. PostHog records:
- Page views (which pages you visit and in what order)
- Clicks and form submissions (which elements you interact with, captured automatically)
- Custom events such as downloading a report, requesting a gated report, or signing up for the newsletter
- Technical metadata: browser type, device type, screen size, and country derived from IP address. The raw IP address is not retained long-term.
- Session recordings: visual replays of your session with all form input values and keystrokes masked. Used to identify UX issues.
- An anonymous distinct ID stored in your browser to recognise you across page loads. This ID is not linked to your name or email unless you actively submit a form on the site.
PostHog data is hosted on EU servers (eu.posthog.com). It is used solely for our own product and content optimisation, and is never passed to advertising platforms. Legal basis: Art. 6 (1) (f) GDPR, legitimate interest in understanding how the site is used. You can object to this processing at any time (see section 6).
2.7 Newsletter and report download requests (Brevo)
When you sign up for The ImpactWorks Brief newsletter, or request a gated report download via the report request form, we collect:
- Your email address
- Your first name, and (for gated report requests) your last name and company
- A source tag indicating which form you submitted
- The timestamp of your consent
- A confirmation flag, set only after you click the double-opt-in link in the confirmation email
- The list of reports you have requested (for gated report downloads)
These data are processed by Brevo (Sendinblue SAS, France) as a data processor (see section 4.6). Brevo is used to send the double-opt-in confirmation email, deliver the newsletter, and track delivery, open, and click rates for our own marketing reporting. Legal basis: Art. 6 (1) (a) GDPR, your explicit consent (newsletter) and Art. 6 (1) (b) GDPR, performance of the service you requested (delivery of a gated report). You can unsubscribe from any email using the link included in every email, and you can request erasure at any time.
3. Legal basis for processing
We process personal data on the following legal bases (Art. 6 GDPR):
- Art. 6 (1) (b): to provide a service you requested (e.g. delivering your assessment results)
- Art. 6 (1) (f): legitimate interest in running and securing the website (server logs, fraud prevention)
- Art. 6 (1) (a): consent, where you actively opt in (e.g. submitting the assessment form)
4. Third parties / processors
The following service providers process data on our behalf as data processors (Art. 28 GDPR):
4.1 Vercel Inc. (hosting)
The website is hosted on Vercel’s infrastructure. Vercel may store technical request logs in the EU and the US. Standard Contractual Clauses are in place for any transfers outside the EEA. See vercel.com/legal/privacy-policy.
4.2 Wix.com Ltd. (forms, CRM, blog)
Form submissions from the AI Readiness Assessment are processed by Wix as a backend service. The Wix Blog (running on a subdomain blog.impactworks.online) and the CRM Contacts and Forms apps are also Wix services. Wix processes data in the EU and globally; see wix.com/about/privacy.
4.3 Cal.eu (calendar booking)
Discovery call bookings are handled by Cal.eu (Cal.com Inc. / Cal.eu hosting). Cal.eu processes the data you provide during booking. See cal.com/privacy.
4.4 Zapier Inc. (workflow automation)
We use Zapier to automate cross-posting from the Wix Blog to LinkedIn. Zapier briefly processes blog post content and metadata. See zapier.com/privacy.
4.5 LinkedIn Corp. (cross-posting target)
Public blog posts may be republished on LinkedIn. No personal data of site visitors is sent to LinkedIn. Comments and reactions on those LinkedIn posts are governed by LinkedIn’s privacy policy.
4.6 Sendinblue SAS / Brevo (email)
Newsletter signups, double-opt-in confirmations, and gated report delivery emails are processed by Brevo (Sendinblue SAS), based in France, with EU-hosted infrastructure. See brevo.com/legal/privacypolicy.
4.7 PostHog Inc. (website analytics)
We use the EU-hosted product of PostHog (PostHog Inc., based in the US, with a dedicated EU data region). All event and session data we collect is stored on PostHog’s EU servers. Standard Contractual Clauses are in place to cover any access by the US parent. See posthog.com/privacy.
5. Data retention
We retain personal data only as long as needed for the purposes described above, or as required by law:
- Server logs: maximum 30 days
- Assessment submissions and CRM contact records: 24 months after the last contact, unless you request earlier deletion
- PostHog event data (page views, clicks, custom events): 12 months. Session recordings: 30 days.
- Brevo contact records (newsletter subscribers, report requesters): for as long as you remain subscribed or until you request erasure. Unsubscribed contacts are kept for 24 months in a suppression list, to honour your unsubscribe request.
- Email correspondence: as long as the business relationship requires, typically up to 24 months after the last contact
- Booking and invoicing records: 10 years where required by Danish tax law
6. Your rights
Under GDPR, you have the following rights:
- Access (Art. 15): to know what personal data we hold about you
- Rectification (Art. 16): to have inaccurate data corrected
- Erasure (Art. 17): to have your data deleted
- Restriction (Art. 18): to limit processing
- Data portability (Art. 20): to receive your data in a structured, commonly used format
- Objection (Art. 21): to object to processing based on legitimate interest
- Withdraw consent: at any time, with effect for the future
To exercise any of these rights, please email christian.schulze@impactworks.online. We will respond within one month.
7. Right to file a complaint
You have the right to lodge a complaint with a data protection supervisory authority. In Denmark, this is the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk). For visitors in Germany, you may also contact the data protection authority of your federal state.
8. International transfers
Some of our processors (notably Vercel, Wix, and the US parent of PostHog) operate globally and may transfer data outside the EEA. Where this happens, we rely on the European Commission’s Standard Contractual Clauses (SCCs) and equivalent safeguards to protect your data. PostHog event and session data is held on EU servers under the EU data region we use.
9. Changes to this statement
We may update this privacy statement to reflect changes to our services, third-party processors, or legal requirements. The latest version is always published here. The current version is effective as of the date below.
Last updated: 22 June 2026
