Privacy policy

What we know about you, and why

This site is a framework you can read from end to end without telling anyone anything. There is nothing to sign up for and nothing to buy. Personal data comes into it only in the few narrow cases set out below — and this page says for each of them what is collected, what allows it, how long it stays, and what you can require of us.

Last written 2026-08-23

Who is responsible

Controller
Andreas Baggesen
Capacity
An individual, not a company. The Omnigoal is run privately, so there is no company registration number.
Address
Grinden 27, 8960 Randers
Denmark

One person decides what happens to this data and answers for it. There is no data protection officer, because the processing is not on a scale that requires one — and the address above reaches the person who makes the decisions rather than a department.

What is collected, and what allows it

Nothing is collected “just in case”. Each row below is a separate purpose with its own legal basis, and none of them is used for a different one later.

A closed list of people who asked to be told

What
For a period this site invited people to leave a name, an email address, which of three groups they belonged to, and anything they chose to add. That form is gone. The entries already given are still held.
Why
To tell those people, once, if what was being built ever becomes available to them. Nothing else is done with it, and no new entries are being taken.
What allows it
Their consent, given by submitting the form at the time (GDPR Article 6(1)(a)). The wording each person agreed to is stored word for word alongside their entry.
How long
Until they have been told, or until they ask to be removed — whichever comes first. If it never becomes available, until the list is deleted.

Having an account

What
Your email address, your name if you gave one, and a cryptographic hash of your password. Never the password itself.
Why
To let the few people who have one sign in. Accounts are made by hand; nobody can create one here.
What allows it
Necessary to provide what you asked for (GDPR Article 6(1)(b)).
How long
While the account exists. Deleted with the account.

Contributing to the framework

What
What you wrote, and whichever of name, role, organisation and email you chose to give — all four are optional and a contribution is read the same way without them. Alongside it: when it was sent, which page you were on, whether the browser was a phone or a computer, the country the host passes along, and your browser string. Your IP address is never written down; what is kept instead is a rolling one-way hash of it, used only to stop the same machine sending a hundred contributions in an hour, and it stops pointing at anyone the moment the secret rolls.
Why
To read the contribution, to weigh it against the framework, and — where you left an address — to be able to come back to you about it. Nothing is sent to you otherwise. It is not a mailing list, and it is never passed on.
What allows it
Legitimate interests in developing and correcting a published framework, and in being able to answer the person who wrote (GDPR Article 6(1)(f)). You chose what to send and what to sign it with, so the interest is narrow and nothing is collected that you did not type — but you can object, and it stops.
How long
The contribution itself is kept as part of the record of how the framework changed. Contact details are removed on request at any time, and that does not affect the contribution.

Keeping the site up and safe

What
Ordinary server logs: IP address, browser, the page requested, the time. Held by the host.
Why
To keep the site running, to find faults, and to stop abuse.
What allows it
Legitimate interests in operating and securing the service (GDPR Article 6(1)(f)). The interest is narrow, the data is not used for anything else, and it is not combined with anything that identifies you.
How long
A short period set by the host, and not longer than needed to investigate a problem.

Counting visits

What
The page seen, the time, whether the browser was a phone or a computer, the country the host passes along, and a rolling pseudonym. The pseudonym is a one-way hash of a secret, the day, your IP address and your browser string. Your IP address itself is never written down, and the secret is replaced every night, so two days of counting cannot be joined back together into a person.
Why
To see how many people come, which pages they read, and whether the site works. This counting is the site’s own: it happens on the server, nothing about it is sent anywhere, and it runs whether or not you allow Google Analytics. A visit is only counted once your browser confirms it loaded the page, which is what keeps search-engine and AI crawlers out of the numbers.
What allows it
Not personal data once the pseudonym is rolled and the address is discarded, and nothing is stored on your device, so no consent is required and none is asked for. If that ever changes, this page changes first.
How long
A little over a year, then deleted.

Google Analytics, if you allow it

What
A randomly generated number in two cookies from Google, the pages you look at, roughly which country you are in, and what kind of device and browser you use. Not your name and nothing that identifies you. Your IP address reaches Google as it reaches any website you open, is used to work out the country, and is not stored — that is Google’s stated behaviour for Analytics, and this site additionally asks for it explicitly.
Why
To see how the framework is found and read, using a tool that can be compared with the rest of the world. It runs alongside the site’s own counting, not instead of it — and the two will not agree, because Google only ever sees the people who said yes here.
What allows it
Your consent, and nothing else (GDPR Article 6(1)(a), and section 10 of the Danish executive order on cookies). Nothing from Google is loaded before you allow statistics — not loaded and silenced, not loaded in a limited mode: not fetched at all. Say no and the site works exactly as before.
How long
Up to two years on your device, and by Google under their own retention. Withdraw consent and the cookies are deleted from your device the moment you do.

Cookies beyond the necessary ones

What
Whatever the categories you agreed to actually collect. Set out in full in the cookie policy.
Why
Only the purposes you agreed to.
What allows it
Your consent (GDPR Article 6(1)(a)), which you can withdraw at any moment.
How long
As stated per item in the cookie policy.

Who else touches it

Two companies, both under a written data processing agreement, both acting only on instruction. Nothing is sold, and nothing is shared for anyone else’s purposes.

Supabase

Database and sign-in

Frankfurt, Germany (eu-central-1)

Holds the closed list and the few accounts that exist. Chosen with an EU region so the data stays in the EU.

Vercel

Hosting

Served from EU edge locations; the company is US-based

Serves the site and runs the code behind it. Transfers outside the EU rest on the EU Standard Contractual Clauses.

Resend

Email

Ireland (eu-west-1)

Sends the one notification that goes out when someone contributes to the framework. Chosen with an EU region, and it never sends anything to the contributor.

Google

Statistics, only with consent

United States, with servers worldwide

Google Analytics. Loads only if you allow statistics in the cookie banner, and not at all otherwise. This is the one processor here that is outside the EU by design; transfers rest on the EU-US Data Privacy Framework and the Standard Contractual Clauses. Saying no costs you nothing — the site counts its own visits without it.

Where data reaches a company outside the EU or EEA, the transfer rests on the European Commission’s Standard Contractual Clauses. You may ask for a copy of them.

What you can require

Write to info@theomnigoal.com and you will have an answer within a month. It is free, and you do not have to give a reason.

See it

Ask for a copy of what is held about you, and why.

Correct it

Have anything wrong put right.

Delete it

Ask for it to be erased. Where it rests on consent, that is nearly always straightforward.

Limit it

Ask that it be held but not used, while something is being sorted out.

Take it with you

Receive what you gave in a machine-readable form, and have it sent elsewhere.

Object

Object to anything resting on legitimate interests, and it stops unless there is a compelling reason it should not.

Withdraw consent

Change your mind, at any time, as easily as you gave it. What was done before stays lawful; nothing further happens.

If you think this is being done wrongly

Tell me first if you like, but you do not have to. You can complain directly to the Danish Data Protection Agency:

Datatilsynet
Carl Jacobsens Vej 35, 2500 Valby, Denmark
datatilsynet.dk

Two things this site does not do

No decisions made by machine alone

Nothing here decides anything about you automatically, and there is no profiling in the legal sense. Nothing on this site builds a picture of you, scores you, or sorts you into a group on the basis of what you have read.

Not for children

The site is meant for people working or studying in business. It is not directed at children, and accounts are not knowingly made for anyone under 16.

Changes

If this policy changes in a way that matters, the date at the top changes with it, and anyone on the waitlist or holding an account is told before it takes effect. Silent rewrites are not a thing that happens here.