Privacy policy
How we collect and process your personal data, and the rights you have. This policy covers our website, our newsletter, and registration for our events.
Last updated: 28 July 2026
1. Who we are
The data controller is Copenhagen Laboratory Automation Network (CphLAN), H.P. Ørums Gade 20, 2100 København Ø, Denmark, CVR 40747141 (“we”, “us”, “the Organizer”). For any question about this policy or your personal data, contact info@cphlan.org.
2. What this policy covers
This is our single, overarching privacy policy. Alongside it, when you register for one of our events you also see the event-specific Terms of Registration on our registration platform (NemTilmeld); those terms and this policy are intended to be consistent, and this policy gives the fuller picture.
3. Our website
Our website (cphlan.org) is a static site. It sets no marketing or analytics cookies, uses no third-party trackers, and loads its fonts from our own server — so simply browsing the site does not require your consent and does not create a profile of you. If you email us using an address on the site, we process your message to reply to you.
The one exception is our newsletter sign-up form, which is provided by EmailOctopus and loads from their servers. If you choose to submit it, the name and email you enter are sent to EmailOctopus so we can add you to our mailing list (see section 4).
4. Our newsletter and event emails
If you sign up to hear from us, we process your name and email address to send you news and invitations. The legal basis is your consent (GDPR Article 6(1)(a)). You can withdraw consent at any time using the unsubscribe link in every email, or by writing to us — after which we stop sending and remove you from the mailing list.
When you apply through our website form we also ask for your employer, job title and department, so we can confirm that our audience is practitioners rather than suppliers or vendors (the same legitimate interest described in section 5). We hold these details only while we review your application; once that is done we keep only your name and email address on the mailing list and do not retain the vetting details there. We likewise add only your name and email address to the mailing list — we do not copy across the other details you give when registering for an event.
We send these emails using EmailOctopus (EmailOctopus Ltd, United Kingdom), which acts as our data processor. EmailOctopus records whether emails are delivered, opened and clicked so we can understand whether our messages are useful; we do not use this to make decisions about you. We keep newsletter data until you unsubscribe or ask to be removed.
5. Event registration
We organise physical meetings roughly twice a year. Registration and any payment are handled through NemTilmeld (NemTilmeld.dk ApS), which acts as our data processor. When you register we collect the information needed to run the event — typically your name, email, phone number and any details specific to that event (for example dietary requirements) — and, for paid events, the payment and billing details needed to take payment.
To keep the network independent, we also ask for your employer, job title and department when you register, so we can confirm that attendees are practitioners rather than suppliers or vendors. We use this only to review registrations; the legal basis is our legitimate interest in keeping our meetings vendor-free (Article 6(1)(f)). This information stays in the event registration system and is not added to our mailing list or used for marketing.
The legal basis for the rest is performance of our agreement with you (Article 6(1)(b)), our legitimate interest in organising and running the event (Article 6(1)(f)), and, for financial records, our legal obligations (Article 6(1)(c)). The event's own Terms of Registration on NemTilmeld describe this in more detail for each event.
6. Where your information goes (recipients)
We share personal data only as needed to run our activities, with:
- NemTilmeld — registration and payment for events (processor).
- EmailOctopus — sending our newsletter and invitations (processor).
- Microsoft (Microsoft Ireland Operations Limited) — we administer our work in a Microsoft 365 environment (email, files, calendars), so attendee lists and correspondence are stored and processed there (processor).
- Payment providers — for paid events, card payments are handled through NemTilmeld's authorised payment providers (Quickpay, Clearhaus, Nets). We never see full card numbers.
- Bookkeeping — for paid events, transaction details are processed in our accounts as required by the Danish Bookkeeping Act (Bogføringsloven).
- At the event — where there is a legitimate interest, a list of attendees may be shared with speakers and other attendees, and event suppliers (e.g. the venue) may receive the information they need.
We do not sell your personal data, and we do not share it for others' marketing.
7. Photos and video at events
We take photographs and video at our meetings to show what the network does — for example in our event recaps on cphlan.org and on our LinkedIn page. For ordinary situational photos — a room, an audience, people networking — we rely on our legitimate interest in documenting and promoting the network (Article 6(1)(f)), having weighed that against your interests. We tell you at registration and at the event that photographs are being taken.
You can ask us — at registration or at any time — that you would prefer not to appear, and we will respect that and avoid featuring you. For a close-up or posed photograph of an individual, we ask that person's consent. You can also ask us to remove any image of you at any time by writing to info@cphlan.org.
8. Our board
With their consent, we publish the name, role, short biography and photograph of our volunteer board members on the Board page of this website, so members know who runs the network.
9. International transfers
Some of our processors may process data outside Denmark. EmailOctopus is in the United Kingdom, which the European Commission recognises as providing adequate protection. Microsoft may process data outside the EU/EEA under appropriate safeguards, such as the European Commission's standard contractual clauses. In each case the data remains protected to an EU-equivalent standard.
10. How long we keep your data
- Newsletter: until you unsubscribe or ask to be removed.
- Event registrations: deleted two years after the end of the event.
- Payment/financial records: kept until the end of the calendar year plus five years, as required by the Danish Bookkeeping Act.
- Correspondence: kept only as long as needed to deal with your enquiry.
11. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to our processing;
- receive your data in a portable format; and
- withdraw consent at any time, where we rely on consent.
To exercise any of these, write to info@cphlan.org (attn. Benjamin Wohl). We may ask you to confirm your identity, and we will respond as soon as we can and within the time limits set by law.
12. Complaints
If you are unhappy with how we handle your data, you can complain to the Danish Data Protection Agency:
Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby · +45 33 19 32 00 · dt@datatilsynet.dk
13. Changes to this policy
We may update this policy from time to time. The current version, with its date, is always available at cphlan.org/privacy.
14. Contact
Copenhagen Laboratory Automation Network · H.P. Ørums Gade 20, 2100 København Ø, Denmark · CVR 40747141 · info@cphlan.org