Short version: training records stay in the EU, we run no advertising or analytics trackers, and we keep completion records for three years after the licence that produced them ends.
Wendel Consult, Platzvej 7, 7100 Vejle, Denmark. Contact for any privacy question or request: bo@wendelconsult.com.
We are not required to appoint a Data Protection Officer, and have not appointed one. Enquiries go to the address above.
This matters, because it determines who decides what happens to your data.
Your employer is the data controller. They decide who is enrolled, on what, and for how long records are kept. We act as their data processor and only process learner data on their documented instructions, under an Article 28 data processing agreement. If you want your data corrected or deleted, ask your employer first — we will refer your request to them.
We are the data controller for that relationship, and this notice describes what we do. No employer is involved and nobody else decides what happens to your data.
| Data | Why | Legal basis |
|---|---|---|
| Name, work email address, employer, department | Create the learner account, enrol on modules, address the learner correctly on the certificate | Performance of a contract (Art. 6(1)(b)), or the customer's instructions where we are processor |
| Course records: enrolments, attempts, scores, pass/fail, completion dates | Deliver the training, mark it, and give the employer the evidence they need for their health & safety management system | As above; the employer's own basis is usually a legal obligation under national law implementing Directive 89/391/EEC |
| Certificate ID and issue date | Issue the certificate and allow it to be verified as genuine | As above |
| Login timestamps, IP address, browser type in server logs | Keep the platform secure and diagnose faults | Legitimate interests (Art. 6(1)(f)) — running a secure service |
| Enquiry details when you email or fill in a form | Answer you, and follow up on a quote | Legitimate interests (Art. 6(1)(f)), or steps prior to a contract (Art. 6(1)(b)) |
| Free demo signup: name, work email address, employer | Create your trial account on the portal and give you 30 days' access to the demo module | Steps taken at your request before entering a contract (Art. 6(1)(b)) |
| A phone number, if you give us one at the end of the free demo, where we ask whether you would like to know more | Call you back about the training, because you asked us to | Steps taken at your request before entering a contract (Art. 6(1)(b)). Giving it is optional and the demo works without it |
| Whether you ticked the marketing box, and when | Send you occasional emails about our training — and prove, if asked, that you agreed | Your consent (Art. 6(1)(a)), and § 10 of the Danish Marketing Practices Act |
| Billing details | Invoice and meet accounting obligations | Legal obligation (Art. 6(1)(c)) — Danish Bookkeeping Act |
We do not collect special category data. We do not ask for, and do not want, health information, and we do not profile learners or make automated decisions with legal effect.
Signing up for the free demo creates an account on our training portal at portal.wendelconsult.com and gives you 30 days' access to the demo module. The demo issues no certificate.
You get the demo whether or not you agree to marketing. The marketing box is separate, it is not ticked for you, and leaving it empty changes nothing about your access. We will not email you about our training unless you tick it.
You can withdraw at any time, free of charge — use the unsubscribe link in any email we send, or write to bo@wendelconsult.com and we will stop. Withdrawing does not affect anything we sent before, and does not affect your access.
Every certificate carries a unique ID. Anyone holding that ID can enter it at wendelconsult.com/verify and see the learner's name, the module title and the completion date. Nothing else is disclosed, and there is no way to browse, list or search certificates — the check only answers a question about an ID the person already has.
This is the point of a certificate: an employer, auditor or inspector holding the document can confirm it is real. If you would rather your certificate were not publicly checkable, tell us or your employer and we can disable verification for that course.
We use a small number of suppliers. All learner data is stored in the EU/EEA.
| Supplier | What for | Where the data sits |
|---|---|---|
| Elestio (managed hosting) on Netcup infrastructure | The training portal and its database | Nuremberg, Germany |
| Hostinger | This website | Netherlands |
| Microsoft 365 | Our email — so anything you email us sits in the mailbox | EU data boundary |
| Brevo | Automated messages from the portal: invitations, password resets, reminders | France |
We do not sell personal data, and we do not share it for advertising. A current sub-processor list is available to customers on request, and we give notice before adding a new one.
The automated messages the portal sends — invitations, password resets, reminders — go out through Brevo, and Brevo records whether a message was opened and rewrites the links inside it so that clicks pass through its own domain before arriving where they say they will. We have turned this down as far as the service allows: previews of your messages are never stored, the tracking is set to anonymous, and Brevo deletes its logs after one month. It cannot be switched off entirely. We are telling you because you would otherwise have no way of knowing, and because the password-reset link in your inbox depends on that redirect working. It is not used for advertising, and nothing about it reaches this website, which still loads nothing from anyone.
Everything stays in the EU/EEA. The one exception is Microsoft, a US-headquartered supplier operating within its EU data boundary and relying on the EU–US Data Privacy Framework and standard contractual clauses. That framework is currently valid but subject to legal challenge, so we prefer EU-hosted suppliers wherever there is a real choice. This website previously loaded its typefaces from Google in the United States; since 12 August 2026 the fonts are served from our own server and the site makes no third-party requests at all.
This website sets no cookies, runs no analytics, advertising or social media trackers, and loads nothing from any third party — every file it uses, including the typefaces, is served from our own server. The only thing stored in your browser is a single flag remembering that you have already seen the opening animation, so it is not replayed on every page. It contains no identifier and is deleted when you close the browser. That is why there is no cookie banner — there is nothing to consent to.
The training portal sets a session cookie that is strictly necessary to keep you logged in.
Our commitment going forward: we may in future measure how the website is used, so we know which pages are useful. If we do, we will use a tool that stores nothing on your device and produces only aggregate statistics — no profiles, no cross-site tracking, no advertising. We will not place anything on your device for analytics or marketing without asking your permission first, and this page will be updated on the same day as any such change.
Under the GDPR you may ask for access to your data, correction of it, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. Write to bo@wendelconsult.com.
We will respond without undue delay and in any event within one month of receiving your request. If your request is unusually complex, or you have made a number of requests, we may extend that by up to two further months — if so, we will tell you within the first month and explain why. If we decide not to act on your request, we will tell you within the same period, with our reasons and your right to complain to a supervisory authority or seek a judicial remedy. Where we have genuine doubts about who you are, we may ask for information to confirm your identity before we act. There is no charge unless a request is manifestly unfounded or excessive.
If your employer bought the training, we will pass your request to them, as they decide the outcome.
If you are unhappy with how we have handled it, you can complain to the Danish Data Protection Agency, Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark — datatilsynet.dk — or to the supervisory authority where you live or work.
Access to the training portal is over HTTPS only. Administrative access is limited to the founder. The portal is hosted on managed infrastructure with automated backups. Customers are given their own company area and can only see their own people's records; company administrators manage their own users, so we do not need routine access to learner accounts.
If we change how we handle data we will update this page and the version number at the top. Customers under contract are told directly about material changes.