Privacy Policy
Last updated: 1 October 2026
At frigg, we respect your privacy and handle personal data with care. This Privacy Policy explains how we collect, use, store and share personal data when you visit friggdk.com, contact us or use our wedding-related services.
It also explains how we handle documents provided for marriage applications, ceremony arrangements and related services.
1. Data Controller
The controller responsible for processing personal data in connection with this website and our services is:
Valeriya Pedersen, trading as frigg
Harvestehuder Stieg 9
20149 Hamburg
Germany
Privacy enquiries: valeriya@friggdk.com
General enquiries: hello@friggdk.com
Phone: +49 152 38986831
In this policy, “frigg”, “we”, “us” and “our” refer to Valeriya Pedersen operating as a sole proprietor.
2. Personal Data We Collect
The personal data we process depends on how you interact with us and which services you request.
Enquiries and initial contact
We may process:
· your name and your partner’s name;
· email address and telephone number;
· country or place of residence;
· nationality;
· preferred wedding date, timeframe and location;
· the type of assistance you are interested in;
· information about previous marriages or shared children, where relevant to your enquiry;
· communication preferences, including whether you would like to use WhatsApp; and
· information you include in messages or conversations with us.
Client services and documents
Where necessary for the agreed service, we may also process:
· date and place of birth, address and other identification details;
· passport or identity-document details and copies;
· information and documents concerning residence status, visas or lawful stay;
· civil-status information and supporting documents, including divorce decisions or documents relating to the end of a previous marriage;
· marriage applications, authorisations, certificates and correspondence with authorities;
· information about children or other individuals where required for the relevant application;
· ceremony details, personal preferences and information needed for agreed coordination services; and
· contracts, invoices, payment records and service correspondence.
Website and technical information
Our website and service providers may process technical information such as IP addresses, browser and device information, access times, pages visited, security-related information and cookie preferences.
Please provide only information relevant to your enquiry or the agreed service. Do not send passport scans or other confidential documents through the initial website contact form. We will explain how to provide documents when they are needed.
3. Purposes and Legal Bases
We process personal data for the following purposes:
Responding to enquiries and preparing offers
Where you contact us about purchasing services, processing is based on Article 6(1)(b) GDPR: taking steps at your request before entering into a contract.
For other business enquiries, processing is based on Article 6(1)(f) GDPR. Our legitimate interest is responding to communications concerning our business.
Providing agreed services
We process information necessary for document guidance, application and booking support, tailored assistance and other agreed services under Article 6(1)(b) GDPR.
Accounting and legal obligations
Where processing is necessary to comply with applicable tax, accounting or other legal obligations, the basis is Article 6(1)(c) GDPR.
Security, business administration and legal claims
Where appropriate, processing is based on Article 6(1)(f) GDPR. Our legitimate interests include protecting our website and business systems, administering our services, preventing misuse and establishing, exercising or defending legal claims.
Optional processing based on consent
Where we request your consent, including for optional WhatsApp contact or non-essential cookies, the basis is Article 6(1)(a) GDPR. You may withdraw consent at any time without affecting the lawfulness of earlier processing.
Providing information necessary for an offer, contract or marriage-related application is generally required for us to carry out the requested steps. If you do not provide it, we may be unable to offer or complete the relevant service. Optional information and consent-based choices are not compulsory.
4. Contact Forms and Enquiries
Our website contact forms are provided through Squarespace.
When you submit a form, we use the information to review your situation, respond to your enquiry and, where appropriate, prepare an offer or discuss the next steps.
Submissions may be stored in Squarespace’s form and contact-management systems. Email notifications are sent to our business email account and may contain the information submitted.
The legal basis is Article 6(1)(b) GDPR for enquiries relating to a potential contract, or Article 6(1)(f) GDPR for other business correspondence.
Submitting an enquiry does not by itself create a service contract or subscribe you to marketing communications.
5. Client Services and Sharing Documents
We process the information and documents necessary to provide the service agreed with you.
This may include reviewing documents, preparing or submitting an application where authorised, communicating with authorities, assisting with ceremony bookings and coordinating other requested services.
Where necessary, relevant information may be shared with:
· the Danish Agency of Family Law and other competent public authorities;
· Danish municipalities and ceremony locations;
· translators, interpreters and other agreed service providers;
· persons assisting with agreed apostille or document-handling services; and
· postal or courier providers where documents need to be delivered.
We share only the information reasonably necessary for the relevant task. For example, a wedding supplier will not receive your passport or application documents merely because they are involved in your ceremony.
Public authorities and independent service providers may process information as separate controllers under their own legal obligations and privacy notices.
The legal basis for our processing is generally Article 6(1)(b) GDPR. Where disclosure is legally required, Article 6(1)(c) GDPR may apply.
6. Document Uploads and Microsoft 365
We use Microsoft 365 business services, including SharePoint Online and, where applicable, OneDrive, to receive, organise, store and work with client documents.
Where documents are required, we provide a designated upload or sharing method. Please use the method indicated by us and do not forward your document-access links to unrelated persons.
Information processed through these services may include uploaded documents, names, email addresses, file names, document changes, access records and technical information generated when the service is used.
The purposes are to provide the agreed service, manage documents and support secure access and business administration.
Processing necessary for the agreed service is based on Article 6(1)(b) GDPR. Processing for system security and administration is based on Article 6(1)(f) GDPR, reflecting our legitimate interest in protecting client information and operating reliable business systems.
Microsoft processes customer data on our behalf under the applicable Microsoft business-service terms and data-processing arrangements. Certain service-related processing may also be carried out by Microsoft for its own purposes as described in its applicable terms and privacy information.
Access to client documents is limited to persons who need it for the agreed service or necessary administration. Where another person assists with a task, access is limited to the information needed for that task.
Microsoft’s data-location commitments depend on the service and account configuration. Some service, support or security processing may involve access or transfers outside the European Economic Area. Section 13 explains international transfers.
7. Information About Other People and Sensitive Information
Marriage-related services may involve information about your partner, children, former spouses or other individuals.
We may receive this information from you, your partner, authorised representatives or relevant authorities and service providers involved in the agreed process.
Please ensure that you are entitled to provide information about another person and make this Privacy Policy available to them. We will provide information directly to affected individuals where required by the GDPR.
Where a person is not a party to our contract, necessary processing may be based on Article 6(1)(f) GDPR. Our legitimate interest is carrying out the requested marriage-related service while limiting processing to relevant information and respecting the affected person’s rights.
Some information may reveal special categories of personal data, such as health information, religious beliefs or sexual orientation. We do not ask for such information unless it is necessary for a specified purpose.
Where such processing is necessary, we will identify an applicable condition under Article 9 GDPR and obtain separate explicit consent where required. Submitting a contact form or accepting this Privacy Policy does not by itself constitute explicit consent to processing special-category data.
Please avoid including unnecessary sensitive information in enquiries or supporting documents.
8. Website Hosting, Cookies and Analytics
Our website is hosted by Squarespace.
Squarespace processes technical information needed to deliver, operate and secure the website. This may include IP addresses, browser and device information, access records and information about website use.
Processing necessary for website operation and security is based on Article 6(1)(f) GDPR. Our legitimate interest is maintaining a functional, reliable and secure website.
Necessary cookies and similar technologies
Necessary technologies support essential website functions, security and the storage of your privacy choices.
Where storage of, or access to, information on your device is strictly necessary to provide a service expressly requested by you, Section 25(2) TDDDG applies. Any associated personal-data processing relies on the appropriate GDPR legal basis.
Optional cookies and analytics
Non-essential analytics, performance or advertising technologies, where used, require your consent before activation.
If you consent to analytics, Squarespace may process information about visits, traffic sources, page views, interactions and browser or device characteristics to help us understand and improve the website.
The legal bases are Article 6(1)(a) GDPR and Section 25(1) TDDDG.
You can accept or decline optional cookies through the cookie banner and subsequently change or withdraw your choices using the Cookie Preferences control.
Withdrawing consent does not affect processing carried out before withdrawal.
9. Google reCAPTCHA
We use Google reCAPTCHA on website forms to help protect against spam, automated submissions and abuse.
Depending on the implementation, reCAPTCHA may process IP addresses, browser and device information, interaction information, cookies and other technical signals used to assess whether an interaction is legitimate.
Google processes reCAPTCHA customer data on behalf of the website operator under the applicable Google Cloud terms and data-processing arrangements.
Our purpose is protecting the website and forms against misuse. The GDPR legal basis is Article 6(1)(f), reflecting that legitimate interest, where applicable.
Storage of or access to information on your device is assessed separately under the TDDDG. Where consent is required, the relevant functionality must operate on the basis of consent under Section 25(1) TDDDG and, where applicable, Article 6(1)(a) GDPR.
10. Website Fonts
Our website uses web fonts through Squarespace’s font integrations, including Adobe Fonts, also known as Typekit. Where Google Fonts are delivered through an external integration, Google is also involved in providing them.
When your browser requests externally hosted fonts or their supporting resources, the relevant provider receives technical information needed to deliver them. This may include your IP address, browser information and information about the website requesting the font.
The purpose is displaying the website’s typography consistently.
Where legally permissible, the GDPR basis is Article 6(1)(f), reflecting our legitimate interest in presenting a functional and consistently designed website. Where an integration requires consent, processing is based on Article 6(1)(a) GDPR and the applicable TDDDG requirements.
Adobe states that its website font-delivery service receives IP addresses to deliver fonts but does not store those IP addresses.
11. Email and WhatsApp Communication
Our business email accounts are provided through Namecheap Private Email.
Email processing may include your name, email address, message content, attachments and technical email metadata.
We use this information to respond to enquiries, communicate with clients and provide agreed services.
The legal basis is Article 6(1)(b) GDPR for contract-related communication or Article 6(1)(f) GDPR for other business correspondence.
WhatsApp is an optional communication channel. You can choose email instead.
Where you opt in to WhatsApp contact, or contact us through WhatsApp yourself, we may process your telephone number, profile information visible to us, messages and related communication information.
For optional WhatsApp contact based on your consent, the legal basis is Article 6(1)(a) GDPR. Processing message content necessary to respond to a contractual enquiry or provide an agreed service may also rely on Article 6(1)(b) GDPR.
You can withdraw your consent to WhatsApp contact at any time by telling us. We will then use another agreed communication method.
WhatsApp Ireland Limited provides WhatsApp services in the European Region and processes service-related information under its applicable terms and privacy policy. End-to-end encryption of messages does not prevent processing of service and usage metadata.
Please use the document-upload method designated by frigg for passport scans and other confidential application documents rather than sending them through WhatsApp.
12. Payments and Revolut
We use Revolut for business banking and, where applicable, payment services.
When you make a payment, we may receive information such as your name, payment amount, currency, payment date, transaction reference and bank-account or other payment details made available with the transaction.
We use this information to identify payments, administer the contract, issue invoices, process refunds and comply with accounting and tax obligations.
The legal bases are Article 6(1)(b) GDPR for payment administration and Article 6(1)(c) GDPR for statutory obligations.
The Revolut entity providing the relevant banking or payment service processes personal data under its own terms and privacy notices. For EEA banking services, this is generally Revolut Bank UAB, including through its applicable branch. Different Revolut services may involve other Revolut entities.
Where you use a payment link or payment page, additional information may be collected directly by the payment provider. The provider’s privacy information applies to that processing.
13. Service Providers and International Transfers
We use the following categories of providers:
· Squarespace: website hosting, forms, website functionality and consent-based analytics;
· Namecheap Private Email: business email;
· Microsoft 365: document uploads, storage, collaboration and business administration;
· Google: reCAPTCHA and externally delivered Google Fonts where used;
· Adobe: Adobe Fonts / Typekit;
· WhatsApp: optional messaging; and
· Revolut: banking and applicable payment services.
Other recipients may include the authorities and providers described in Section 5, professional advisers where necessary, and recipients entitled to information under applicable law.
Providers acting as processors are subject to the applicable data-processing arrangements. Independent controllers process information under their own legal obligations and privacy notices.
Some providers operate internationally. Personal data may therefore be processed outside the European Economic Area, including in the United States.
Where required, transfers must be supported by a valid mechanism under Chapter V GDPR. Depending on the recipient and service, this may include:
· an applicable European Commission adequacy decision; or
· European Commission Standard Contractual Clauses, together with supplementary measures where necessary.
An adequacy framework applies only where the recipient and processing fall within its scope. European storage locations do not necessarily exclude access from outside Europe.
You may contact us for information about the transfer mechanism applicable to a particular provider and to request a copy or description of relevant safeguards, subject to necessary redactions protecting confidential information.
We do not sell personal data.
14. How Long We Keep Personal Data
We retain personal data only for as long as necessary for its purpose or as required by law.
Client identification and application documents
Working copies of identification documents and marriage-application documents are deleted from active client folders and other active storage locations under our control within 30 days after the agreed services have been fully completed or the contract has otherwise ended, unless a specific legal obligation or a necessary legal-claims purpose justifies continued retention.
Where several services have been agreed, completion means completion of those services, including any agreed post-ceremony assistance.
Recycle bins, versions and backups
Deletion from active storage does not always mean immediate removal from every technical recovery system.
Deleted SharePoint and OneDrive files may remain recoverable in recycle bins for up to 93 days under standard service settings, unless removed earlier. Retention settings, preserved versions or legal holds may affect deletion.
Residual copies in backup or recovery systems are subject to the relevant provider’s deletion cycles and applicable configuration. They are not retained for continued routine service use.
Where an erasure request applies, we assess and address relevant active and recoverable copies, subject to lawful retention requirements.
Contracts, invoices and accounting records
Records subject to tax, accounting or other statutory obligations are retained for the applicable legal period. Depending on the record, German statutory periods may generally be six, eight or ten years.
These obligations do not automatically require us to retain all passport scans or all application documents for the same period.
Enquiries without a client relationship
Enquiries that do not result in a contract are generally deleted within 12 months after the last meaningful communication, unless a specific legal or legitimate reason requires longer retention.
Legal claims
Where particular information is necessary to establish, exercise or defend a legal claim, it may be retained for the relevant limitation period or until the matter is resolved. Such retention is limited to the information needed.
Consent records and technical information
Consent records may be retained as necessary to demonstrate compliance. Technical logs and security information are retained according to their operational purpose and relevant service settings.
Independent authorities, banks and other controllers determine their own retention periods. Our deletion commitments apply to processing under our control.
15. Data Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure.
Measures are selected according to the type of information, the processing involved and the associated risks. Access to client documents is limited to what is necessary for the relevant service or administration.
Please keep document-access links confidential and tell us promptly if you believe a link or document has been accessed by an unauthorised person.
No internet transmission or storage system can eliminate every security risk.
16. Your Rights
Subject to the conditions and exceptions in the GDPR, you may have the right to:
· access your personal data and obtain a copy;
· correct inaccurate or incomplete information;
· request deletion;
· request restriction of processing;
· receive eligible information in a portable format;
· object to processing based on legitimate interests;
· withdraw consent; and
· lodge a complaint with a data protection supervisory authority.
To exercise your rights, contact valeriya@friggdk.com.
We may request information reasonably necessary to verify your identity. We will not ask for more identification information than necessary.
We normally respond within one month of receiving a request. Where permitted by the GDPR, this may be extended by up to two further months because of the complexity or number of requests. We will inform you of an extension and its reasons within the initial month.
Withdrawing consent does not affect earlier lawful processing or processing that continues on another valid legal basis.
17. Right to Object and Complaints
Right to object
Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation.
We will stop the relevant processing unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or the processing is necessary for legal claims.
If personal data is processed for direct marketing, you may object at any time without giving a reason. The data will then no longer be processed for that purpose.
Supervisory authority
You may complain to a competent data protection supervisory authority, including in the country of your habitual residence, place of work or the alleged infringement.
The authority responsible for us in Hamburg is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Straße 22
20459 Hamburg
Germany
Email: mailbox@datenschutz.hamburg.de
Website: https://datenschutz-hamburg.de
18. Automated Decisions and Policy Updates
frigg does not use personal data to make decisions based solely on automated processing that produce legal effects or similarly significantly affect individuals within the meaning of Article 22 GDPR.
Technical tools used to prevent spam or abuse may automatically assess website interactions.
We may update this Privacy Policy when our services, providers, processing practices or legal requirements change. The current version will be available on our website, with the update date shown above.
For questions about this policy or our processing of personal data, contact valeriya@friggdk.com.

