About CookieHawk
1. Legal information
| Legal name | Webkompaniet AS |
|---|---|
| Organisation number | 999 529 860 · Brønnøysundregistrene |
| Register | Norwegian Register of Business Enterprises (Brønnøysundregistrene) |
| Value added tax | VAT registered (NO 999 529 860 MVA) |
| kontakt@cookiehawk.com | |
| Phone | 23 96 33 41 |
| Response time | Enquiries are normally answered within one working day. |
2. Who we are
- Mikael is the founder.
- Stine handles delivery and customer contact.
3. Suppliers
The list distinguishes suppliers for our own administration from subprocessors processing data on behalf of customers. It is updated when something changes; customers with a data processing agreement are notified 30 days before changes.
| Supplier | Role | Service | Data | Processing location | Basis | Used since |
|---|---|---|---|---|---|---|
| Hetzner Online GmbH | Processor | Servers and storage (website, scanner, reports, lead records) | Lead records, reports (URLs, request/cookie metadata, screenshots), configuration, logs | Finland (Helsinki, EEA) | Data processing agreement (Hetzner DPA) | 2026-08 |
| Resend, Inc. | Processor | Email delivery (lead and report notifications, our receipts) | Email address, website URL, type, timestamp, message content | EU region (eu-west-1, Ireland) for sending; US company, transfers under the EU-US Data Privacy Framework and SCCs | Data processing agreement (Resend DPA) | 2026-08 |
| Tripletex AS | Processor for Webkompaniet AS acting as an independent controller | Invoicing and accounting | Customer name, registration number, billing address, contact details, service, amount, tax and payment status. Accounting records are retained under statutory bookkeeping obligations. | See Tripletex’s current data processing agreement | Contract and bookkeeping obligations; not a subprocessor for consent logs | Invoice workflow |
| Stripe Payments Europe, Limited and relevant Stripe entities | Processor and, for certain payment, security and regulatory purposes, independent controller | Card payments, subscriptions, invoicing and fraud prevention | Contact, business, order, payment, IP/device and payment method data (card details held only by Stripe); no access to reports or end user data | Ireland and worldwide, including the USA | Stripe DPA, Data Transfers Addendum/SCCs and Stripe’s privacy policy | From launch |
| Cloudflare, Inc. | Processor (network/CDN in front of the website) | Traffic routing, DDoS protection and DNS for cookiehawk.com | IP address and technical request data in transit; no reports or lead records are stored with Cloudflare | Worldwide, including outside the EEA (default configuration); Cloudflare DPA and SCCs/DPF. EU regionalisation applies only if enabled and documented. | Data processing agreement (Cloudflare DPA) | 2026-08 |
| Loopia AB | Other supplier | Domain registrar (cookiehawk.com) | CookieHawk’s own registrant details, not customer data | Sweden (EEA) | · | 2026-08 |
Scanning runs on our own servers using Chromium; no external scanning services are used.
4. Security
- The public website and report delivery use HTTPS. Servers in the EEA with a firewall, key-based access and a restricted group of authorised users.
- Scanner traffic passes through a local outbound proxy that blocks private and local IP addresses, pins connections to a verified public IP and permits ports 80 and 443 (websites that only respond over HTTP are tested over HTTP). Each test state runs in an isolated browser context that closes after the run.
- Reports are marked confidential and shared via links with a random ID and a separate key; links expire after 30 days (extendable on request). Internal dashboards are password protected. We do not store cookie values from tested websites.
- Reports are generated automatically; a report is labelled manually reviewed only when the review is documented.
- Nightly backups of customer data with a seven-day rotation, stored on the same server in the EEA with restricted access. Logs are rotated continuously.
- Incidents: in the event of a personal data breach, affected customers are notified without undue delay and the Norwegian Data Protection Authority within 72 hours where required by law.
- Responsible vulnerability disclosure: security@cookiehawk.com. We have no ISO or SOC certification and do not claim otherwise.
5. Cookies and storage on this website
Read about cookies and local storage on this website in the privacy policy. (in Norwegian)
6. Accessibility
Automated functional tests of the banner run in Chromium, WebKit and Firefox. Selected WCAG 2.1 A/AA rules (axe-core), keyboard and focus checks have been tested automatically in Chromium. Manual testing at 200% zoom and with a screen reader is not complete. Results and known issues are updated here; send feedback to kontakt@cookiehawk.com. We say “tested against”, not “certified”.
7. Status and changelog
- Working: testing in three states, technical reports, the banner (snippet and WordPress plugin), Google Consent Mode v2. The banner supports nb, nn, sv and en. The website has six languages. Automated results are delivered in Norwegian Bokmål or English; the installation guide and full report are in Norwegian.
- Ready for delivery: ongoing nightly checks with alerts and portfolio reports for agencies.
- Planned: white-label reports, IAB TCF 2.4, Shopify.
| Date | Change |
|---|---|
| 2026-08 | Banner v0.5 (cross-tab consent synchronisation, 12-month validity checks, policy version, WCAG fixes). Scanner: rejection checks via selected CMP APIs, visits to subpages, protection against misattribution from cross-domain redirects in portfolio reports; infrastructure cookies do not raise priority. Calibration v7 frozen (data/KALIBRERING-V7-FRYST.md). Public “Check your website” (MVP). |
| 2026-08-22 | Legal texts v1.2 published (Stripe subscription terms, Resend/Stripe/Cloudflare suppliers, retention periods). |