Page Design ApS

Denmark · owned by Independent (Denmark) · www.pagedesign.dk · 16 vendors

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 16 sub-vendors.

Insights

Last updated 2026-09-13 · revision 1

16 direct vendors, 201 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 3/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Page Design ApS demonstrates low migration readiness, primarily due to its deeply entrenched and 'heavily customised, proprietary' OpenCart platform, which underpins nearly all client solutions. This indicates a monolithic architecture with significant internal vendor lock-in, making any migration away from this specific platform extremely complex, time-consuming, and costly. There is no evidence of cloud-native adoption, containerization, or microservices architecture, suggesting a legacy technology stack (PHP, MySQL) that would require substantial re-engineering to migrate to modern cloud environments. While the company integrates with various external services, the core platform's proprietary nature is the dominant factor hindering readiness. Data on regulatory environment and specific data residency requirements is not provided, which could introduce unforeseen complexities during a migration. Furthermore, the absence of financial stability data (revenue concentration, growth history) makes it impossible to assess the company's capacity to fund a potentially expensive and resource-intensive migration effort. The high degree of customisation and reliance on a single, proprietary platform for its core offering places Page Design ApS at a very low level of migration readiness.

Compliance

5 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

SOC 2 is a voluntary framework developed by the AICPA for service organizations that store, process, or transmit customer data in the cloud. Page Design ApS provides hosting services (via sub-processors Curanet and Worldstream), webshop management, and digital services to its clients, meaning it acts as a service organization handling client data. However, SOC 2 is primarily a US-market expectation and is not legally mandated in Denmark or the EU. For a small Danish web agency serving primarily Danish SME clients, SOC 2 certification is not typically expected or required. Risk is Low because the market demand for SOC 2 from Danish SME clients is minimal, and GDPR/ISO 27001 are the more relevant EU frameworks. Assessment is recommended only if the company seeks to serve US enterprise clients.

Evidence: https://www.pagedesign.dk/om-page-design/forretningsbetingelser, https://www.aicpa-cima.com/resources/landing/soc-2-reporting-on-an-examination-of-controls-at-a-service-organization-relevant-to-security-availability-processing-integrity-confidentiality-or-privacy

Danish Marketing Practices Act — Partially Compliant

As a Danish company providing digital marketing services, email newsletters, and operating a commercial website, Page Design ApS is subject to the Danish Marketing Practices Act (Markedsføringsloven, LBK nr. 426 af 03/05/2017 as amended) and the Danish E-Commerce Act (E-handelsloven). The newsletter service requires explicit opt-in consent under both GDPR and the Danish Act on Electronic Communications (Lov om elektroniske kommunikationsnet og -tjenester). The company states it collects explicit consent for newsletters and provides unsubscribe links — positive indicators. However, the cookie policy lacks a modern consent management platform with granular pre-consent controls, which is required under the Danish Cookie Order (Cookiebekendtgørelsen) enforced by the Danish Business Authority (Erhvervsstyrelsen). Risk is Medium due to active Danish enforcement of cookie consent requirements.

Evidence: https://www.pagedesign.dk/cookies, https://www.retsinformation.dk/eli/lta/2017/426, https://www.erhvervsstyrelsen.dk/cookies

GDPR (source) — Partially Compliant

Page Design ApS is headquartered in Denmark (EU), making GDPR universally applicable. The company processes personal data of customers, employees, newsletter subscribers, and website visitors. Evidence of partial compliance exists: a published privacy/cookie policy referencing GDPR, a downloadable Data Processing Agreement (DPA) template for customers, and a documented list of sub-processors (Curanet, Worldstream, Cloudflare, Quickpay, Altapay). However, several compliance gaps are identified: (1) the privacy policy explicitly states that customer data is NOT stored encrypted ('Vi opbevarer ikke kundeoplysninger krypteret'), which is a notable security risk under GDPR Article 32; (2) the cookie policy lacks a proper consent management platform (CMP) or cookie banner with granular opt-in/opt-out controls as required by the Danish Cookie Order and GDPR; (3) Google Analytics IP addresses are shared with Google without clear adequacy mechanism documentation post-Schrems II; (4) no Data Protection Officer (DPO) is publicly identified. Risk is Medium rather than High because the company is a small SME with limited data volumes, no sensitive/special category data processing, and has made visible GDPR compliance efforts. Danish DPA (Datatilsynet) enforcement against small web agencies is active but typically targets more egregious violations first.

Evidence: https://www.pagedesign.dk/cookies, https://www.pagedesign.dk/om-page-design/forretningsbetingelser, https://www.datatilsynet.dk/english, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679

Financials

Three-year financials

Financial Resilience Score: 6/10

Page Design ApS demonstrates qualitative financial resilience through its long operating history since 1996, having survived multiple economic cycles including the dot-com bust, 2008 financial crisis, and COVID-19. The company benefits from a diversified service portfolio spanning websites, webshops, SEO, digital marketing, print, photo/video, and custom database solutions, reducing dependence on any single revenue line. Owner-managed continuity under founder Heine Krog suggests stability and consistent strategy. The agency likely enjoys recurring-revenue characteristics from hosting, SSL, maintenance, and SEO retainers, providing predictable cash flow. Its deep specialization in a customized OpenCart stack creates client stickiness and a modest technology moat. The broad SMB-oriented customer base across sectors including hospitality, retail, trades, and cultural institutions reduces single-customer concentration risk. However, as a small Danish ApS web agency, revenue is likely in the low double-digit million DKK range, providing limited buffer against loss of key staff or clients. Structural risks include talent dependence typical of the agency model, technology risk from reliance on OpenCart (smaller ecosystem than WordPress or Shopify), competitive pressure from fragmented Danish market and DIY platforms (Wix, Squarespace, Shopify), geographic concentration in Denmark with no FX diversification, and emerging AI disruption commoditizing website and copywriting services.

Key strengths: 29-year operating history surviving multiple economic cycles, Diversified service portfolio across web, e-commerce, SEO, print, and video, Owner-managed continuity with founder still leading, Recurring revenue from hosting, SSL, maintenance, and SEO retainers, OpenCart technology specialization creating client stickiness, Broad SMB customer base reducing concentration risk

Risk factors: Small-agency scale with limited financial buffer, Talent dependence typical of agency model, Heavy reliance on OpenCart with smaller ecosystem than competitors, Competitive pressure from fragmented market and DIY platforms, Geographic concentration in Denmark with no FX diversification, AI disruption commoditizing website and copywriting services

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report