Privacy policy for privaci.io
How Privaci processes personal data: what we collect, why, how long we keep it, who we share it with, and the rights you have under the GDPR.
Last updated
At Privaci we take the protection of your personal data seriously. This privacy policy describes what information we collect, why we collect it, how we process it, and what rights you have under the EU General Data Protection Regulation (GDPR).
1. Data controller
bon.do ApS
Company registration (CVR): 43473425
Denmark
Email: hello@privaci.io
bon.do ApS is the controller of the personal data processed in connection with the use of the Privaci service and visits to privaci.io. If you have questions about how we process your data, you are always welcome to contact us.
2. What data we collect
We only collect the information necessary to deliver our services. Depending on how you interact with Privaci, we may collect the following categories of information:
Contact and account details
Name, email address and company name that you provide when you sign up or contact us.
Payment details
Invoicing details are processed through our payment provider. We do not store full card details in our own systems.
Technical information
When you visit privaci.io, our consent snippet stores your consent choice and a random, pseudonymous visit ID locally in your browser. We do not store your IP address or user agent as part of the consent service. Anonymised, aggregated usage data may inform the operation of the platform.
Customer data (as processor)
When you use Privaci to manage cookie consent on your own platforms, we act as a processor on your behalf. The data processed in that context is governed by our data processing agreement.
3. Why we process your data
We process your personal data for the following purposes:
- Providing and operating the Privaci service, including creating and administering your account.
- Processing payments and issuing invoices.
- Customer support and answering enquiries.
- Improving and developing our services on the basis of anonymised usage data.
- Sending product updates and newsletters where you have given your consent.
- Meeting legal obligations, including bookkeeping law and the GDPR.
4. Legal basis for processing
We process your personal data on the following legal bases under Article 6 GDPR:
- Art. 6(1)(b) — Performance of a contract. Processing necessary to deliver the services you have ordered, including account creation and invoicing.
- Art. 6(1)(a) — Consent. Newsletters and marketing communication, which you can withdraw at any time.
- Art. 6(1)(c) — Legal obligation. Retention of accounting records under bookkeeping law and other legal requirements.
- Art. 6(1)(f) — Legitimate interest. Improving our services and preventing abuse, to the extent this does not override your fundamental rights.
5. Retention and deletion
We keep your personal data for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law.
- Account details are kept for as long as you are an active user and deleted no later than 30 days after your subscription ends.
- Accounting records and invoices are kept for 5 years under bookkeeping law.
- Support enquiries are kept for up to 2 years after the case is closed.
- Consent log records for cookie consent are kept for up to 24 months (730 days) from the time consent was given, in line with the rule that applied to the decision.
When a retention period ends, the information is deleted or anonymised securely.
6. Sharing with third parties
We do not sell your personal data to third parties. We may share your information with the following categories of recipients to the extent necessary:
Processors
Providers of infrastructure, hosting, payment processing and email communication, who process data on our behalf and are covered by data processing agreements. The subprocessors we use are listed in the data processing agreement.
Auditors and advisers
In connection with audits and legal advice, relevant information may be shared with advisers bound by confidentiality.
Authorities
Information may be disclosed to public authorities where we are legally obliged to do so.
Every third party that processes personal data on our behalf is required to comply with the GDPR and is covered by a data processing agreement with appropriate technical and organisational safeguards. Transfers to countries outside the EU/EEA take place only on the basis of the European Commission's standard contractual clauses (SCCs) or equivalent approved transfer mechanisms.
7. Your rights
As a data subject you have a number of rights under the GDPR. You can exercise them at any time by contacting us at hello@privaci.io. We answer your request as quickly as possible and no later than 30 days.
Right of access
You have the right to confirmation of whether we process information about you and, if so, to receive a copy of it.
Right to rectification
You have the right to have inaccurate or incomplete information about you corrected without undue delay.
Right to erasure
In certain cases you have the right to have your personal data deleted, unless we are obliged to retain it.
Right to data portability
You have the right to receive the information you have provided yourself in a structured, commonly used and machine-readable format.
Right to restriction
You have the right to request restriction of processing while a dispute about accuracy or lawfulness is resolved.
Right to object
You have the right to object to processing based on legitimate interest, including direct marketing.
Complaints to a supervisory authority. If you believe our processing of your personal data breaches data protection law, you have the right to lodge a complaint with the Danish Data Protection Agency, Datatilsynet (datatilsynet.dk). We do encourage you to contact us first, so that we have a chance to resolve the issue.
8. Cookies
privaci.io loads our own consent snippet from cdn.privaci.io. The snippet stores your consent choice locally in your browser and does not set cookies to do so. We set neither analytics nor marketing cookies on our own site today. If that changes, such cookies will only be set with your explicit consent, and this policy will be updated first.
You can read the exact keys, purposes and retention periods in our cookie policy, where you can also change or withdraw your consent.
9. Security
We implement appropriate technical and organisational safeguards to protect your personal data against unauthorised access, loss, misuse or alteration. This includes encryption of data in transit (TLS) and at rest, access control and regular security assessments.
In the event of a security breach that poses a high risk to your rights and freedoms, we will notify you as quickly as possible in accordance with Article 34 GDPR.
10. Changes to this policy
We reserve the right to update this privacy policy when necessary to reflect changes in our services, legislation or practice. The date shown at the top will always reflect the latest version. For material changes we will notify you by email or through a clear notice in the platform.
11. Contact
If you have questions about this privacy policy, or wish to exercise your rights, you are welcome to contact us:
bon.do ApS — Privaci
Company registration (CVR): 43473425
Denmark
Email: hello@privaci.io
Response time: we answer your request within 30 days.