Privacy policy
Version 1.2, effective 3 September 2026
Notice: this document has been prepared internally and has not been reviewed by external legal counsel. It reflects the operation of the Website as at the date stated above.
1. Scope
1.1 This privacy policy governs the processing of personal data carried out by Apptivate in connection with the website published at apptivate.dk (the "Website").
1.2 This policy does not govern the processing of personal data carried out in the course of a client engagement. Such processing is governed by the written agreement concluded for that engagement and, where applicable, by a separate data processing agreement.
2. Data controller
2.1 The data controller is Apptivate, Copenhagen, Denmark (the "Controller", "we" or "us").
2.2 Enquiries concerning this policy or the exercise of the rights set out in clause 8 shall be directed to [email protected].
2.3 The Controller has not appointed a data protection officer, no such appointment being required under Article 37 of Regulation (EU) 2016/679 (the "GDPR") in respect of the processing described in this policy.
3. Categories of personal data
3.1 Where a data subject submits the contact form made available on the Website, the Controller processes the following categories of personal data: name; email address; organisation name, which is a required field; and the content of the message submitted.
3.2 Upon each submission of the contact form, the Controller transiently processes the internet protocol address of the requesting device in the form of a rate limiting key consisting of that address, together with a counter of submissions made from that address, for the purpose described in clause 4.4.
3.3 In the course of delivering the Website, the Controller's hosting provider processes technical data relating to each request, including the internet protocol address of the requesting device, the user agent string, and the time of the request.
3.4 The Controller does not process special categories of personal data within the meaning of Article 9 GDPR by means of the Website, and requests that data subjects refrain from submitting such data through the contact form.
3.5 In respect of each request to the Website, the analytics provider identified in clause 5.1(c) processes the address of the page requested, the address of the referring page where one exists, and the approximate country, browser and device type derived from the request. That derivation is performed at the time of the request and the internet protocol address of the requesting device is not retained by the analytics provider. No identifier is written to the data subject's device for this purpose.
4. Purposes and legal bases
4.1 Personal data submitted through the contact form is processed for the purpose of receiving, assessing and responding to the enquiry. The legal basis is Article 6(1)(f) GDPR, the legitimate interests pursued by the Controller in responding to enquiries concerning its services, such interests being balanced against the interests of the data subject, who has initiated the communication.
4.2 Where an enquiry proceeds toward the conclusion of a contract, processing carried out at the request of the data subject prior to entering into that contract is additionally founded on Article 6(1)(b) GDPR.
4.3 Technical data described in clause 3.3 is processed for the purposes of delivering the Website, maintaining its security, and preventing abuse. The legal basis is Article 6(1)(f) GDPR.
4.4 The rate limiting key described in clause 3.2 is processed for the purpose of protecting the contact facility against automated abuse, by refusing a sixth submission made from the same internet protocol address within a period of 600 seconds. The legal basis is Article 6(1)(f) GDPR, the legitimate interests pursued by the Controller in maintaining the security and availability of the Website.
4.5 The Controller does not carry out profiling or automated decision making producing legal effects concerning data subjects within the meaning of Article 22 GDPR, does not process personal data for advertising, and does not track a data subject across websites or over time. The aggregate measurement described in clause 4.6 is not behavioural analytics and does not identify a data subject.
4.6 The data described in clause 3.5 is processed for the purpose of measuring, in aggregate, how many people visit the Website and which pages they read, so that the Controller may judge whether the Website is doing its work. The legal basis is Article 6(1)(f) GDPR, the legitimate interests pursued by the Controller in understanding the use of its own website, such interests being balanced against the interests of the data subject by the absence of any identifier stored on the data subject's device, the absence of any profile, and the absence of any retained internet protocol address.
5. Recipients and processors
5.1 The Controller engages the following processors within the meaning of Article 28 GDPR:
(a) Cloudflare, Inc., which provides hosting of the Website and the automated filtering applied to contact form submissions in order to distinguish human from automated senders (Cloudflare Turnstile). The challenge is run when the data subject submits the contact form, and the challenge widget is displayed only where the challenge requires interaction by the data subject. The processing carried out by Cloudflare Turnstile is further described in the Cloudflare Turnstile Privacy Addendum. Cloudflare, Inc., in its capacity as the Website's hosting provider, additionally stores the rate limiting counter described in clause 3.2 in a Cloudflare Workers KV namespace;
(b) Resend (Plus Five Five, Inc.), which transmits contact form submissions to the Controller by electronic mail.
(c) Cloudflare, Inc., which additionally provides the aggregate measurement described in clause 4.6 (Cloudflare Web Analytics). The measurement script is inserted by Cloudflare into the pages of the Website as they are served. It writes no cookie and no other identifier to the data subject's device.
5.2 Each processor acts on documented instructions from the Controller under a written agreement satisfying Article 28(3) GDPR.
5.3 Personal data submitted through the contact form is not written to any database operated by the Controller, is not sold, and is not disclosed to any third party other than the processors identified in clause 5.1, save where disclosure is required by law. The Cloudflare Workers KV namespace referred to in clause 5.1(a) holds the rate limiting counter only and holds no part of the content of any submission.
6. Transfers to third countries
6.1 The processors identified in clause 5.1 are established in the United States and may process personal data outside the European Economic Area.
6.2 Such transfers are carried out on the basis of the standard contractual clauses adopted by the European Commission pursuant to Article 46(2)(c) GDPR, and, where the recipient is certified under the EU-US Data Privacy Framework, on the basis of the adequacy decision adopted pursuant to Article 45 GDPR. A copy of the relevant safeguards may be requested at the address given in clause 2.2.
7. Retention
7.1 Correspondence arising from a contact form submission is retained for so long as the enquiry remains active and thereafter for a period of twenty-four months from the date of the last communication, in order to provide continuity in the event that the enquiry is resumed.
7.2 Where an engagement results, personal data forming part of the contractual record is retained for the period required by the Danish Bookkeeping Act and other applicable law.
7.3 Personal data is erased at the end of the applicable period, or earlier upon a request made under clause 8.1(c) where no overriding legal obligation requires its retention.
7.4 The rate limiting key described in clause 3.2 is retained for at most 600 seconds from the time at which it is written, whereupon it is deleted automatically.
7.5 The measurement data described in clause 3.5 is retained by the analytics provider in aggregate form only, for a rolling period not exceeding six months, and cannot be resolved to a data subject.
8. Rights of the data subject
8.1 Subject to the conditions and exceptions provided in the GDPR, a data subject has the right to:
(a) obtain confirmation of processing and access to the personal data concerned (Article 15);
(b) obtain rectification of inaccurate personal data (Article 16);
(c) obtain erasure of personal data (Article 17);
(d) obtain restriction of processing (Article 18);
(e) receive the personal data in a structured, commonly used and machine-readable format (Article 20);
(f) object at any time to processing founded on Article 6(1)(f), on grounds relating to the data subject's particular situation (Article 21).
8.2 Requests shall be submitted to the address given in clause 2.2. The Controller shall respond without undue delay and in any event within one month of receipt, which period may be extended by two further months where necessary, in accordance with Article 12(3) GDPR.
8.3 No fee is payable in respect of a request, except where a request is manifestly unfounded or excessive within the meaning of Article 12(5) GDPR.
9. Cookies and similar technologies
9.1 The Controller does not set cookies on the Website, and does not employ any technology for the purpose of tracking a data subject across websites or over time. The measurement described in clause 4.6 writes no cookie and no other identifier to the data subject's device, and is for that reason not subject to the consent requirement in section 4(1) of the Danish Executive Order on Cookies (bekendtgoerelse nr. 1148 of 9 December 2011). No consent banner is presented, none being required for the operation described in this policy.
9.2 The automated filtering referred to in clause 5.1(a) may store a value in the data subject's browser for the sole purpose of recording that a submission has been verified. That value is strictly necessary to provide the service requested by the data subject and is not used for any other purpose.
10. Security
10.1 The Controller implements appropriate technical and organisational measures within the meaning of Article 32 GDPR, including transport encryption for all traffic to and from the Website, restriction of access to received correspondence, and the minimisation of stored personal data by design.
11. Complaints
11.1 A data subject who considers that the processing of personal data relating to them infringes the GDPR has the right to lodge a complaint with a supervisory authority pursuant to Article 77 GDPR.
11.2 The competent supervisory authority in Denmark is Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark.
12. Amendments
12.1 The Controller may amend this policy to reflect changes in the operation of the Website or in applicable law. The version number and effective date stated above shall be advanced on each amendment.