The company details are still missing. The marked fields are filled in before the page is used.
Version 1.0 · effective 29 September 2026
This policy explains how we process personal data when you visit our website, use Tracepas, upload documents through the supplier portal or open a product passport. It fulfils our duty to inform under Articles 13 and 14 of the General Data Protection Regulation (GDPR).
1. Controller
[TODO: COMPANY DETAILS: legal name] CVR [TODO: CVR] [TODO: COMPANY DETAILS: address] Email: [TODO: CONTACT: email]
If you have questions about the processing or want to exercise your rights, write to [TODO: CONTACT: email].
2. When we are the controller and when we are a processor
We are the controller for data we decide about ourselves: website visits, the contact form, user accounts, the customer relationship, invoicing, support and security.
We are a processor for the data our customers put into the system: documents, product data, supplier information, declarations, product passports and scan statistics. Here the customer (the business using the system) is the controller, and we only process the data on the customer's instructions and under our data processing agreement. If you have questions about that data, contact the business that asked you for documents or published the product passport. We help the customer answer you.
3. What we process, why, and on what legal basis
3.1 Visits to the website and the system
| Data | IP address, time, the page requested and the browser's user agent |
| Purpose | To deliver the pages, protect against misuse and find errors |
| Legal basis | GDPR Art. 6(1)(f) (legitimate interest in secure and stable operation) |
| Retention | Our hosting provider's access log: 30 days. Our error log: 14 days. To limit attempts at login, upload and the contact form, a value derived from the IP address is kept for at most 1 hour |
About cookies: see our cookie policy. We do not use statistics or marketing cookies today.
3.2 Contact form and "Book a walkthrough"
| Data | Name, company, CVR or VAT number, role, email, phone, description of products, number of SKUs, your message and language |
| Purpose | To answer your request and plan a walkthrough |
| Legal basis | Art. 6(1)(f) (legitimate interest in answering requests from businesses) and, if you ask for a quote, Art. 6(1)(b) (steps before entering into a contract) |
| Retention | 12 months after our last contact, unless an agreement is made |
The name, company and email fields are needed for us to reply. The other fields are optional.
3.3 User accounts
| Data | Name, email, password (stored only as a hash), language, role in the organisation, two-step verification data if you switch it on, and active sessions with IP address and user agent |
| Purpose | To give you access to the system, secure the account and send service messages, such as invitations, password resets and service request status |
| Legal basis | Art. 6(1)(f) (legitimate interest in providing the service your employer has bought and keeping it secure) |
| Retention | For as long as you have an account. Sessions are deleted automatically after they expire. When you are removed from an organisation or the customer relationship ends, the account is deleted within 90 days. Your name may still appear in the customer's activity log and in issued declarations, for which the customer is the controller |
3.4 Customer relationship, payment and invoicing
| Data | Company name, CVR and VAT number, address, contact person, email, chosen plan, invoices and payments |
| Purpose | To enter into and perform the agreement, invoice and comply with bookkeeping rules |
| Legal basis | Art. 6(1)(b) (contract), Art. 6(1)(c) (legal obligation under the Danish Bookkeeping Act) and Art. 6(1)(f) for contact persons |
| Retention | Accounting records for 5 years from the end of the financial year they relate to (Danish Bookkeeping Act, section 12). Other data for as long as the customer relationship lasts and 12 months after |
3.5 Support and Assisted onboarding
Messages in service requests and documents sent to us are processed as a processor for the customer. When you write to us directly about support, we are the controller for the correspondence (Art. 6(1)(f)) and keep it for as long as the customer relationship lasts and 12 months after.
3.6 The supplier portal
If a business has sent you a link to upload documents, that business is the controller for the documents, your comment and your contact details. We store them on the business's behalf in the system. The documents may be read automatically with AI (see section 4). We are the controller for the technical data in section 3.1.
3.7 Product passports
When you scan a QR code or open a product passport:
- we use the IP address in the request to look up the country. The IP address is not stored in our database;
- we store only country, device type (mobile, tablet or computer), language and date as statistics for the business that published the passport;
- we set no cookies and use no tracking technologies. If you have previously chosen a language on our website, we read that choice.
We process the statistics as a processor for the business that published the passport (the manufacturer). For operation and security (section 3.1) we are the controller.
Product passports and declarations may contain the name and position of the person who signed the declaration and a contact address for access to restricted information. The business that published the passport is the controller for that data.
4. Automatic document reading (AI)
Documents that customers and suppliers upload may be read automatically using artificial intelligence (AI), so the system can propose values with a source. For this we use Google as a sub-processor (see sections 5 and 6). A person at the customer checks and approves each value before it is used. We do not use the data for training AI, and we only use a service where Google, under its terms, may not use the content to improve its products. No decisions about individuals are made solely by automated processing.
5. Recipients
We only share personal data with:
- Simply.com A/S, Denmark: hosting of the website, system, database and files.
- Google Cloud EMEA Limited, Ireland: automatic document reading.
- [TODO: email provider]: sending emails.
- [TODO: payment provider]: payment and invoicing.
- [TODO: accountant/bookkeeper]: bookkeeping.
- Public authorities where the law requires us to.
The current list of sub-processors is on the Sub-processors page.
Data in published product passports is publicly available because the business that published the passport has chosen this. Restricted information is only shown to those the business has given an access link.
6. Transfers outside the EU/EEA
Our hosting is in Denmark. For automatic document reading, Google may process the data in countries outside the EU/EEA, including the United States. The basis is the Commission's adequacy decision for the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795), under which Google LLC is certified, and the Commission's standard contractual clauses (Implementing Decision (EU) 2021/914) in Google's data processing terms. [TODO: adjust this section if document reading runs through Vertex AI in the EU. Processing then takes place in the EU.]
7. Your rights
Under the GDPR you have the right to:
- access the data we process about you (Art. 15);
- have incorrect data corrected (Art. 16);
- have data erased (Art. 17);
- have the processing restricted (Art. 18);
- receive data you have given us in a structured format (Art. 20);
- object to processing based on our legitimate interest (Art. 21).
These rights have certain limits, for example where we must keep data under the Bookkeeping Act. Where we are a processor, we pass your request on to the business that is the controller.
You can complain to the Danish Data Protection Agency (Datatilsynet), www.datatilsynet.dk.
8. Changes
We update this policy when we change how we process data. The current version and its date are shown at the top of the page.