Privacy
Privacy policy
How PrivateGPT ApS processes personal data collected through this website — which data we process, on what legal basis, how long we retain it, and what rights you have.
Last updated: 23 June 2026.
About this policy
This policy covers our processing of personal data — purposes, legal basis, retention, recipients and your rights.
For specific information about cookies and embedded third-party services on the website, see our cookie policy.
Data controller
PrivateGPT ApS is the data controller for the personal data we collect through this website. Contact details are at the bottom of this page.
We are not required to appoint a Data Protection Officer (DPO), but privacy-related enquiries are handled by us at mail@privategpt.dk.
Personal data we process
We collect both data you provide yourself and data that is generated automatically when you use the site.
Data you provide
- Name, company, email address and phone number — when you book a meeting or send us an enquiry.
- Free-text input in forms and chat conversations — when you enter it yourself.
Data we collect automatically
- IP address, browser type, operating system, language and screen resolution.
- Anonymised geographic location (typically at city level).
- Which pages you visit, for how long, and how you navigate.
- Referrer (where you came from) and any UTM parameters.
Purposes and legal basis
We process personal data for the following purposes, each with its own legal basis under the GDPR:
- Responding to enquiries and demo bookings — legal basis: legitimate interest in handling the contact you have initiated (Art. 6(1)(f)), or measures taken at your request prior to entering into a contract (Art. 6(1)(b)).
- Newsletters and direct marketing — legal basis: your consent (Art. 6(1)(a)).
- Statistics and improving the website — legal basis: your consent via the cookie banner (Art. 6(1)(a) + the Danish Cookie Order § 3).
- Targeted advertising — legal basis: your consent via the cookie banner (Art. 6(1)(a)).
- Bookkeeping for any purchases and invoicing — legal basis: legal obligation under the Danish Bookkeeping Act (Art. 6(1)(c)).
- IT security and abuse prevention (e.g. server logs) — legal basis: legitimate interest in operating a secure website (Art. 6(1)(f)).
Retention
We only retain personal data for as long as necessary for the purpose it was collected for, or as long as we are legally required to. Specifically:
- Contact enquiries and demo bookings: up to 12 months after the case is closed — unless a customer relationship is established.
- Newsletter consent: until you withdraw the consent.
- Bookkeeping records: 5 years after the end of the financial year, per the Danish Bookkeeping Act § 12.
- Statistics cookies: up to 24 months.
- Marketing cookies: up to 24 months.
- Chat demo conversations: not persisted — the session is discarded on inactivity.
- Server and access logs: up to 90 days.
Recipients and processors
Personal data is passed to processors who process it on our behalf and strictly on our instructions. Data processing agreements are in place with every processor.
Personal data is not shared with third parties without your consent, unless sharing is necessary to fulfil a contract or required by law.
- Hosting and infrastructure: Vercel and Microsoft Azure (EU regions).
- Chat backend: publicgpt.dk (operated by us on Microsoft Azure).
- Analytics: Google Analytics, Google Tag Manager.
- Advertising: Google Ads, LinkedIn.
- Fonts and maps: Google Fonts, Google Maps.
- Email and calendar: Microsoft 365.
Transfers to third countries
Some of the processors and services we use transfer data to the United States. The transfer bases are as follows:
Google services (Analytics, Ads, Tag Manager, Fonts, Maps): Google LLC is certified under the EU-US Data Privacy Framework (DPF). The European Commission recognised the DPF as providing an adequate level of protection in its decision of 10 July 2023, and transfers take place on that basis.
LinkedIn (Microsoft Corporation): transfers take place under the EU-US Data Privacy Framework, under which Microsoft is certified.
Where the DPF is not available, we conclude the European Commission's Standard Contractual Clauses (SCCs) with the processor and apply supplementary measures such as encrypted transport and access control.
You can request a copy of the transfer basis by contacting us at mail@privategpt.dk.
Chat demo on the home page
The home page includes a chat demo where you can send messages to our platform. Messages are relayed through a proxy to our backend at publicgpt.dk, which is operated by PrivateGPT ApS on Microsoft Azure (EU region).
Messages are not persisted after the session ends, and they are not used to train or fine-tune AI models. Please do not enter sensitive information in the chat — it is intended as a product demo, not a production channel.
AI processing
PrivateGPT is an AI product. For clarity: we do not use data from this website — neither visit data, form input nor chat conversations — to train or fine-tune AI models.
The chat demo calls a model we operate ourselves on Microsoft Azure (Azure OpenAI). The model provider processes input as a processor and is not permitted to use input to improve foundation models.
Automated processing and profiling
The marketing cookies we use (Google Ads, LinkedIn) involve profiling — meaning a profile is created about you based on your behaviour in order to target ads. The profiling has no legal effect on you and does not significantly affect you.
Profiling only takes place if you have given consent via the cookie banner. You can withdraw consent or object to profiling at any time, without affecting the lawfulness of processing that took place prior to withdrawal.
Security and data breaches
We have implemented appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration or destruction. This includes encrypted transport (TLS), access control via Microsoft Entra ID, logging and ongoing security updates.
In the event of a personal data breach we will nevertheless notify the Danish Data Protection Authority within 72 hours, in accordance with GDPR Art. 33. If the breach entails a high risk to your rights, we will also notify you directly without undue delay.
Persons under 15 years of age
Our services are not directed at children. We do not knowingly collect personal data from persons under 15 years of age without the consent of a parent or legal guardian. If we become aware that we have received data about a person under 15 without valid consent, we will delete the data as soon as possible.
Your rights
Under the GDPR you have a number of rights over the personal data we process about you:
- Right of access — you can request confirmation of and a copy of the personal data we process about you.
- Right to rectification — you can have inaccurate data corrected.
- Right to erasure (the "right to be forgotten") — you can request deletion of data when it is no longer necessary.
- Right to restriction of processing in certain cases.
- Right to data portability — you can receive your data in a structured, commonly used and machine-readable format.
- Right to object to processing based on legitimate interest and to direct marketing, including profiling for that purpose.
- Right to withdraw consent — consent can be withdrawn at any time without affecting the lawfulness of processing that has already taken place.
Complaints
You can lodge a complaint about our processing of your personal data with:
The Danish Data Protection Authority (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, phone +45 33 19 32 00, email dt@datatilsynet.dk, datatilsynet.dk.
Changes to this policy
We may update this policy from time to time to reflect changes in our services or in legislation. Changes take effect on publication. The date at the top shows when the policy was last changed.