The policy covers apply.dk, every form on the site and any enquiry you send us by email. It does not cover data we handle on behalf of our clients; that processing is governed by a data processing agreement with each client.
Data controller
The controller is Apply, Copenhagen, Denmark. You can reach us at office@apply.dk.
The legal entity behind Apply and apply.dk is Apply LLP:
- Legal name - Apply LLP, director Andrey Vasin
- Registered address - Bukhar Zhyrau Boulevard 62B, 050057 Almaty, Kazakhstan
- BIN - 220540005599
- Email - office@apply.dk
Data we collect
We only gather what is needed to answer you and deliver what was agreed. The website never asks for sensitive data or your CPR number.
- Contact form - your name, phone number or email address, the topic you pick and whatever you type in the message box.
- Technical details on submission - the page the form was sent from, your IP address and the browser user agent, used to fight spam and abuse.
- Client relationship - contact persons, billing information and correspondence once you or your company become a client.
- Support tickets - fault descriptions and the conversation that follows while we fix them.
Never send passwords through the form. Access to your systems is arranged separately and handed over only through a secure channel agreed with you.
Purposes
- Replying to your enquiry and preparing a quote.
- Entering into and performing a contract with you or your organisation.
- Handling support tickets and keeping a record of the work done.
- Invoicing and complying with the Danish Bookkeeping Act.
- Protecting the website against spam, misuse and attacks.
Legal basis and retention
The legal basis comes from Article 6 GDPR and varies with the purpose.
| Purpose | Legal basis | Retention |
|---|---|---|
| Answering a form enquiry | Art. 6(1)(b) and (f): steps prior to a contract and legitimate interest | 12 months after our last contact |
| Delivering contracted services | Art. 6(1)(b): performance of a contract | Term of the contract plus 3 years |
| Invoices and accounting records | Art. 6(1)(c): legal obligation under the Bookkeeping Act | 5 years from the end of the financial year |
| Security and spam prevention | Art. 6(1)(f): legitimate interest | IP address and user agent: 12 months |
| Technical settings in your browser | Strictly necessary for the site to work | Until you clear them |
Cookies and local storage
We use no cookies for analytics, advertising or tracking. The site only sets a session cookie and a CSRF security cookie, both required for the contact form, and both expire with the session.
Your browser also keeps three small values in local storage: your answer to the cookie banner, your choice of light or dark theme, and the region you selected. They never leave your device, and you can remove them in your browser settings. Should we ever introduce an analytics tool, this policy will be updated and your consent requested before any such cookie is placed.
Who receives data
Personal data is never sold and never used for advertising. It is disclosed only when necessary.
- Processors - our hosting provider and our email and accounting platforms. They act solely on our instructions under a data processing agreement.
- Auditors and authorities - where the law demands it, for example the Danish Tax Agency in relation to bookkeeping.
- Payment providers - when you pay by card or MobilePay. Card details are never visible to us.
Data is processed and stored within the EU/EEA. If a supplier were ever to transfer data outside the EU/EEA, this would only happen under the European Commission's standard contractual clauses or an adequacy decision.
Deletion and security
When the retention period in the table has run out, the data is erased or anonymised.
- Only staff who need the information for their work can access it.
- Every account is personal and protected by two-step verification.
- Data travels encrypted, and backups are kept apart from the production environment.
- Once a year we review what we collect and drop anything we can do without.
Your rights
The GDPR gives you several rights that you can exercise whenever you wish.
- Access to the data we hold about you (Art. 15).
- Correction of inaccurate data (Art. 16) and erasure (Art. 17).
- Restriction of processing (Art. 18) and data portability (Art. 20).
- Objection to processing based on legitimate interest (Art. 21).
Write to us and we will respond as quickly as we can, and within one month at the latest. If you are unhappy with how we handle your data, you may lodge a complaint with Datatilsynet, the Danish Data Protection Agency, at datatilsynet.dk.
Records that the Bookkeeping Act obliges us to retain cannot be erased before the statutory period ends, even at your request.
Data protection contact
Send questions about this policy, or requests for access or erasure, to office@apply.dk, ideally with »Personal data« in the subject line. We read it Monday to Friday, 08:00 to 17:00. More on how to reach us is on our contact page.