Privacy policy
Last updated: 24 October 2024
1. Introduction
This privacy policy explains how we collect, use and protect your personal data when you use our website. We are committed to protecting the confidentiality and security of your personal data in line with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Data controller
We are inciro K/S, based in Denmark. As the data controller, we are responsible for the processing of your personal data.
Contact details:
- Contact form: Available on our website
- Address: Fuglehavevej 35, 2750 Ballerup, Denmark
3. Personal data we collect
We collect and process the following personal data:
- Name
- Email address
- Message content
We only collect this information when you voluntarily submit it through our contact form.
4. How we use your personal data
We process your personal data solely for the purpose of:
- Responding to your enquiries and communication
- Keeping records of our communication
The legal basis for processing your data is:
- Your consent (Article 6(1)(a) GDPR)
- Our legitimate interests in responding to your enquiries (Article 6(1)(f) GDPR)
5. Data retention
We retain the personal data submitted through the contact form for as long as necessary to fulfil the communication purpose, and afterwards only for as long as we have a legitimate reason to keep it. You have the right to request deletion of your personal data at any time.
6. Third-party providers
We use the following third-party providers to process your data:
6.1 Brevo (formerly Sendinblue)
- Purpose: Handling contact form submissions
- Data location: EU data centres
- More information: brevo.com/legal/privacypolicy
6.2 Microsoft Exchange Online
- Purpose: Email storage and administration
- Data location: EU data centres
- More information: privacy.microsoft.com
6.3 Cloudflare
- Purpose: Website hosting, security and performance
- Function: Sets necessary cookies for security and caching
- Data location: EU data centres
- More information: cloudflare.com/privacypolicy
7. Cookies
We use minimal cookies that are necessary for website functionality:
Language preference cookie
- Purpose: Remembers your language choice
- Duration: Session cookie
- Type: Functional
Cloudflare cookies
- Purpose: Security and caching functionality
- Duration: Up to 30 days for security cookies
- Type: Functional
No tracking or marketing cookies are used on our website.
8. Your rights
Under the GDPR, you have the following rights:
- Right of access to your personal data
- Right to rectification of inaccurate personal data
- Right to erasure (the right to be forgotten)
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
To exercise any of these rights, please contact us through the contact form on our website.
9. Data security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Data encryption
- Regular security assessments
- Access control
- EU-based data processing and storage
10. International data transfers
All of our data processing activities are carried out within the European Union through our service providers' EU-based data centres.
11. Changes to this privacy policy
We reserve the right to update this privacy policy at any time. Any changes will be published on this page with an updated revision date.
12. Supervisory authority
You have the right to lodge a complaint with the Danish Data Protection Agency:
Datatilsynet
Carl Jacobsens Vej 35
2500 Valby, Denmark
Phone: +45 33 19 32 00
Email: dt@datatilsynet.dk
Website: www.datatilsynet.dk
13. Contact us
If you have questions about this privacy policy or our data processing practices, please contact us via:
- Our website contact form
- Address: Fuglehavevej 35, 2750 Ballerup, Denmark
Data protection commitment
EU compliance by design
At inciro, we prioritise the security and protection of your data. Our data handling is designed around EU-based services and controls, helping ensure compliance with European data protection requirements. This approach supports a high standard of confidentiality, security and operational trust.