Privacy Policy
Complyon Software ApS | Last updated: 3 April 2026

 

 

 

Welcome to Complyon! Complyon Software ApS (“we”, “our”, “us”) is committed to
protecting your personal data. This Privacy Policy explains how we collect, use, store, and
share your personal information when you visit our website at https://complyon.com, use our
GRC and IT Audit services, or engage with us in any other capacity.

Please read this policy carefully. By continuing to use our website and services, you agree to
the collection and use of information as described herein. If you have any questions, contact
us at contact@complyon.com.

 

1. Interpretation and Definitions

The following terms are used throughout this Privacy Policy:

• Privacy Policy – This document governing the collection and use of personal data by
Complyon Software ApS.
• Personal Data – Any information relating to an identified or identifiable natural person.
• Website – The website located at https://complyon.com.
• Services – The GRC Solution, IT Audit, GDPR Compliance, and other software
services provided by Complyon.
• We / Us / Our – Complyon Software ApS, a Danish company.
• You / Your – Any individual accessing our Website or using our Services.
• Data Processor – An entity that processes personal data on behalf of a Data
Controller.
• Data Controller – The entity that determines the purposes and means of processing
personal data.

 

2. What Personal Data Do We Collect?

 

2.1 Customer and User Information

As a B2B solution provider, we process personal data primarily as an accessory to delivering
our services. We may collect:

• Contact/admin persons: name, email address, phone number, company name, job
title.
• Customer profile users (employees/consultants): name, email address, phone
number, profile picture (voluntary).

The legal basis for this processing is Article 6(1)(b) of the GDPR (performance of a contract).

 

2.2 Website Visitors

When you visit our website or submit a contact form inquiry, we collect the personal data you
voluntarily provide (name, email, message content) in order to respond to your request.

The legal basis is Article 6(1)(f) of the GDPR (legitimate interest), as you have initiated the
contact and expect a response.

 

2.3 Information Collected Automatically

When you access our Website, certain technical data is collected automatically, including:

• Device information (device type, identifiers, characteristics).
• Usage information (page visits, interactions, choices made on the website).
• Browser information (operating system, browser version, plug-ins, time zone).
• Location information (general device location).

This information is used for improving our website, internal analytics, and security purposes.
It does not, on its own, identify you personally.

 

2.4 Cookies and Tracking Technologies

We use cookies and similar technologies (web beacons, tags, scripts) to track activity on our
Website. Please refer to our Cookie Policy available at https://complyon.com/cookie-policy/ 
for full details.

 

2.5 Sensitive Information

We do not intentionally collect sensitive personal data (such as racial or ethnic origin,
political views, religious beliefs, or health data). If any such data is submitted voluntarily, you
do so at your own discretion.

 

2.6 Information from Minors
We do not knowingly collect personal data from individuals under the age of 18. If we
become aware that we have collected data from a minor, we will take reasonable steps to
delete it promptly. Please contact us at contact@complyon.com if you have concerns.

 

3. How Do We Use Your Information?

We use your personal data for the following purposes:

• Delivering our services to business customers under contract.
• Responding to inquiries submitted via our contact form.
• Sending marketing and promotional communications (with your consent).
• Conducting customer satisfaction surveys and market research.
• Improving and maintaining our website and platform.
• Complying with legal obligations and protecting our legitimate interests.
• Preventing fraudulent activity and ensuring platform security.
• Managing user accounts and onboarding via third-party login plugins.

 

4. Third-Party Services and Data Sharing

 

4.1 General Sharing Principles

We may share your personal data with authorized third-party service providers only when:

• It is necessary to deliver our services or fulfil a contract.
• You have given explicit consent for a specific purpose.
• We are legally required to do so by law, court order, or regulation.
• It is necessary to prevent fraud or enforce our policies.

 

4.2 Third-Party Login Plugins

Users may log in to the Complyon platform via third-party plugins (visible on the login page).
These plugins are used solely for authentication; Complyon does not grant third parties
access to your data beyond login validation. Please consult the relevant third party’s privacy
policy for details on how they handle your data.

 

4.3 Webinar Platform

Our webinar hub is hosted by TwentyThree, who acts as a data processor. By signing up for
our webinars, you consent to the processing of your personal data by TwentyThree. Please
review TwentyThree’s privacy and legal information for further details.

 

4.4 Email Marketing

We use customer contact information to send promotional emails only where we have
received a valid marketing consent (Article 6(1)(a) GDPR). You may withdraw consent at
any time via the unsubscribe link in any email or by contacting contact@complyon.com.

 

4.5 Potential Customer Outreach

We may process publicly available contact information of potential B2B customers (name,
email, phone, company, job title, LinkedIn URL) to present our services in accordance with
Danish marketing rules. The legal basis is Article 6(1)(f) GDPR (legitimate interest).

 

5. International Data Transfers

All personal data is stored on secure servers located within the European Union (EU).
Where we transfer personal data outside the EU/EEA, we ensure that appropriate
safeguards are in place (e.g., Standard Contractual Clauses) to maintain an equivalent level
of protection in accordance with applicable data protection legislation.

 

6. Data Retention

We retain your personal data only for as long as necessary for the purposes described in
this policy:

• Customer contact data: up to 6 months after contract termination/expiry.
• Bookkeeping data: up to 6 years in accordance with the Danish Bookkeeping Act
(Article 6(1)(c) GDPR).
• Customer user profiles (data processor role): deleted within a short period after
contract end, or maximum 6 months.
• Contact form inquiries: up to 6 months after the last correspondence.
• Feedback data: up to 5 years (stored anonymously where possible).
• Marketing consent data: retained until consent is withdrawn.
• Potential customer data: retained until no interest is demonstrated.

We may retain data for longer periods where necessary to protect our legitimate interests
(e.g., in case of a legal dispute), until the dispute has been resolved.

 

7. Security

We have implemented appropriate technical, organizational, and physical measures to
protect your personal data from accidental or unlawful destruction, loss, alteration,
unauthorized disclosure, or access. These measures include:

• Encryption of data in transit and at rest.
• Access control policies based on the principle of least privilege.
• Secure development practices aligned with OWASP guidelines.
• Regular security reviews and monitoring.

Despite these measures, no transmission of data over the internet can be guaranteed to be
completely secure. We encourage you to take appropriate precautions on your own devices.

 

8. Your Rights Under GDPR

As a data subject under the General Data Protection Regulation (GDPR), you have the
following rights:

Right of Access: Request a copy of the personal data we hold about you.
Right to Rectification: Request correction of inaccurate or incomplete personal data.
Right to Erasure: Request deletion of your personal data where there is no longer a valid
legal basis for processing.
Right to Object: Object to processing based on legitimate interests or for direct marketing
purposes.
Right to Restriction: Request that we restrict processing in certain circumstances.
Right to Portability: Receive your personal data in a structured, machine-readable format.
Right to Withdraw Consent: Withdraw any previously given consent at any time (without
affecting the lawfulness of prior processing).

All requests should be submitted in writing to contact@complyon.com. If you believe your
rights have been violated, you may lodge a complaint with the Danish Data Protection
Agency (Datatilsynet), Borgergade 28, DK-1300 Copenhagen.

 

9. Third-Party Websites and Links

Our Website may contain links to third-party websites. We are not responsible for the privacy
practices of those websites and recommend you review their privacy policies before
engaging with them. Our Cookie Policy, referenced above, provides further detail on
analytics and advertising tools we may use.

 

10. Updates to This Policy

We reserve the right to update this Privacy Policy at any time. Any changes will be posted on
this page with a revised “Last updated” date. We encourage you to review this page
periodically. Continued use of our website and services following any changes constitutes
your acceptance of the revised policy.

 

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data
practices, please contact us:

• Company: Complyon Software ApS
• Copenhagen, Denmark
• Company registration number: 38 44 67 70
• Website: https://complyon.com
• Email: contact@complyon.com