Privacy policy
Ceptiv ApS, CVR 37576476. Secondary business name of Acenta Group ApS.
Last updated: 29 September 2026
Scope of this policy
This privacy policy explains how we process personal data when you visit ceptiv.net, contact us or request a quote, start a project through the project start flow, use the Client Panel, or communicate with us by email, chat, phone or notifications in connection with a project. It constitutes the information we are required to give you under Articles 13 and 14 of the General Data Protection Regulation (GDPR).
The policy does not cover the software we develop for our clients. When you use a solution we have built for a client, that client is the data controller and its privacy policy applies. Our role in that situation is described under "Our two roles" below.
Data controller
The data controller is Acenta Group ApS, CVR 37576476, Lyngbyvej 83A, 2100 København Ø, Denmark, which operates under the registered secondary name Ceptiv ApS ("Ceptiv", "we", "us"). We process personal data in accordance with Regulation (EU) 2016/679 (GDPR), the Danish Data Protection Act (Act no. 502 of 23 May 2018) and the Danish Cookie Order (Executive Order no. 1148 of 9 December 2011), which implements the ePrivacy Directive.
You can contact us by post at the address above, by email at support@ceptiv.dk or by phone on +45 81 98 32 71. We are not required to designate a data protection officer under Article 37 of the GDPR and have not done so. Questions about data protection are handled directly by us.
Our two roles
We are the data controller for the processing on this website, in the project start flow, in the Client Panel and in our own communication with you. We determine the purposes and means of that processing, and this policy applies to it.
When we develop, host or maintain systems on behalf of a client, we act as data processor under Article 28 of the GDPR. The client is the controller, and we process personal data only on the client’s documented instructions under a data processing agreement, which we enter into with every client whose system processes personal data. If you are an end user of such a system, please direct requests concerning your rights to the company that operates it. We will assist that company in responding.
Categories of personal data
We collect only the personal data that is necessary for specified and explicit purposes (data minimisation, Article 5(1)(c) of the GDPR). The data falls into the following categories.
Enquiries and quote requests
When you use the contact form, we process your first and last name, email address, company name and the content of your message. If you contact us by phone or email, we process the information you choose to give us. We use the data to answer your enquiry and, where relevant, to prepare a quote.
Project start flow
When you start a project, we process the type of project, your description of it, the integrations and functions you need, and your contact details: name, company, email address and phone number. We use the data to assess the project and prepare a fixed-price quote.
Client Panel accounts
For a Client Panel account we process your email address, name, company name, CVR or VAT number, billing address, country, preferred currency and language, and a hashed sign-in code; the code itself is never stored. We also process your projects and tasks, quotes, invoices and subscriptions, the messages, comments, files, screen recordings and video messages exchanged in a project, your notification settings, a technical push identifier for devices on which you have allowed notifications, and a log of the emails we send you so that we can confirm delivery.
Usage data on the public website
If you accept statistics cookies, we measure how the public website is used with Google Analytics and our own first-party visit counting. This covers pages viewed, referring page, browser and device information, screen size, language, time zone, approximate country and IP address. No statistics data is collected until you have given your consent, and if you decline, your visit is not measured.
Operational logs in the Client Panel and admin
When you are signed in to the Client Panel or the admin area, we log page views, account identity, IP address, browser and approximate country, regardless of your cookie choice. The logs are used for support, troubleshooting, security and the detection of account misuse, not for marketing or profiling. The legal basis is our legitimate interest (Article 6(1)(f) of the GDPR), and the logs are deleted after 30 days.
We do not request special categories of personal data under Article 9 of the GDPR, such as data concerning health, biometric data, political opinions, religious beliefs, trade union membership or sexual orientation, nor data relating to criminal offences under Article 10. Please do not include such data in a project description. If a specific project genuinely requires it, this is agreed separately and in writing with a valid legal basis in place. Our services are aimed at businesses, and we do not knowingly process personal data about children.
Sources of personal data
Most personal data is provided by you directly: through forms on this website, the project start flow, email, phone calls, meetings, and what you write or upload in the Client Panel.
Some data is generated automatically when you use our services: through cookies and similar technologies on the public website once you have given your consent, and through the operational logs described above when you are signed in.
Where necessary, we obtain publicly available company information, for example from the Danish Central Business Register (CVR), to verify a billing address or VAT number. We do not buy contact lists or enrich data with information from data brokers.
You are not legally obliged to provide personal data to us. However, the data marked as required in our forms and in the Client Panel is necessary for us to answer you, prepare a quote or perform a contract. Without it, we cannot provide the service.
Legal bases for processing
All processing is based on one or more of the legal bases in Article 6(1) of the GDPR.
Contract and pre-contractual steps: Article 6(1)(b)
Preparing a quote at your request and, once a contract has been concluded, performing it: developing, hosting and maintaining the agreed solution, operating your Client Panel account, managing projects and subscriptions, and invoicing. This basis applies where you are yourself a party to the contract, for example as a sole trader.
Legitimate interests: Article 6(1)(f)
Where you act on behalf of a company, we process your data as a contact person on the basis of our legitimate interest in communicating with and delivering to our business customers. We also rely on legitimate interests for the operational logs in the Client Panel and admin, for information security and the prevention of misuse, and for the establishment, exercise or defence of legal claims. We have balanced these interests against your interests and fundamental rights and freedoms and concluded that they are not overridden, in particular because the data is limited, business-related and kept for a short period. You have the right to object; see "Your rights" below.
Legal obligation: Article 6(1)(c)
Retaining accounting records under the Danish Bookkeeping Act, complying with VAT rules, documenting consent as required by Article 7(1) of the GDPR, and complying with lawful requests from public authorities.
Consent: Article 6(1)(a)
Statistics and marketing cookies on the public website and the services they activate, push notifications you have allowed on a device, and any electronic marketing, cf. section 10 of the Danish Marketing Practices Act. Consent is voluntary, is obtained before the processing begins, and can be withdrawn at any time without giving reasons. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Purposes of processing
We process personal data only for the purposes set out below and do not further process it in a manner incompatible with those purposes (purpose limitation, Article 5(1)(b) of the GDPR).
Delivery and operation of your solution
Developing the agreed solution, hosting and maintaining it, installing security updates, correcting errors, monitoring operations, taking backups, and giving you access to the Client Panel, where you can follow projects, tasks, quotes, invoices and your subscription.
Quotes and communication
Assessing your request, sending a fixed-price quote, usually within 24 hours, and the ongoing dialogue by email, chat, comments, video messages or phone that a project requires.
Website statistics
Understanding which pages are read and where visitors leave, so that we can improve the website. This takes place only after you have accepted statistics cookies. Google Analytics runs with IP anonymisation and Google Consent Mode. You can withdraw your consent at any time via Cookie settings in the footer.
Information security and prevention of misuse
Limiting the number of requests, logging sign-ins, keeping the operational logs described above, and investigating suspected unauthorised access.
Legal and accounting obligations
Issuing and retaining invoices, meeting the retention requirements of the Danish Bookkeeping Act, handling VAT, and responding to public authorities where the law requires it.
We do not send newsletters or unsolicited electronic marketing. Should we introduce it, it will require your prior consent, cf. section 10 of the Danish Marketing Practices Act, every message will contain an unsubscribe link, and unsubscribing will take effect immediately.
Automated decisions and profiling
We do not make decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you, cf. Article 22 of the GDPR. Every quote is prepared and approved by a person at Ceptiv.
Recipients of personal data
We do not sell personal data, and we do not disclose it for the marketing purposes of others. Personal data is disclosed or made available to others only in the following cases.
Data processors
We use a limited number of data processors to operate our services. They process personal data only on our documented instructions under a data processing agreement in accordance with Article 28 of the GDPR, and may not use the data for their own purposes. The current overview is shown below.
Overview of data processors
The following third parties process personal data on our behalf. We update the overview when we add or replace a provider.
| Provider | What they do for us | Processing location | Transfer basis |
|---|---|---|---|
| Google Ireland Ltd. | Google Analytics (statistics) and Google Ads (marketing) on the public website. Activated only after you have consented to statistics or marketing cookies respectively. | EU/EEA and United States | EU-US Data Privacy Framework and EU Standard Contractual Clauses |
| Apple, Google, Mozilla (push services) | Delivery of browser and app push notifications to devices on which you have expressly allowed notifications. The services receive a technical push identifier, not the content of the message you are notified about. | EU/EEA and United States | EU-US Data Privacy Framework and EU Standard Contractual Clauses |
Public authorities, advisers and group companies
We disclose personal data where required by Danish or EU law, for example to the Danish Tax Agency or under a court order. Where necessary, we also disclose data to our auditor and legal advisers, who are bound by a duty of confidentiality, and within our group where a shared function such as bookkeeping requires it.
Transfers to third countries
Some of our data processors are established in, or have parent companies in, the United States. Where personal data is transferred outside the EU/EEA, the transfer is based on the European Commission’s adequacy decision for the EU-US Data Privacy Framework (Article 45 of the GDPR) for certified companies and/or on the Commission’s Standard Contractual Clauses (Article 46(2)(c)), supplemented by encryption in transit and at rest. The overview below states the transfer basis for each provider. You can obtain a copy of the relevant safeguards by contacting us.
We never sell personal data to third parties, and our data processors are not permitted to do so either.
Retention periods
We keep personal data no longer than necessary for the purposes for which it is processed (storage limitation, Article 5(1)(e) of the GDPR), after which it is deleted or anonymised:
- Enquiries and quotes that do not lead to a contract: up to 12 months after our last contact.
- Project, contract and Client Panel data: for the duration of the collaboration and thereafter up to five years from the end of the financial year in which it ended, to the extent the data forms part of our accounting records or is necessary for the establishment, exercise or defence of legal claims.
- Invoices and other accounting records: five years from the end of the financial year to which they relate, as required by the Danish Bookkeeping Act. They cannot be deleted on request during that period.
- Website statistics: up to 14 months in Google Analytics. Our own first-party visit data and the operational logs from the Client Panel and admin are deleted after 30 days.
- Consent records: the consent cookie is stored for six months, and the server log documenting your choice for up to two years.
- Screen recordings, video messages and uploaded files: for the duration of the project, unless you ask us to delete a specific item earlier.
Security of processing
We have implemented appropriate technical and organisational measures in accordance with Article 32 of the GDPR, including encryption in transit (HTTPS) and at rest, access controls ensuring that clients can only see their own data, hashed sign-in credentials, access limited to employees with a work-related need, limits on requests to public endpoints, automated backups and logging of administrative actions.
If a personal data breach occurs, we assess it without delay. Where the breach is likely to result in a risk to your rights and freedoms, we notify the Danish Data Protection Agency within 72 hours, cf. Article 33 of the GDPR, and where the risk is high, we inform you without undue delay, cf. Article 34. Where we act as data processor, we notify the client without undue delay so that the client can meet its obligations.
Your rights
Under Articles 15 to 20 of the GDPR, you have the right of access to the personal data we process about you, the right to rectification of inaccurate data, the right to erasure, the right to restriction of processing, and the right to data portability for data you have provided to us on the basis of consent or contract. Where processing is based on consent, you may withdraw your consent at any time.
Right to object: Under Article 21 of the GDPR, you have the right to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests. We will then no longer process the data unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims. You always have an unconditional right to object to processing for direct marketing purposes.
To exercise your rights, write to support@ceptiv.dk. We respond within one month of receiving your request. Taking into account the complexity and number of requests, this period may be extended by two further months, in which case we will inform you within the first month, cf. Article 12(3) of the GDPR. Exercising your rights is free of charge unless the request is manifestly unfounded or excessive. We may need to verify your identity, and certain rights are limited by law; for example, we cannot erase accounting records we are required to retain.
If you are dissatisfied with how we process your personal data, we encourage you to contact us first. You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, dt@datatilsynet.dk, www.datatilsynet.dk, cf. Article 77 of the GDPR.
Changes to this policy
We update this policy when our processing changes, for example when we start using a new data processor or feature, or when the law changes. The date at the top shows the current version. If a change significantly affects how we process your personal data, we will inform you by email or with a clear notice on the website before it takes effect, and where the processing is based on consent, we will ask for your consent again.
Contact
Questions about this policy or requests to exercise your rights can be sent to Acenta Group ApS (Ceptiv ApS), Lyngbyvej 83A, 2100 København Ø, Denmark, by email to support@ceptiv.dk or by phone on +45 81 98 32 71. CVR: 37576476.
Frequently asked questions
Ceptiv's privacy policy explains how we collect, use, and protect your personal data. Full GDPR compliance, minimal data collection, and your rights regarding your information.
What data do you collect?
Only what a purpose requires: your contact details when you reach out or start a project, your account and project data if you use the Client Panel, and usage analytics on the public site once you have accepted statistics cookies. We never sell your data.
How long do you keep my data?
Enquiries that do not become a project are kept for up to 12 months. Project and Client Panel data is kept for the engagement plus up to five years, because the Danish Bookkeeping Act requires it for anything with accounting relevance. Analytics is deleted after 30 days on our own servers and up to 14 months in Google Analytics.
Do you use cookies?
Necessary cookies keep the site working. Statistics and marketing cookies are only placed if you accept them — reject sits on the first screen next to accept. You can change or withdraw that choice at any time from Cookie settings in the footer.
How can I request my data or deletion?
Email us at support@ceptiv.dk with your request. We'll provide a copy of your data within 30 days or confirm deletion. GDPR rights are fully supported for all users, regardless of location.
