Privacy policy

Ceptiv ApS, CVR 37576476. Secondary business name of Acenta Group ApS.

Last updated: 27 August 2026

What this policy covers

This policy explains how we handle personal data on the public website at ceptiv.net, in the project start flow where you describe a project and receive a quote, in the Client Panel where our clients follow their projects and invoices, and in the email, chat and notifications we send around a project.

It does not cover the software we build for our clients. When you use an application we developed for one of our clients, that client decides what data is collected and why, and their privacy policy applies. Our role in that case is described under "Two different roles" below.

Who is responsible for your data

Ceptiv ApS, CVR 37576476, Lyngbyvej 83A, 2100 København Ø, is the data controller for the processing described in this policy. Ceptiv ApS is a registered secondary business name of Acenta Group ApS. We process personal data under the EU General Data Protection Regulation (GDPR), the Danish Data Protection Act and the Danish rules implementing the ePrivacy Directive.

You can reach us at Lyngbyvej 83A, 2100 København Ø, Denmark, by email at support@ceptiv.dk or by phone on +45 81 98 32 71. We are not required to appoint a Data Protection Officer and have not appointed one, so data protection questions go to the address above and are handled by us directly.

Two different roles

For everything on this website, in the Client Panel and in our own communication with you, we are the data controller. We decide what is collected and why, and this policy applies.

For the systems we build, host and maintain on behalf of a client, we are a data processor. The client is the controller and decides the purpose; we only act on their documented instructions under a data processing agreement, which we enter into with every client whose system handles personal data. If you are an end user of such a system, contact the client that operates it to exercise your rights, and we will assist them in answering you.

What personal data we collect

We try to collect as little as we can get away with, and what we do collect is tied to a specific purpose. In practice it falls into five groups.

When you contact us or ask for a quote

The contact form asks for your first and last name, email address, company name and your message. If you call or email us instead, we hold whatever you choose to tell us. This is used to answer you and to prepare a quote.

When you start a project

The project start flow collects the type of project, your description of it, the integrations you need, and your contact details: name, company, email and phone. If you choose to use the AI review step, your project description and the messages you write in that chat are sent to our AI provider so it can respond. That step is optional, and you should not paste confidential information or other people's personal data into it.

When you have a Client Panel account

An account holds your email address, name, company name, VAT number, billing address, country, preferred currency and language, and a hashed sign-in PIN. We never store the PIN itself. Alongside it we hold your projects and tasks, quotes and invoices, the messages, comments, files, screen recordings and video messages exchanged about a project, your notification preferences, and a log of emails we have sent you so we can tell whether they were delivered.

Usage data on the public site

If you accept statistics cookies, we measure how the public site is used through Google Analytics, Contentsquare and our own first-party visit counting. That covers pages viewed, referring page, browser and device details, screen size, language, time zone, approximate country and an IP address recorded on our server. None of it is collected on the public site until you accept. If you decline, we do not measure your visit at all.

Usage data inside the Client Panel and admin

Once you are signed in to the Client Panel or the admin area, we record page views, your account identity, IP address, browser and approximate country regardless of your cookie choice. This is not analytics for marketing — it exists so we can support you, see what a user actually did when something breaks, and detect misuse of an account. We rely on legitimate interests for it, these records are kept for 30 days, and they are never used to build an advertising profile. Your cookie choice still governs everything on the public site.

We do not ask for special categories of data — health, biometrics, political or religious views, trade union membership, sexual orientation — and we do not want them in a project brief. If a specific project genuinely requires such data, we agree it separately in writing with the appropriate legal basis in place. We also do not knowingly collect data about children; our services are sold to businesses.

How we get your data

Nearly all of it comes directly from you: forms on this site, the project start flow, email, phone calls, meetings and whatever you type or upload into the Client Panel.

Some is generated automatically when you use the site — cookies and similar technologies on the public site once you have accepted them, and the operational records described above once you are signed in.

Occasionally we look up publicly available business information, such as a CVR record, to get an invoice address or VAT number right. We do not buy contact lists and we do not enrich your profile from data brokers.

Our legal basis for each purpose

Every processing activity needs a legal basis under Article 6 of the GDPR. Ours break down as follows.

Performing a contract — Article 6(1)(b)

Delivering the software we agreed to build, hosting and maintaining it, running your Client Panel account, managing projects and subscriptions, and invoicing you. Without this data we cannot deliver the service you asked for.

Legitimate interests — Article 6(1)(f)

Answering enquiries and preparing quotes before a contract exists, keeping the site and our systems secure, the operational records inside the Client Panel and admin, and defending or pursuing legal claims. We have weighed these against your interests and concluded they do not override your rights, partly because the data involved is limited, business-related and kept for a short time. You can object to any of it — see your rights below.

Legal obligation — Article 6(1)(c)

Keeping accounting records for five years under the Danish Bookkeeping Act, handling VAT, and responding to lawful requests from Danish or EU authorities.

Consent — Article 6(1)(a)

Statistics and marketing cookies on the public site, the analytics services they enable, and any marketing email. Consent is always optional, always asked for before anything happens, and you can withdraw it at any time without giving a reason. Withdrawing it does not affect processing that already took place.

What we use it for

We process your personal data for a short list of purposes, and we do not repurpose it later for something unrelated without telling you first.

Delivering and running your solution

Building what we agreed, hosting and maintaining it, applying security updates, fixing bugs, monitoring uptime, taking backups, and giving you a Client Panel where you can follow projects, tasks, quotes, invoices and your subscription.

Quotes, proposals and communication

Reviewing what you describe, coming back with a fixed-price quote within 24 hours, and the ordinary back-and-forth by email, chat, comment, video message or phone that a project involves.

Understanding how the site is used

Seeing which pages people read and where they drop off, so we can improve the site. On the public site this runs only after you accept statistics cookies. Google Analytics runs with IP anonymisation and Google Consent Mode, and you can withdraw consent at any time from Cookie settings in the footer.

Security and abuse prevention

Rate-limiting requests, recording sign-ins, keeping the operational records described above, and investigating anything that looks like unauthorised access. This protects your data as much as ours.

Legal and accounting obligations

Issuing and retaining invoices, meeting the five-year bookkeeping requirement, handling VAT, and responding to authorities where the law requires it.

We do not run a newsletter and we do not send unsolicited marketing. If that ever changes, it will be opt-in, every message will carry an unsubscribe link, and unsubscribing will take effect immediately.

Automated decisions and profiling

We do not make decisions about you by automated means alone, and we do not profile you in a way that produces legal effects or similarly significantly affects you. The AI review step in the project start flow suggests things about scope for a human to consider; it does not decide whether you get a quote or on what terms. A person at Ceptiv writes and approves every quote.

Who we share it with

We never sell personal data, we never trade it, and we do not share it for anyone else's marketing. Data leaves us in only three situations.

Service providers acting on our instructions

We use a small number of sub-processors to run the service. Each is bound by a data processing agreement, may only act on our instructions, and may not use your data for their own purposes. The current list is below, and we keep it up to date as the service changes.

Our sub-processors

These are the third parties that process personal data on our behalf. We update this list when we add or replace a provider.

ProviderWhat they do for usProcessing locationTransfer basis
Vercel Inc.Hosting and content delivery for ceptiv.net, including server logs and IP addresses handled while serving a request.EU/EEA and United StatesEU-US Data Privacy Framework and EU Standard Contractual Clauses
Supabase Inc.Database, file storage and sign-in for the Client Panel and admin. This is where project, invoice, message and account data is stored.EU/EEA and United StatesEU Standard Contractual Clauses
x.ai (Grok)Optional AI review in the project start flow. The project description and your messages in that chat are sent to the model. Do not paste confidential or personal data into it.United StatesEU Standard Contractual Clauses
Microsoft Ireland Operations Ltd.Sending quotes, invoices, notifications and replies from our Microsoft 365 mailbox. Recipient address, subject and message content pass through Microsoft.EU/EEAEU Standard Contractual Clauses
Google Ireland Ltd.Google Analytics and Google Ads on the public site. Only runs after you accept statistics or marketing cookies.EU/EEA and United StatesEU-US Data Privacy Framework and EU Standard Contractual Clauses
Contentsquare SAMeasures how pages on the public site are used. Only runs after you accept statistics cookies.EU/EEANo transfer outside the EU/EEA
Apple, Google, Mozilla (push services)Delivering browser and app push notifications to a device you have explicitly allowed notifications on. They receive an anonymous push endpoint, not the message you are notified about.EU/EEA and United StatesEU-US Data Privacy Framework and EU Standard Contractual Clauses

Authorities and professional advisers

We disclose data where Danish or EU law requires it, for example to SKAT or a court order, and to our accountant and, if a dispute arises, our lawyers. We also share data with our own group where a shared function such as bookkeeping makes that necessary.

Transfers outside the EU/EEA

Some providers are established in, or have parent companies in, the United States. Where data reaches a third country we rely on the provider's certification under the EU-US Data Privacy Framework, on the European Commission's Standard Contractual Clauses, or both, together with encryption in transit and at rest. The table above states the basis for each provider. You can request a copy of the relevant safeguards from us.

To be explicit: we never sell personal data to third parties, and we do not allow our sub-processors to do so either.

Cookies and similar technologies

The public site uses necessary cookies to function. Statistics and marketing cookies are optional and nothing in those categories is placed until you accept it in the cookie banner. The same applies to storage in your browser that works like a cookie, such as local storage — we treat it the same way and ask for consent first.

How consent works

The banner asks before anything optional is placed. Reject all and Accept all are the same size and sit together on the first screen, so refusing is no harder than agreeing. You can also accept statistics and marketing separately. Your choice is stored for six months, after which we ask again, and we log the choice on our server so we can demonstrate that consent was given. You can change or withdraw it at any time from Cookie settings in the footer.

Necessary cookies — your language preference, staying signed in and the record of this consent choice — do not require consent, because they are strictly necessary to deliver the service you asked for. Everything else does.

Cookies and storage we may use

CookieProviderDurationPurpose
ceptiv_consentCeptiv6 monthsStores your cookie choice so we do not ask again on every page.
ceptiv_locale_prefCeptiv1 yearRemembers the language you picked.
sb-*-auth-tokenCeptiv / SupabaseSession / up to 1 weekKeeps you signed in to the Client Panel or admin.
_ga, _ga_*Google AnalyticsUp to 2 yearsIdentifies a returning browser so visits can be counted. Runs with IP anonymisation. Google may transfer data to the United States under the EU-US Data Privacy Framework. Only loaded if Google Analytics is switched on for the site.
_gidGoogle Analytics24 hoursDistinguishes visitors within a single day.
_cs_*ContentsquareSession up to 13 monthsSession and page-interaction measurement to see how the site is used.
ceptiv_av (local storage)CeptivUntil you clear browser storageA random id that lets us count a returning visitor without knowing who you are.
ceptiv_as, ceptiv_aa (session storage)CeptivUntil the browser tab is closedGroups your page views into one visit. Together with the id above we record pages viewed, referring page, language, time zone, screen size, browser, approximate country and IP address on our own server. Deleted after 30 days. No advertising profile is built from it.
_gcl_au, _gcl_awGoogle AdsUp to 90 daysAdvertising measurement and conversion signals, used if we run Google Ads campaigns. Nothing in this category is placed unless you turn marketing on.

How long we keep it

We keep personal data only as long as the purpose requires, then delete or anonymise it. In practice:

  • Enquiries and quotes that do not become a project: up to 12 months from our last contact, so we can pick up the thread if you come back.
  • Project, contract and Client Panel data: for as long as the engagement runs, then up to five years after the end of the financial year in which it ended, because the Danish Bookkeeping Act requires it for anything with accounting relevance.
  • Invoices and accounting records: five years after the end of the relevant financial year, as required by law. We cannot delete these on request during that period.
  • Public-site analytics: up to 14 months in Google Analytics. Our own first-party visit records and the operational records from the Client Panel and admin are deleted after 30 days.
  • Consent records: six months for the cookie itself, and up to two years for the server-side log that proves the choice was made.
  • Screen recordings, video messages and uploaded files: for the life of the project, unless you ask us to remove a specific item sooner, which we will do.

How we protect it

We apply technical and organisational measures appropriate to the risk, as required by Article 32 of the GDPR: encryption in transit over HTTPS and at rest in the database, row-level access rules so one client cannot see another's data, hashed sign-in credentials, access limited to the people who need it, rate limiting on public endpoints, automated backups, and logging of administrative actions.

No system is perfect. If a personal data breach occurs, we assess it immediately, notify the Danish Data Protection Agency within 72 hours where the breach is likely to pose a risk to your rights, and tell you directly without undue delay where the risk is high. Where we act as processor for a client, we notify that client without undue delay so they can meet their own obligations.

Your rights

Under the GDPR you can ask us for a copy of the personal data we hold about you, have inaccurate data corrected, have data deleted where we no longer need it, restrict how we use it while a dispute is resolved, receive data you gave us in a portable machine-readable format, and object to processing we base on legitimate interests. Where processing rests on consent, you can withdraw it at any time.

To exercise any of these, email support@ceptiv.dk. We answer within one month and may extend that by two further months for genuinely complex requests, in which case we will tell you why within the first month. It is free, unless a request is manifestly unfounded or repetitive. We may need to verify your identity first, and we cannot delete data we are legally required to retain, such as issued invoices.

If you are unhappy with how we have handled your data, please tell us first so we can fix it. You also have the right to complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, at dt@datatilsynet.dk or via www.datatilsynet.dk.

Changes to this policy

We update this policy when the service changes — a new sub-processor, a new feature that collects something new, or a change in the law. The date at the top always reflects the current version. If a change materially affects how we use your data, we will tell you by email or with a clear notice on the site before it takes effect, and where the change relies on consent we will ask again.

Contact us

For anything in this policy, or to exercise your rights, write to Ceptiv ApS (Acenta Group ApS), Lyngbyvej 83A, 2100 København Ø, Denmark, email support@ceptiv.dk or call +45 81 98 32 71. CVR: 37576476.

Frequently Asked Questions

Ceptiv's privacy policy explains how we collect, use, and protect your personal data. Full GDPR compliance, minimal data collection, and your rights regarding your information.