Privacy Policy
Draft. About the information Todai processes as data controller.
In case of discrepancies, the Danish version prevails.
Last updated [date]
Data controller
Todai A/S
CVR no. 41776641
Olivia Hansens Gade 3, 2nd floor, 1799 Copenhagen V
[privacy@todai.ai]
Two different roles
It is important to distinguish between two situations:
Todai is the data controller for the information we process about our own customers' users and contact persons — that is, information for which we ourselves determine the purpose. This policy concerns that information.
Todai is a data processor for the information our customers input into Todai Contracts — including information about the persons who receive and sign the customer's contracts. In this case, the customer is the data controller and determines what may be done with the information. Our processing is governed by a data processing agreement with the individual customer.
If you have been asked to sign a contract via Todai Contracts and wish to know how your information is processed, please contact the company that sent you the contract.
What information we process
About users at our customers: name, work email, telephone number, job title, user role, times of login and activity in the service, IP address and information about browser and device.
About contact persons at potential customers: name, company, email address and the content of our correspondence with you.
About payment and billing: the company's name, CVR number, address, billing information and payment history. We do not store full card details; card payments are handled by our payment provider.
We do not process sensitive personal data as part of operating the service.
Purposes and legal basis
To provide and administer the service — creating and maintaining user accounts, granting access, providing support and communicating about the operation of the service. Legal basis: performance of the agreement with the company the user represents, and our legitimate interest in being able to administer the customer relationship, cf. Article 6(1)(b) and (f) of the GDPR.
Security and misuse prevention — logging of login, IP addresses and activity to be able to detect and investigate unauthorised access. Legal basis: legitimate interest, Article 6(1)(f).
Invoicing and bookkeeping — legal basis: legal obligation, Article 6(1)(c), including the Danish Bookkeeping Act.
Communication about the service — operational notices, security updates and material changes. Legal basis: performance of the agreement and legitimate interest.
Marketing by email takes place only with prior consent, which may be withdrawn at any time.
Who we share information with
We use the following suppliers as data processors:
- [Hosting and database provider] — operation of the service. Data is hosted in the EU.
- [Mailgun] — sending of email. EU region.
- [Twilio] — sending of SMS with one-time codes.
- [Payment provider] — payment processing.
- [Any AI providers] — processing of text for preparing and reviewing documents.
We enter into a data processing agreement with all suppliers that process personal data on our behalf.
We do not disclose personal data to others unless required by law or necessary to establish or defend a legal claim.
We do not use personal data or customer data to train language models.
Transfer to third countries
The service is set up so that personal data is processed within the EU/EEA.
[If a supplier, by way of exception, processes information outside the EU/EEA, this occurs on the basis of the European Commission's standard contractual clauses or a valid adequacy decision. Confirm and complete — this point must be accurate.]
How long we retain the information
User information is deleted no later than 3 years after the customer relationship has ended, or after the user has been deactivated.
Login logs and security logs are retained for [12] months.
Bookkeeping material is retained for 5 years from the end of the financial year to which the material relates, cf. the Danish Bookkeeping Act.
Correspondence with potential customers is deleted no later than [2] years after the last contact.
Your rights
Under the GDPR you have the right to:
- obtain access to the information we process about you
- have incorrect information corrected
- have information deleted in certain cases
- have processing restricted in certain cases
- object to processing carried out on the basis of legitimate interest
- receive your information in a structured, commonly used format (data portability)
- withdraw consent where processing is based on consent
Inquiries should be sent to [privacy@todai.ai]. We respond to inquiries within one month.
Complaints
You may lodge a complaint with the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, dt@datatilsynet.dk, datatilsynet.dk.
Changes
We may update this policy. Material changes will be announced by email to our customers' contact persons. The version in force at any given time is available on this page, with an indication of the date it was last updated.