Legal, Effective Date: 8. aug. 2026
Privatlivspolitik
This Privacy Policy explains how Enia ("we", "us", "our") collects, uses, and protects personal data when you register for and use Hubverk ("the Service"). We act as the Data Controller for your account and administrative data, and as a Data Processor for end-consumer data uploaded by your business.
1. Data Controller Identity and Contact Details
The entity responsible for processing your account and billing information under Danish and EU data protection laws is:
- Company / Owner Name: Enia
- CVR / Business ID: "Pending"
- Address: Mågevej 5, 4773 Stensved
- Contact Email:
2. Data We Collect and Processing Roles
A. As a Data Controller (Your Account & Billing Data)
We collect and process personal data directly related to your subscription and use of the platform:
- Account Information: Name, business name, work email address, phone number, and password hash.
- Billing and Invoicing Data: Payment transaction metadata, invoice history, tax ID (CVR), and billing addresses.
- Technical Logs: IP addresses, login timestamps, user agent data, and system diagnostic logs required to ensure server security and performance.
B. As a Data Processor (Your Customers' B2C Data)
When you use the platform to manage leads, quotes, jobs, and customer contacts, you act as the Data Controller, and we act as the Data Processor. We process this data strictly on your behalf to provide the software functionality, as governed by our Data Processing Agreement (DPA).
3. Legal Basis for Processing (GDPR Art. 6)
- Contractual Necessity (Art. 6(1)(b)): Processing account and usage data is necessary to fulfill our obligations under the Terms and Conditions (delivering service access, core features, and account support).
- Legal Obligation (Art. 6(1)(c)): Processing and storing financial transaction records to comply with the Danish Bookkeeping Act (Bogføringsloven).
- Legitimate Interests (Art. 6(1)(f)): Maintaining infrastructure security, detecting abuse or fraud, and maintaining performance logs.
4. Data Sharing and Third-Party Sub-Processors
We do not sell, rent, or trade personal data. We share necessary data only with trusted infrastructure sub-processors required to run the Service:
- Cloud Infrastructure & Database Hosting: [e.g., Hetzner] (Servers located within EU/EEA).
- Transactional Email & Notifications: [e.g., Resend / Twilio] (For sending system emails and alerts).
- Payment Gateways: Payment details entered for your subscription are processed directly by payment providers (e.g., Stripe) in accordance with PCI-DSS standards.
5. Data Retention Policies
- Account Data: Retained while your subscription is active. Following account termination, non-financial operational data is permanently purged within 90 days.
- Accounting & Tax Records: Pursuant to the Danish Bookkeeping Act (Bogføringsloven), transaction logs, invoices, and billing metadata are retained in a secure archive for 5 years following the end of the relevant financial year.
- Application Logs: Technical access and security logs are automatically rotated and purged after 30 to 90 days.
6. Security Measures (GDPR Art. 32)
We implement technical and organizational security controls to protect data against unauthorized access, loss, or alteration:
- Enforced encryption in transit using TLS/HTTPS across all endpoints.
- Strict logical tenant data isolation in database architecture.
- Encrypted database backups and restricted access controls limited to authorized system maintainers.
7. Your Data Subject Rights
Under GDPR, you have the following rights regarding your personal data held directly by us:
- Right of Access & Portability: Request a copy of the personal data we hold about you or export your data via in-app tools.
- Right to Rectification: Correct inaccurate or incomplete account details directly in your account settings.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your account data, subject to statutory retention obligations under the Bookkeeping Act.
- Right to Restrict or Object: Object to processing based on legitimate interests.
To exercise any of these rights, contact us at .
8. Right to Lodge a Complaint
If you believe our processing of your personal data violates data protection laws, you have the right to lodge a complaint with the Danish Data Protection Agency:
- Datatilsynet
- Carl Jacobsens Vej 35, 2500 Valby, Denmark
- Website: www.datatilsynet.dk