Introduction
This Privacy Policy explains how CAPACITY365 ApS (“CAPACITY365”, “we”, “us”, “our”) collects, uses and protects personal data in connection with our website at capacity365.dk and our business as an independent Nordic executive advisory, business transformation and flexible capacity delivery company.
We are committed to protecting the personal data of our website visitors, prospective customers, customers, partners and business contacts, and to complying with the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) and the Danish Data Protection Act (databeskyttelsesloven).
This Privacy Policy applies to personal data collected through our website and through our business communications with you. It does not apply to third-party websites that our website links to, such as LinkedIn. Please read the privacy policies of those third parties separately.
Who is the Data Controller
The data controller responsible for your personal data is:
CAPACITY365 ApS
Company registration (CVR) number: 46757173
Copenhagen, Denmark
Email: info@capacity365.dk
Telephone: +45 5353 1553
We have not appointed a Data Protection Officer. You can reach us about any privacy matter using the details above.
What Personal Data We Collect
The categories of personal data we collect depend on how you interact with us.
When you visit our website
You can browse our website without registering or logging in. When you visit, our hosting provider records technical data in standard server logs, which may include:
- your IP address;
- the date, time and duration of your visit;
- the pages you accessed and the address of the page you came from;
- your browser type, operating system and device type; and
- other diagnostic information needed for the security, availability and operation of the website.
If you accept statistics cookies in our cookie banner, we also use Google Analytics to understand how our website is used. This collects pseudonymous data such as the pages you view, how long you stay, your approximate location (country and city), your device and browser type, and the website you came from. Google Analytics 4 does not store IP addresses. If you do not give consent, no analytics data is collected.
Please see our Cookie Policy for more information about cookies and similar technologies.
When you contact us
Our contact form asks for your full name, work email address, company name and a message describing what you need. The information you submit is stored in our website database and sent to us by email. When you email or call us directly, we receive:
- your name, email address or telephone number;
- the content of your message and any attachments; and
- any additional contact information you choose to share.
When we work with you as a business contact or customer
If you are (or work for) a customer, prospective customer, partner, supplier, professional adviser or other business counterparty, we may process additional personal data in the ordinary course of the relationship, including:
- your name, job title, employer, business address, telephone number and email address;
- records of our correspondence and communications with you;
- administrative and billing information needed to deliver our services and manage the relationship; and
- any personal data you choose to share with us during an engagement.
Purposes and Legal Bases for Processing
We process personal data only where we have a lawful basis to do so under Article 6 of the GDPR. The main purposes and legal bases are:
- Responding to enquiries. We process contact details and message content to respond to enquiries you send through our website, by email or by telephone. Legal basis: legitimate interests (Article 6(1)(f) GDPR), namely responding to communications you start, and, where you ask about our services, taking steps at your request before entering into a contract (Article 6(1)(b) GDPR).
- Providing our services. Where you are a customer or partner, we process personal data to enter into and perform our agreement with you or your organisation. Legal basis: performance of a contract (Article 6(1)(b) GDPR), or legitimate interests in managing the business relationship where the agreement is with your employer.
- Website statistics. We use Google Analytics to understand and improve how our website is used. Legal basis: your consent (Article 6(1)(a) GDPR), given through our cookie banner. You can withdraw it at any time.
- Operating and securing our website. We process technical data recorded in server logs to operate, secure, monitor and troubleshoot our website. Legal basis: legitimate interests (Article 6(1)(f) GDPR), namely maintaining a functional and secure online presence.
- Managing our business and meeting legal obligations. We process personal data as needed for accounting, bookkeeping, tax and record-keeping. Legal basis: compliance with legal obligations (Article 6(1)(c) GDPR), for example under the Danish Bookkeeping Act, and legitimate interests (Article 6(1)(f) GDPR) in running our business.
How Long We Keep Personal Data
We keep personal data only for as long as necessary for the purposes for which it was collected, taking into account legal, accounting and tax retention requirements.
- Contact enquiries. Personal data received through the contact form, by email or by telephone is kept for up to 24 months from the last communication, unless the correspondence forms part of an ongoing customer, partner or supplier relationship.
- Customer, partner and supplier records. Personal data in these records is kept for the duration of the relationship and afterwards for as long as Danish bookkeeping and tax rules require (generally five years from the end of the financial year), or longer where a specific legal obligation applies.
- Website statistics. Google Analytics data is kept for up to 14 months and is then deleted automatically.
- Server logs. Technical data in server logs is kept for a short period sufficient for diagnostics and security review, and is then deleted or overwritten.
Who We Share Personal Data With
We do not sell personal data, and we do not share personal data for advertising purposes.
We share personal data only with the following categories of recipient, and only as far as needed for the purposes in this Privacy Policy:
- Service providers. Our website hosting provider (Simply.com), the email service that delivers messages sent through our website, the provider of our cookie consent tool, and Google Ireland Limited for website statistics (only if you consent). These act as data processors on our behalf under appropriate agreements.
- Professional advisers and banks. Such as our accountants, auditors, lawyers and banks, who may act as independent controllers for their own services.
- Public authorities. Where we are legally required or permitted to disclose personal data to a court, regulator, tax authority or other public authority.
- Successors in corporate transactions. In connection with a merger, acquisition, reorganisation or sale of business or assets, subject to appropriate confidentiality obligations.
International Data Transfers
Most of our processing takes place within the European Economic Area (EEA). Google may process website statistics in countries outside the EEA, including the United States. Where personal data is transferred outside the EEA, we make sure an appropriate level of protection applies in line with Chapter V of the GDPR, for example through the European Commission’s adequacy decision for the EU-US Data Privacy Framework where the recipient is certified, or through the Commission’s Standard Contractual Clauses.
You can ask for more information about the safeguards we rely on by contacting us using the details in the section “How to Contact Us and How to Complain”.
Your Rights
Subject to the conditions in the GDPR, you have the following rights in relation to your personal data:
- Right of access. To find out whether we process personal data about you and, if so, to receive a copy and information about how we use it.
- Right to rectification. To have inaccurate personal data corrected and incomplete personal data completed.
- Right to erasure. To have your personal data deleted in certain circumstances, sometimes called the “right to be forgotten”.
- Right to restriction of processing. To have the processing of your personal data restricted in certain circumstances.
- Right to data portability. To receive certain personal data in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
- Right to object. To object, on grounds relating to your particular situation, to processing based on our legitimate interests.
- Right to withdraw consent. Where we rely on your consent, to withdraw it at any time, without affecting the lawfulness of processing carried out before you withdrew it.
We do not use automated decision-making or profiling that produces legal effects for you.
To exercise any of these rights, please contact us using the details in the section “How to Contact Us and How to Complain”. We will respond within one month, subject to any extension the GDPR permits.
Security
We use appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and access. These include encrypted connections (HTTPS), access controls, backups, confidentiality obligations and the use of reputable service providers.
No transmission over the internet and no method of electronic storage is completely secure. We take reasonable steps to protect your personal data, but we cannot guarantee absolute security.
Cookies
For information about the cookies and similar technologies used on our website, please see our Cookie Policy.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, in the services we offer or in applicable law. The current version is always the one published on this page, and the “Effective from” date at the top shows when it was last updated. We encourage you to review it from time to time.
How to Contact Us and How to Complain
If you have questions about this Privacy Policy, want to exercise any of your rights, or have a concern about how we handle your personal data, please contact us at:
CAPACITY365 ApS
Company registration (CVR) number: 46757173
Copenhagen, Denmark
Email: info@capacity365.dk
Telephone: +45 5353 1553
If you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. In Denmark, the competent authority is the Danish Data Protection Agency (Datatilsynet), whose contact details are published at www.datatilsynet.dk.