Legal / GDPR

Privacy policy.

Issued 2026.06.15 — Rev 2.0 — GDPR + DK

§1

Who this applies to

This privacy policy describes how Cimalys ApS processes personal data of visitors to cimalys.com, people who submit our forms (booking, contact), prospective clients, and contractual clients. It is written to comply with Regulation (EU) 2016/679 (GDPR), the Danish Data Protection Act (Databeskyttelsesloven), and the Danish Marketing Practices Act (Markedsføringsloven). It is supplemented by our cookie policy for matters governed by the ePrivacy Directive and the Danish Cookie Order.

The service is offered to businesses (B2B). It is not directed at children under 16.

§2

Data controller

Cimalys ApS

CVR 46502493 / EU VAT DK46502493

Næstvedvej 34 st., 4100 Ringsted, Denmark

Contact: hello@cimalys.com

We are not required to appoint a Data Protection Officer under GDPR Article 37; questions about this policy or your rights are handled directly by the founder, Nicolas Lejeune, at the address above.

§3

What we collect and why

A. Information you give us

  • Contact & booking forms — name, work email, phone (optional), company, role, chosen meeting topic, free-text context, and the boolean confirmations that you are a decision-maker and have read the consent statement. Stored to schedule and follow up on the call.
  • Email subscriptions — work email and a timestamped record of the consent text you confirmed. Used only for the list you signed up for (writing, service updates) and includes an unsubscribe link in every message.

B. Information collected automatically

  • Server logs — IP address, browser user-agent, request timestamps, response codes. Retained ≤ 30 days for security, abuse prevention, and debugging.
  • Marketing attribution (consent-gated) — with your consent we store campaign attribution (UTM parameters, ad click identifiers such as fbclid, referrer, landing-page URL) in a first-party cookie for 30 days. Full detail in the cookie policy.
  • Meta Pixel (consent-gated) — with your consent, the Meta Pixel sets the _fbp / _fbc cookies and transmits PageView, ViewContent, Lead, and Schedule events to Meta Platforms Ireland Ltd.

C. Special categories

We do not knowingly collect special-category data (Art 9 GDPR). Please do not enter it into our forms.

§4

Purposes and legal basis (Art 6 GDPR)

  • Reply to your enquiry / book your call — pre-contractual measures and contract performance, Art 6(1)(b).
  • Deliver paid services and issue invoices — contract performance, Art 6(1)(b); legal obligation for bookkeeping under the Danish Bookkeeping Act (Bogføringsloven), Art 6(1)(c).
  • Send email newsletter / service updates you signed up for — consent, Art 6(1)(a), captured with an audit trail per Danish Marketing Practices Act § 10.
  • First-party attribution cookie — consent, Art 6(1)(a), expressed via the cookie banner.
  • Meta Pixel + Conversions API (browser-side) — consent, Art 6(1)(a), via the cookie banner. Cimalys and Meta are joint controllers for this processing within the meaning of Art 26.
  • Server-side Meta Conversions API call on form submission — contract performance, Art 6(1)(b), and our legitimate interest in measuring ad conversion, Art 6(1)(f). You can opt out by contacting us; details in the cookie policy §5.
  • Site security and abuse prevention — legitimate interest, Art 6(1)(f).
§5

Sub-processors and data sharing

We use the following service providers, each under a Data Processing Agreement compliant with Art 28 GDPR:

  • Vercel Inc. (United States) — site hosting and CDN. Standard Contractual Clauses; EU-region edge for static delivery.
  • Cloudflare, Inc. (United States) — edge proxy, DNS, DDoS protection. Standard Contractual Clauses; EU Data Privacy Framework certified.
  • Supabase Inc. (United States; EU project region: Frankfurt) — primary database for lead, booking, and subscriber records.
  • Resend, Inc. (United States) — transactional and confirmation emails (booking confirmations, internal alerts, newsletter). Standard Contractual Clauses.
  • Notion Labs, Inc. (United States) — internal lead CRM mirror of booking submissions. EU-US Data Privacy Framework + Standard Contractual Clauses.
  • Google LLC (Ireland / United States) — Google Calendar API for booking events; attendee email is shared with Google to create the calendar invite and Meet link. EU-US Data Privacy Framework + Standard Contractual Clauses.
  • Meta Platforms Ireland Ltd (Ireland; US transfers covered by EU-US Data Privacy Framework + Standard Contractual Clauses) — Meta Pixel and Conversions API. Receives hashed email, hashed phone where in international format, IP address, browser user agent, ad click identifiers, and event names. Plaintext contact details are never shared.
  • Stripe Payments Europe Ltd (Ireland) — used for any future paid transactions on the site. Card data is collected by Stripe directly and is not seen or stored by Cimalys.

We do not sell personal data to anyone. We do not use it for automated decision-making with legal or similarly significant effects (Art 22). Meta Custom Audiences built from the events above involve profiling for advertising purposes; that is the only profiling activity and you can opt out by declining marketing consent in the cookie banner.

§6

International transfers

Several of the sub-processors above are established outside the European Economic Area. Transfers rely on the EU-US Data Privacy Framework where the recipient is certified (Meta, Notion, Google Cloud, Cloudflare), and on the EU Commission's Standard Contractual Clauses (2021/914) in all other cases, together with supplementary measures including encryption in transit (TLS 1.2+) and at rest, hashed identifiers where technically possible, and access controls.

§7

Retention

  • Server logs — up to 30 days.
  • First-party attribution cookie — 30 days.
  • Meta Pixel cookies (_fbp, _fbc) — 90 days, set by Meta.
  • Cookie-consent record — 180 days, then refresh on next visit.
  • Booking submissions — up to 2 years from the last interaction, then deleted, unless you become a paying client.
  • Newsletter subscribers — until you unsubscribe, then deleted within 30 days.
  • Accounting records (invoices, contracts, payment receipts) — 5 years from the end of the financial year, as required by the Danish Bookkeeping Act § 12.
  • Client engagement notes and deliverables — duration of the relationship plus 5 years (limitation period for contractual claims under DK Forældelsesloven § 3).
§8

Your rights

Under GDPR Articles 15–22 and the Danish Data Protection Act you have the right to:

  • access the personal data we hold about you (Art 15);
  • have inaccurate data corrected (Art 16);
  • have your data erased where the legal basis no longer applies (Art 17);
  • restrict our processing while a dispute is resolved (Art 18);
  • receive your data in a portable, machine-readable format (Art 20);
  • object to processing based on legitimate interest (Art 21);
  • withdraw consent at any time, without affecting the lawfulness of prior processing (Art 7(3)).

Write to hello@cimalys.com. We respond within 30 days (Art 12(3)). If you are not satisfied with our response you may lodge a complaint with Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark — phone +45 33 19 32 00 — datatilsynet.dk.

§9

Security

All data is transmitted over HTTPS (TLS 1.2 or higher). Database access is restricted by row-level security and least-privilege service accounts. Integration credentials are stored in encrypted secret managers and rotated on a regular cadence. Backups are encrypted at rest. We log access to personal data for audit purposes.

§10

Data breach notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify Datatilsynet without undue delay and in any case within 72 hours of becoming aware (Art 33), and affected data subjects without undue delay where the breach is likely to result in a high risk (Art 34).

§11

Cookies

Strictly necessary cookies are loaded automatically. All other cookies (analytics and marketing) are loaded only after you opt in via our cookie banner. You can change your choice at any time using the Cookie preferences link in the footer. The full list of cookies, durations, and recipients is in our cookie policy.

§12

Marketing communications

Cimalys does not send unsolicited commercial emails. Marketing emails are sent only with prior consent obtained under § 10 of the Danish Marketing Practices Act, captured with the consent text shown to you at signup and a timestamp. Every marketing email includes a one-click unsubscribe link.

Existing clients may receive directly related service communications and post-engagement updates on the basis of the existing customer relationship (Markedsføringsloven § 10(2)), with an opt-out available in every message.

§13

Changes to this policy

We update this policy when the underlying processing changes. The version, revision number, and issue date are shown in the header above. Material changes that affect your rights will be announced on the site and, where applicable, by email to subscribers and active clients.

§14

Contact

Questions about this policy or your data: hello@cimalys.com. Postal: Cimalys ApS, Næstvedvej 34 st., 4100 Ringsted, Denmark.