Privacy Policy for Ellypsis ApS
Version 2Last updated 21 September 2026
This privacy policy describes how Ellypsis ApS (Ellypsis) processes personal data as data controller, including when you visit ellypsis.dk, contact us, are a customer or a contact person at a customer, receive consultancy services from us, or use Ellypsis Apps.
The privacy policy does not apply to personal data that Ellypsis processes as a data processor or sub-processor on behalf of a customer. That processing is governed by the relevant data processing agreement.
Data controller
Ellypsis ApSCVR: 46324447Email: hello@ellypsis.dkWhen you visit ellypsis.dk
When you visit the website, technical information is processed, including your IP address and information about your browser and device, to the extent this is necessary to deliver the website, keep it running and protect it against abuse.
We also use cookie-free, aggregated traffic statistics to get an overall picture of how the website is used.
The processing is based on our legitimate interest in operating, improving and protecting the website, cf. Article 6(1)(f) GDPR.
When you contact us
The contact form (/en/contact)
When you use the contact form, we process your company name, your email address, the systems you tick, and any other information you write in the message.
The information is used to handle and answer your enquiry.
The processing is based on our legitimate interest in being able to communicate with the people and companies who contact us, cf. Article 6(1)(f) GDPR.
The assessment form (/en/assessment)
When you use the assessment form, we process information about your company, your email address, your role and your answers to the questions in the form.
The information is used to assess the possible task and a possible collaboration.
The processing is based on our legitimate interest in being able to assess enquiries, potential tasks and possible business collaborations, cf. Article 6(1)(f) GDPR.
The mandatory fields in the forms are necessary for us to be able to handle the enquiry.
When a form is submitted, your IP address may also be processed briefly in order to prevent spam and abuse. That processing is based on our legitimate interest in protecting the website and the forms, cf. Article 6(1)(f) GDPR.
When you are a customer, a potential customer or a contact person
When we establish, administer or communicate about an existing or possible customer relationship, we may process information about people at the customer or the potential customer.
We process name, work email address and telephone number, job title or role, company affiliation, and information contained in relevant correspondence, quotes, agreements and other documentation of the customer relationship.
The information is used to communicate with the customer, to prepare and administer the collaboration, to deliver our services and to document the contractual relationship.
When you act on behalf of a company, the processing is as a rule based on our legitimate interest in establishing, administering and documenting our business relationships, cf. Article 6(1)(f) GDPR.
If you are yourself a party to the agreement with Ellypsis, the processing may instead be necessary in order to enter into or perform that agreement, cf. Article 6(1)(b) GDPR.
We also process information where this is necessary in order to comply with legal obligations, including rules on bookkeeping and accounting, cf. Article 6(1)(c) GDPR.
As a rule we receive the information from you, from the company you represent, or from other people at that company. We may also process information that is publicly available.
Consultancy services
When Ellypsis delivers advice, setup, customization or other consultancy services, we may process personal data about the people who take part in the work or who are contact persons for it.
We process name, contact details, job title or role, and information contained in communication, meeting notes, project material and other documentation relating to the work.
The information is used to plan, carry out and administer the consultancy service, to communicate with the customer and to document the collaboration.
When you take part in the consultancy work on behalf of a company, the processing is as a rule based on our legitimate interest in delivering and administering the consultancy service and the customer relationship, cf. Article 6(1)(f) GDPR. If you are yourself a party to the agreement on the consultancy service, the processing necessary in order to enter into or perform that agreement may instead be based on Article 6(1)(b) GDPR.
Where Ellypsis processes personal data on behalf of the customer as part of a consultancy service, that processing is not covered by this privacy policy.
Ellypsis Apps
Ellypsis Apps is Ellypsis' subscription-based platform at app.ellypsis.dk.
When you use Ellypsis Apps, we process information about your account and your use of the platform. We process your email address, user ID, role and information about which apps you have access to, as well as technical information and metadata about your use of the platform and about administrative actions.
The information is used to identify you, to administer users and access, to operate and secure the platform, to prevent abuse and to document the contractual relationship. Information about which account you belong to, your role and your access may also be given to us by the company you are attached to.
If you accept a contractual document on behalf of the company, we may also record which document and which version was accepted, the time of acceptance, your email address and role, your IP address and information about your browser or device.
The processing is based on our legitimate interest in delivering, administering and protecting Ellypsis Apps and in documenting our contractual relationships, cf. Article 6(1)(f) GDPR.
Subscription and invoicing
In connection with subscription and payment, we process company name, address, country, VAT number, subscription status and the relevant customer, subscription and payment identifiers from our payment provider.
The information is used to administer subscription, payment and invoicing. The processing is based on our legitimate interest in administering the customer relationship, cf. Article 6(1)(f) GDPR, and on our legal obligations, including under bookkeeping legislation, cf. Article 6(1)(c) GDPR.
Ellypsis does not store payment card details. These are handled by the payment provider.
Ellypsis Apps may also process personal data on behalf of the customer. That processing is not covered by this privacy policy.
Who we share information with
We use external providers for hosting, email, login, payment and technical operation.
We use the following providers for the processing described in this privacy policy:
- Vercel for hosting ellypsis.dk and for traffic statistics
- Resend for sending emails from the forms on the website
- Google Workspace for email and for handling enquiries and customer relationships internally
- Scaleway for hosting and operating Ellypsis Apps
- Logto for login and identity management in Ellypsis Apps
- Stripe for subscription, payment and invoicing
- GitHub in connection with development, deployment and technical operating routines.
Where a provider processes personal data on our behalf, it does so on our instructions and under a data processing agreement.
Transfers to countries outside the EU/EEA
We use providers that may process personal data in countries outside the EU/EEA. When personal data is transferred to third countries, we rely on the European Commission's standard contractual clauses or another lawful basis for transfer under Chapter V of the GDPR.
How long we keep the information
We do not keep personal data for longer than is necessary for the purposes it was collected for, unless we are obliged or entitled to keep it longer.
Enquiries
Information from the contact and assessment forms is as a rule kept for up to 2 years after the last contact.
If the enquiry leads to a customer relationship, relevant information may instead form part of the documentation of that relationship and be kept under the rules that apply to it.
Customer and consultancy relationships
Information about contact persons, communication, agreements and consultancy work is kept for as long as it is necessary in order to administer and document the collaboration and any subsequent claims.
Accounting records, and the personal data they contain, are kept for 5 years from the end of the financial year the material relates to, in accordance with the Danish Bookkeeping Act.
Ellypsis Apps
Metadata about the use of Ellypsis Apps that forms part of the work log is as a rule kept for 90 days.
Information about an individual user's consumption in Ellypsis Apps is as a rule kept for 365 days.
Information that is necessary in order to document the contractual relationship may be kept after the customer relationship ends, where this is necessary in order to document the agreement or to comply with legal obligations.
Cookies and local storage
ellypsis.dk
The website does not use cookies.
Your browser may store functional settings, such as your choice of theme, locally on your own device. That information is not sent to us.
Ellypsis Apps
Ellypsis Apps uses necessary cookies for login, session management and security.
An ordinary login session lasts up to 12 hours. Short-lived security cookies are also used, among other things when logging in and when connecting external systems. These expire as a rule after approx. 10 minutes.
Cookies in Ellypsis Apps are not used for marketing or for tracking across websites.
When you are sent on to an external provider's website, for example a login or payment provider, that provider may use its own cookies under its own rules.
Your rights
Under the GDPR you have a number of rights in relation to our processing of your personal data.
- Right of access
- You have the right to obtain access to the personal data we process about you, cf. Article 15 GDPR.
- Right to rectification
- You have the right to have inaccurate personal data about you corrected and incomplete data completed, cf. Article 16 GDPR.
- Right to erasure
- You have the right to have personal data about you erased in the cases set out in Article 17 GDPR.
- Right to restriction of processing
- You have the right to have the processing of your personal data restricted in the cases set out in Article 18 GDPR.
- Right to data portability
- You have the right to receive the personal data you have given us in a structured, commonly used and machine-readable format, and to have it transmitted to another data controller, cf. Article 20 GDPR.
- Right to object
- You have the right to object to our processing of your personal data where the processing is based on our legitimate interests, cf. Article 21 GDPR.
Conditions or limitations may apply to your rights. Whether a request can be met therefore depends on the specific processing.
If you want to exercise your rights, you can contact us at hello@ellypsis.dk.
Complaints
If you are unhappy with the way we process your personal data, you are welcome to contact us.
You also have the right to complain to Datatilsynet, the Danish Data Protection Agency:
Contact
If you have questions about this privacy policy or about our processing of personal data, you can contact us at:
Ellypsis ApSEmail: hello@ellypsis.dkChanges to this privacy policy
We may update this privacy policy. When we do, we update the date and the version number. The privacy policy in force at any given time is available on our website at https://ellypsis.dk/en/privacy.
Version 2 - Current version - updated 21 September 2026Version 1 - 24 August 2026