This policy explains what personal data Builderve collects when you visit builderve.com, contact us or become a customer, what we do with it, and your rights. We aim to write it in plain language.
1. Who is responsible for your data
The data controller for the processing described in this policy is:
Builderve Nordic (trading as Builderve)
Prøvestensvej 11, 3450, Denmark
Email: customer@builderve.com
Phone: +45 42 74 01 24
We have not appointed a data protection officer because the law does not require it for our activities. Send any privacy question or request to customer@builderve.com (or danmark@builderve.com if you are in Denmark).
2. What we collect, why, and on what basis
We only collect what we need. The table shows each purpose, the data involved and our legal basis under the General Data Protection Regulation (GDPR).
| Purpose | Data | Legal basis |
|---|---|---|
| Answering enquiries sent through the contact form or by email | Name, email, company, project details and anything else you write | Steps at your request before entering a contract (Art. 6(1)(b)); our legitimate interest in running our business (Art. 6(1)(f)) |
| Delivering our services and managing the customer relationship | Contact details of your staff, project, hosting and support records, correspondence | Performance of a contract (Art. 6(1)(b)) |
| Client portal accounts | Name, email, Client ID, a hashed password (never the password itself), project, invoice and support data, sign-in times, IP address and browser details | Performance of a contract (Art. 6(1)(b)); security (Art. 6(1)(f)) |
| Invoicing and bookkeeping | Invoice details, payment status, company and contact details | Legal obligation, including the Danish Bookkeeping Act (Art. 6(1)(c)) |
| Running and securing this website | IP address, request time, pages requested and browser type in server logs; rate-limit counters for the contact form | Our legitimate interest in security and stability (Art. 6(1)(f)) |
| Remembering your cookie choice | Your consent choice and its date | Legal obligation to document consent (Art. 6(1)(c)) |
| Website analytics, only if you accept | Anonymous page views, referrer, country, device and browser | Your consent (Art. 6(1)(a)) |
Providing the details marked as needed for a contact or a contract is voluntary, but we cannot reply to you or deliver a service without them. We do not make decisions about you by automated means, and we do not sell personal data.
3. Where the data comes from
Mostly from you. For business customers, the contact person at your company may give us details of colleagues who need access to the client portal. We may also receive public company information, for example from the Danish Central Business Register (CVR).
5. Transfers outside the EU/EEA
Some providers are based in, or access data from, the United States. Where personal data leaves the EU/EEA we rely on an adequacy decision, such as the EU–US Data Privacy Framework for certified providers, or on the European Commission's Standard Contractual Clauses together with additional safeguards. You can ask us for a copy of the safeguards in place.
6. How long we keep data
- Enquiries that do not lead to a customer relationship: deleted after 12 months.
- Customer and project records: for the duration of the relationship and, where needed to handle claims, up to 3 years afterwards (the general Danish limitation period).
- Invoices and accounting records: 5 years after the end of the financial year in which they were created, as required by the Danish Bookkeeping Act.
- Client portal sign-in sessions and security logs: a few weeks to a few months, then deleted automatically or on a regular schedule.
- Server logs: a short period set by our hosting provider, normally no more than 30 days.
- Cookie consent record: 6 months, after which we ask again.
7. Your rights
Under the GDPR you have the right to:
- get access to the personal data we hold about you and a copy of it;
- have inaccurate data corrected and incomplete data completed;
- have data erased, where the law gives you that right;
- restrict how we use your data in certain cases;
- receive data you gave us in a structured, commonly used format, and have it transferred (data portability);
- object to processing based on our legitimate interests;
- withdraw consent at any time. This does not affect earlier processing. Use Cookie settings in the footer to change cookie choices.
To use a right, email customer@builderve.com. We reply without undue delay and within one month. We may ask you to confirm who you are first.
You can also complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, datatilsynet.dk. We would appreciate the chance to resolve your concern first.
8. When we handle data on behalf of our customers
When we host a website or build software for you and, in doing so, process personal data about your customers or staff, you are the controller and we are your processor. That processing is covered by a data processing agreement that we will conclude with you on request, or as part of our terms of service. Requests from your end users about that data should be sent to you.
9. How we protect data
We use encrypted connections (HTTPS), store passwords only as salted hashes, limit access to people who need it, keep software up to date, and review access regularly. No system is perfectly secure. If a personal data breach affects you, we will notify you and the authorities as the law requires. See also our security page.
10. Children
Our website and services are for businesses and are not aimed at children. We do not knowingly collect data from anyone under 16.
12. Links to other websites
This site may link to other websites. We are not responsible for their content or privacy practices, so please read their policies.
13. Changes to this policy
We update this policy when our practices or the law change. The date at the top shows the latest version. If a change significantly affects you, we will tell you in a suitable way.

