Last updated: September 30, 2026
This is a translation. In case of discrepancies, the Danish version applies.
Danro processes personal data in accordance with the General Data Protection Regulation (GDPR), the Danish Data Protection Act (databeskyttelsesloven) and other applicable legislation. Here you can read what data Danro processes, why, how long it is kept, who it is shared with, and what rights you have.
1. Data controller
The data controller responsible for processing your personal data is:
- Company
- Danro
- CVR no. (Danish business reg. no.)
- 37899283
- Address
- Mærsk Andersens Vej 16, 1. th., 8930 Randers
- hello@danro.dk
Danro is the data controller for personal data processed in connection with the website, inquiries, client projects, the client portal, purchases and other services, unless expressly stated otherwise.
2. Inquiries and quotes
When you contact Danro through the contact form, by email, by phone or in any other way, we may process:
- your name, email address and, if provided, phone number
- your company and CVR number (Danish business registration number)
- the content of your inquiry
- information about the service, package, template or industry you are asking about
The purpose is to respond to your inquiry, prepare a quote and, where relevant, prepare an agreement. Processing is based on GDPR Article 6(1)(b) when it is necessary to take steps at your request prior to entering into an agreement. For general inquiries, processing is based on Article 6(1)(f), on the basis of Danro's legitimate interest in being able to communicate with those who get in touch.
You receive an email receipt when you have sent an inquiry. Inquiries that do not lead to a client relationship are deleted or anonymized when they are no longer necessary, and as a rule no later than 12 months after the last relevant contact, unless there is a specific reason to keep them longer.
3. Clients, projects and agreements
When you become a Danro client, we may process:
- name, contact and company details
- quotes, agreements and order confirmations
- correspondence, project material, files and comments
- information about ordered services and subscriptions
- invoice, payment and order history
Processing takes place in order to enter into and perform the agreement, cf. GDPR Article 6(1)(b), and to comply with legal obligations, cf. Article 6(1)(c).
Accounting records, including invoices and payment information, are kept for 5 years from the end of the financial year to which they relate, cf. § 12 of the Danish Bookkeeping Act (bogføringsloven). Other client data is deleted when it is no longer necessary for the agreement or for documenting it.
4. Client portal and login
If you use Danro's client portal, we process the data needed to identify your account, log you in securely, keep your session active, protect the account against misuse and show your projects, payments and products. Danro uses Clerk as its login provider.
The legal basis is GDPR Article 6(1)(b) when the account is necessary to provide an agreed service, and Article 6(1)(f) for necessary security measures. Account data is kept for as long as the account or client relationship is active, and after that only for as long as necessary for documentation, security or legal reasons.
5. Payment
Online payments are handled by Stripe on Stripe's own payment page. Stripe processes name, email, payment method, transaction details, IP address and the information needed for payment and fraud prevention. Danro receives the payment status, amount and order details, but never your full card number. The legal basis is GDPR Article 6(1)(b) and (c).
6. Emails and notifications
Danro sends system and transactional emails from notification@danro.dk via Resend, e.g. a receipt for an inquiry, notice of a new invoice, a subscription offer, a change in your project's status and the result of the SEO test. Resend processes the recipient's email address, the content of the email and technical information about delivery.
Emails that are necessary for an agreement or a service you have requested are sent under GDPR Article 6(1)(b). Replies to these emails go to hello@danro.dk.
7. SEO test and other free tools
When you use Danro's SEO test, Danro processes your email address, the address you want tested, the test result, the time and documentation of your consent. The data is used to run the test, send you the result and contact you about what you have consented to.
If you separately agree to receive tips and news, this is based on your consent, cf. GDPR Article 6(1)(a) and § 10 of the Danish Marketing Practices Act (markedsføringsloven). Consent is voluntary and can always be withdrawn free of charge by writing to hello@danro.dk. Withdrawal does not affect the lawfulness of processing before the withdrawal. Danro may keep documentation that consent was given or withdrawn for a limited period.
8. Statistics (Google Analytics)
If you accept statistics cookies, Danro uses Google Analytics to see how the website is used, e.g. which pages are visited, where visitors come from and what type of device they use. Google Analytics is not loaded until you have accepted.
The legal basis is your consent, cf. GDPR Article 6(1)(a) and § 3 of the Danish Cookie Order (cookiebekendtgørelsen). You can change or withdraw your consent at any time via "Cookie settings" at the bottom of the page. Data in Google Analytics is kept for no more than 14 months. Read more in the cookie policy.
9. Operations, security and technical data
When you use the website or the client portal, technical data such as IP address, time, browser and device as well as server, error and security logs are processed. The purpose is operations, troubleshooting and protection against misuse, and the legal basis is Danro's legitimate interest in running and securing its services, cf. GDPR Article 6(1)(f). Logs are deleted or rotated on an ongoing basis, unless a specific security incident makes longer retention necessary.
10. Recipients and data processors
Danro uses external suppliers that process personal data on Danro's behalf. This is done under a data processing agreement, cf. GDPR Article 28. Data is never sold and is not disclosed to unauthorized parties.
| Supplier | Purpose | Location |
|---|---|---|
| Hosting | Running the website, CMS and client portal | EU |
| Clerk | Login and accounts in the client portal | USA |
| Stripe | Online payment and fraud prevention | EU/USA |
| Resend | Sending system and transactional emails | USA |
| Google Workspace | Email (hello@danro.dk) | EU/USA |
| Google Analytics | Visitor statistics, only with consent | EU/USA |
Beyond this, Danro only discloses personal data when it is necessary to provide a service, follows from an agreement, is required by law, or when you have asked for it.
11. Transfers outside the EU/EEA
Some suppliers or their sub-processors process data outside the EU/EEA, including in the USA. When this happens, Danro ensures a valid transfer mechanism under Chapter V of the GDPR, e.g. the EU-U.S. Data Privacy Framework where the supplier is certified, or the European Commission's standard contractual clauses.
12. Your rights
Under the GDPR, depending on the circumstances, you have the right to:
- access the data Danro processes about you (Article 15)
- have inaccurate data rectified (Article 16)
- have data erased (Article 17)
- have processing restricted (Article 18)
- receive your data in a commonly used format (Article 20)
- object to processing based on legitimate interests (Article 21)
- withdraw consent where processing is based on consent (Article 7(3))
These rights are not always absolute. For example, Danro may be required to keep data under the Danish Bookkeeping Act. Write to hello@danro.dk if you want to exercise your rights. You will receive a reply within one month, cf. Article 12(3).
13. Automated decisions
Danro does not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you, cf. GDPR Article 22.
14. Security
Danro uses appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration and unauthorized access, cf. GDPR Articles 5 and 32, including encrypted connections (HTTPS), access control and regular updates.
15. Complaints
If you believe Danro is processing your data in breach of the rules, please contact hello@danro.dk first. You can also file a complaint with Datatilsynet (the Danish Data Protection Agency), Carl Jacobsens Vej 35, 2500 Valby, Denmark, datatilsynet.dk, cf. GDPR Article 77.
16. Changes
This privacy policy is updated if Danro's services, suppliers or processing of personal data change, or if the law changes. The current version is always available on this page.