Privacy Policy
Last updated: 2026-03-02
VCAD ApS respects your privacy and processes personal data in accordance with applicable data protection law, including the GDPR and the Danish Data Protection Act.
This Privacy Policy applies to VCAD websites, customer portals, SaaS products, and locally installed software that authenticates against or interacts with VCAD systems.
Contact Details
VCAD ApS
Østergaardsvej 117, 5683 Haarby
CVR: 45856771
Denmark
Email: info@vcad.dk
1. Who We Are
VCAD ApS is the data controller for the personal data described in this Privacy Policy, unless otherwise stated.
If you have questions about this Privacy Policy or about how we process personal data, you can contact us using the details in the contact box above.
2. What We Process
Depending on how you use our services, we may process:
- account data such as name, email address, phone number, company affiliation, and role
- company data such as company name, address, country, phone number, and CVR number
- authentication and session data such as login timestamps, IP address, user agent, and session identifiers
- records of legal acceptance, including accepted document version, timestamp, IP address, and user agent
- product settings and user preferences stored in our systems
- support communications and related technical details
- security and anti-abuse data, including rejected signup attempts and verification results
- locally stored data on your device, such as cookies, localStorage, and IndexedDB data required for product functionality
3. Why We Process Personal Data
- to create and manage accounts
- to authenticate users and provide access to our services
- to administer companies, users, and licenses
- to send transactional emails such as password resets and invitations
- to maintain settings and service functionality
- to protect our systems and prevent abuse
- to document legal acceptance of our terms and policies
- to comply with legal obligations and defend legal claims
4. Legal Basis
- performance of a contract (GDPR Article 6(1)(b))
- legal obligation (GDPR Article 6(1)(c))
- legitimate interests, including security, operations, and documentation (GDPR Article 6(1)(f))
- consent, where a specific activity requires it (GDPR Article 6(1)(a))
5. Who We Share Data With
We do not sell personal data. We may share personal data with service providers who process data on our behalf where necessary to operate our services.
This includes relevant infrastructure, hosting, storage, communications, security, and technical service providers where needed to deliver and protect our services.
In a business context, administrators within your organisation may also be able to view and manage information connected to your organisation’s account.
6. International Transfers
We may use service providers located inside or outside the EU or EEA.
Where personal data is transferred outside the EU or EEA, we will rely on an appropriate transfer mechanism such as an adequacy decision, the European Commission’s Standard Contractual Clauses, or another valid safeguard under GDPR.
7. Retention
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required by law.
- account and company data are kept while the account is active and for a reasonable period afterward where needed for administration, security, or legal documentation
- security and audit-related logs are kept as long as reasonably necessary for security, compliance, and documentation
- legal acceptance records are kept as long as necessary to document contractual acceptance and compliance
- locally stored data remains on your device until deleted by you, the application, or your browser or device environment
8. Cookies and Local Storage
Our services use cookies and similar storage technologies only where needed for operation of the service, including authentication, session handling, security, language preference, and locally stored settings or working data.
We do not currently use marketing cookies or third-party advertising trackers in these services.
9. Your Rights
- access to your personal data
- correction of inaccurate data
- deletion where applicable
- restriction of processing
- objection to processing based on legitimate interests
- data portability where applicable
- withdrawal of consent where processing is based on consent
- the right to lodge a complaint with a supervisory authority
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, processing activities, or legal requirements.
When required, we will provide notice of material changes through our website, our services, or by email.