Home Use cases Meet DPO Agent Pricing FAQ Knowledge base Trust Center Privacy by design Whitepaper DPA Contact Team Sign in
PRIVACY POLICY

How we handle your personal data

DPO Agent ApS is committed to processing your personal data lawfully, fairly and transparently. This policy explains what data we collect, why, and your rights.

Data controllerDPO Agent ApS
AddressThoras Vænge 34, 2th, 2950 Vedbæk, Denmark
Contactcontact@dpoagent.dk
Last updatedAugust 2026
Version1.1

1. Who we are

DPO Agent ApS (CVR: 46574168) is the data controller for personal data processed in connection with your use of DPO Agent at dpoagent.dk.

If you have questions about how we process your personal data, please contact us at contact@dpoagent.dk.

2. What personal data we collect and why

Category Data collected Purpose Retention
Authentication Name, email address (from your Microsoft account) To verify your identity and provide access to the service
Legal basis: Art. 6(1)(b)
Duration of subscription
Service queries Questions and scenarios you submit in the chat To generate a response from the knowledge base
Legal basis: Art. 6(1)(b)
Zero retention — not stored after processing
Contact form Name, email, company name, message To respond to your inquiry or process your order
Legal basis: Art. 6(1)(b) / Art. 6(1)(f)
Up to 3 years
Order data Company name, CVR, billing address, EAN, contact person To fulfil your subscription and issue invoices
Legal basis: Art. 6(1)(b) / Art. 6(1)(c)
5 years (bookkeeping act)
We do not process special categories of personal data (GDPR art. 9). We do not make automated decisions with legal or similarly significant effects. We do not use your data for profiling or marketing.

3. Zero data retention — your queries are not stored

When you submit a question in DPO Agent, your query is processed in real time to generate a response. We do not store your questions or the AI responses after processing.

Azure OpenAI (our AI provider) is configured with zero data retention — Microsoft does not log or store your queries. This means that even if you include personal data in a scenario description, it is not retained after your session ends.

For fair use enforcement, an anonymised identifier derived from your Microsoft Entra ID account is temporarily held in server memory (RAM) to count daily queries against the usage limit (100 queries per user per day). This data is never written to disk or any database, is not linked to your queries or session content, and is automatically discarded at the end of the calendar day.

4. Cookies

DPO Agent does not use tracking cookies, advertising cookies, or analytics cookies. No third-party cookies are set by dpoagent.dk. The Microsoft authentication flow (Entra ID) may set session cookies strictly necessary for login — these are managed by Microsoft and are not accessible to DPO Agent.

5. Data processors and third-party recipients

We use the following data processors. All processing takes place within the EU/EEA:

Processor Service Location
Microsoft Azure Cloud infrastructure, AI processing (Azure OpenAI), authentication (Entra ID), storage Sweden Central (EU)
SendGrid (Twilio) Email delivery for contact form and order confirmations EU
Billy Invoicing and billing — processes name, company name, CVR number and billing email address Denmark (EU)

We do not sell your personal data to third parties. We do not transfer personal data outside the EU/EEA.

6. Your rights

Under GDPR, you have the following rights regarding your personal data:

To exercise your rights, contact us at contact@dpoagent.dk. We will respond within 30 days.

7. Complaints

If you believe we are processing your personal data in violation of GDPR, you have the right to lodge a complaint with the Danish Data Protection Agency:

8. Changes to this policy

We may update this privacy policy from time to time. The current version is always available at dpoagent.dk/privacypolicy/. We will notify active subscribers of material changes by email.