Legal & privacyLegal

Privacy Policy

Last updated 1 July 2026

This policy explains what personal data Kompena ApS processes when you use our platform, why, where it's hosted, how long we keep it, and the rights you have under the GDPR.

1. Controller

For data about you as our customer or user (account holder, billing contact, team member), Kompena ApS, CVR 44 12 87 65, Vesterbrogade 20, 1620 Copenhagen V, Denmark, is the data controller. Where you connect your own data sources (e.g. your Shopify store, ad accounts, your customers' order and email data), you remain the controller of that data and we act as your processor. See the Data Processing Agreement.

2. What we collect

  • ·Account data: name, work email, company, role, password hash, language preference.
  • ·Billing data: company name, VAT/CVR number, billing address, and payment status via our payment processor (we do not store full card numbers).
  • ·Connected-source data: read-only metrics and metadata from sources you connect (e.g. traffic, orders, ad spend, campaign performance, email engagement, review scores, Core Web Vitals). We never request write access.
  • ·Free-audit data: publicly observable signals about a storefront you submit a URL for (page performance, tracking setup, ad presence, public reviews), before any account or login exists.
  • ·Product usage data: pages viewed, features used, and diagnostic logs, collected to operate and improve the service.
  • ·Support and execution communications: messages, task briefs and files exchanged with our team when you use the execution retainer.

3. Why we process it (legal basis)

  • ·Contract performance: operating your account, computing scores and recommendations, delivering execution tasks you accept.
  • ·Legitimate interest: securing the platform, improving the scoring engine and benchmarks, and running the free external audit you request.
  • ·Consent: optional product-update emails and, where applicable, non-essential cookies (see Section 8).
  • ·Legal obligation: bookkeeping and tax records, retained per Danish law.

4. Where your data is hosted

All production data (your account, connected-source metrics, and derived scores and recommendations) is hosted with Supabase on infrastructure in the EU (eu-central-1, Frankfurt). We do not transfer personal data outside the EU/EEA except where a sub-processor requires it, in which case we rely on Standard Contractual Clauses or an equivalent adequacy mechanism. See the sub-processor register for the current list and each processor's location.

5. Read-only connectors

Every data-source connection we support (Shopify, Google Analytics 4, Meta Ads, Google Ads, Klaviyo, Search Console, Trustpilot, and others) is scoped to read-only access. We cannot modify, delete, or take action inside your connected accounts. We only read the metrics needed to compute your score and recommendations. You can revoke any connection at any time from Data Sources in your dashboard.

6. Retention

  • ·Account & connected-source data: retained for the life of your account plus 30 days after closure, to allow reactivation, then permanently deleted.
  • ·Free-audit data (no account): retained for 90 days, then permanently deleted, unless you create an account from it.
  • ·Billing records: retained for 5 years to meet Danish bookkeeping-law requirements.
  • ·Support & execution communications: retained for 2 years after the related task closes, for quality and dispute-resolution purposes.

7. Your rights

Under the GDPR, you have the right to:

  • ·Access the personal data we hold about you.
  • ·Correct inaccurate or incomplete data.
  • ·Request erasure (“right to be forgotten”), subject to legal retention obligations.
  • ·Request restriction of, or object to, certain processing.
  • ·Receive your data in a portable format.
  • ·Withdraw consent at any time where processing is based on consent.
  • ·Lodge a complaint with the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk).

To exercise any of these rights, email privacy@kompena.com or use the data-export and account-deletion controls in your dashboard settings. We respond within 30 days.

8. Cookies

We use strictly necessary cookies to keep you signed in and remember basic preferences (such as language). We use a small set of analytics cookies to understand product usage, which you can decline from the cookie banner without affecting core functionality. We do not use third-party advertising cookies.

9. Security

Data is encrypted in transit (TLS) and at rest. Access to production data is restricted by role and protected by row-level security at the database layer, so each customer's data is isolated from every other customer's. We conduct periodic access reviews and maintain an incident-response process; we will notify affected customers of a personal-data breach without undue delay, and in any case within the timelines required by the GDPR.

10. Changes to this policy

We will post updates here and, for material changes, notify you by email or in-product notice at least 14 days before they take effect.

11. Contact

Privacy questions or requests: privacy@kompena.com. Postal address: Kompena ApS, Vesterbrogade 20, 1620 Copenhagen V, Denmark.