Detta dokument finns på danska och engelska. Nedan visas den engelska versionen.

Privacy policy

Updated 21 September 2026. This policy explains personal-data processing at Din Firmaadresse, including accounts, address services, mail, payments, identity checks and digital documents. The portal's products also have their own privacy policy.

1. Controller and roles

Dansk Online Marketing ApS, Danish company registration (CVR) 45957969, Gunderupvej 16, 9260 Gistrup, Denmark, is controller for its own account, contract, payment, support, security and statutory customer-due-diligence purposes. Contact kontakt@dinfirmaadresse.dk or +45 44 10 40 52.

When handling customer mail, generating customer documents or storing content on customer instructions, the customer is normally controller and we are processor. The Data Processing Agreement describes this processing. Requests concerning content belonging to a customer are referred to that customer, whom we assist under the agreement.

2. Accounts, service delivery and support

We process names, emails, telephone numbers, addresses, preferred language, business/CVR details, user and organisation memberships, chosen services, agreement acceptance and correspondence. Sources include you, your business administrator, our contact forms, incoming email and relevant public business registers, including CVR.

Purposes are account administration, delivery of ordered services, contract evidence and responding to enquiries. The basis is GDPR Article 6(1)(b) where necessary for a contract with you, and Article 6(1)(f) for business-contact administration and our legitimate interests in customer service, contract evidence and handling claims.

Account details are retained while the account and associated services are used. After termination, deletion is assessed according to closing support, contract evidence, outstanding claims and statutory retention. Support content is retained only while relevant to the specific matter or evidence of a claim; deletion requests are reviewed individually.

3. Payment, subscriptions and accounting

Stripe handles full payment-card details. We do not store full card numbers or security codes. We do process and retain billing names and addresses, company/VAT numbers, Stripe customer, subscription, invoice and payment references, amounts, currency, payment status, periods, payment dates and invoice/receipt links.

Purposes include collection, renewal, reconciliation, crediting, payment-failure handling and bookkeeping. Bases are contract performance (Article 6(1)(b)), legal accounting and tax obligations (Article 6(1)(c)) and legitimate interests in evidencing and handling payment claims (Article 6(1)(f)). Contact, invoice and payment details may be sent to Dinero for bookkeeping and reconciliation.

Accounting records are generally retained for five years from the end of the financial year they relate to. Additional information about a specific dispute is retained while a claim can be brought or the matter is ongoing. This does not require retaining all customer mail or document content as accounting material.

4. Identity checks and anti-money-laundering

For address services we process identity and business details, beneficial owners, identity evidence, and identity/AML check outcomes and reasons. Data can include verified name, date of birth, nationality, document type and number, issuing country, expiry date and relevant check results. Sources are you, the business, Didit and registers involved in checks.

Purposes are statutory customer due diligence, risk assessment and preventing money laundering. The basis is Article 6(1)(c) together with Danish anti-money-laundering law. The specific documents and steps required are shown during verification; further information may be requested. Necessary information is required to provide the address service. Document-only purchases do not require address-service identity checks.

Didit performs digital checks, and verification status can automatically affect address-service access, including suspension when the displayed deadline expires. Contact us to have an outcome or restriction reviewed by a staff member, correct information or submit more evidence. Read the information in your specific verification flow about the checks and data required there.

Statutory customer-due-diligence records are generally retained for five years after the customer relationship ends and then deleted unless other lawful retention is specifically required. Information collected for this purpose is not used for marketing.

5. Mail and digital documents on customer instructions

Mail handling involves sender/recipient details, receipt time, scanned content, delivery address, forwarding and messages. Document tools process customer answers, contracting parties, employee or contact details and the completed document, including the purchased locked version. Customers determine content and should avoid unnecessary information. Sensitive data or national identification numbers should not be entered without a specific need and lawful basis.

Content is processed and retained under customer instructions and the Data Processing Agreement. PDFs are generated through our document service hosted by Hetzner; necessary document content is sent to that service. Historical telephone messages may be processed to close or document previous agreements; the service is no longer sold.

Unused document drafts are subject to cleanup after 90 days of inactivity. Paid documents are retained so customers can retrieve the delivered version and evidence their purchase; the same draft cleanup does not automatically delete them. Customers can contact us about return or deletion. After the agreement ends, customer content follows the DPA's return/deletion rules. Statutory invoice retention is separate from the need to retain document content itself.

6. Operations, usage measurement and marketing

We process technical details, session data, error reports and usage records linked to user, organisation, tool and day to secure the service, resolve errors and understand usage. The basis is our legitimate interest in a secure, stable and usable service (Article 6(1)(f)). Error and security data is retained while needed to investigate incidents, identify recurring faults or evidence a relevant claim, and restricted to those purposes.

Umami provides statistics without analytics cookies. Optional advertising, affiliate and review technologies are enabled after marketing consent. With consent, campaign parameters, referrer and first landing page may be associated with an account to measure which channels bring customers. This separate acquisition measurement does not store advertising click IDs; advertising and affiliate providers may use their own identifiers as described in the Cookie Policy.

Newsletters and consent-based marketing rely on Article 6(1)(a). Withdraw consent through the unsubscribe link, cookie settings or by contacting us. Withdrawal does not affect the lawfulness of earlier processing. We retain necessary evidence of consent text, version, time and source, and a limited suppression record to document consent and respect opt-outs. These records are not used to restart marketing.

7. Recipients and providers

Supabase (AWS) provides the database, login and file storage, including mail scans and documents, with primary storage in Ireland. Vercel provides application hosting and server functions with runtime in Ireland. Hetzner hosts our PDF service, which processes necessary address-agreement and document content.

Stripe processes payments and may act as processor or independent controller depending on the activity. Dinero is used for accounting and invoice reconciliation. Didit provides identity and AML checks. Resend handles both outgoing email and incoming support replies, including sender/recipient, email content and delivery details.

Brevo is used for newsletters and consent status. Sentry provides error monitoring and operational security with primary data storage in Germany. After marketing consent, Meta, Google Ads, Partner-ads and Trustpilot can receive data necessary for advertising, affiliate or review functions. Trustpilot may also receive necessary contact and order details when a review invitation is sent.

Relevant carriers receive necessary delivery details for forwarding. Accountants, advisers and authorities may receive data necessary for a specific task, claim or legal obligation. We do not sell customer mail or document content.

8. Transfers and security

Primary EU storage does not mean every provider's support and other processing occurs exclusively in the EU/EEA. Providers may process relevant data in the US or other countries. Transfers must have a valid GDPR Chapter V basis, such as an applicable adequacy decision or European Commission Standard Contractual Clauses with necessary supplementary measures. Contact us for details of the specific mechanism and a copy of relevant safeguards.

We use access controls, private file storage and encrypted connections. Access to a customer's mail scan requires ownership checks before a time-limited link can be issued. Staff and provider access is limited to the task. The DPA describes safeguards for customer content in more detail.

9. Your rights and contact

Subject to GDPR conditions, you may request access, correction, deletion, restriction and portability. You may object to processing based on legitimate interests and always to direct marketing. You may withdraw consent. Deletion is not unconditional where, for example, statutory retention or a legal claim requires the data.

Write to kontakt@dinfirmaadresse.dk. We may request information needed to verify your identity and locate relevant processing. You may complain to the Danish Data Protection Agency, Carl Jacobsens Vej 35, 2500 Valby, Denmark, or through www.datatilsynet.dk. Policy changes are published here; affected customers receive appropriate information about material changes.