Final logo v.2. 28-01-25.svg
  • Prices
  • Security
  • About us
    • About us
    • Contact us
  • Blog
  • Municipalities
    • Danish
Contact us
Promte
    • Danish
  • Prices
  • Security
    • About us
    • Contact us
  • Blog
  • Municipalities
Contact us
Privacy PolicyTerms
Open in Promte Docs

Last updated: 15 July 2026

This Privacy Policy explains how Promte ApS processes personal data when you visit our website, contact us, subscribe to our newsletter, have a customer or supplier relationship with us, or use a Promte account. The Policy also explains the difference between situations in which Promte is the data controller and situations in which we process data solely on behalf of a customer.

1. Data Controller and Contact Details

Promte ApS is the data controller for the processing activities described in section 3.

Promte ApS

Company registration no. (CVR): 44041405

Kanonbådsvej 2

1437 Copenhagen K

Denmark

Email: contact@promte.com

Telephone: +45 28 76 22 98

You may use the contact details above if you have questions about this Policy or wish to exercise your rights.

2. When Is Promte a Data Controller and When Is Promte a Data Processor?

Promte is the data controller when we determine the purposes and means of processing personal data. This applies in particular to the operation and security of promte.com, handling enquiries, newsletters, administration of customer and supplier relationships, and the administration and security of Promte accounts.

As a general rule, Promte is a data processor when a municipality, company or other organisation uses the Promte platform to process personal data for its own purposes. In these cases, the customer is the data controller, and Promte processes data only on the customer's documented instructions and in accordance with the applicable data processing agreement. The data controller customer's own privacy policy applies to this processing.

If your enquiry concerns content processed in the Promte platform by your employer, municipality or another organisation, you should therefore generally contact that organisation. Promte assists the customer in responding to requests where necessary.

3. Processing Activities for Which Promte Is the Data Controller

3.1 Visits to Our Website

When you visit promte.com, we may process technical information about your device and your visit, including your IP address, time of access, browser and device type, operating system, pages visited, referring page, approximate geographical area, and information about errors, response times and security incidents.

The purposes are to provide the website, protect it against misuse and attacks, troubleshoot errors, maintain necessary operational and security logs, and compile aggregated statistics about the website's performance and use.

The legal basis is Article 6(1)(f) of the General Data Protection Regulation (GDPR). Promte's legitimate interests are to provide a functional and secure website, prevent misuse and improve the website's technical quality. Where processing requires consent, the processing is instead based on Article 6(1)(a).

Ordinary server and security logs are normally retained for up to 90 days. Data may be retained for longer where necessary to investigate or document a specific security incident. Documentation concerning personal data breaches may be retained for up to five years.

3.2 Cookies, Consent and Analytics

We use necessary cookies and similar technologies to make the website and the consent solution work. Among other things, the necessary cookies record your cookie preferences and a consent ID. Your preferences are normally stored for up to 180 days, after which you will be asked to make a new choice.

We use a technical analytics service for aggregated visitor and performance statistics. The service does not use third-party cookies and is designed not to link aggregated measurements to an identified visitor. A technical visitor identifier expires after 24 hours. The processing is based on our legitimate interest in measuring and improving the website's operation and performance, pursuant to Article 6(1)(f).

If you consent to analytics cookies, we use an external analytics and tag management service. The service may receive information about pages visited, events on the website, time of access, device and browser information, the referring page, approximate geographical area, and a cookie or device identifier. Upon receipt, the IP address may be used to determine an approximate geographical area, but it is not logged or stored in the analytics service. User and event data are retained for up to 14 months. Aggregated reports may be retained for longer where they cannot be linked to a particular visitor.

Optional analytics and marketing technologies are used only on the basis of your consent, pursuant to Article 6(1)(a) and the Danish cookie rules. You may change or withdraw your consent at any time via the Cookie Settings link on the website. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

The current list of individual cookies, their providers, purposes and lifetimes is available in the cookie settings on the website.

3.3 Enquiries, Meeting Bookings and Demo Requests

When you contact us by email, telephone, contact form or meeting booking, we process the information you provide. This may include your name, business contact details, organisation, job title, telephone number, the content of your enquiry and information about subsequent correspondence or action.

The purposes are to respond to your enquiry, arrange a meeting or demonstration, prepare a quotation, and follow up on a potential or existing business relationship.

The processing is based on Article 6(1)(f), as we have a legitimate interest in responding to relevant enquiries and developing our business relationships. If you are personally a party to an agreement, or the processing is necessary in order to take steps at your request prior to entering into an agreement, the legal basis may be Article 6(1)(b).

Enquiries that do not result in a customer relationship are normally deleted no later than 12 months after the matter has been concluded. If the enquiry results in a customer relationship or is needed to document an agreement or a specific claim, the relevant data is retained in accordance with section 3.5.

Do not send us special categories of personal data, Danish civil registration numbers (CPR numbers) or confidential information through an ordinary contact form or email unless we have expressly requested it and provided a secure channel.

3.4 Newsletters and Other Electronic Marketing

When you subscribe to a newsletter, we process your email address and, where applicable, your name, organisation, selected interests, the time and method of subscription, and evidence of your consent. Where the feature is enabled, we may also process delivery information and information about opens and clicks to assess whether the content is relevant and has been delivered correctly.

The purposes are to send the newsletter and marketing you have requested, manage your subscription and document that we have valid consent. The processing is based on your consent pursuant to Article 6(1)(a) and is carried out in accordance with the Danish Marketing Practices Act rules on electronic marketing.

You may unsubscribe at any time using the link in each email or by writing to contact@promte.com. Once you unsubscribe, we will stop sending communications. We may retain limited evidence of consent and unsubscription for up to two years after the consent was last relied upon, so that we can demonstrate compliance and ensure that you are not subscribed again without a new legal basis.

Newsletter forms are provided through an external newsletter service. When a form is displayed, the provider may receive necessary technical information, including IP address and browser information, in order to deliver and protect the form. This limited technical processing is based on Article 6(1)(f) and our legitimate interest in providing a secure subscription form. Non-essential cookies or similar technologies may be activated only with the relevant consent. Subscription and subsequent marketing take place only following your active choice.

3.5 Customer, Contract and Supplier Administration

If you are a contact person at a customer, prospective customer, business partner or supplier, we may process your name, business contact details, job title and organisation, as well as correspondence, meeting notes, agreement information, invoice information, and information about services provided or received.

The purposes are to enter into and perform agreements, administer the relationship, provide support, issue invoices, maintain accounting records, process payments, and document rights and obligations.

The processing is based on Article 6(1)(f), as Promte and the organisation you represent have a legitimate interest in administering the relationship. If you are personally a party to the agreement, Article 6(1)(b) may apply. Data that we are legally required to process is processed under Article 6(1)(c), including in connection with the Danish Bookkeeping Act.

Ordinary contact and agreement information is deleted when it is no longer necessary. Data needed to handle a specific contractual or legal claim may be retained for as long as the claim may be asserted. Accounting records are retained for the current financial year and a further five years in accordance with the Danish Bookkeeping Act.

3.6 Account, Access, Support and Security Administration

When you are given access to a Promte solution, we may, as an independent data controller, process limited data necessary for account and security administration. This may include your name, email address, organisation, user ID, roles and permissions, login and authentication information, login times, technical events, access logs, and information included in a support enquiry.

The purposes are to create and administer the account, control access, prevent misuse, protect systems, document security incidents and provide support. The processing is based on Article 6(1)(b) where it is necessary for an agreement with you, and otherwise on Article 6(1)(f). Our legitimate interests are secure operation, access control, documentation and support.

Account information is retained while the account is active and is subsequently deleted or anonymised when no longer necessary. Ordinary access and security logs are normally retained for up to 12 months. Logs and correspondence forming part of a specific security or support matter may be retained for longer where necessary to conclude and document the matter.

4. Processing on Behalf of Promte's Customers

When a customer uses the Promte platform for its own purposes, the customer is the data controller and Promte is the data processor. The customer determines the purposes, legal basis, which data may be processed, who may use the solution, and how long the data is to be retained within the terms of the agreement.

Depending on the customer's configuration and use, the Promte platform may process:

  • identity and account data, including name, email address, user ID, organisation, roles and login information;
  • user queries, chat messages, responses, timestamps, feedback and assistant configurations;
  • documents, data sources, text extracts, embeddings and other context provided by the customer or user;
  • audio recordings, transcriptions, speaker diarisation, meeting minutes and subsequent queries, if the customer uses the meeting features; and
  • activity, operational and security logs necessary to provide and protect the solution.

Promte processes this data only on the customer's documented instructions and for the purpose of providing, securing, supporting and maintaining the solution ordered by the customer. Customer data is not used for Promte's own marketing or other unrelated purposes. Any customisation or improvement of a customer's assistant is carried out solely for that customer's solution and within the scope of the customer's instructions.

Support access is granted only to authorised staff with a specific work-related need and normally at the customer's request. Access is limited to what is necessary and ends when the support task has been completed.

Unless otherwise agreed or instructed by the customer, personal data in the platform is retained for up to three years from the user's interaction. Data may be deleted earlier on the customer's instructions and will in all cases be deleted no later than one month after termination of the contract. The customer may also request annual deletion of its content.

5. Recipients and Service Providers

We disclose or entrust personal data to others only where this is necessary, lawful and limited to the relevant purpose. Service providers that process data on our behalf are subject to written data processing agreements and confidentiality and security requirements.

5.1 Sub-processors for Customer Data in the Promte Platform

In the standard configuration described in Promte's data processing agreement, we use sub-processors in the following categories:

  • a Danish hosting and operations provider that hosts Promte's backend, databases, embeddings, uploaded documents and logs, and provides storage, access management, activity logging, backup and deletion on instruction; and
  • a European cloud and AI service provider that supplies embedding and language models and, in doing so, processes user queries and relevant context to generate embeddings and text.

Processing in the standard configuration takes place within the EU. The current and exhaustive list of sub-processors, their processing locations and tasks is set out in Appendix B to the customer's data processing agreement. Customers are notified of intended changes in accordance with the data processing agreement.

5.2 Service Providers Used for Promte's Own Purposes

Where Promte is the data controller, we also use service providers for other, separate purposes. These providers are not sub-processors listed in customers' Appendix B because they do not process customers' platform content as part of the platform service described. They may include:

  • providers of hosting, technical distribution, web analytics and website performance monitoring;
  • providers of consent-based analytics and tag management;
  • providers of subscription forms and newsletter distribution; and
  • providers of email, communications, bookkeeping, audit and legal advice.

These providers receive only the data necessary for their specific task and may process it only on our instructions, unless they act as independent data controllers under applicable law.

We may also disclose data to public authorities, courts or others where we are legally required to do so or where this is necessary to establish, exercise or defend a legal claim.

We do not sell personal data.

6. Processing Outside the EU/EEA

Customer data in the standard configuration described in the data processing agreement is processed in Denmark, Sweden and France. Promte does not transfer such customer data to a third country without the customer's explicit documented instructions and a valid transfer mechanism under Chapter V of the GDPR.

In connection with the operation and analysis of our public website, our service providers or their sub-processors may process technical data in countries outside the EU/EEA, including the United States. If a recipient country has not been recognised by the European Commission as providing an adequate level of protection, we base the transfer on the European Commission's Standard Contractual Clauses and relevant supplementary measures. Where a recipient is covered by a valid adequacy decision, the transfer may be based on that decision.

Newsletter subscriber data is generally stored in the EU/EEA. If a service provider or authorised sub-processor transfers personal data to a third country, the transfer must be based on a valid mechanism under Chapter V of the GDPR.

You may contact us if you would like further information about the relevant transfer mechanism or a copy of the essential safeguards.

7. Information Security

Promte implements technical and organisational measures designed to ensure a level of security appropriate to the nature and risk of the processing. These measures include:

  • encryption in transit using TLS and encryption of stored customer data using AES-256;
  • role-based access control, the need-to-know principle and ongoing access reviews;
  • multi-factor authentication for administrative access;
  • secure management and rotation of keys and other secrets;
  • logging, monitoring and procedures for managing security incidents;
  • separation of user histories and customer environments;
  • managed work devices and encrypted remote access;
  • testing, change management, backup, recovery and secure deletion procedures; and
  • confidentiality obligations, training and regular assessments of security measures and service providers.

Promte also has features that can warn about possible personal data in text and uploads. If a feature requires material that may contain personal data to be sent to an external AI service, this must take place within the customer's configuration and instructions and with the necessary permission from the user or customer.

No security measure can eliminate all risk. Where a personal data breach is suspected, we investigate, contain and document the incident and notify the data controller customer without undue delay and, where possible, within 24 hours.

8. Where Does the Data Come From?

We generally receive data directly from you. We may also receive business contact details from the organisation you represent, a colleague, publicly available business sources, or our technical service providers in connection with operation and security.

Where Promte is the data processor, we receive data from the data controller customer, the customer's users, the customer's integrated data sources, or the individuals who use the customer's solution.

9. Is It Mandatory to Provide Data?

Subscribing to newsletters and accepting optional cookies is voluntary. If you do not provide the data necessary to respond to an enquiry, create an account, enter into an agreement or comply with legal requirements, we may be unable to provide the requested service.

10. Your Rights

Where Promte is the data controller, depending on the circumstances, you have the right to:

  • obtain access to the personal data we process about you;
  • have inaccurate or incomplete data rectified;
  • have data erased;
  • have processing restricted;
  • object to processing based on a legitimate interest;
  • receive data in a structured, commonly used and machine-readable format and have it transmitted where the conditions for data portability are met; and
  • withdraw consent at any time.

These rights are not absolute. For example, we may be legally required to retain certain data or entitled to process it in order to establish, exercise or defend a legal claim.

You always have the right to object to direct marketing. If you object, we will stop processing your data for this purpose.

Contact us at contact@promte.com to exercise your rights. We may request information necessary to verify your identity. As a general rule, we respond to your request without undue delay and no later than one month after receipt. In exceptional cases, the deadline may be extended by up to two months; if so, we will inform you of the extension and the reasons for it before the end of the first month.

If your request concerns customer data that Promte processes solely as a data processor, we will forward the request to or refer you to the data controller customer, unless otherwise required by the customer's instructions.

11. Automated Decision-Making

In its capacity as an independent data controller, Promte does not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you.

The Promte platform may generate AI-based responses, summaries, transcriptions and other content. Where a customer uses such features, the customer is responsible for the purpose, legal basis, necessary human oversight, and ensuring that output is not used for unlawful automated decisions. AI-generated content should be reviewed by a human before being used as a basis for decisions about individuals.

12. Complaints to the Danish Data Protection Agency

You are welcome to contact us first if you are dissatisfied with our processing of your personal data. You also have the right to lodge a complaint with:

The Danish Data Protection Agency (Datatilsynet)

Carl Jacobsens Vej 35

2500 Valby

Denmark

Telephone: +45 33 19 32 00

Email: dt@datatilsynet.dk

Website: www.datatilsynet.dk

13. Changes to This Privacy Policy

We update this Policy when our processing activities, service providers, solutions or applicable rules change. The current version is published at promte.com/privacy-policy together with the date on which it was last updated. If a change materially affects processing that already concerns you, we will notify you separately where relevant and reasonably practicable.

Final logo 28-01-25.svg

Sign up for our newsletter

Microsoft for startups (1).svgInnovation Foundation Denmark (1).svg
  • Resources

    • Blog
    • Documentation
    • Privacy Policy
    • Terms of Use
  • Company

    • Contact
    • Prices
    • About Promte
    • Security & GDPR
    • LinkedIn

How would you like to continue?

Log in with existing user (municipality or organisation)Create user or log in to the open solution
Close