Legal
Privacy Policy
This policy explains what personal data Trevantodes collects, why we collect it, the legal basis we rely on, how long we keep it, who we share it with, and the rights you have. It is written to be read, not to be survived.
- Version
- 1.0
- Effective from
- Last updated
1. Who is responsible for your data
The data controller for the processing described in this policy is:
| Legal entity | Trevantodes |
|---|---|
| Company registration number | 36709294 |
| Country of registration | Denmark |
| Registered address | Mørdrupvej 125, Mørdrup, 3060 Espergærde, Denmark |
Data protection officer
We have assessed our processing against Article 37 GDPR and have concluded that we are not required to appoint a data protection officer: we are not a public authority, our core activities do not consist of large-scale systematic monitoring of individuals, and we do not process special category data at scale. Privacy queries are handled directly by our team via our Contact page. If a DPO is appointed in future, this section will name them and their contact details.
2. What this policy covers
This policy covers personal data we process as a controller — that is, where we decide why and how the data is used. In practice that means:
- visitors to trevantodes.com;
- people who contact us by form, email or telephone;
- contact persons at prospective, current and former client organisations;
- contact persons at suppliers and partners;
- people who apply to work with us.
It does not cover personal data we handle on behalf of a client — for example when we work inside a client's advertising accounts, analytics or CRM. In those situations the client is the controller and we act as a processor under a written data processing agreement. See section 9.
3. Categories of personal data we collect
We collect as little as we can get away with, and we do not buy contact lists. The categories below are exhaustive for our own processing.
3.1 Data you give us
- Identity and contact data — name, work email address, telephone number, employer or brand name, job title.
- Enquiry content — the budget range you select and the free-text description of what you are trying to fix, plus anything else you choose to write to us.
- Consent records — the fact that you ticked the consent box on our contact form, the wording you agreed to, and the date and time.
- Contract and billing data — for clients: company details, billing address, VAT number, purchase order references, named contacts, and bank or payment reference data where relevant.
- Correspondence — emails, meeting notes, call summaries and shared documents relating to an enquiry or engagement.
- Application data — where you apply to work with us: CV, covering note, portfolio links and interview notes.
3.2 Data collected automatically
- Server log data — IP address, date and time of request, requested URL, HTTP status, referring URL, user-agent string. This is generated by our hosting infrastructure and is needed to serve pages and to detect abuse.
- Consent state — a single first-party cookie recording your cookie choices. It contains no identifier and no personal data. See the Cookie Policy.
- Analytics data, only if you consent — aggregated statistics about pages viewed, approximate region, device category and referral source. Nothing analytical runs unless you switch it on.
- Marketing measurement data, only if you consent — whether a visit followed one of our own advertisements, so we can judge whether our own marketing works.
3.3 Data we do not collect
We do not collect special category data under Article 9 GDPR (such as health, religious belief, political opinion, trade union membership or biometric data), we do not process criminal offence data under Article 10, and we do not knowingly collect data from children. Please do not send us special category data; if you do, we will delete it.
4. Purposes and legal bases under Article 6
Every processing activity we carry out is listed below with the Article 6(1) legal basis it relies on. Where we rely on legitimate interests, the balancing test we performed is summarised in the same row.
| Activity | Purpose | Legal basis | Notes |
|---|---|---|---|
| Serving the website | Delivering pages, maintaining security and availability, preventing abuse | Art. 6(1)(f) — legitimate interests | Our interest in operating a functioning, secure website. Log data is minimal, short-lived and never used to profile visitors. |
| Storing your cookie choice | Remembering whether you accepted or rejected optional cookies | Art. 6(1)(f) — legitimate interests, and strictly necessary under ePrivacy rules | Not remembering your choice would mean asking again on every page, which is worse for you. |
| Optional analytics cookies | Understanding which pages are useful so we can improve them | Art. 6(1)(a) — consent | Off by default. Withdraw at any time via . |
| Optional marketing cookies | Measuring whether our own campaigns produce enquiries | Art. 6(1)(a) — consent | Off by default. Withdraw at any time via . |
| Responding to your enquiry | Reading your message, replying, arranging and holding a call | Art. 6(1)(a) — consent, and Art. 6(1)(b) — steps prior to a contract | The consent box on the form records your permission; where the enquiry concerns a possible engagement, Art. 6(1)(b) also applies. |
| Providing services to clients | Delivering the engagement, project management, reporting, support | Art. 6(1)(b) — performance of a contract | Applies to the named contacts at a client organisation. |
| Invoicing and accounting | Issuing invoices, collecting payment, keeping statutory books | Art. 6(1)(c) — legal obligation, and Art. 6(1)(b) | Danish bookkeeping legislation requires accounting material to be retained; see section 6. |
| Client relationship communication | Sending service updates and relevant commercial information to existing clients | Art. 6(1)(f) — legitimate interests | Limited to existing business contacts, always relevant to services already bought, and every message carries a one-click opt-out. |
| Case studies and references | Publishing results and naming a client | Art. 6(1)(a) — consent | Never published without the client's specific written approval of both figures and wording. |
| Recruitment | Assessing an application | Art. 6(1)(a) — consent, and Art. 6(1)(b) — pre-contractual steps | We keep unsuccessful applications only with the applicant's agreement. |
| Legal claims and compliance | Establishing, exercising or defending legal claims; responding to lawful requests | Art. 6(1)(f) — legitimate interests, and Art. 6(1)(c) — legal obligation | Used only where a dispute or a lawful request actually arises, and limited to what is relevant to it. |
Where we rely on consent, you may withdraw it at any time under Article 7(3). Withdrawal does not affect the lawfulness of processing carried out before you withdrew.
5. Cookies and similar technologies
No cookie other than the strictly necessary consent cookie is set before you make a choice, and no analytics or marketing script is loaded before you allow it. The Cookie Policy lists every cookie by name, purpose, duration and category, and explains how to withdraw consent.
Our contact page includes a map. It stays a static placeholder until you press Load map, because loading it would disclose your IP address to Google and may set Google cookies. That is your decision to make, not ours.
6. How long we keep personal data
We keep personal data only as long as it serves the purpose it was collected for, or as long as the law requires. When a period expires the data is deleted, or irreversibly anonymised where we want to keep aggregate statistics.
| Data | Retention period | Trigger for deletion |
|---|---|---|
| Enquiries that do not become engagements | 24 months | 24 months from our last substantive exchange with you |
| Consent records for enquiries | 24 months, or 5 years where the enquiry became a contract | Kept as evidence of the lawfulness of processing, then deleted with the underlying record |
| Client contract and project records | Duration of the engagement plus 5 years | End of the calendar year in which the limitation period for claims expires |
| Invoices and accounting material | 5 years from the end of the financial year to which they relate | Statutory bookkeeping retention under Danish law; deleted in the first purge after expiry |
| Email correspondence with clients | Up to 5 years | Aligned with the contract record it belongs to |
| Server and security logs | Up to 90 days | Automatic rotation; retained longer only for a specific incident under investigation |
Consent cookie (trv_consent) |
180 days | Expires automatically; you can clear it in your browser at any time |
| Analytics data, if consented | Up to 14 months | Automatic expiry in the analytics tool; aggregate reports may be kept without personal data |
| Unsuccessful job applications | 6 months, or up to 12 months with your agreement | Expiry of the agreed period, or immediately on request |
| Suppression list for opt-outs | Indefinite, minimal | Retained deliberately: we keep an email address on a do-not-contact list so we honour your objection |
7. Who we share personal data with
We do not sell personal data and we do not share it for anyone else's marketing. We do use a small number of service providers who process data on our instructions under Article 28 data processing agreements. The categories are:
| Category | Provider | What they process | Role |
|---|---|---|---|
| Website hosting and CDN | Server log data, IP addresses | Processor | |
| Contact form handling | Everything you submit through the enquiry form | Processor | |
| Email and productivity | Correspondence, calendar entries, shared documents | Processor | |
| CRM and pipeline management | Contact details, enquiry history, engagement notes | Processor | |
| Website analytics, if consented | Aggregated usage data, truncated IP address | Processor | |
| Advertising platforms, if consented | Campaign measurement data relating to our own marketing | Independent or joint controller, depending on the platform | |
| Accountant and auditor | Professional advisers engaged by us | Invoices and accounting material | Independent controller under professional obligations |
| Legal advisers and authorities | Only where a dispute or lawful request arises | Whatever is strictly relevant | Independent controller |
We will provide the current, named list of processors on request. Sub-processor changes are governed by our agreements with each provider.
8. International transfers
We prefer providers that keep data inside the European Economic Area. Some of the services listed above are provided by organisations established outside the EEA, or process data outside the EEA. Where that happens we rely on one of the following safeguards under Chapter V GDPR:
- an adequacy decision under Article 45 — including the EU–US Data Privacy Framework, where the provider is certified under it;
- the European Commission's Standard Contractual Clauses under Article 46(2)(c), together with a transfer impact assessment and, where needed, supplementary technical measures such as encryption in transit and at rest and pseudonymisation;
- your explicit consent under Article 49(1)(a), where no other route is appropriate and the transfer is occasional.
You can ask us for a copy of the relevant transfer mechanism and, where applicable, the transfer impact assessment, by writing to us via our Contact page. We may redact commercially confidential terms.
9. When we act as a processor for our clients
A large part of our work involves operating inside systems that belong to a client: their advertising accounts, analytics properties, tag managers, CRM and customer data platforms. Personal data of the client's own customers and prospects may be visible to us there.
In those situations the client is the controller and we are a processor. We act only on the client's documented instructions and under a written data processing agreement that covers confidentiality, security measures, sub-processor approval, assistance with data subject requests, breach notification and deletion or return of data at the end of the engagement.
If you are a customer of one of our clients and you want to exercise your rights over data held in their systems, please contact that organisation directly — they are the controller and only they can decide the outcome. If you contact us instead, we will forward your request to them without undue delay and tell you that we have done so.
10. Automated decision-making and profiling
We do not make decisions about you that are based solely on automated processing and that have legal effects or otherwise significantly affect you, within the meaning of Article 22(1) GDPR. Enquiries are read and answered by a person.
Advertising platforms we use for our own marketing do apply their own algorithmic targeting. That processing is governed by those platforms' own terms and privacy notices, and it only involves you if you have consented to marketing cookies.
11. Your rights
Under the GDPR you have the following rights in relation to your personal data. They are free to exercise, and exercising them will never affect how we treat you commercially.
- Right of access — Article 15
- Confirmation of whether we process your data, a copy of it, and information about purposes, recipients, retention and the source.
- Right to rectification — Article 16
- Correction of inaccurate data and completion of incomplete data.
- Right to erasure — Article 17
- Deletion where the data is no longer needed, where you withdraw consent and no other basis applies, where you successfully object, or where processing was unlawful. Statutory retention — for example accounting records — can override this, and we will tell you if it does.
- Right to restriction of processing — Article 18
- A freeze on processing while an accuracy dispute or an objection is being resolved, or instead of erasure where you need the data preserved for a legal claim.
- Right to data portability — Article 20
- Where processing is based on consent or contract and is carried out automatically, a copy of the data you provided in a structured, commonly used, machine-readable format, and transmission to another controller where technically feasible.
- Right to object — Article 21
- An objection to processing based on legitimate interests, which we will honour unless we can demonstrate compelling grounds that override your interests. An objection to direct marketing is absolute: we stop immediately, with no balancing test.
- Rights in relation to automated decisions — Article 22
- Not to be subject to solely automated decisions with legal or similarly significant effects. As set out in section 10, we do not make such decisions.
- Right to withdraw consent — Article 7(3)
- Withdrawal at any time, as easily as it was given. For cookies, use . For anything else, email us.
- Right to be informed of a data breach — Article 34
- Where a breach is likely to result in a high risk to your rights and freedoms, we will tell you without undue delay and explain what happened and what to do.
How to exercise a right
Write to us via our Contact page with "Data request" in the subject line and tell us which right you are exercising. You do not need to use a particular form or cite an article number.
- We respond within one month of receiving the request. If it is complex we may extend by up to two further months, and we will tell you within the first month if we do.
- We may ask for information to confirm your identity, but only what is necessary and only where we have genuine doubt.
- Requests are free. We may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive — and we will explain our reasoning if that ever happens.
12. Complaining to a supervisory authority
If you think we have handled your personal data unlawfully, please tell us first — we would rather fix it than argue about it. That is not a precondition, however, and you have an unconditional right under Article 77 GDPR to lodge a complaint with a data protection supervisory authority.
The competent authority for our processing is:
| Supervisory authority | Datatilsynet (the Danish Data Protection Agency) |
|---|---|
| Country | Denmark |
You may also complain to the supervisory authority in the EU or EEA country where you live or work, or where you believe the infringement took place. You additionally have the right under Article 79 to an effective judicial remedy before a court.
13. How we protect personal data
We apply technical and organisational measures appropriate to the risk, as required by Article 32 GDPR. Concretely:
- TLS encryption for all traffic to this website and to the systems we use;
- encryption at rest on the devices and storage we control;
- multi-factor authentication on every business system that supports it;
- a password manager and unique credentials per service, never shared by email or chat;
- access granted on a least-privilege basis and reviewed when roles change;
- immediate revocation of access when an engagement ends;
- written data processing agreements with every processor;
- a documented breach procedure, including notification to the supervisory authority within 72 hours where Article 33 requires it;
- a strong preference for not collecting data we do not need, which remains the most reliable security control available.
No system is perfectly secure. If you believe you have found a vulnerability in this site, please tell us via our Contact page; we will not pursue researchers who report in good faith and do not access other people's data.
14. Children
Our services are sold to businesses and this website is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Changes to this policy
We update this policy when our processing changes or when guidance from regulators makes something clearer. The version number and both dates at the top of the page always reflect the current text.
If a change materially affects how we use data we already hold about you, we will tell you directly — by email where we have your address — before the change takes effect, and where the change requires consent we will ask for it again rather than assume it.
16. Contact
For anything in this policy, including data subject requests:
TrevantodesMørdrupvej 125, Mørdrup
3060 Espergærde
Denmark
Related pages: Contact · Cookie Policy · Terms of Service · Imprint