1. Introduction
Advaice ("Company," "we," "us," or "our") is committed to respecting your privacy and safeguarding the personal information you share with us when you use our website, applications, and any related online services (collectively, the "Services"). This Privacy Policy describes how we collect, use, disclose, and protect your personal data, as well as the rights you may have regarding your information.
This Privacy Policy is intended to help ensure compliance with applicable privacy laws, including the EU General Data Protection Regulation (GDPR) and Danish data protection legislation. If you have any questions, please contact us at privacy@advaice.dk.
By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with these terms, please do not use the Services.
2. Scope
This Privacy Policy applies to personal information we collect through the Services, as well as through any related interactions (such as emails or customer support) that reference or link to this policy. Our Services may include links to third-party websites or integrate with third-party tools — these third parties have their own privacy practices, and we do not control or assume responsibility for their actions.
3. Information We Collect
A. Information You Provide Directly
- Account Registration: Name, email address, and password.
- Profile Information: Additional details you may provide, such as job role, industry, competence level, and response preferences.
- Communications: Content of messages you send to us via email or support channels.
- User Content: Documents, meeting materials, and other content you upload or submit to receive AI-powered advisory responses.
B. Information Collected Automatically
- Usage Data: Information about your interaction with the Services, such as features used and time spent.
- Device & Log Information: IP address, browser type, operating system, and timestamps.
- Cookies: We use only essential cookies required for the Services to function (e.g., session authentication). We do not use tracking, analytics, or advertising cookies.
C. Information From Third Parties
If you register or log in using a third-party service (e.g., Google), we may receive certain profile information from that third party in accordance with their privacy policy and your account settings.
4. How We Use Your Information
- Service Provision: To create and maintain your account, operate the Services, and generate AI-powered advisory board sessions and responses.
- Personalization: To tailor advisory responses based on your profile preferences and uploaded materials.
- Communication: To respond to inquiries and send transactional messages (e.g., password resets, service announcements).
- Security & Compliance: To protect the integrity of our Services, detect and prevent fraud or abuse, and comply with legal obligations.
- Improvement: To analyze usage patterns and improve the Services.
5. Legal Bases for Processing
We rely on the following legal bases under the GDPR:
- Performance of Contract (Art. 6(1)(b)): Processing necessary to provide the Services you have requested under our Terms of Service.
- Legitimate Interests (Art. 6(1)(f)): Processing necessary for our legitimate interests, such as improving user experience and securing the Services, where these interests are not overridden by your rights.
- Legal Obligations (Art. 6(1)(c)): Processing necessary to comply with legal obligations.
6. AI Data Processing
Advaice uses third-party AI providers (OpenAI, Anthropic) to generate advisory responses. When you use AI features:
- Your content is sent to these providers solely for generating responses.
- These providers act as data processors under GDPR and process data in accordance with their respective data processing agreements.
- AI-generated responses are provided for informational and advisory purposes only and should not be construed as professional, legal, financial, or medical advice.
- You may restrict AI processing of your data at any time through your account settings.
7. Disclosure of Your Information
We may share personal information in the following circumstances:
- Service Providers: Third-party companies that facilitate the Services (e.g., hosting, AI providers, payment processors). These parties process data on our behalf and are contractually obligated to protect it.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction.
- Legal Compliance: When required by law, court order, or to protect our rights, property, or safety.
- Aggregated Data: We may share data that has been aggregated or de-identified so it cannot be associated with a specific individual.
8. International Data Transfers
Advaice is based in Denmark. Your personal data may be transferred to, processed, and stored in countries outside the EU/EEA (e.g., the United States for AI processing). We ensure adequate protection through Standard Contractual Clauses (SCCs) and other appropriate safeguards as required by GDPR Chapter V.
9. Data Retention
We retain personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy or as required by law. When retention is no longer required, we will securely delete or anonymize your data. You may request deletion of your account and associated data at any time.
10. Security Measures
We implement administrative, technical, and physical safeguards to protect your personal data, including:
- AES-256-GCM encryption of documents at rest
- Argon2id password hashing
- TLS encryption for all data in transit
- Role-based access controls
- Regular security reviews and monitoring
No method of transmission or storage is completely secure. While we strive to protect your data, we cannot guarantee absolute security.
11. Children's Privacy
Our Services are intended for users who are at least 18 years old, or at least 16 years old with parental or guardian consent. We do not knowingly collect personal information from individuals under 13. If we become aware that a child under 13 has provided personal information, we will delete such information and terminate the account.
12. Your Rights
Under the GDPR and applicable Danish law, you have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate data through your account settings or by contacting us.
- Right to Erasure: Request deletion of your personal data, subject to legal exceptions.
- Right to Restrict Processing: Request that we limit processing of your personal data in certain circumstances.
- Right to Data Portability: Request a machine-readable copy of your personal data.
- Right to Object: Object to processing based on legitimate interests.
To exercise these rights, use the relevant features in your account settings or contact us at privacy@advaice.dk. You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) at dt@datatilsynet.dk.
13. Managing Your Information
- Account Settings: You can update your name, email, password, and profile preferences in your account settings.
- Data Export: You can export your data in a machine-readable format from your account settings.
- Account Deletion: You can request deletion of your account and all associated data.
- Contact: For any difficulties, email us at privacy@advaice.dk.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated policy on our website or through the Services. Your continued use of the Services after changes take effect signifies your acceptance of the revised policy.
15. Contact Us
If you have any questions about this Privacy Policy or our privacy practices:
Advaice
Email: privacy@advaice.dk