Privacy Policy
Last updated: 12 August 2026
This privacy policy explains how Payper ApS, CVR no. 46639766 ("Payper", "we", "us") collects, uses and protects personal data in accordance with the EU General Data Protection Regulation (GDPR) and Danish law.
It covers our website, app, support, sales and marketing. When our customers enter information about their own end customers in the Platform, the customer is generally the controller and Payper is the processor. That relationship is governed separately by the Data Processing Agreement and the Terms of Service.
1. Controller
Payper ApS
CVR no. 46639766
Hundstrupvej 18, 5750 Ringe, Denmark
Email: info@payper.dk
Phone: +45 32 35 88 08
Payper has not appointed a separate DPO. Privacy requests go to info@payper.dk.
2. Who is covered?
- Visitors to payper.dk and related sites
- Prospective customers and contact persons
- Customer administrators and Platform users
- Suppliers and partners
- Other people who contact us
This policy does not cover end-customer personal data for which our customers are controllers, beyond describing Payper's processor role.
3. What data do we collect?
- Identity and contact data: name, email, phone, address
- Company data: company name, CVR, industry, role/title
- Account data: login, profile, settings, permissions
- Billing and subscription data: plan, modules, payment status, billing address (card data is handled by Stripe)
- Communication data: emails, support messages, meeting notes, call logs
- Usage and technical data: IP address, device, browser, logs, cookies, clicks and page views
- Integration data: if connected voluntarily, e.g. Google Calendar IDs/event IDs, accounting system IDs
4. Purposes and legal bases
4.1 Delivering contracted services
Create and manage accounts, provide the Platform, process payments, support and onboarding.
Legal basis: contract (Art. 6(1)(b)) and legitimate interests for B2B contact persons (f).
4.2 Operations, security and improvement
Bug fixing, logs, security monitoring, statistics and product development on anonymised/aggregated level.
Legal basis: legitimate interests (f) and legal obligation regarding security (c / GDPR Art. 32).
4.3 Marketing and sales
Respond to enquiries, book demos, send relevant B2B communication. Newsletters and non-essential marketing use consent or applicable marketing rules, with opt-out.
Legal basis: consent (a) and/or legitimate interests (f).
4.4 Legal obligations
Bookkeeping, statutory retention, authority requests and legal claims.
Legal basis: legal obligation (c) and legitimate interests (f).
5. Sources
- You (forms, signup, support, meetings)
- Your company (admin creates users)
- Public sources (e.g. CVR) where relevant for B2B sales
- Technical systems (cookies, logs)
- Integration partners you connect
6. Sharing and processors
We do not sell personal data. We share data with vendors that help us deliver the Services, including:
- Supabase (database and authentication)
- Stripe (payments)
- Resend (email)
- Twilio (SMS)
- Cloudflare (CDN/security)
- Hetzner/Coolify (hosting in Germany)
- Google (calendar integration, only if connected)
- OpenAI/Anthropic (AI features in the Platform)
- Dinero/Billy (accounting integrations, only if connected)
Processors may only process data on our instructions and under processor agreements where required.
7. Transfers outside the EU/EEA
Primary hosting is in Germany (EU). Some vendors may process data outside the EU/EEA. Where they do, we use lawful transfer tools, typically EU Standard Contractual Clauses and/or adequacy decisions (e.g. EU-US Data Privacy Framework where relevant).
8. Retention
- Account data is kept while the agreement is active
- After termination, data can generally be retrieved for up to 3 months, then deleted unless otherwise agreed or law requires longer retention
- Inactive accounts may be deleted after 3 months
- Bookkeeping records are kept for up to 5 years under Danish bookkeeping rules
- Support and sales correspondence is kept for a relevant period for follow-up and documentation
9. Your rights
Depending on the circumstances, you have the right to:
- Access
- Rectification
- Erasure
- Restriction
- Objection (including to direct marketing)
- Data portability
- Withdraw consent
- Lodge a complaint with the Danish Data Protection Agency (Datatilsynet)
Contact info@payper.dk. We generally respond within one month and may need to verify your identity.
10. Cookies
We use necessary cookies for operation and security. Statistics and marketing cookies are used only with consent where required. You can change preferences via the cookie banner on the website.
11. AI features
Payper may use AI to support Platform features (e.g. drafts and assistance). Processing is done to deliver the Services. We do not use Customer Data to train third-party general models in identifiable form. Anonymised/aggregated data may be used for operations and improvement.
12. Google Calendar integration
If you voluntarily connect Google Calendar, Payper requests access to read and write calendar events via Google OAuth. Data is used only to sync appointments you create or manage through Payper.
We do not sell Google user data.
We do not share Google user data with third parties for advertising, and we do not use it for independent profiling.
You can revoke access via Google account permissions.
Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
13. Security
We implement appropriate technical and organisational measures, including access control, encryption in transit, logging and limited employee access. No system is 100% secure, but we work continuously to reduce risk.
14. Changes
We may update this policy. The latest version is published on this page with an update date. For material changes we will inform you by email or in the Platform where relevant.
15. Contact
Payper ApS
Email: info@payper.dk
Phone: +45 32 35 88 08
Address: Hundstrupvej 18, 5750 Ringe, Denmark