Privacy Policy
1. Data controller
DLN MobilOrdre is the data controller for personal data processed via this SaaS platform. Contact details:
- Email: support@mobilordre.dk
- Company registration: [VAT/CVR number to be inserted]
- Address: [Business address to be inserted]
2. What information do we process?
As a SaaS provider we process several categories of personal data:
2.1 About platform users (your employees)
- Identity: name, initials, job title, username
- Contact: email, phone, work email, private email
- Login: hashed password, security stamp, login timestamps
- HR data: payroll number, payroll period, vacation balance, flex balance, sick-day corrections
- Bank details: registration + account number (only visible to user + accounting role)
- Work schedule: per-day working hours, home-to-work distance
- Activity: time entries, cases, driving logs, invoice lines
2.2 About your customers + suppliers
- Company name, VAT number, EAN number
- Contact persons with name, email, phone
- Addresses (billing + delivery)
- Bank details (IBAN, SWIFT) for suppliers
2.3 Technical data
- IP address + browser info during platform use
- Server logs (error messages, security events)
3. Purposes + legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Delivering platform features (login, cases, invoicing, etc.) | Contract performance (b) |
| Bookkeeping of invoices + payroll documents | Legal obligation (c) — Danish Bookkeeping Act |
| Security logging, brute-force mitigation, audit trails | Legitimate interest (f) |
| User support via email | Contract performance (b) |
| Platform improvement + operations | Legitimate interest (f) |
4. Who do we share data with?
We share data with the following processors — all governed by data-processor agreements under GDPR Art. 28:
- Microsoft Corporation (Azure, Microsoft Graph, Microsoft 365) — cloud services + email delivery. Data processed in EU data centres.
- Uniconta A/S — ERP integration (customers, suppliers, invoices, employees) for customers who have activated this integration.
- Curanet A/S (or other hosting provider) — server hosting in Denmark.
We NEVER sell or rent personal data to third parties. We do not use data for marketing or profiling.
5. Retention periods
- Active users: for the duration of employment/customer relationship + 6 months
- Vouchers, invoices, accounting data: 5 years per Danish Bookkeeping Act §10
- Integration log (audit): 60 days
- Server logs: 30 days
- Backups: point-in-time-restore for 35 days
6. Your rights
Under GDPR you have the right to:
- Access the data we hold about you (Art. 15) — via My Profile → Download personal data
- Rectify incorrect data (Art. 16) — via My Profile
- Erasure ("right to be forgotten", Art. 17) — via My Profile → Delete personal data. Note that accounting data is retained per legal requirements but anonymised so it can no longer be attributed to you.
- Restrict processing (Art. 18) — contact support
- Data portability (Art. 20) — download your data as JSON
- Object to processing (Art. 21) — contact support
- Complain to the Danish Data Protection Agency if you believe we process data incorrectly: datatilsynet.dk
7. Cookies + local storage
We only use strictly necessary cookies — no analytics, no marketing, no tracking. Hence no cookie banner.
| Cookie | Purpose | Duration |
|---|---|---|
.AspNetCore.Identity.Application | Login session (keeps you logged in) | 8 hours |
.AspNetCore.Antiforgery.* | CSRF protection | Session |
.AspNetCore.Culture | Remembers your selected language | 1 year |
In addition, the following is stored in your browser's localStorage (not cookies):
dln-theme— whether you prefer light or dark theme. No personal data.
8. Security
We protect your data with:
- HTTPS/TLS encryption on all network traffic
- Encrypted password storage (PBKDF2 hash via ASP.NET Identity)
- Multi-tenant isolation: data from one company is technically separated from others
- Bank details + other sensitive fields are only visible to relevant roles
- Rate limiting + lockout after failed login attempts
- Daily security updates + monitoring of critical integrations
- Credentials stored in Azure Key Vault — never in source code
9. Changes to this policy
We may update this policy. Material changes will be communicated via email or in-app message at least 30 days before they take effect. The current version is shown on this page with the date.
10. Contact
Questions about this policy or your rights? Email support@mobilordre.dk.
