This is an English translation provided for convenience. The Danish version is the legally binding document; in case of any discrepancy, the Danish text prevails.
This cookie and privacy policy describes how Webits ApS ("Webits", "we", "us") collects, uses, shares and protects personal data when you use the website https://webits.dk with its associated sub-sites, domains and self-service solutions, or when you are a customer of ours. The policy also describes our use of cookies and similar technologies.
Webits is the data controller for the personal data processed about you as a visitor, customer or applicant. Where we process personal data on behalf of a customer as part of delivering a service, we do so as a data processor under our separate data processing agreement.
All processing of personal data takes place in accordance with the EU General Data Protection Regulation 2016/679 (GDPR) and the Danish Data Protection Act.
1. Collection of information
You can visit our website without providing personal data. We only collect information that is necessary for the purpose for which it is to be used.
When you contact us via the contact form, we register your name, company name, telephone number and email address, as well as the content of your enquiry.
When you are set up as a customer, we register information about the company (company name, CVR number, company address and any delivery and invoicing address) as well as about the contact person (name, email address and telephone number).
When you purchase and pay, we register your name, invoicing details and the information necessary to complete the payment. For card payments, the card details themselves are handled by our payment provider Stripe; Webits does not store full card numbers. The information necessary to complete and support the payment is exchanged with Stripe, including the purchase amount and invoicing details.
When you sign up for the newsletter, we register your email address.
When you submit a job application, we process your name, address, email address, telephone number, your CV, any photo and other documents you upload during the application process.
On all visits, our systems automatically register the visiting host's IP address for the purpose of maintaining active DDoS protection on our network. As a rule, the IP address is not retained for more than 12 hours, unless there is a specific suspicion of, or threat against, our systems, our customers' personal data or our customers' services.
2. Use of information
We process your personal data for the following purposes:
- to respond to enquiries and prepare non-binding quotations,
- to create and administer you as a customer in our CRM and accounting system,
- to deliver, invoice and support the products and services you have ordered, as well as to handle complaint and warranty cases,
- to send out the newsletter, if you have given your consent to this,
- to process and assess job applications,
- to operate, improve and optimise our website and customer service, and
- to maintain the security of our network and systems, including DDoS protection.
Legal basis for processing. We process your information on one of the following bases under GDPR Article 6:
- Performance of a contract (Article 6(1)(b)) — where the processing is necessary in order to enter into or perform a contract with you, e.g. account creation, delivery, invoicing and support.
- Legal obligation (Article 6(1)(c)) — e.g. retention of accounting records for 5 years pursuant to the Danish Bookkeeping Act.
- Consent (Article 6(1)(a)) — e.g. sending out the newsletter. Consent may be withdrawn at any time.
- Legitimate interest (Article 6(1)(f)) — e.g. network security, DDoS protection and the ongoing improvement of our website, where our interest is not overridden by your rights.
3. Sharing of information
We never sell your personal data and do not share it with third parties for marketing purposes.
We only disclose or entrust information in the following cases:
- Data processors/subcontractors. We use data processors to deliver our services, including Microsoft (Azure and Office 365), OVHcloud, DigitalOcean, Curanet A/S, Plesk and Stripe. The data processors only process information in accordance with our documented instructions and on the basis of data processing agreements that comply with GDPR Article 28. An up-to-date overview is set out in our data processing agreement.
- Naming and registry authorities. In connection with domain administration, we may disclose necessary information to official authorities and registries such as Punktum dk, ICANN and RIPE.
- Public authorities. We may disclose information where we are legally obliged to do so, or to industry organisations in cases concerning misuse of the internet.
Data processing generally takes place within the EU/EEA. Where a data processor is established outside the EU/EEA, or where a transfer to a third country exceptionally takes place, the transfer is safeguarded on a valid transfer basis — for example an adequacy decision, the European Commission's Standard Contractual Clauses (SCC) or the EU-U.S. Data Privacy Framework.
4. Your rights
Under the data protection rules, you have a number of rights when we process your personal data:
- Right of access — you can obtain access to the information we process about you, and obtain a range of information about the processing.
- Right to rectification — you can have incorrect information corrected.
- Right to erasure — in certain cases you can have information about you erased before the time of our ordinary general erasure.
- Right to restriction — in certain cases you can have the processing of your information restricted.
- Right to data portability — in certain cases you can receive your information in a structured, commonly used and machine-readable format and have it transferred to another data controller.
- Right to object — you can object to an otherwise lawful processing of your information.
- Right not to be subject to automated decisions, including profiling, which produce legal effects or similarly significantly affect you.
You can exercise your rights or ask questions about our processing by contacting our Data Protection Officer (see below). You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) if you are dissatisfied with our processing of your personal data — see contact details at https://www.datatilsynet.dk.
Retention periods. We retain your information for as long as there is an active customer relationship, and for as long as it is necessary for the purpose for which it was collected. It is then erased. Accounting records are retained for 5 years as required by the Danish Bookkeeping Act. If you unsubscribe from the newsletter, your email address is retained for up to 12 months before it is erased, so that we do not mistakenly continue to contact you. In special cases, information may be retained for longer if it is necessary in order to establish, exercise or defend a legal claim.
Data Protection Officer (DPO). If you have questions about the processing of your information, or if you wish to exercise your rights, you can contact our Data Protection Officer:
- Email: dpo@webits.dk
- Telephone: +45 44 14 44 30
- Post: Webits ApS, att. Data Protection Officer, Fadet 43 st. tv., 1799 København V
5. Cookies and tracking
What are cookies?
A cookie is a small text file that is placed on your computer, tablet or smartphone when you visit a website. The cookie enables the website to recognise your device and remember information about your visit. A cookie is not a program and cannot spread viruses or damage your device. Some cookies collect anonymous data, while others — including IP addresses — may constitute personally identifiable information.
Categories of cookies
- Necessary cookies are essential for the website to function correctly, including basic functionality and security. These cookies do not require consent and do not store any personal data for other purposes.
- Visitor statistics help us understand how the website is used, so that we can continuously improve it. When statistics are enabled, we use Plausible Analytics, which measures aggregated visits without cookies, persistent identifiers or cross-site tracking. Plausible processes data in the EU and does not store the visitor's raw IP address.
- Marketing cookies are used to track visitors across websites in order to display relevant advertisements. We do not use marketing cookies.
Lifespan
Cookies have different lifespans. Some are deleted when you close the browser (session cookies), while others are stored for a period (persistent cookies). Plausible Analytics does not place cookies.
How to delete or disable cookies
You can block or delete cookies in your browser's settings. Please note that certain functions on the website may cease to work if you disable necessary cookies.
Publisher
The website is owned and published by:
Webits ApS CVR number: 41336404 Fadet 43 st. tv. 1799 København V
Telephone: +45 44 14 44 30 Email: info@webits.dk
Chief Executive Officer: Martin Bennetzen