This policy explains how bySoko ApS ("bySoko", "we") processes personal data when you visit bysoko.com, sign up for our newsletter, or use the bySoko service. bySoko is built for business customers; we collect as little personal data as the service allows. 1. Who is responsible bySoko ApS, Prøvekæret 6, 2800 Kgs. Lyngby, Denmark (CVR 46628691) is the data controller for the processing described in this policy. Contact: contact@bysoko.com. For product data our customers upload to the service, the customer is the data controller and bySoko is a data processor. That processing is governed by our [Data Processing Agreement], not by this policy (see section 8). 2. What we process, and why Visiting the website. We process technical data (IP address, browser type, pages visited, timestamps) to deliver the site securely and detect abuse. Legal basis: legitimate interest (GDPR art. 6(1)(f)). [TBD: analytics tool and cookie details — see the Cookie Policy.] Newsletter. If you sign up, we process your e-mail address to send the newsletter. Legal basis: consent (art. 6(1)(a)), given by double opt-in. You can withdraw it at any time via the unsubscribe link in every mail. [TBD: newsletter tool.] Creating an account and using the service. We process your name, work e-mail address, company details, login data, and settings to provide the service under our Terms of Service. Legal basis: contract (art. 6(1)(b)). We also process usage data (features used, jobs run, volumes) to operate, secure, and improve the service. Legal basis: legitimate interest (art. 6(1) (f)). Payments. Payments are handled by Stripe. We receive confirmation of payment, invoicing details, and your balance history; we never see or store full card numbers. Legal basis: contract (art. 6(1)(b)) and legal obligation (bookkeeping, art. 6(1)(c)). Support and contact. If you write to us, we process your message and contact details to answer you. Legal basis: legitimate interest (art. 6(1)(f)) or contract, depending on the context. 3. What we do not do We do not sell personal data. We do not use your data or your uploaded product data to train AI models. We do not profile visitors for advertising. 4. Who we share data with We use a small number of service providers (processors) to run bySoko: bySoko ApS · Privacy Policy · Draft v0.1 · Page 1Provider Purpose Location / transfer basis DigitalOcean Hosting and infrastructure Germany (EU datacenter) Google Cloud (Gemini via Vertex AI) AI processing of product data during enrichment Google Cloud with data processing terms; customer data is not used to train models. SCCs + EU–US Data Privacy Framework where applicable. [TBD: confirm EU region for Vertex AI endpoints] Google Workspace E-mail and internal administration EU/US — SCCs + EU–US Data Privacy Framework Stripe Payment processing EU/US — SCCs + EU–US Data Privacy Framework [TBD: newsletter tool] Newsletter delivery [TBD] [TBD: analytics] Website statistics [TBD] Where a provider processes data outside the EU/EEA, transfers are protected by an adequacy decision (including the EU–US Data Privacy Framework) or the EU Standard Contractual Clauses. The current list of sub-processors for the service itself is published at processors]. We may also disclose data where the law requires it. 5. How long we keep data Account data: for as long as your account exists, and up to [/legal/sub[TBD: e.g. 90 days] after deletion for backup cycling. Bookkeeping records (invoices, payments): 5 years after the end of the financial year, as Danish law requires. Newsletter data: until you unsubscribe. Support correspondence: [TBD: e.g. 2 years]. Uploaded product data: governed by the customer's instructions and the DPA. 6. Your rights Under the GDPR you can ask for access, rectification, erasure, restriction, and portability of your personal data, and you can object to processing based on legitimate interest. Where processing is based on consent, you can withdraw it at any time without affecting past processing. Write to contact@bysoko.com. You can also complain to the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk) or your local supervisory authority. 7. Security Data is encrypted in transit. Access to production systems is restricted and logged. Customer catalogs are isolated per customer. More detail: [/legal/security]. 8. When bySoko is a processor Product data that customers upload — supplier feeds, product texts, images — is processed only on the customer's instructions to deliver the service. If that data contains personal data, the customer remains the controller, and our [Data Processing Agreement] applies, including the sub-processor list and international transfer safeguards. bySoko ApS · Privacy Policy · Draft v0.1 · Page 29. Changes We will update this policy when the service or our providers change, and note the date at the top. Significant changes affecting account holders are announced by e-mail.
Rechtliches