Privacy Policy - Consile ApS
1. Data Controller
Consile ApS
CVR No.: 45643360
Under Hvidtjørnen 47, 7500 Holstebro
Email: martin@consile.dk
Phone: 93 63 04 95
Consile ApS (“Consile,” “we”) is the data controller for the processing of personal data described in this policy. Questions regarding this policy or our processing of your information may be directed to the contact information above.
2. Who This Policy Applies To
This policy applies to:
- visitors to our websites (consile.dk, app.consile.ai, docs.consile.ai),
- contact persons at customers, suppliers, and partners,
- users of our Consile MCP product (portal and MCP endpoints), and
- individuals who contact us, receive our communications, or are otherwise involved in our customer relationships.
3. Key Roles in Consile MCP
Consile MCP connects our customers’ own AI clients (e.g., Claude or ChatGPT) with the customer’s own business systems (e.g., Shopify, e-conomic, Uniconta, or HubSpot).
- For data in the customer’s business systems —such as information about the customer’s customers, suppliers, or employees that passes through the service— the customer is the data controller, and Consile is the data processor. This processing is governed by our Data Processing Agreement (DPA), not by this policy. If you are registered in a system that one of our clients has connected, you must exercise your rights with that company.
- For information regarding our customers’ own users and account details —such as accounts, logins, payments, support, etc.— Consile is the independent data controller. This is the processing described in sections 4–9 of this policy.
4. What Information We Process About Users of Consile MCP
| Category | Information | Source |
|---|---|---|
| Account and login information | Name, work email, organization (tenant), role/membership, login history | You / your organization, via our login provider |
| Payment and Subscription Information | Company name, business registration number, billing information, payment method (with the payment provider), subscriptions, and purchase history | You / your company when making a purchase |
| Contract documentation | Acceptance of terms and data processing agreement: version, time, IP address, and browser information (user-agent) at the time of acceptance; similarly for explicit opt-ins for storage features | Recorded upon your acceptance in the portal |
| Support and contact inquiries | The content of your messages (e.g., support requests and requests for new integrations), name, email | You |
| Usage statistics | Aggregated daily counters for service calls (number, success/failure) per organization and integration | Generated during use |
| Security and audit logs | Event log of administrative and security events (e.g., purchases, connections, deletions) with organization, action, and time | Generated upon use |
| Connection data | Which business systems your organization has connected to, and the status of the connection. The access keys themselves are stored in encrypted form and processed as a data processor, see section 3 | Generated upon use |
| Website data | Cookies/analytics on consile.dk, consile.ai, and app.consile.ai use only necessary session cookies | Your visit |
We do not process sensitive personal data about users, and we ask that you refrain from sending such information in support inquiries.
5. Purpose and Legal Basis
| Purpose | Legal basis (GDPR Art. 6(1)) |
|---|---|
| Creation and operation of accounts, login, and access control | Subparagraph (b) (contract) |
| Provision of the service, including connection and subscription management | Subparagraph (b) (contract) |
| Billing and payment | Subsection b (agreement) and subsection c (Accounting Act) |
| Documentation of accepted terms and optional features (including IP/user-agent) | Subsection f (legitimate interest: preservation of evidence of contract conclusion) |
| Support and customer service | Subsection b (agreement) and subsection f (legitimate interest) |
| Security, prevention of misuse, and audit trails | Section f (legitimate interest: secure operation and accountability, cf. Art. 5(2)) |
| Fair use enforcement and capacity management via aggregated usage statistics | Subsection (f) (legitimate interest) |
| Customer relationship management (CRM) and relevant communications to business customers | Article 5(f) (legitimate interest); marketing otherwise only in accordance with applicable marketing regulations |
| Establishment and defense of legal claims | Article 6(f) (legitimate interest) |
Where we base processing on legitimate interest, you can obtain further information about the balancing of interests by contacting us.
6. Recipients of Personal Data
We never sell your information. We share it only with:
Data processors (who process data on our behalf and in accordance with our instructions):
| Supplier | Service | Location | Legal basis for transfer |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting and operation of the service and databases | EU (Frankfurt, eu-central-1) | Processing in the EU/EEA |
| Stytch, Inc. | Login and identity (user accounts) | United States | EU-U.S. Data Privacy Framework / SCC |
| HubSpot, Inc. | CRM and Customer Communication (contact information, support inquiries, contract documentation, subscription status) | EU data center | DPF / SCC |
Independent data controllers:
- Stripe (payment processing): Stripe processes your payment information as a data processor on our behalf and, for certain purposes (e.g., fraud prevention and its own legal requirements), as an independent data controller. See Stripe’s Privacy Policy.
- Government agencies, auditors, and advisors, where we are required to do so or have a legitimate interest.
7. Transfers to Countries Outside the EU/EEA
Our core service is hosted in the EU (AWS Frankfurt). A few suppliers process data in the U.S. (see the table in section 6).
Transfers are made on the basis of the EU-U.S. Data Privacy Framework or the European Commission’s Standard Contractual Clauses (SCCs) with supplementary measures where applicable.
A copy of the legal basis for the transfer can be requested using the contact information in section 1.
8. Retention and Deletion
| Information | Retention Period |
|---|---|
| Account and login information | As long as the account exists; deleted upon account deletion (after a 14-day cancellation period) |
| Encrypted access keys for connected systems | Deleted immediately upon disabling the integration and immediately upon request to delete the account |
| Payment and accounting records | 5 years from the end of the fiscal year (Accounting Act); upon account deletion, customer information is otherwise anonymized by the payment provider |
| Contract documentation (acceptance of terms, opt-ins) | For as long as the account exists; deleted upon account closure. May be retained for up to 3 years after termination for legal claims—decision |
| Support and contact inquiries | For as long as the account exists; deleted upon account closure. CRM copy: see next row |
| CRM information (customer relationship) | Up to 5 years after the end of the customer relationship, after which they are deleted |
| Aggregated usage statistics | As long as the account exists (for billing purposes); deleted upon account closure |
| Detailed usage events | Disabled by default; if enabled: maximum 90 days |
| Security and audit logs | Up to 400 days from the event— even after account closure, for security, accountability, and documentation purposes (Art. 5, para. 2) |
| Deletion receipts | Stored as documentation that deletion has been completed |
| Website data | See cookie policy |
When requesting account deletion, a 14-day cooling-off period applies, after which the deletion is carried out automatically. However, access keys are deleted immediately, and OAuth access is simultaneously revoked with the relevant provider. Upon deletion, your organization will also be deleted from our login provider.
9. Self-Service in Consile MCP
In the portal, as a user or administrator, you can:
- export your organization’s account data (master data, subscriptions, connection status, acceptances, and opt-ins) in a machine-readable format (JSON), and
- request deletion of your organization’s account, see section 8.
The export never contains access keys or other confidential information.
10. Your Rights
Under the General Data Protection Regulation, you have the right to:
- access to the information we process about you (Art. 15),
- to have inaccurate informationcorrected (Art. 16),
- erasure (“the right to be forgotten”) (Art. 17),
- restriction of processing (Art. 18),
- data portability (Art. 20),
- objection to processing based on legitimate interests, including direct marketing (Art. 21), and
- withdrawal of consent where processing is based on consent—without affecting the lawfulness of processing prior to withdrawal.
Please direct inquiries to martin@consile.dk.
We generally respond within one month. If your inquiry concerns information in a business system that one of our customers has connected to Consile MCP, we refer you to the relevant company, which is the data controller in this regard (see section 3); we will assist our customer to the extent necessary.
You may file a complaint with the Danish Data Protection Agency, Carl Jacobsens Vej 35, 2500 Valby, www.datatilsynet.dk.
11. Security
We protect your information with technical and organizational measures commensurate with the risk, including encryption in transit and at rest, access control by organization for each call, encryption keys per customer, automatic removal of sensitive information from system logs, and ongoing monitoring.
A more detailed description is provided in our Data Processing Agreement (Appendix C).
13. Changes to This Policy
We update this policy as needed, for example, in the event of changes to our suppliers or services. The current version, dated, is always available on this page. Users of Consile MCP will be notified of significant changes via the portal or email.
Version: (publication date to be inserted).