Docs
Try Consile

Privacy Policy - Consile ApS

1. Data Controller

Consile ApS
CVR No.: 45643360
Under Hvidtjørnen 47, 7500 Holstebro
Email: martin@consile.dk
Phone: 93 63 04 95

Consile ApS (“Consile,” “we”) is the data controller for the processing of personal data described in this policy. Questions regarding this policy or our processing of your information may be directed to the contact information above.

2. Who This Policy Applies To

This policy applies to:

  • visitors to our websites (consile.dk, app.consile.ai, docs.consile.ai),
  • contact persons at customers, suppliers, and partners,
  • users of our Consile MCP product (portal and MCP endpoints), and
  • individuals who contact us, receive our communications, or are otherwise involved in our customer relationships.

3. Key Roles in Consile MCP

Consile MCP connects our customers’ own AI clients (e.g., Claude or ChatGPT) with the customer’s own business systems (e.g., Shopify, e-conomic, Uniconta, or HubSpot).

  • For data in the customer’s business systems —such as information about the customer’s customers, suppliers, or employees that passes through the service— the customer is the data controller, and Consile is the data processor. This processing is governed by our Data Processing Agreement (DPA), not by this policy. If you are registered in a system that one of our clients has connected, you must exercise your rights with that company.
  • For information regarding our customers’ own users and account details —such as accounts, logins, payments, support, etc.— Consile is the independent data controller. This is the processing described in sections 4–9 of this policy.

4. What Information We Process About Users of Consile MCP

Category Information Source
Account and login information Name, work email, organization (tenant), role/membership, login history You / your organization, via our login provider
Payment and Subscription Information Company name, business registration number, billing information, payment method (with the payment provider), subscriptions, and purchase history You / your company when making a purchase
Contract documentation Acceptance of terms and data processing agreement: version, time, IP address, and browser information (user-agent) at the time of acceptance; similarly for explicit opt-ins for storage features Recorded upon your acceptance in the portal
Support and contact inquiries The content of your messages (e.g., support requests and requests for new integrations), name, email You
Usage statistics Aggregated daily counters for service calls (number, success/failure) per organization and integration Generated during use
Security and audit logs Event log of administrative and security events (e.g., purchases, connections, deletions) with organization, action, and time Generated upon use
Connection data Which business systems your organization has connected to, and the status of the connection. The access keys themselves are stored in encrypted form and processed as a data processor, see section 3 Generated upon use
Website data Cookies/analytics on consile.dk, consile.ai, and app.consile.ai use only necessary session cookies Your visit

We do not process sensitive personal data about users, and we ask that you refrain from sending such information in support inquiries.

5. Purpose and Legal Basis

Purpose Legal basis (GDPR Art. 6(1))
Creation and operation of accounts, login, and access control Subparagraph (b) (contract)
Provision of the service, including connection and subscription management Subparagraph (b) (contract)
Billing and payment Subsection b (agreement) and subsection c (Accounting Act)
Documentation of accepted terms and optional features (including IP/user-agent) Subsection f (legitimate interest: preservation of evidence of contract conclusion)
Support and customer service Subsection b (agreement) and subsection f (legitimate interest)
Security, prevention of misuse, and audit trails Section f (legitimate interest: secure operation and accountability, cf. Art. 5(2))
Fair use enforcement and capacity management via aggregated usage statistics Subsection (f) (legitimate interest)
Customer relationship management (CRM) and relevant communications to business customers Article 5(f) (legitimate interest); marketing otherwise only in accordance with applicable marketing regulations
Establishment and defense of legal claims Article 6(f) (legitimate interest)

Where we base processing on legitimate interest, you can obtain further information about the balancing of interests by contacting us.

6. Recipients of Personal Data

We never sell your information. We share it only with:

Data processors (who process data on our behalf and in accordance with our instructions):

Supplier Service Location Legal basis for transfer
Amazon Web Services (AWS) Hosting and operation of the service and databases EU (Frankfurt, eu-central-1) Processing in the EU/EEA
Stytch, Inc. Login and identity (user accounts) United States EU-U.S. Data Privacy Framework / SCC
HubSpot, Inc. CRM and Customer Communication (contact information, support inquiries, contract documentation, subscription status) EU data center DPF / SCC

Independent data controllers:

  • Stripe (payment processing): Stripe processes your payment information as a data processor on our behalf and, for certain purposes (e.g., fraud prevention and its own legal requirements), as an independent data controller. See Stripe’s Privacy Policy.
  • Government agencies, auditors, and advisors, where we are required to do so or have a legitimate interest.

7. Transfers to Countries Outside the EU/EEA

Our core service is hosted in the EU (AWS Frankfurt). A few suppliers process data in the U.S. (see the table in section 6).
Transfers are made on the basis of the EU-U.S. Data Privacy Framework or the European Commission’s Standard Contractual Clauses (SCCs) with supplementary measures where applicable.
A copy of the legal basis for the transfer can be requested using the contact information in section 1.

8. Retention and Deletion

Information Retention Period
Account and login information As long as the account exists; deleted upon account deletion (after a 14-day cancellation period)
Encrypted access keys for connected systems Deleted immediately upon disabling the integration and immediately upon request to delete the account
Payment and accounting records 5 years from the end of the fiscal year (Accounting Act); upon account deletion, customer information is otherwise anonymized by the payment provider
Contract documentation (acceptance of terms, opt-ins) For as long as the account exists; deleted upon account closure. May be retained for up to 3 years after termination for legal claims—decision
Support and contact inquiries For as long as the account exists; deleted upon account closure. CRM copy: see next row
CRM information (customer relationship) Up to 5 years after the end of the customer relationship, after which they are deleted
Aggregated usage statistics As long as the account exists (for billing purposes); deleted upon account closure
Detailed usage events Disabled by default; if enabled: maximum 90 days
Security and audit logs Up to 400 days from the event— even after account closure, for security, accountability, and documentation purposes (Art. 5, para. 2)
Deletion receipts Stored as documentation that deletion has been completed
Website data See cookie policy

When requesting account deletion, a 14-day cooling-off period applies, after which the deletion is carried out automatically. However, access keys are deleted immediately, and OAuth access is simultaneously revoked with the relevant provider. Upon deletion, your organization will also be deleted from our login provider.

9. Self-Service in Consile MCP

In the portal, as a user or administrator, you can:

  • export your organization’s account data (master data, subscriptions, connection status, acceptances, and opt-ins) in a machine-readable format (JSON), and
  • request deletion of your organization’s account, see section 8.

The export never contains access keys or other confidential information.

10. Your Rights

Under the General Data Protection Regulation, you have the right to:

  • access to the information we process about you (Art. 15),
  • to have inaccurate informationcorrected (Art. 16),
  • erasure (“the right to be forgotten”) (Art. 17),
  • restriction of processing (Art. 18),
  • data portability (Art. 20),
  • objection to processing based on legitimate interests, including direct marketing (Art. 21), and
  • withdrawal of consent where processing is based on consent—without affecting the lawfulness of processing prior to withdrawal.

Please direct inquiries to martin@consile.dk.
We generally respond within one month. If your inquiry concerns information in a business system that one of our customers has connected to Consile MCP, we refer you to the relevant company, which is the data controller in this regard (see section 3); we will assist our customer to the extent necessary.

You may file a complaint with the Danish Data Protection Agency, Carl Jacobsens Vej 35, 2500 Valby, www.datatilsynet.dk.

11. Security

We protect your information with technical and organizational measures commensurate with the risk, including encryption in transit and at rest, access control by organization for each call, encryption keys per customer, automatic removal of sensitive information from system logs, and ongoing monitoring.
A more detailed description is provided in our Data Processing Agreement (Appendix C).

13. Changes to This Policy

We update this policy as needed, for example, in the event of changes to our suppliers or services. The current version, dated, is always available on this page. Users of Consile MCP will be notified of significant changes via the portal or email.

Version: (publication date to be inserted).