Legal

Privacy Policy

This policy explains what personal data Valido Insight processes, why we use it, who helps us, and the rights available to you.

Effective from

1. Data controller and contact details

Valido Insight is provided personally by Stefan Hilbert, who is the data controller for personal data processed about visitors, account holders, payers, and business contacts.

  • Service: Valido Insight by Stefan Hilbert
  • Address: Stationsvej 6, 9362 Gandrup
  • Email: kontakt@valido.dk
  • Phone: +45 52 60 41 87
  • Danish business registration: CVR 36354836

Contact us if you have questions or want to exercise your privacy rights.

2. When this policy applies

This policy applies to valido.dk, app.valido.dk, Valido Insight accounts, dashboards, reports, support, waiting lists, and the technical flows described below.

Valido Insight is the controller for its own account, operations, security, and payment purposes. Where we process personal data from a customer website solely on the customer's instructions, the customer will normally be the controller and Valido Insight the processor. An Article 28 data processing agreement must be in place where required.

3. Data we process

Depending on how you use the service, we process:

  • identity and contact details, including name, business name, email, phone number, locale, and time zone;
  • account and security data, including authentication identifiers, session and MFA information, IP-derived security events, and audit logs;
  • subscription and transaction data, including plan, billing market and currency, Stripe customer and subscription references, accepted contract version, totals, tax, and payment status;
  • project, website, scan, WordPress plugin, Search Console, report, forum, support, and notification data you submit or connect;
  • technical information such as browser, device, timestamps, request diagnostics, and necessary cookie or local-storage values.

We do not ask for card details directly. Stripe processes payment credentials.

4. Purposes and legal bases

  • Contract: create accounts, deliver scans and reports, provide integrations, support, subscriptions, and billing.
  • Legitimate interests: secure, troubleshoot, improve, document, and prevent abuse of the service; communicate with business users; and establish legal claims.
  • Legal obligations: accounting, tax, sanctions, and other mandatory record keeping.
  • Consent: where an optional communication or non-essential technology specifically requires it. Consent can be withdrawn prospectively.

Providing required account, project, or billing data is necessary to supply the relevant function.

5. WordPress plugin and public website scanning

The WordPress plugin sends the authenticated technical evidence described in our product documentation. Public scans retrieve content and technical responses that a website makes publicly available. Customers must have authority to connect a website and must not deliberately submit unnecessary sensitive personal data.

Reports can contain URLs, page titles, text excerpts, author information, or other data present on the connected or public website. Customers control their source content and access permissions.

6. Service providers and recipients

We disclose data only as needed to operate the service, comply with law, or protect legal rights. Categories include hosting and infrastructure, database and authentication, transactional email, payment and tax, security and diagnostics, and connected services requested by the customer.

Core providers include Netlify, Supabase, Stripe, and Resend. Google receives and returns data when a customer connects Search Console. Providers act under their own terms where they are independent controllers and under processor terms where they process on our behalf.

7. Transfers outside the EU/EEA

Some providers or their support functions may process data outside the EU/EEA, including in the United States. Where EU data-transfer rules apply, we rely on an adequacy decision, the EU Standard Contractual Clauses with supplementary safeguards, or another lawful mechanism. Contact us for information about the relevant safeguard.

8. How long we retain data

We keep data only for the period needed for the stated purpose, security, legal claims, and mandatory records. Active account and project data is retained while the service is supplied. Deleted accounts and projects are removed or anonymized through the documented deletion process and backup cycle.

Accounting and transaction records are normally retained for the period required by Danish law. Security and operational logs use shorter risk-based periods. Shared-report access expires according to the sharing settings. Immutable contract acceptance and transaction evidence remains in the language and form accepted at the time.

9. Cookies and browser storage

We currently use necessary cookies and browser storage for authentication, security, preferences, and requested functionality. The separate Cookie Policy lists the technologies, purposes, and durations.

10. Security

We use access controls, encryption in transit, restricted service credentials, row-level database controls, signed callbacks, logging, backups, and supplier controls appropriate to the risk. No internet service can guarantee absolute security. Please report suspected security incidents promptly to kontakt@valido.dk.

11. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection. You may withdraw consent and object to processing based on legitimate interests. We may need to verify identity and may retain data where the law or legal claims require it.

Send requests to kontakt@valido.dk. We normally respond within one month under EU/EEA law. Depending on where you live, additional local rights may apply; we will honor mandatory rights applicable to our processing.

12. Children and automated decisions

The service is a business product and is not directed to children. Valido Insight does not make decisions producing legal or similarly significant effects solely by automated processing. Scan scores and recommendations are decision support and should be reviewed by a person.

13. Complaints

Please contact us first so we can investigate. You may also complain to the Danish Data Protection Agency, Carl Jacobsens Vej 35, 2500 Valby, Denmark, through datatilsynet.dk, or to the competent supervisory authority where applicable.

14. Changes to this policy

We update this policy when data flows, providers, retention, or legal requirements change. The effective date appears above. Where required, we notify active account holders before a material change takes effect. Questions can be sent to kontakt@valido.dk.