GDPR
Privacy policy
inciro K/S is the data controller for the personal data we process through the contact form, the customer onboarding form and inciro AI. This page describes what data we collect, why, how long we keep it, and who we share it with.
Last updated: 14 August 2026
- Home
- Privacy policy
1. Introduction
This privacy policy explains how we collect, use and protect your personal data when you use our website. We are committed to the confidentiality and security of your personal data under the General Data Protection Regulation (GDPR) and other applicable data protection law.
2. Data controller
We are inciro K/S, based in Denmark. As data controller, we are responsible for the processing of your personal data.
Contact details
- Contact form: available on our website
- Address: Borupvang 3, 2750 Ballerup, Denmark
3. Personal data we collect
We collect personal data in three places on our website: the contact form, the customer onboarding form and inciro AI. Each is described in more detail further down this page.
Contact form
- Name
- Email address
- Message content
This data is collected only when you voluntarily submit it through the contact form.
Customer onboarding form
- Company VAT number, name, address, postcode, city, phone number, email and invoice email
- The legally authorised signatory's full name, job title, email and phone number
- Any daily contact person: the same four fields (name, job title, email and phone number)
inciro AI
Your message text is processed to generate a reply. We also store a hash of your IP address plus rate-limit counters. See the inciro AI section below for retention details.
4. How we use your personal data
We use data from the contact form solely to:
- Respond to your enquiries and your communication with us
- Keep records of our communication
The legal basis for this processing is your consent (Article 6(1)(a)) combined with our legitimate interest in responding to enquiries (Article 6(1)(f)). The legal basis for the customer onboarding form and for inciro AI is described in their own sections below, because the purposes differ.
5. Data retention
We keep contact form enquiries that do not lead to a customer relationship for 12 months. If an enquiry leads to a customer relationship, we keep it for 5 years under the Danish bookkeeping act. We keep submissions through the customer onboarding form for 5 years under the same rule. You may request deletion of your personal data at any time, subject to the retention obligations of the bookkeeping act.
6. inciro AI
When you use inciro AI, we send your message text to Cloudflare Workers AI to generate a reply. Your replies are not stored: the message text is never written to any database or storage on our side.
What we do store is a SHA-256 hash of your IP address plus numeric rate-limit counters, in Cloudflare Workers KV, for at most 48 hours. Your raw IP address is never stored. A hashed identifier that can be used to recognise a user is still personal data under GDPR, so we disclose it explicitly rather than omitting it.
The legal basis is Article 6(1)(f), legitimate interests: operating and securing a free advisory tool you have chosen to use, including preventing abuse. No consent or cookie banner is required for this.
Cloudflare Workers AI
According to Cloudflare's own documentation (developers.cloudflare.com/workers-ai/platform/data-usage/, last updated 21 April 2026), inputs and outputs constitute "Customer Content", which belongs to the customer. Cloudflare states that it does not use Customer Content to train AI models or to improve Cloudflare's or third-party services, and would not do so without explicit consent. Cloudflare further states that it does not make Customer Content available to any other Cloudflare customer.
Cloudflare states that Customer Content may be stored by Cloudflare if a storage service such as R2, KV, Durable Objects or Vectorize is used alongside Workers AI. inciro uses KV, but only for the hashed IP address and the counters, never for message content.
Cloudflare states that it neither creates nor trains the AI models made available through Workers AI; the models are third-party services under their own licence terms.
7. Customer onboarding
When you complete the customer onboarding form, we collect the company's VAT number, name, address, postcode, city, phone number, email and invoice email; the legally authorised signatory's full name, job title, email and phone number; and, where relevant, a daily contact person with the same four fields.
The legal basis is Article 6(1)(b) for steps taken at your request prior to entering into an agreement, since the form prepares a framework agreement, combined with Article 6(1)(c), legal obligation, for the 5-year retention under the Danish bookkeeping act.
The submission is sent through Brevo and received in our Microsoft 365 environment, in a Teams channel and a shared mailbox.
8. Customer data
Once a framework agreement is in place, we process customer data in the following systems:
- Microsoft 365 – our working environment.
- Visma e-conomic – invoicing and bookkeeping. This is where the 5-year retention period above applies.
- Cloud Factory – a Microsoft cloud indirect provider (distributor) with a Danish presence, which we use for customers who purchase licence subscriptions. Cloud Factory receives limited customer data, only what is necessary to assign Microsoft 365 services.
All three are based in the EU/Denmark. See their respective privacy policies for their current position.
9. Third-party providers
We use the following third-party providers to process your data:
Brevo
- Purpose: processing of contact form and onboarding submissions
- Data location: EU
- More information: brevo.com/legal/privacypolicy
Microsoft 365
- Purpose: email, Teams and administration of submitted data
- Data location: EU
- More information: privacy.microsoft.com
Cloudflare
- Purpose: website hosting, security, performance and inciro AI
- Data location: global edge network. A request may be answered from the location nearest to you
- More information: cloudflare.com/privacypolicy
Cloudflare Turnstile
According to Cloudflare's Turnstile Privacy Addendum (cloudflare.com/turnstile-privacy-policy, last updated 18 June 2025), Turnstile runs on the contact form, the customer onboarding form and inciro AI, and processes the client's IP address, TLS fingerprint, User-Agent header, and the sitekey together with its associated origin.
Cloudflare states that it is not able to directly identify individuals from any of the signals Turnstile collects, including IP addresses, and that the purpose is not to identify, profile or target individuals, but solely to detect and block bots.
Cloudflare is a processor for inciro for bot-blocking purposes, and an independent data controller when the signals are used to improve Turnstile's own bot detection, based on Cloudflare's own legitimate interest. The signals are strictly necessary, so no consent is required.
Visma e-conomic
- Purpose: invoicing and bookkeeping for customers
- Data location: EU/Denmark
- More information: visma.dk/e-conomic/privatlivspolitik
Cloud Factory
- Purpose: distribution and assignment of Microsoft 365 licences to customers
- Data location: EU/Denmark
- More information: cloudfactorygroup.com
11. Your rights
Under GDPR, you have the following rights:
- Right of access to your personal data
- Right to rectification of inaccurate personal data
- Right to erasure ("the right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
To exercise any of these rights, you can contact us through the contact form on our website.
12. Data security
We apply appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Data encryption
- Regular security assessments
- Access control
- Data processors chosen with EU data residency, see the international data transfers section
13. International data transfers
inciro operates no datacentres of its own and chooses data processors that offer EU data residency. Brevo and Microsoft 365 process data in the EU. Cloudflare runs the website on a global edge network, so a request may be answered from the location nearest to you; see Cloudflare's own documentation on data localisation for details.
14. Changes to this privacy policy
We reserve the right to update this privacy policy from time to time. Any change is published on this page with an updated revision date.
15. Supervisory authority
You have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet):
- Datatilsynet
- Carl Jacobsens Vej 35
- 2500 Valby, Denmark
- Phone: +45 33 19 32 00
- Email: dt@datatilsynet.dk
- Website: www.datatilsynet.dk
16. Contact us
If you have questions about this privacy policy or our data processing, please contact us via:
- The contact form on our website
- Address: Borupvang 3, 2750 Ballerup, Denmark
Data protection commitment
inciro operates no datacentres of its own. Instead, we choose data processors that offer EU data residency: Brevo and Microsoft 365 process data in the EU, while Cloudflare runs a global edge network and may answer a request from the location nearest to you. This approach supports compliance with the General Data Protection Regulation (GDPR).
Information about our data processors is based on their own documentation as of 14 August 2026.
Ready for the next step?
Shall we have an informal conversation about your next step in the Microsoft Cloud?
Contact us