Privacy Policy
Version 2.0 · Effective date: 31.10.2026 · Last updated: 23.09.2026
This Privacy Policy explains how Semantic ApS processes personal data as data controller when you visit semantic.biz, contact us, attend our events, receive our newsletters, or act as contact person or user for a customer, supplier or partner.
When we process personal data on behalf of our customers in the Semantic platform (e.g. personal data contained in Peppol invoices and logistics documents), we act as data processor. That processing is governed by our Data Processing Agreement with the customer, and the customer is responsible for informing the data subjects.
1. Data controller and contact
Semantic ApS · CVR 43789406 · Venlighedsvej 1, 2970 Hørsholm, Denmark
E-mail: info@semantic.biz · Phone: +45 53 71 03 04
Semantic has not appointed a data protection officer, as we are not required to do so. Please contact us at the address above with any questions about data protection.
2. What we process, why, and on which legal basis
| Purpose | Personal data | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Customer, supplier and partner relationships, including contracts, onboarding and account administration in the Semantic Portal | Name, job title, business e-mail, phone, company name, address and CVR, user ID, login and access logs | Art. 6(1)(b) (contract) where you are the contracting party; otherwise Art. 6(1)(f) – our legitimate interest in administering our relationship with your organisation | Duration of the relationship min 3 month max 3 years (limitation period) |
| Support and communication | Contact details, communication history, support tickets | Art. 6(1)(b) and (f) – legitimate interest in handling enquiries and providing support | 1 years after the ticket is closed |
| Invoicing and bookkeeping | Name, company details, billing information, payment history | Art. 6(1)(c) – legal obligation under the Danish Bookkeeping Act | 5 years from the end of the financial year |
| Security, fraud prevention and logging of the platform and website | IP address, device and browser data, log data | Art. 6(1)(f) – legitimate interest in securing our systems | 90 days (logs), longer if needed for an incident |
| Webinars, courses and events | Name, company, title, contact details, attendance, dietary preferences (if provided) | Art. 6(1)(b) (registration) and 6(1)(f) | 12 months after the event |
| Newsletters and direct marketing by e-mail | Name, e-mail, company, interests, opening/click data | Art. 6(1)(a) – consent (and section 10 of the Danish Marketing Practices Act) | Until you withdraw consent + documentation of consent for 1 years |
| B2B sales and prospecting (e.g. contact persons at relevant companies) | Name, title, business contact details, company | Art. 6(1)(f) – legitimate interest in marketing our services to businesses | 24 months after last contact |
| Compliance with legal obligations and legal claims | Relevant data as necessary | Art. 6(1)(c) and 6(1)(f) | As required |
Where we rely on legitimate interests, we have balanced our interests against your rights. You can request more information about this balancing.
Providing personal data is voluntary. However, we need certain data to conclude and perform a contract with your organisation, and to comply with legal requirements.
We do not use automated decision-making, including profiling, that produces legal effects or similarly significantly affects you.
3. Where we collect data from
We collect data directly from you, from your employer (e.g. when a colleague registers you as a user), from public sources (e.g. the Danish Central Business Register (CVR), company websites and professional networks such as LinkedIn), and from partners who refer you to us.
4. Recipients
We disclose or give access to personal data only when necessary:
- IT and service providers acting as our data processors, e.g. hosting (Microsoft Azure), service desk and CRM (Atlassian), website hosting (Webflow), e-mail and accounting systems;
- professional advisers (lawyers, auditors) bound by confidentiality;
- public authorities where required by law;
- other Peppol participants and service providers, to the extent necessary to exchange documents that you or your organisation have chosen to send.
All data processors are bound by data processing agreements.
5. Transfers outside the EU/EEA
Some of our providers (e.g. Webflow, Inc., Atlassian and Microsoft) are established in or may access data from the USA. Such transfers are based on the EU Commission’s adequacy decision for the EU-US Data Privacy Framework (for certified companies) or the EU Commission’s standard contractual clauses (Article 46(2)(c) GDPR). You can request a copy of the relevant safeguards by contacting us.
6. Your rights
Under the GDPR you have the right to:
- access the personal data we process about you;
- have inaccurate data rectified;
- have your data erased;
- restrict the processing;
- data portability (receive your data in a structured, commonly used and machine-readable format);
- withdraw your consent at any time, without affecting the lawfulness of processing before withdrawal.
Right to object: You have the right to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests (Art. 6(1)(f)). You may always object to the use of your data for direct marketing, and we will then stop such processing.
To exercise your rights, contact info@semantic.biz. We respond within one month. There may be conditions or limitations to these rights.
Complaint: You may lodge a complaint with the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, dt@datatilsynet.dk, www.datatilsynet.dk.
7. Cookies and similar technologies
semantic.biz does not use cookies for tracking, analytics or marketing. If this changes, we will ask for your consent via a cookie banner before any non-necessary cookies are set, and this section will list each cookie, its purpose, provider and duration.
When you visit the website, your browser connects to our website host (Webflow) and content delivery networks, which receive your IP address and browser information for the technical delivery and security of the website (Art. 6(1)(f)). The website loads fonts from Google Fonts, whereby Google receives your IP address.
The Semantic Portal (portal.semantic.biz) uses only strictly necessary cookies for login and session management. These do not require consent and are not used for tracking.
8. Security
We use appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration and unauthorised disclosure or access, including encryption, access control and logging.
9. Changes
We update this Privacy Policy when our processing changes. The current version is always available at semantic.biz/terms-and-conditions/privacy-policy, and the date of the latest change is stated at the top.