CVR Pilot provides a B2B lead-generation platform at cvrpilot.dk and app.cvrpilot.dk. We are the data controller for the personal data described here — including the dataset of business contacts we build.
This policy covers two groups: A. platform users (people who create an account — §3) and B. lead/prospect data (business contacts we collect from public sources and make available in the product — §4). If you landed here because your details appear as a lead, §4 and §7 are for you.
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Account (name, email, hashed password, workspace) | Create & secure your account; provide the service | Contract — Art. 6(1)(b) |
| Google login identity, session tokens | Secure login | Contract — Art. 6(1)(b) |
| Billing (plan, credits, transactions) | Take payment, manage subscription | Contract — Art. 6(1)(b); Legal obligation (bookkeeping) — Art. 6(1)(c) |
| Usage & technical (activity, IP, logs) | Operate, secure, debug & improve; prevent abuse | Legitimate interests — Art. 6(1)(f) |
| Marketing email (optional) | Send updates you asked for | Consent — Art. 6(1)(a), withdrawable at any time |
We collect no sensitive data, and the service is not directed at children. Card details are entered directly with Stripe and are never seen or stored by CVR Pilot.
CVR Pilot finds and qualifies companies and shows publicly available business contact data. We are not an outreach tool — how a customer contacts a lead is the customer's own action and the customer's own responsibility.
info@, switchboard, CVR
number) are not personal data. A named individual can object or have their name erased and
suppressed — including across backups (§7).CVR Pilot provides data; we do not send marketing on anyone's behalf. Our customers warrant in our terms that their outreach is lawful (including § 10 of the Danish Marketing Practices Act). A message you receive as a lead was sent by the customer — not by CVR Pilot. You can still exercise your rights with us (§7).
We share personal data only with selected vendors under a data-processing agreement. We do not sell personal data.
| Vendor | Purpose | Transfer basis |
|---|---|---|
| Anthropic | AI enrichment of lead data (Claude) | US — SCCs + DPA (incorporated into Anthropic's commercial terms); no training on submitted data; inputs/outputs deleted within 30 days |
| DigitalOcean | Hosting app + database | EU — Frankfurt (fra1) |
| DigitalOcean Spaces | Encrypted off-server database backups | EU — Frankfurt; AES-256-encrypted before upload |
| Login (OAuth) + Maps/Places lookups | SCCs / EU-US Data Privacy Framework | |
| Stripe | Payments | SCCs / EU-US Data Privacy Framework |
| Brevo (Sendinblue) | Transactional & (opt-in) marketing email | EU (France) |
| Cloudflare (Turnstile) | Bot & abuse protection at signup & login | SCCs / DPF |
| Simply.com | Marketing-site hosting + email | EU (Denmark) |
Where a vendor processes data outside the EEA, the transfer is covered by SCCs and/or the vendor's Data Privacy Framework certification.
You have the right to access, rectification, erasure, restriction of processing, objection and data portability — and you can withdraw a consent at any time.
Send a request — we'll email you a link so we know it's you, then handle the request within one month:
We respond within one month. You can also complain to Datatilsynet (the Danish Data Protection Authority).
Active accounts: kept while the account is active. Deleted accounts: removed from the live system immediately on confirmed deletion — except records required by law. Inactive free accounts: deleted after 12 months. Bookkeeping data: per the Danish Bookkeeping Act (typically 5 years). Raw collected lead page text: 90 days, after which the text is deleted automatically. Structured lead data (company details and — where publicly listed — a contact person's name and job function): kept while the company is active and relevant as a business lead, and erased and suppressed immediately on objection or an erasure request (§7). Security access logs (with IP address): 7 days, rolling. Application & error logs: 90 days. Backups: encrypted, EU-hosted, rolling ~30-day retention.
When you delete your account (a two-step, email-confirmed process), your workspace data is removed from the live system immediately and your Stripe subscription is cancelled. Residual copies exist only in encrypted backups, which expire within ~30 days. Because backups are point-in-time snapshots, we keep a separate erasure log that is re-applied whenever a backup is restored — so restoring an older backup never brings deleted data back. The same erasure-and-suppression approach applies to erasure requests for lead/prospect data (§7).
We use a single essential session cookie (__Host-lv_session; HttpOnly, Secure, SameSite=Lax) to
keep you signed in. Essential cookies do not require consent. On the signup, login and privacy-request
forms we additionally load Cloudflare Turnstile for bot and abuse protection — a
third-party service that accesses your device and may set a cookie strictly necessary for that purpose.
It is not used for profiling or marketing. We use no third-party advertising or analytics trackers.
TLS/HTTPS in transit (HSTS), scrypt-hashed passwords, HttpOnly session tokens with expiry and revocation on logout/password reset, strict security headers, tenant isolation, rate-limiting, and automated edge-level blocking of abusive traffic (e.g. request floods) informed by short-lived access logs. In the event of a notifiable breach we notify you and Datatilsynet as required.
We may update this policy; material changes are notified by email and/or in the app, and the "Last updated" date changes.