Privacy Policy
Last Updated: 30.10.2024
1. Introduction
Welcome to BetterDanish ("we," "us," or "our"), a service provided by Dotmethod ApS. We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Danish learning tool ("Service").
2. Data Controller
Dotmethod ApS is the data controller for your personal data. If you have any questions about this Privacy Policy or our data practices, please contact our Data Protection Officer (DPO):
3. Personal Data We Collect
We collect the following personal data:
- Identity Data: Name, email address, and avatar image.
- Payment Data: Billing address and credit card information (processed securely by Stripe).
- Usage Data: Information about how you interact with our Service.
- Authentication Data: Google account information (name, email, avatar) when you use Google for authentication.
4. How We Collect Your Data
We collect data through:
- Direct Interactions: When you create an account, subscribe to our Service, or contact us.
- Automated Technologies: Through your use of the Service, we collect Usage Data using cookies and similar technologies.
- Third Parties: We receive personal data from Google when you use it for authentication.
5. Purpose of Processing
We process your personal data for the following purposes:
- Account Creation and Management: To register you as a user and manage your account.
- Service Delivery: To provide and personalize our Service.
- Payment Processing: To process your payments securely via Stripe.
- Analytics: To analyze Usage Data for improving our Service (using our own tool, joinstorywise.com).
- Legal Compliance: To comply with legal obligations.
6. Legal Basis for Processing
Our legal bases for processing your personal data under GDPR are:
- Contractual Necessity: Processing is necessary for the performance of a contract with you.
- Legal Obligation: To comply with applicable laws and regulations.
- Legitimate Interests: For our legitimate interests in improving and securing our Service.
- Consent: When you have given consent for specific processing activities.
7. Cookies and Similar Technologies
We use essential cookies that are necessary for the operation of our Service. These cookies enable core functionalities such as security, network management, and accessibility. Without them, the Service cannot function properly, and they cannot be switched off in our systems.
The essential cookies we use are:
- auth_session: This cookie is used to manage your authentication session. It allows you to log in securely and maintain your session while you navigate through the Service.
- INGRESSCOOKIE: This cookie is used by our infrastructure for load balancing and to ensure that your requests are properly routed within our server infrastructure.
These cookies are classified as "strictly necessary" under the EU ePrivacy Directive and do not require your consent. However, we believe in transparency and want to inform you about their use.
For more information on how to manage cookies in your browser settings, please refer to your browser's help documentation. Please note that disabling essential cookies may affect the functionality of the Service.
8. Data Sharing and Disclosure
We do not sell or rent your personal data. We may share your data with:
- Service Providers: Third-party vendors such as OpenAI (for API services), Hetzner (for cloud hosting), Stripe (for payment processing), Google (for authentication), Sendgrid (for email delivery).
- Legal Authorities: If required by law or to protect our rights.
9. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), such as when using OpenAI's API services. We ensure appropriate safeguards are in place to protect your data, including standard contractual clauses or other legal mechanisms.
10. Data Security
We implement robust security measures to protect your personal data:
- Encryption: Data encryption in transit (HTTPS) and encryption of backups.
- Secure Storage: Data is stored securely on our servers with appropriate access controls.
11. Data Retention
We retain your personal data for as long as your account is active and for an additional 30 days in backup storage. Payment information may be retained longer to comply with legal and regulatory obligations.
12. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Access: Request access to your personal data.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data.
- Objection: Object to processing based on legitimate interests.
- Restriction: Request restriction of processing.
- Data Portability: Request transfer of your data to you or a third party.
- Withdrawal of Consent: Withdraw consent at any time, where we are relying on consent to process your data.
To exercise your rights, please contact our DPO at [email protected].
13. Age Restrictions
Our Service is intended for users who are 18 years of age or older. We do not knowingly collect data from minors.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this Privacy Policy periodically. If we make material changes, we may notify you via email or through our Service.
15. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us:
Please review this Privacy Policy carefully. By using our Service, you acknowledge that you have read and understood this policy.