Last Updated: 9 August 2026
§1. Introduction and Purpose
§2. Data Controller
§3. Personal Data We Collect
Depending on how you interact with us, we may process:
Contact and Identity Data
Your name, employer, job title, business address, email address, telephone number and other contact details.
Enquiry and Communication Data
Messages, meeting notes, correspondence, support requests and other information you provide when contacting or communicating with us.
Client, Supplier and Project Data
Contract details, project records, business requirements, account contacts, deliverables, approvals, time records and information required to manage an engagement or commercial relationship.
Transaction and Administration Data
Billing details, invoice information, payment status, VAT information and related accounting records. We do not normally receive or store complete payment-card details.
Website and Technical Data
IP address, browser and device information, timestamps, requested pages, referral information, security logs and similar technical information generated when you use our website.
Preference and Consent Data
Your communication preferences, cookie choices and any consent you give or withdraw.
Recruitment Data
Your CV, application, portfolio, professional history, interview notes, references and related recruitment information when you apply to work or collaborate with us.
Public and Professional Information
Relevant information obtained from public registers, company websites, professional networks or referrals, such as your role, employer and publicly available professional contact details.
Please do not send us special-category personal data, criminal-offence data or confidential personal information unless it is necessary and we have agreed an appropriate method for handling it.
§4. How We Collect Personal Data
We may collect personal data:
directly from you through email, forms, calls, meetings, contracts or other interactions;
from the organisation you represent, project participants or professional advisers;
automatically through our website and essential technical infrastructure;
from public registers, company websites and professional platforms; or
from service providers used to operate our business, where permitted by law.
If we receive your personal data from another source, we will provide any additional information required by law within the applicable period, unless an exemption applies.
§5. Why We Process Personal Data and Our Legal Bases
We process personal data only when we have a lawful basis.
Operating and Securing the Website
We process technical and security data to deliver the website, maintain performance, prevent misuse, diagnose faults and protect our systems.
Legal basis: our legitimate interests in operating a reliable and secure website, GDPR Article 6(1)(f), and compliance with legal obligations where applicable, GDPR Article 6(1)(c).
Responding to Enquiries and Developing Business Relationships
We process contact and communication data to respond to requests, arrange meetings, prepare proposals and discuss possible engagements.
Legal basis: steps taken at your request before entering a contract, GDPR Article 6(1)(b), or our legitimate interests in communicating with prospective clients and partners, GDPR Article 6(1)(f).
Providing Services and Managing Engagements
We process client, project and communication data to enter into and perform agreements, deliver consulting and development services, provide support, manage projects and maintain professional relationships.
Legal basis: performance of a contract or pre-contractual steps, GDPR Article 6(1)(b), and our legitimate interests in administering business-to-business engagements, GDPR Article 6(1)(f).
Billing, Accounting and Legal Compliance
We process transaction, contract and administration data to issue invoices, receive payments, keep accounting records, establish or defend legal claims and meet tax, bookkeeping and other legal obligations.
Legal basis: compliance with legal obligations, GDPR Article 6(1)(c), and our legitimate interests in financial administration and protecting our legal rights, GDPR Article 6(1)(f).
Recruitment and Professional Collaboration
We process recruitment data to assess applications, conduct interviews, communicate with candidates and decide whether to enter into an employment or collaboration agreement.
Legal basis: steps taken before entering a contract, GDPR Article 6(1)(b), and our legitimate interests in recruiting suitable personnel and collaborators, GDPR Article 6(1)(f). Where required for particular information, we rely on consent or another basis permitted by law.
Analytics, Preferences and Non-Essential Technologies
Where we use non-essential cookies or similar technologies, we process related identifiers and usage data to understand website performance or support other disclosed purposes.
Legal basis: your consent, GDPR Article 6(1)(a). You may withdraw consent at any time through the website’s cookie settings without affecting processing carried out before withdrawal.
Direct Marketing
We may send relevant business communications where you have requested them, consented to receive them, or where another lawful basis permits us to do so. You can opt out at any time using the method in the communication or by contacting us.
Legal basis: consent where required, GDPR Article 6(1)(a), or our legitimate interests in communicating about relevant business services where permitted, GDPR Article 6(1)(f). Applicable electronic-marketing rules also apply.
§6. Whether You Must Provide Personal Data
You may browse the public parts of our website without directly identifying yourself, although essential technical data may still be processed.
Where personal data is needed to respond to an enquiry, enter into an agreement, deliver services, make payment or meet a legal requirement, failure to provide it may mean that we cannot respond, contract with you or provide the relevant service. We will indicate where information is required when this is not otherwise clear.
§7. Cookies and Similar Technologies
Our website may use cookies and similar technologies. Technologies that are strictly necessary for the website may operate without consent where permitted by law. Analytics, marketing or other non-essential technologies will not be used until any consent required by law has been obtained.
The cookie banner or cookie settings available on the website provide current information about the technologies in use, their purposes, providers and durations. You can use those settings to give, refuse or withdraw consent. You can also configure your browser to restrict cookies, although this may affect website functionality.
§8. How We Share Personal Data
We may share personal data, where necessary, with the following categories of recipients:
hosting, website, communications, cloud, collaboration and IT-support providers;
professional advisers, including accountants, auditors, legal advisers and insurers;
payment, banking and financial-administration providers;
contractors and specialist collaborators involved in an engagement and subject to appropriate confidentiality obligations;
public authorities, courts, regulators or law-enforcement bodies where disclosure is required or permitted by law;
a purchaser, investor or adviser involved in a genuine corporate transaction, subject to appropriate safeguards; and
other parties where you instruct us or give valid consent.
Service providers that process personal data on our behalf may do so only under our instructions, for agreed purposes and subject to appropriate contractual, confidentiality and security obligations.
We do not sell personal data.
§9. International Data Transfers
We aim to use service providers and storage locations within the European Economic Area (“EEA”) where reasonably practicable. Some providers or their support operations may nevertheless process personal data outside the EEA.
Where personal data is transferred to a country outside the EEA that has not been recognised as providing an adequate level of protection, we use an approved transfer mechanism where required, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where appropriate.
You may contact us for further information about the safeguards relevant to your personal data.
§10. Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including to meet legal, accounting, security and reporting requirements and to establish or defend legal claims.
Our typical retention approach is:
enquiries and pre-contract correspondence: normally up to two years after the last substantive contact, unless an engagement begins or a longer period is justified;
client, supplier and project records: for the duration of the relationship and normally up to five years after it ends, subject to contractual and legal requirements;
invoices and accounting records: for the period required by applicable Danish bookkeeping and tax law;
unsuccessful recruitment applications: normally up to six months after the recruitment process ends, unless you consent to longer retention;
security and technical logs: for a limited period appropriate to operational and security needs; and
consent records: for as long as needed to document the consent and an appropriate period after withdrawal.
Specific records may be kept for a shorter or longer period where necessary because of an ongoing relationship, a legal obligation, a dispute, a security incident or the establishment, exercise or defence of legal claims. We delete or anonymise personal data when it is no longer required.
§11. Data Security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are selected according to the nature of the data, the context of processing and the relevant risks and may include access controls, authentication, encryption, backups, system updates, logging, data minimisation and confidentiality requirements.
No method of transmission or storage is completely secure. If a personal-data breach is likely to create a risk to individuals, we will notify the relevant supervisory authority without undue delay and, where required, notify affected individuals.
§12. Client Data and AI Services
Our consulting, software and AI work may involve data supplied or controlled by a client. The relevant agreement determines each party’s role and responsibilities.
Where Graph acts as a data processor, we process personal data only on the client’s documented instructions, subject to the applicable data processing agreement. Requests concerning that data should normally be directed to the relevant client as controller.
We do not use client personal data to train general-purpose AI models for our own purposes unless this has been expressly agreed with the client and a valid legal basis and appropriate safeguards are in place. The use of any third-party AI service, including its data location and retention configuration, is assessed in the context of the relevant engagement.
Clients should avoid supplying personal data that is unnecessary for an engagement and should not provide special-category data or criminal-offence data unless its use has been expressly agreed and is lawful.
§13. Automated Decision-Making
We do not currently use personal data covered by this policy to make decisions based solely on automated processing that produce legal effects or similarly significant effects for individuals.
If this changes, we will provide the information required by law, including meaningful information about the logic involved and the significance and expected consequences of the processing.
§14. Your Data-Protection Rights
Subject to the conditions and limitations in applicable law, you may have the right to:
request access to your personal data and information about how it is processed;
request correction of inaccurate or incomplete personal data;
request deletion of personal data;
request restriction of processing;
object to processing based on legitimate interests and object at any time to direct marketing;
receive personal data you provided in a structured, commonly used and machine-readable format and, where applicable, have it transmitted to another controller;
withdraw consent at any time, without affecting the lawfulness of earlier processing; and
obtain human intervention and contest a qualifying solely automated decision.
To exercise a right, email hello@graphtechnologies.xyz with the subject line “Personal Data Request”. Please describe your request and the interaction or service concerned. We may ask for information necessary to verify your identity and protect personal data against unauthorised disclosure.
We normally respond without undue delay and within one month. The period may be extended by up to two further months for complex or numerous requests, in which case we will explain the extension. Rights are not absolute, and we may retain or continue processing information where law permits or requires it.
§15. Complaints
If you have concerns about how we process personal data, please contact us first so that we can investigate and respond.
You also have the right to lodge a complaint with the Danish Data Protection Agency:
Datatilsynet,
Carl Jacobsens Vej 35,
2500 Valby,
Denmark
https://datatilsynet.dk
If you live or work elsewhere in the EEA, you may also contact the data-protection authority in the relevant country.
§16. Children
Our website and services are intended for businesses and professionals and are not directed at children. We do not knowingly collect personal data from children through the website. If you believe a child has provided personal data to us without appropriate authorisation, please contact us.
§17. Third-Party Websites and Services
Our website may link to websites or services operated by third parties. Their processing of personal data is governed by their own privacy notices, and we are not responsible for their independent privacy practices. We encourage you to review the relevant notice before providing personal data.
§18. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our services, technology, legal obligations or processing practices. The current version will be published on this page with an updated “Last Updated” date.
Where a change materially affects how we process personal data, we will provide additional notice where required by law.