Privacy Policy
Konverto Performance ApS
Last updated: 13 August 2026
This is a translation provided for convenience. The Danish version is the legally binding one.
This privacy policy covers both our web platform (konverto.dk) and our mobile apps for iOS and Android.
1. Data controller
We are the data controller for the processing of the personal data we receive about you. You will find our contact details below:
Konverto Performance ApS
Company reg. no. (CVR): 45602052
Address: Dunkerquegade 17, 2th, 2150 Nordhavn, Denmark
Email: support@konverto.dk
If you have questions about our processing of your personal data, you are always welcome to contact us.
2. Purposes of the processing
We process personal data for the following purposes:
2.1 Lead handling and customer service
When a potential customer fills in a contact form, for example via Facebook Lead Ads, we process the information in order to contact that person and deliver the requested service. The legal basis is GDPR article 6(1)(b) (performance of a contract) and (f) (legitimate interest in responding to enquiries).
2.2 Email communication and automation
We use automated systems to handle email correspondence on behalf of our customers. This includes receiving, categorising and replying to emails. The legal basis is GDPR article 6(1)(b) (performance of a contract with our customers) and (f) (legitimate interest in efficient customer service).
2.3 SMS communication
We send SMS messages to leads and customers as part of the follow-up process. SMS is only sent where there is an existing customer relationship or consent. The legal basis is GDPR article 6(1)(a) (consent) or (f) (legitimate interest based on an existing customer relationship).
2.4 Software-assisted communication
We use artificial intelligence from OpenAI (OpenAI LLC) and Anthropic (Anthropic PBC), both in the USA, for: drafting suggested replies to email and SMS, assessing enquiries, support chat, analysis of customers' websites, transcription and analysis of phone calls, building company profiles from public sources, and extracting appointments from emails. In that connection, names, message content, email and SMS text, phone numbers, audio recordings of calls and company information may be processed. Data is transferred encrypted (TLS) to the providers' APIs. Under OpenAI's and Anthropic's standard terms for their APIs, data is not used to train their models. The legal basis is GDPR article 6(1)(f) (legitimate interest in efficient communication and quality assurance).
2.5 Telephony and call recording
Our platform includes telephony via Twilio. When a lead calls your company's dedicated phone number, or when a lead is called from our dialer, the conversation is recorded (both parties). The recording is stored with Twilio in the USA, and an audio URL as well as a transcription is stored in our system. The transcription is made by OpenAI (Whisper) and may be analysed by AI for the purpose of summaries, quality assessment and follow-up suggestions. For incoming calls, your company can choose to play a spoken message stating that the call is recorded. For outgoing calls no automatic message is played, and it is the person placing the call who is responsible for informing the other party about the recording. We process the following: phone numbers, audio recording, transcription, call duration, direction and time. The legal basis is GDPR article 6(1)(f) (legitimate interest in documentation and quality assurance).
3. What personal data do we process?
We process the following categories of personal data:
3.1 Contact details
Name, email address, phone number, address and company information (including company registration number).
3.2 Communication data
Content of emails and SMS messages, times of communication and reply history.
3.3 Lead data
Information collected via contact forms, including which service is requested, the time of the enquiry and the source (for example Facebook Lead Ads).
3.4 Connected integrations
If you connect email services, we may process:
- Gmail metadata and email content
- Outlook metadata and email content
- Email from other providers (via IMAP/SMTP)
3.5 Automatically collected data
Cookies, IP address, browser type, device information, interaction logs and authentication tokens. See section 15 on cookies below.
3.6 Mobile app - push notifications
When you install our mobile app and allow notifications, we collect and store a unique device token that is used to send you relevant notifications (for example about new emails, bookings or chat replies). The token cannot be used to identify you across apps or websites. You can turn notifications off at any time in your device settings.
For sending push notifications we use:
- Firebase Cloud Messaging (FCM, Google LLC) for both iOS and Android. On iOS, Firebase passes the notification on to the Apple Push Notification Service (APNs).
3.7 Mobile app - technical data
Our mobile app automatically collects the following technical data:
- Device type and model
- Operating system and version (iOS/Android)
- App version
- Pseudonymous diagnostic and stability data (crash reports) that may contain technical identifiers and that is processed by Sentry in order to improve the app's stability
This data helps us ensure the app's stability and improve the user experience. We do NOT collect precise location data, contacts, photos or other data from your device without explicit permission.
4. Recipients of personal data
We disclose or entrust personal data to the following categories of recipients:
4.1 Data processors
We use a number of data processors who process personal data on our behalf. We have entered into data processing agreements with all of our data processors to ensure that your data is processed securely and in accordance with the GDPR. Our main data processors are:
- Supabase Inc. (database and data storage), USA, with EU SCCs
- OpenAI LLC (AI-assisted communication), USA, with EU SCCs
- Anthropic PBC (AI-assisted extraction of appointments from email), USA, with EU SCCs
- Twilio Inc. (SMS, telephony, call recording and provisioning of phone numbers), USA, with EU SCCs
- Google LLC (email integration via the Gmail API, push notifications via Firebase Cloud Messaging and Google Analytics), USA, with EU SCCs
- Microsoft Corporation (email integration via Microsoft Graph), USA, with EU SCCs
- Meta Platforms (lead collection and ad measurement), USA, with EU SCCs
- Resend Inc. (transactional emails, for example welcome emails and notifications), USA, with EU SCCs
- Functional Software, Inc. (Sentry) (error and stability monitoring on web and in the app), USA, with EU SCCs
- Hostinger International Ltd. (web hosting and server infrastructure), Lithuania (EU)
- Stripe Inc. (payment handling and subscription management), USA, with EU SCCs
4.2 Our customers' businesses
When we process leads on behalf of our customers, the relevant information is passed on to the business in question, which is an independent data controller for the further processing.
4.3 Ad measurement when you book a meeting
If you book a meeting with us via one of our ad landing pages (for example konverto.ai/se), we send a single message to Meta Platforms Ireland Ltd. confirming that a booking took place, so we can measure whether our ads work. The message contains your email address and phone number in encrypted (hashed) form, an identifier from your ad click, and the time of the booking. We never send the content of your enquiry. The legal basis is our legitimate interest in measuring the effect of our advertising (GDPR article 6(1)(f)). You can object to this at any time by contacting us at team@konverto.dk.
5. Transfers to third countries
Some of our data processors are located in the USA (including OpenAI, Anthropic, Supabase, Twilio, Google, Microsoft, Meta, Resend, Sentry and Stripe). We ensure that the transfer takes place in accordance with the GDPR by using the European Commission Standard Contractual Clauses. We have assessed that there are adequate safeguards for the protection of your personal data.
6. Storage of personal data
We store your personal data for as long as it is necessary to fulfil the purposes for which it was collected. Specifically, the following applies:
- Lead data: Deleted after 24 months without activity, unless a customer relationship arises
- Email correspondence: Stored for up to 5 years for documentation purposes
- SMS logs: Stored for 12 months
- Call recordings and transcriptions: Stored for as long as the account is active and the associated lead exists. They are deleted when the associated lead is deleted (including by the automatic lead deletion after 24 months) or when the account is deleted.
- Device tokens for push notifications: Stored for as long as the account is active and deleted when the account is deleted.
- Accounting records: Stored for 5 years pursuant to the Danish Bookkeeping Act
Users may request deletion at any time.
7. Your rights
Under the General Data Protection Regulation you have a number of rights in relation to our processing of information about you:
- Right of access: You have the right to obtain access to the data we process about you, as well as a range of further information.
- Right to rectification: You have the right to have inaccurate data about yourself corrected.
- Right to erasure: In special cases you have the right to have data about you deleted before the time of our ordinary general deletion.
- Right to restriction: In certain cases you have the right to have the processing of your personal data restricted.
- Right to object: You have the right to object to our processing of your personal data, including to marketing.
- Right to data portability: In certain cases you have the right to receive your personal data in a structured, commonly used and machine-readable format.
You can exercise your rights by contacting us at support@konverto.dk.
8. Complaint to the Danish Data Protection Agency
You have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) if you are dissatisfied with the way we process your personal data. You will find the contact details of Datatilsynet at www.datatilsynet.dk.
9. Security
We have implemented appropriate technical and organisational security measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. This includes encryption of data in transit (TLS/HTTPS), encryption of sensitive tokens and passwords at rest, access restriction at database level (Row Level Security), regular security updating of systems and ongoing monitoring for security incidents. Our database is hosted with a provider that encrypts storage at disk level.
10. Responsibility for communication
Konverto provides a technical platform for automated communication. Customers are fully responsible for content, accuracy, compliance, legal basis, required consent, marketing legislation and email and SMS rules. Konverto cannot be held liable for communication sent via the platform.
For telephony, the customer is responsible for informing the other party that the conversation is being recorded, to the extent required by law. For incoming calls the customer may choose to have an automatic message about the recording played. For outgoing calls no automatic message is given, and the customer must inform the other party about the recording.
11. Role as data processor
Konverto acts as data controller for users visiting our website, and as data processor for customers who use our system to process leads and communication.
When Konverto is used to send messages to leads, the customer remains the data controller and Konverto acts solely as data processor under the instruction of the customer and in accordance with the GDPR and the data processing agreement.
12. Changes to the privacy policy
We reserve the right to update this privacy policy. In the event of material changes we will inform you by email or on our website. The latest version will always be available at konverto.dk.
13. Email API Services - limited use
Our use of information received from email APIs complies with the respective provider's limited use requirements.
13.1 Supported providers
- Google Gmail (via the Gmail API)
- Microsoft Outlook (via the Microsoft Graph API)
- Other providers (via IMAP/SMTP)
13.2 What data we access
- Reading and sending emails on behalf of the user
- Email metadata (sender, recipient, subject, time)
- Email content for processing and replying
13.3 How data is used
- Only to send and receive emails as part of our automated communication platform
- Data is used solely for the purposes the user has approved
- Emails are processed to generate software-assisted replies
13.4 Storage and security
- OAuth tokens (Google/Microsoft) and IMAP/SMTP passwords are encrypted with strong encryption (AES) and stored securely in the database
- Email content is only logged to the extent necessary to maintain conversation history
- Tokens and passwords are deleted automatically when the user disconnects the integration
13.5 Sharing of data
- Email data is not shared with third parties beyond the data processors listed in section 4
- Data is transferred to AI services (OpenAI and Anthropic) for generating replies, transcription and analysis of communication as described in section 2.4
13.6 Deletion
- Users can disconnect the email integration via the platform at any time
- On disconnection, all tokens and passwords are deleted immediately
- Conversation history is deleted automatically when the user's account is deleted, or on request pursuant to section 7
13.7 Google API Services
Our use of Google APIs complies with Google's Limited Use Requirements.
13.8 Microsoft API Services
Our use of the Microsoft Graph API complies with Microsoft's API Terms of Use.
14. SMS API Services
14.1 Provider
We use Twilio (Twilio Inc.) for sending and receiving SMS messages and for telephony. Twilio is located in the USA, and the transfer takes place on the basis of the European Commission Standard Contractual Clauses (EU SCCs).
14.2 What data we process
- Phone numbers
- SMS content
- Time of sending and receiving
14.3 Storage
- SMS logs are stored for 12 months
- When a user account is deleted, all SMS history is deleted
16. Contact
Konverto Performance ApS
Email: support@konverto.dk
Website: konverto.dk
17. Data deletion - mobile app
If you have installed our mobile app and want your data deleted, you can:
- Log in to the app and go to Settings → Delete account, or
- Send a request to support@konverto.dk from the email you used to create the account
We process deletion requests within 30 days. Please note: if you delete your account, you lose access to all of your data, including conversation history, contact details and settings.
See also our dedicated page on data deletion at /en/data-deletion.