Lead Integration

Privacy Policy

Konverto Performance ApS

Last updated: 13 August 2026

This is a translation provided for convenience. The Danish version is the legally binding one.

This privacy policy covers both our web platform (konverto.dk) and our mobile apps for iOS and Android.

1. Data controller

We are the data controller for the processing of the personal data we receive about you. You will find our contact details below:

Konverto Performance ApS
Company reg. no. (CVR): 45602052
Address: Dunkerquegade 17, 2th, 2150 Nordhavn, Denmark
Email: support@konverto.dk

If you have questions about our processing of your personal data, you are always welcome to contact us.

2. Purposes of the processing

We process personal data for the following purposes:

2.1 Lead handling and customer service

When a potential customer fills in a contact form, for example via Facebook Lead Ads, we process the information in order to contact that person and deliver the requested service. The legal basis is GDPR article 6(1)(b) (performance of a contract) and (f) (legitimate interest in responding to enquiries).

2.2 Email communication and automation

We use automated systems to handle email correspondence on behalf of our customers. This includes receiving, categorising and replying to emails. The legal basis is GDPR article 6(1)(b) (performance of a contract with our customers) and (f) (legitimate interest in efficient customer service).

2.3 SMS communication

We send SMS messages to leads and customers as part of the follow-up process. SMS is only sent where there is an existing customer relationship or consent. The legal basis is GDPR article 6(1)(a) (consent) or (f) (legitimate interest based on an existing customer relationship).

2.4 Software-assisted communication

We use artificial intelligence from OpenAI (OpenAI LLC) and Anthropic (Anthropic PBC), both in the USA, for: drafting suggested replies to email and SMS, assessing enquiries, support chat, analysis of customers' websites, transcription and analysis of phone calls, building company profiles from public sources, and extracting appointments from emails. In that connection, names, message content, email and SMS text, phone numbers, audio recordings of calls and company information may be processed. Data is transferred encrypted (TLS) to the providers' APIs. Under OpenAI's and Anthropic's standard terms for their APIs, data is not used to train their models. The legal basis is GDPR article 6(1)(f) (legitimate interest in efficient communication and quality assurance).

2.5 Telephony and call recording

Our platform includes telephony via Twilio. When a lead calls your company's dedicated phone number, or when a lead is called from our dialer, the conversation is recorded (both parties). The recording is stored with Twilio in the USA, and an audio URL as well as a transcription is stored in our system. The transcription is made by OpenAI (Whisper) and may be analysed by AI for the purpose of summaries, quality assessment and follow-up suggestions. For incoming calls, your company can choose to play a spoken message stating that the call is recorded. For outgoing calls no automatic message is played, and it is the person placing the call who is responsible for informing the other party about the recording. We process the following: phone numbers, audio recording, transcription, call duration, direction and time. The legal basis is GDPR article 6(1)(f) (legitimate interest in documentation and quality assurance).

3. What personal data do we process?

We process the following categories of personal data:

3.1 Contact details

Name, email address, phone number, address and company information (including company registration number).

3.2 Communication data

Content of emails and SMS messages, times of communication and reply history.

3.3 Lead data

Information collected via contact forms, including which service is requested, the time of the enquiry and the source (for example Facebook Lead Ads).

3.4 Connected integrations

If you connect email services, we may process:

  • Gmail metadata and email content
  • Outlook metadata and email content
  • Email from other providers (via IMAP/SMTP)

3.5 Automatically collected data

Cookies, IP address, browser type, device information, interaction logs and authentication tokens. See section 15 on cookies below.

3.6 Mobile app - push notifications

When you install our mobile app and allow notifications, we collect and store a unique device token that is used to send you relevant notifications (for example about new emails, bookings or chat replies). The token cannot be used to identify you across apps or websites. You can turn notifications off at any time in your device settings.

For sending push notifications we use:

  • Firebase Cloud Messaging (FCM, Google LLC) for both iOS and Android. On iOS, Firebase passes the notification on to the Apple Push Notification Service (APNs).

3.7 Mobile app - technical data

Our mobile app automatically collects the following technical data:

  • Device type and model
  • Operating system and version (iOS/Android)
  • App version
  • Pseudonymous diagnostic and stability data (crash reports) that may contain technical identifiers and that is processed by Sentry in order to improve the app's stability

This data helps us ensure the app's stability and improve the user experience. We do NOT collect precise location data, contacts, photos or other data from your device without explicit permission.

4. Recipients of personal data

We disclose or entrust personal data to the following categories of recipients:

4.1 Data processors

We use a number of data processors who process personal data on our behalf. We have entered into data processing agreements with all of our data processors to ensure that your data is processed securely and in accordance with the GDPR. Our main data processors are:

  • Supabase Inc. (database and data storage), USA, with EU SCCs
  • OpenAI LLC (AI-assisted communication), USA, with EU SCCs
  • Anthropic PBC (AI-assisted extraction of appointments from email), USA, with EU SCCs
  • Twilio Inc. (SMS, telephony, call recording and provisioning of phone numbers), USA, with EU SCCs
  • Google LLC (email integration via the Gmail API, push notifications via Firebase Cloud Messaging and Google Analytics), USA, with EU SCCs
  • Microsoft Corporation (email integration via Microsoft Graph), USA, with EU SCCs
  • Meta Platforms (lead collection and ad measurement), USA, with EU SCCs
  • Resend Inc. (transactional emails, for example welcome emails and notifications), USA, with EU SCCs
  • Functional Software, Inc. (Sentry) (error and stability monitoring on web and in the app), USA, with EU SCCs
  • Hostinger International Ltd. (web hosting and server infrastructure), Lithuania (EU)
  • Stripe Inc. (payment handling and subscription management), USA, with EU SCCs

4.2 Our customers' businesses

When we process leads on behalf of our customers, the relevant information is passed on to the business in question, which is an independent data controller for the further processing.

4.3 Ad measurement when you book a meeting

If you book a meeting with us via one of our ad landing pages (for example konverto.ai/se), we send a single message to Meta Platforms Ireland Ltd. confirming that a booking took place, so we can measure whether our ads work. The message contains your email address and phone number in encrypted (hashed) form, an identifier from your ad click, and the time of the booking. We never send the content of your enquiry. The legal basis is our legitimate interest in measuring the effect of our advertising (GDPR article 6(1)(f)). You can object to this at any time by contacting us at team@konverto.dk.

5. Transfers to third countries

Some of our data processors are located in the USA (including OpenAI, Anthropic, Supabase, Twilio, Google, Microsoft, Meta, Resend, Sentry and Stripe). We ensure that the transfer takes place in accordance with the GDPR by using the European Commission Standard Contractual Clauses. We have assessed that there are adequate safeguards for the protection of your personal data.

6. Storage of personal data

We store your personal data for as long as it is necessary to fulfil the purposes for which it was collected. Specifically, the following applies:

  • Lead data: Deleted after 24 months without activity, unless a customer relationship arises
  • Email correspondence: Stored for up to 5 years for documentation purposes
  • SMS logs: Stored for 12 months
  • Call recordings and transcriptions: Stored for as long as the account is active and the associated lead exists. They are deleted when the associated lead is deleted (including by the automatic lead deletion after 24 months) or when the account is deleted.
  • Device tokens for push notifications: Stored for as long as the account is active and deleted when the account is deleted.
  • Accounting records: Stored for 5 years pursuant to the Danish Bookkeeping Act

Users may request deletion at any time.

7. Your rights

Under the General Data Protection Regulation you have a number of rights in relation to our processing of information about you:

  • Right of access: You have the right to obtain access to the data we process about you, as well as a range of further information.
  • Right to rectification: You have the right to have inaccurate data about yourself corrected.
  • Right to erasure: In special cases you have the right to have data about you deleted before the time of our ordinary general deletion.
  • Right to restriction: In certain cases you have the right to have the processing of your personal data restricted.
  • Right to object: You have the right to object to our processing of your personal data, including to marketing.
  • Right to data portability: In certain cases you have the right to receive your personal data in a structured, commonly used and machine-readable format.

You can exercise your rights by contacting us at support@konverto.dk.

8. Complaint to the Danish Data Protection Agency

You have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) if you are dissatisfied with the way we process your personal data. You will find the contact details of Datatilsynet at www.datatilsynet.dk.

9. Security

We have implemented appropriate technical and organisational security measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. This includes encryption of data in transit (TLS/HTTPS), encryption of sensitive tokens and passwords at rest, access restriction at database level (Row Level Security), regular security updating of systems and ongoing monitoring for security incidents. Our database is hosted with a provider that encrypts storage at disk level.

10. Responsibility for communication

Konverto provides a technical platform for automated communication. Customers are fully responsible for content, accuracy, compliance, legal basis, required consent, marketing legislation and email and SMS rules. Konverto cannot be held liable for communication sent via the platform.

For telephony, the customer is responsible for informing the other party that the conversation is being recorded, to the extent required by law. For incoming calls the customer may choose to have an automatic message about the recording played. For outgoing calls no automatic message is given, and the customer must inform the other party about the recording.

11. Role as data processor

Konverto acts as data controller for users visiting our website, and as data processor for customers who use our system to process leads and communication.

When Konverto is used to send messages to leads, the customer remains the data controller and Konverto acts solely as data processor under the instruction of the customer and in accordance with the GDPR and the data processing agreement.

12. Changes to the privacy policy

We reserve the right to update this privacy policy. In the event of material changes we will inform you by email or on our website. The latest version will always be available at konverto.dk.

13. Email API Services - limited use

Our use of information received from email APIs complies with the respective provider's limited use requirements.

13.1 Supported providers

  • Google Gmail (via the Gmail API)
  • Microsoft Outlook (via the Microsoft Graph API)
  • Other providers (via IMAP/SMTP)

13.2 What data we access

  • Reading and sending emails on behalf of the user
  • Email metadata (sender, recipient, subject, time)
  • Email content for processing and replying

13.3 How data is used

  • Only to send and receive emails as part of our automated communication platform
  • Data is used solely for the purposes the user has approved
  • Emails are processed to generate software-assisted replies

13.4 Storage and security

  • OAuth tokens (Google/Microsoft) and IMAP/SMTP passwords are encrypted with strong encryption (AES) and stored securely in the database
  • Email content is only logged to the extent necessary to maintain conversation history
  • Tokens and passwords are deleted automatically when the user disconnects the integration

13.5 Sharing of data

  • Email data is not shared with third parties beyond the data processors listed in section 4
  • Data is transferred to AI services (OpenAI and Anthropic) for generating replies, transcription and analysis of communication as described in section 2.4

13.6 Deletion

  • Users can disconnect the email integration via the platform at any time
  • On disconnection, all tokens and passwords are deleted immediately
  • Conversation history is deleted automatically when the user's account is deleted, or on request pursuant to section 7

13.7 Google API Services

Our use of Google APIs complies with Google's Limited Use Requirements.

13.8 Microsoft API Services

Our use of the Microsoft Graph API complies with Microsoft's API Terms of Use.

14. SMS API Services

14.1 Provider

We use Twilio (Twilio Inc.) for sending and receiving SMS messages and for telephony. Twilio is located in the USA, and the transfer takes place on the basis of the European Commission Standard Contractual Clauses (EU SCCs).

14.2 What data we process

  • Phone numbers
  • SMS content
  • Time of sending and receiving

14.3 Storage

  • SMS logs are stored for 12 months
  • When a user account is deleted, all SMS history is deleted

15. Cookies

We use cookies on our website to ensure that the platform works correctly and to improve your experience. On your first visit a cookie banner is shown where you can choose which cookies you accept.

15.1 Necessary cookies

These cookies are necessary for the website to work and cannot be switched off in our systems. They are usually only set in response to actions you take, such as logging in or filling in forms.

  • Session cookies: Keep you logged in during your visit. Expire when the browser is closed.
  • Authentication tokens: Verify your identity and access to your account. Stored securely and encrypted.
  • Cloudflare bot protection (__cf_bm): Set by our hosting provider (Supabase/Cloudflare) when video is streamed from our pages, to protect against abuse and bots. Expires after 30 minutes.
  • Calendly (booking calendar): When you open our booking calendar, it is delivered by Calendly LLC in an embedded frame, which sets cookies necessary for the calendar to work. See Calendly’s own cookie policy for details.

Our ad landing pages (konverto.ai/se) run without marketing or statistics cookies by default. Instead of the full cookie modal they show a small consent bar: only if you choose "Accept" do we load the Meta Pixel and Google Analytics described above. If you choose "Necessary only", or do nothing, no marketing or statistics cookies are set and only our own cookie-free measurement runs.

15.2 Functional cookies

These cookies make it possible to remember your preferences, such as language and theme (light/dark mode).

15.3 Marketing cookies

These cookies are set only if you give consent via our cookie banner. They are used to measure the effect of our ads and to understand how visitors interact with our website.

  • Meta Pixel (Facebook): Used to measure conversions from Facebook and Instagram ads. Sets cookies via the facebook.com domain. Data is processed by Meta Platforms Ireland Ltd. and may be transferred to the USA under the EU Standard Contractual Clauses (EU SCCs). Read more in Meta's privacy policy.

15.4 Statistics cookies

These cookies are set only if you give consent via our cookie banner. They are used to understand how visitors interact with our website so that we can improve the user experience.

  • Google Analytics 4 (Google LLC): Used to measure anonymised visit statistics, page views and conversions (signup and demo view). Sets the cookies _ga and _ga_JM6LWGSVQF on the konverto.dk domain. We have enabled IP anonymisation. Data is processed by Google LLC and may be transferred to the USA under the EU Standard Contractual Clauses (EU SCCs). Read more in Google's privacy policy.

15.5 First-party form measurement (konverto.dk)

When you fill in and submit a contact form on our website, we record the information you enter yourself (typically name, email, phone number and your message) as well as which page the form was sent from, so that we can follow up on your enquiry. The measurement is done with a first-party script that sets no cookies and shares no data with third parties. The processing is carried out by Konverto as data controller with the legal basis in GDPR article 6(1)(f) (legitimate interest in being able to respond to enquiries).

15.6 Your choices

On your first visit a cookie banner is shown where you can choose between "Accept all" (including statistics and marketing cookies) or "Necessary only". Your choice is saved so the banner is not shown again. You can change your choice at any time by deleting your cookies in the browser and reloading the page. Necessary and functional cookies do not require consent, as they are necessary for the operation of the website.

For logged-in users we record your cookie choice together with your user ID so that we can document your consent. For visitors who are not logged in, the choice is stored locally in your browser only.

16. Contact

Konverto Performance ApS
Email: support@konverto.dk
Website: konverto.dk

17. Data deletion - mobile app

If you have installed our mobile app and want your data deleted, you can:

  1. Log in to the app and go to Settings → Delete account, or
  2. Send a request to support@konverto.dk from the email you used to create the account

We process deletion requests within 30 days. Please note: if you delete your account, you lose access to all of your data, including conversation history, contact details and settings.

See also our dedicated page on data deletion at /en/data-deletion.