How we handle personal data
DitaExchange ApS is the data controller for personal data collected through this website and in the course of customer engagements. This notice explains what we collect, why, how long we keep it, and what rights you have under the EU General Data Protection Regulation and the Danish Data Protection Act.
Effective date: 2026-08-12
The data controller
DitaExchange ApS
Åbogade 15
8200 Aarhus N
Denmark
CVR-nr: 39700522
Email: privacy@ditaexchange.com
For data-protection questions, the fastest route is the privacy inbox above. We will respond within one Danish business week, and within 30 days on formal requests under GDPR Articles 15 to 22.
We are not required to appoint a Data Protection Officer under GDPR Article 37 and have not done so. Data-protection questions are handled directly by the privacy inbox.
The minimum needed to run the site and respond to inquiries
- Server logs: IP address, browser type, page requested, timestamp. Captured by our hosting provider (Cloudflare) for the operational purposes of running the site, protecting against abuse, and producing aggregated traffic statistics. Retained for 30 days.
- Contact form and email submissions: name, email address, organization, and the content of the message you send us. Used to respond to your inquiry. Retained for the duration of any resulting commercial conversation, plus the statutory retention period under Danish bookkeeping law where invoicing follows.
- Newsletter subscriptions: if you subscribe to a newsletter, your email address and any preferences you provide. Used to send the newsletter you signed up to. Retained until you unsubscribe; an unsubscribe link is in every email.
- Cookies: see the dedicated section below.
Strictly necessary cookies only on this website
This website uses cookies that are strictly necessary for the site to function. We do not use marketing cookies, analytics cookies, or third-party advertising cookies on this site. If analytics or marketing cookies are added in future, this section will be updated to reflect that and the appropriate consent mechanism will be put in place before any non-essential cookie is set.
Legal basis for processing
- Legitimate interest (Article 6(1)(f)), for server logs and abuse protection. The legitimate interest is operating a secure website.
- Consent (Article 6(1)(a)), for newsletter subscriptions, which you opt into and can withdraw at any time.
- Performance of a contract or pre-contractual steps (Article 6(1)(b)), for contact-form submissions and the commercial conversations that follow.
- Legal obligation (Article 6(1)(c)), for invoicing and bookkeeping records, which Danish law requires us to retain for five years from the end of the financial year.
Where your data is processed
We use a small number of carefully selected sub-processors to operate this website and our customer-facing services. Each one is bound by a data-processing agreement consistent with GDPR Article 28.
- Cloudflare, website hosting and content-delivery network. Server logs are processed at Cloudflare's edge nodes; Cloudflare's published data-processing addendum applies.
- Microsoft, corporate email and productivity tools (Microsoft 365). Email correspondence with us is processed inside Microsoft 365 under the Microsoft Data Protection Addendum.
- Hetzner Online GmbH, infrastructure hosting (EU, Germany). Contact and demo-request submissions made through this site are stored in our self-hosted customer-relationship-management system (Twenty), which runs on Hetzner servers in the EU under Hetzner's data-processing agreement.
If additional sub-processors are engaged after publication (for example a newsletter platform or web-analytics provider), they will be added to the list above as soon as the engagement begins.
We do not sell or rent personal data to third parties.
Where personal data leaves the EU
Some of the sub-processors above operate infrastructure outside the EU and EEA. Where personal data is transferred to such locations, we rely on the legal mechanisms recognized under GDPR Chapter V: the European Commission's 2021 Standard Contractual Clauses (Implementing Decision 2021/914), modules 2 or 3 as appropriate, and, for transfers to the United States, on each sub-processor's certification under the EU-US Data Privacy Framework where applicable. Cloudflare and Microsoft both maintain DPF certification. Hetzner Online GmbH operates within the EU, so contact and demo-request submissions stored in our self-hosted customer-relationship-management system do not leave the EEA and no third-country transfer arises for them.
Under GDPR Articles 15 to 22
- Access, request a copy of the personal data we hold about you.
- Rectification, ask us to correct inaccurate or incomplete data.
- Erasure, ask us to delete data, subject to our legal retention obligations.
- Restriction, ask us to limit how we process your data while a question is being resolved.
- Portability, receive your data in a structured, commonly used, machine-readable format.
- Objection, object to processing based on our legitimate interest.
- Withdraw consent, for processing based on consent (such as newsletter subscriptions), at any time.
To exercise any of these rights, email privacy@ditaexchange.com. We will respond within 30 days of receiving a valid request.
If you are not satisfied with our response, you have the right to complain to the Danish Data Protection Agency (Datatilsynet). Their contact details are at datatilsynet.dk.
Personal data inside the DitaExchange platform
This notice covers personal data we collect as a data controller: typically through this website, through marketing activity, and through commercial conversations with prospective customers.
Personal data that customers store inside the DitaExchange Dx5 platform (typically usernames, author identifiers, approval records, and metadata captured by the editorial workflow) is processed by DitaExchange as a data processor on behalf of the customer (the data controller). The terms of that processing are set out in the data-processing agreement that forms part of every DitaExchange customer contract. The customer remains the data controller for that data, and end-user rights requests should be directed to the customer in the first instance.
Changes to this notice
We update this notice when our processing changes. Material changes are flagged on the website and, where appropriate, communicated to active contacts by email. The effective date at the top of the page reflects the most recent update.
Previous versions are available on request from privacy@ditaexchange.com.
Questions about how your data is handled
Email privacy@ditaexchange.com. A real person reads it and will respond within one Danish business week.
Send us an email