
Legal
Privacy Policy
This Privacy Policy explains how WeStorix ApS (“WeStorix”, “we”, “us” or “our”) processes personal data when you visit westorix.com, contact us, or interact with us in a business capacity. WeStorix is the data controller for the processing described in this policy unless another WeStorix group company is expressly identified at the point where personal data is collected.
1. Who we are and how to contact us
Data controller: WeStorix ApS, CVR no. 44293218, 2920 Charlottenlund, Denmark.
Email: info@westorix.com
Website: https://westorix.com
If you contact another WeStorix group company directly, that company may be an independent or joint controller for the relevant interaction. Where this is material, you will receive additional information at the point of collection.
2. Scope of this policy
This policy applies to personal data processed through the public website and to ordinary corporate communications connected with the website, including inquiries from customers, suppliers, investors, advisers, public authorities, project partners and other business contacts. It does not replace separate privacy information that may be provided for employees, job applicants, project counterparties, investors, contractual due diligence processes or other specific processing activities.
3. Personal data we may collect
Depending on how you interact with us, we may process the following categories of personal data:
-
Identity and professional information, such as name, job title, employer or organization and professional role.
-
Contact information, such as business email address, telephone number and postal address where relevant.
-
Communication data, including the content of emails, inquiries, meeting requests and other correspondence.
-
Technical and usage data, such as IP address, browser and device information, operating system, pages viewed, timestamps, referring page, approximate location derived from IP address, and website interaction data.
-
Cookie and consent data, including cookie identifiers, consent choices, consent timestamps and related technical identifiers.
-
Business relationship data, such as information relevant to a potential or existing commercial relationship, project, supplier relationship, investment dialogue or professional engagement.
-
Information you enter in a form on the website, such as your name, organization, role, email address, the topic you select and your message. If you send an open application, also your CV and any documents you attach.
-
Information required by law or for compliance purposes where relevant to a specific interaction.
We do not intentionally collect special categories of personal data through the public website. Please do not send sensitive personal data through general website or email inquiries unless it is necessary and appropriate for the purpose of your communication.
4. Why we process personal data and our legal bases
The table below summarizes the main website-related processing activities. The applicable legal basis depends on the context.
| Processing activity | Data typically involved | Purpose | Legal basis under GDPR |
|---|---|---|---|
| Website operation and security | IP address, device/browser data, logs, timestamps | Provide, maintain and secure the website; detect errors, abuse and cyber threats | Art. 6(1)(f) - legitimate interests in secure and reliable website operation |
| Responding to inquiries | Name, contact details, organization, message content | Reply to requests and manage follow-up | Art. 6(1)(f), or Art. 6(1)(b) where the inquiry concerns steps toward a contract |
| Business relationship management | Professional contact and correspondence data | Develop and manage relationships with customers, suppliers, investors, advisers and partners | Art. 6(1)(f), and Art. 6(1)(b) where relevant to a contract |
| Website forms (contact, investor materials request, white paper request) | Name, organization, role, email address, selected topic, message content | Route the request to the right person, reply and follow up | Art. 6(1)(f), or Art. 6(1)(b) where the request concerns steps toward a contract |
| Open applications | Name, contact details, CV and attached documents | Assess the application against current and upcoming positions | Art. 6(1)(b) - steps at your request before a contract; Art. 6(1)(a) - consent, where you agree to longer storage |
| Legal and compliance obligations | Relevant contact, transaction and documentation data | Comply with accounting, legal, regulatory and audit requirements; establish or defend legal claims | Art. 6(1)(c) and, where relevant, Art. 6(1)(f) |
| Analytics and non-essential cookies | Cookie ID, online identifiers, usage and device data | Understand website use, improve content and measure website performance | Art. 6(1)(a) - consent, where consent is required |
| Consent management | Consent selections, timestamp and technical identifiers | Record and respect cookie choices and demonstrate compliance | Art. 6(1)(c) and/or Art. 6(1)(f) |
Where we rely on legitimate interests, those interests include operating a professional corporate website, protecting our systems, responding to business communications, developing and managing B2B relationships and protecting our legal rights. We consider whether those interests are overridden by the rights and interests of the individual concerned.
5. Cookies and similar technologies
We use cookies and similar technologies for necessary website functions and, where you have consented, for analytics or other optional purposes. Non-essential technologies are not activated before you have given valid consent. More information is provided in our Cookie Policy.
6. Where we obtain personal data
We usually obtain personal data directly from you, for example when you email us or interact with the website. In a business context, we may also receive professional contact information from your employer or organization, from another participant in a project or transaction, from publicly available professional sources, or from a person who introduces you to us. Where GDPR Article 14 requires additional information, we will provide it within the applicable timeframe unless an exemption applies.
7. Who we share personal data with
We may disclose or make personal data available to recipients where this is necessary for the purposes described above. These may include:
-
Website hosting, maintenance, cybersecurity, backup and IT service providers.
-
Email, collaboration, document management and cloud service providers.
-
Analytics and consent-management providers, but only in accordance with your cookie choices where consent is required.
-
Professional advisers such as legal counsel, accountants, auditors, technical advisers and financing advisers where relevant.
-
Other WeStorix group companies where necessary for the relevant business interaction.
-
Public authorities, courts, regulators or law-enforcement bodies where disclosure is required or permitted by law.
-
Potential transaction counterparties in connection with a corporate transaction, financing, investment, restructuring or transfer of a business or asset, subject to appropriate confidentiality and data-protection safeguards.
Service providers processing personal data on our behalf are required to process it only in accordance with our instructions and applicable data-protection requirements, unless they act as independent controllers for a particular service.
8. International transfers
Some service providers may process personal data outside Denmark or the European Economic Area (EEA). Where personal data is transferred to a country that is not covered by an EU adequacy decision, we use an appropriate transfer mechanism where required, such as the European Commission’s Standard Contractual Clauses, together with supplementary safeguards when necessary. Where an adequacy framework applies to a relevant recipient, we may rely on that framework in accordance with applicable law.
9. How long we keep personal data
We keep personal data only for as long as necessary for the purpose for which it was collected, taking account of legal, contractual, security and documentation requirements. Typical retention periods are:
| Category | Typical retention approach |
|---|---|
| Routine website/security logs | Normally a short operational period, typically up to 30-90 days, unless a longer period is required to investigate an incident or protect legal rights. |
| General inquiries with no continuing relationship | Normally deleted or anonymized when no longer needed, typically within 24 months after the inquiry is closed. |
| Open applications | Normally deleted 6 months after receipt, unless you have agreed to a longer period. |
| Business relationship correspondence | For the duration of the relationship and thereafter for a period appropriate to contractual, limitation, audit and documentation requirements. |
| Accounting and transaction records | Retained for the period required by applicable Danish bookkeeping and tax rules, generally at least five years where the information forms part of statutory accounting records. |
| Cookie/consent records | Kept for the period necessary to respect choices and document consent or withdrawal; consent preferences are currently configured for up to 365 days on the website, subject to the live consent configuration. |
| Analytics data | According to the configured retention period of the relevant analytics service and only where the required consent has been provided. |
We may retain information for a longer period where required by law, where a dispute or investigation is ongoing, or where necessary to establish, exercise or defend legal claims.
10. Your data-protection rights
Subject to the conditions and limitations in applicable law, you may have the following rights in relation to your personal data:
-
Right of access - to obtain confirmation of whether we process your personal data and receive a copy together with relevant information about the processing.
-
Right to rectification - to have inaccurate personal data corrected and incomplete data completed.
-
Right to erasure - to request deletion in circumstances where we are required to erase the data.
-
Right to restriction - to request that processing is restricted in certain circumstances.
-
Right to object - in particular where processing is based on legitimate interests. You also have the right to object to processing for direct marketing at any time.
-
Right to data portability - where processing is based on consent or contract and is carried out by automated means, where applicable.
-
Right to withdraw consent - at any time, without affecting the lawfulness of processing carried out before withdrawal.
-
Rights relating to solely automated decisions - where such processing falls within GDPR Article 22.
To exercise a right, contact info@westorix.com. We may need to verify your identity before acting on a request. We do not charge a fee for ordinary requests, but GDPR permits a reasonable fee or refusal in the case of manifestly unfounded or excessive requests.
11. Complaints
If you have concerns about our processing of personal data, we encourage you to contact us first so that we can address the matter. You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet).
Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark
Email: dt@datatilsynet.dk
Website: https://www.datatilsynet.dk
12. Security
We use appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. Measures are selected according to risk and may include access controls, encryption in transit, system hardening, backups, logging, vulnerability management, updates and contractual controls with service providers. No internet transmission or information system can be guaranteed to be completely secure.
13. Children
westorix.com is a corporate and professional website and is not directed to children. We do not knowingly seek to collect personal data from children through the public website.
14. External websites and social media
The website may contain links to third-party websites or social-media services. When you follow such a link, the third party may process personal data under its own terms and privacy information. WeStorix is not responsible for the privacy practices of third-party websites that we do not control.
15. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in the website, our processing activities, service providers or applicable law. The current version will be available on westorix.com and will state the date of the latest update. Where a change materially affects an existing processing activity, we will provide additional notice where required.
