LLinkivo
CookiesPrivacyTerms
DAEN
Home

Data protection

Privacy policy

This policy explains which personal data CT-IT ApS processes in Linkivo, why we process it and the rights available to you.

Version 2.22Updated 30 September 2026

1. Controller

CT-IT ApS, CVR 45578267, is the controller for data about visitors, contact persons, onboarding, accounts, subscriptions and support. Contact us at support@linkivo.dk.

When Linkivo transfers order, customer or employee data between a customer's systems, the customer is normally the controller and CT-IT ApS is a processor under a separate data processing agreement.

2. Data and purposes

We process company name, contact details, billing address, tax identification number, user identity, roles, login and security events, selected recipients of operational emails, product, capacity, subscription status, support enquiries and technical integration data, including selected e-conomic customer, supplier, contact, delivery, bank and invoice information. If the customer enables Linkivo supplements, we also store the selected source fields and separately stored user edits or imported files to make otherwise unsupported information available for review, maintenance and export. We use this data to enter into and perform the agreement, calculate VAT, issue invoices, send required approval, warning and error messages, secure and support the service, administer payment and document operations.

Credentials for Shopify, Rackbeat, e-conomic and other systems are encrypted before storage. One-time codes are stored only as HMAC hashes. Stripe collects the billing address, business name and supported tax identification number in Checkout. We do not store full card details.

3. Legal basis

Processing related to a business agreement is generally necessary to perform the agreement or based on our legitimate interest in delivering and securing the service. Statutory accounting data is processed to comply with legal obligations. Electronic marketing is sent only where a valid basis exists.

4. Recipients and suppliers

We use Render for hosting, Supabase for database and user administration, Stripe for payments and subscriptions, Simply.com for domain and email, and Linear for managing support enquiries and tickets. Support emails may therefore be forwarded to and stored in Linear as well as Simply.com. Our staff may also use OpenAI Codex to classify enquiries, investigate errors and prepare and send replies. This may involve processing the relevant enquiry text, contact details and necessary technical information through OpenAI. We limit the information used to what is needed for the specific enquiry; CT-IT ApS remains responsible for support. Shopify, Rackbeat, e-conomic and other connections process data under the customer's own agreement with that supplier. We share data only where required for the service, by law or by agreement. Necessary technical error and subscription notices are also sent to authorised Linkivo operations staff, separately from customer notices. Disabling customer incident emails does not disable operational incident monitoring.

If a supplier processes data outside the EU/EEA, an applicable transfer mechanism is used, such as the European Commission's standard contractual clauses where required.

5. Retention

Operational logs, operational mail queues, webhook flow data and Stripe event receipts are normally kept for no more than seven days. Login restrictions and used one-time codes are normally deleted within one day after expiry. Unverified onboarding data is normally deleted after one day, unpaid applications after 30 days and the temporary copy no later than seven days after account activation.

Minimal run counts without event content may be kept for up to 13 months to enforce and document subscription capacity. Customer, subscription, mapping and accounting data is retained as long as required for the agreement, security, documentation or legal requirements. Linkivo supplement records and transfer receipts follow the customer account retention period and are deleted with that account. Disabling a flow stops further collection but does not delete previously stored supplements. The customer can export these records before account deletion.

System choices and connection credentials

We store the selected systems, data routes, connected account identifiers and permanent links between customer and product records. Financial transfer receipts contain source and target identifiers, content hashes and transfer status so an interrupted transfer or a later system change does not create the same record again. They follow the account retention period. Open reconciliation issues are retained until resolved or the account is deleted; resolved issues expire after seven days. Operational run links may expire while the permanent receipt remains.

Shopify is connected using a customer-owned app. Client ID and client secret are encrypted before storage and used by the server to request temporary access tokens. Credentials are not included in email or support tickets. The customer can revoke access in Shopify and update the stored connection in Linkivo.

6. Security

Measures include encryption of integration secrets, HTTPS, HttpOnly cookies, one-time codes, persistent rate limiting, signed webhooks, server-side access control, customer separation and restricted database access. Employees and suppliers receive only the access they need.

7. Your rights

Depending on the circumstances, you may request access, correction, erasure, restriction or portability, or object to processing. Contact support@linkivo.dk. You may complain to the Danish Data Protection Agency at datatilsynet.dk.

8. Optional visitor statistics

Where enabled, we use Google Analytics 4 only with your consent to statistics. The legal basis is consent under Article 6(1)(a) GDPR. We measure visits to known public pages, not login, onboarding or the dashboard. Data includes cleaned page URLs and referrers, page titles, campaign labels, pseudonymous cookie identifiers and technical browser/device information. Google processes network information, including the IP address needed to receive requests; statistics are not anonymous data.

Analytics cookies and your consent choice are stored for up to 12 months. GA4 is set to retain user- and event-level data for 14 months. This setting does not apply to aggregated standard reports.

Google is an external supplier and recipient of statistics data. Processing may involve transfers outside the EU/EEA. We enable statistics only once the contractual and applicable transfer arrangements for CT-IT's account have been established. Contact support@linkivo.dk for information about the applicable arrangements.

You can withdraw consent at any time through Cookie settings → Only necessary. This stops future measurement and removes accessible GA cookies. Withdrawal does not affect the lawfulness of processing before withdrawal. See the cookie policy for details.

9. Changes

This policy is updated when processing, suppliers or the legal basis changes materially. The current version and date appear at the top of the page.

Linkivo is provided by CT-IT ApS · CVR 45578267

support@linkivo.dk

Your privacy

Choose cookies

We use necessary cookies for language, security and login. With your consent, Google Analytics measures visits to our public pages. Statistics are optional. We do not use advertising cookies. You can change or withdraw consent in Cookie settings at any time.

Cookie policy · Privacy policy