Privacy Policy

1. Summary

2. Who is responsible

Webkonsulenterne A/S is the data controller for Projectly accounts, the public website and our operation of the service. Questions and requests to exercise your rights can be sent to [email protected].

An organisation using a Projectly workspace may separately be the controller for personal data it puts into that workspace. In that situation, we process the workspace content to provide Projectly on the organisation's instructions.

3. What we process and why

We receive account data from you, workspace content from you and other members, and limited delivery or event data from services you connect. Projectly is not directed to children under 18, and we do not knowingly create accounts for them.

4. How we use information

We use personal data to authenticate you; operate workspaces and permissions; save, search and display your work; send requested notifications; provide integrations; answer support requests; monitor reliability and security; and comply with legal obligations. We do not use your workspace content to build advertising profiles, and we do not sell personal data.

Workspace members can see content and profile information according to their workspace and project permissions. Owners and authorised administrators can manage membership and may be able to access activity and AI-usage information for their workspace.

5. AI features and connected services

AI is optional. When you use an AI feature, Projectly sends your prompt and the relevant task, project, comment or planning context to the provider configured for you or the workspace. Supported configurations include OpenAI, Anthropic, Google Gemini, OpenRouter and a custom OpenAI-compatible endpoint. The chosen provider processes that data under its own terms and privacy policy. A workspace owner or administrator may supply the key used by members.

Projectly stores encrypted API keys and usage metadata, not a separate permanent prompt log. AI chat history is held in your signed-in session, Telegram assistant context is cached for about 30 minutes, and generated responses may be cached for up to 12 hours depending on the feature. Content is retained normally if you choose to save an AI result into a task, comment or other workspace record.

6. Who receives data

We disclose data only as needed to operate Projectly: to hosting, storage, email and real-time infrastructure providers acting for us; to the AI or messaging provider you choose; to workspace members you collaborate with; to professional advisers under confidentiality; or to authorities when the law requires it. We may transfer relevant records to a successor if Projectly or our business is reorganised or sold, subject to appropriate protections.

7. Transfers outside the EU/EEA

Projectly is operated by a Danish company. Some providers, particularly AI, cloud, email and messaging services, may process data outside the EU/EEA. Where GDPR requires it, transfers rely on an adequacy decision, the European Commission's standard contractual clauses or another lawful safeguard. Contact us for information about the safeguards used for a specific provider.

8. How long we keep information

You can delete your account from Settings. Some content shared in a workspace may remain under another member's or organisation's control. We may retain records longer where necessary to establish legal claims, respond to an incident or comply with law.

9. Cookies and local storage

The signed-in service uses strictly necessary cookies for your session, sign-in persistence and protection against cross-site request forgery. Projectly also uses browser storage for interface preferences such as appearance. These technologies are needed for the service you request and are not used for third-party advertising. If you block them, sign-in and parts of the interface may not work.

10. Security

We use measures appropriate to the service, including password hashing, encryption of stored AI credentials, authenticated access controls, role-based workspace permissions, private attachment downloads, signed or secret integration URLs, rate limiting and transport encryption in production. No internet service is risk-free, so keep your credentials and private calendar links secure and tell us promptly about suspected misuse.

11. Your rights

Under the GDPR, you may have rights to access, correct or delete personal data; restrict or object to processing; receive portable data; and withdraw consent where processing is based on consent. Email [email protected]. We may ask you to verify your identity and will normally respond within one month.

You may complain to your local supervisory authority. In Denmark, the authority is Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark — datatilsynet.dk.

12. Changes to this policy

We update this policy when Projectly, our providers or applicable law changes. Material changes will be announced in the service or by email where appropriate. The current version and effective date are shown at the top.

13. Company details

Webkonsulenterne A/S
CVR 45330710
Hadsundvej 112, 9550 Mariager, Denmark
+45 54 62 54 21
[email protected] · webkonsulenterne.dk