§ Legal
Privacy Policy
- Summary
- Who is responsible
- What we process
- How we use it
- AI and integrations
- Who receives data
- International transfers
- Retention
- Cookies
- Security
- Your rights
- Company details
1. Summary
Projectly stores the account and workspace information needed to run a collaborative task manager. We do not sell personal data or use workspace content for advertising. Optional AI, Telegram, email and calendar features share data only when needed to provide the feature you choose.
2. Who is responsible
Webkonsulenterne A/S is the data controller for Projectly accounts, the public website and our operation of the service. Questions and requests to exercise your rights can be sent to [email protected].
An organisation using a Projectly workspace may separately be the controller for personal data it puts into that workspace. In that situation, we process the workspace content to provide Projectly on the organisation's instructions.
3. What we process and why
| Category | Examples | Purpose and legal basis |
|---|---|---|
| Account and security | Name, email, password hash, verification status, two-factor details, recovery codes, sign-in session, IP address and browser information. | Create and secure your account; perform our contract and protect the service and users (legitimate interests). |
| Profile and preferences | Time zone, appearance, notification settings, planning preferences and account status. | Personalise and operate the service; perform our contract. |
| Workspace content | Workspace and project names, tasks, descriptions, deadlines, assignments, comments, attachments, time entries, tags, dependencies and membership roles. | Store, organise, search and share the work you ask Projectly to manage; perform our contract. |
| Communications | Invitations, notification email addresses, Telegram chat identifiers and messages, inbound task emails, feedback and support messages. | Deliver invitations, reminders, notifications, task capture and support; perform our contract and respond to requests. |
| AI configuration and usage | Selected provider and model, encrypted API keys, feature used, token counts, duration, estimated cost and error information. | Provide optional AI tools, protect credentials, troubleshoot and attribute usage; consent/request and legitimate interests. |
| Operational data | Application logs, notification delivery status, timestamps, rate-limit counters and error reports. | Keep Projectly reliable, prevent abuse and diagnose incidents; legitimate interests. |
We receive account data from you, workspace content from you and other members, and limited delivery or event data from services you connect. Projectly is not directed to children under 18, and we do not knowingly create accounts for them.
4. How we use information
We use personal data to authenticate you; operate workspaces and permissions; save, search and display your work; send requested notifications; provide integrations; answer support requests; monitor reliability and security; and comply with legal obligations. We do not use your workspace content to build advertising profiles, and we do not sell personal data.
Workspace members can see content and profile information according to their workspace and project permissions. Owners and authorised administrators can manage membership and may be able to access activity and AI-usage information for their workspace.
5. AI features and connected services
AI is optional. When you use an AI feature, Projectly sends your prompt and the relevant task, project, comment or planning context to the provider configured for you or the workspace. Supported configurations include OpenAI, Anthropic, Google Gemini, OpenRouter and a custom OpenAI-compatible endpoint. The chosen provider processes that data under its own terms and privacy policy. A workspace owner or administrator may supply the key used by members.
Projectly stores encrypted API keys and usage metadata, not a separate permanent prompt log. AI chat history is held in your signed-in session, Telegram assistant context is cached for about 30 minutes, and generated responses may be cached for up to 12 hours depending on the feature. Content is retained normally if you choose to save an AI result into a task, comment or other workspace record.
- Telegram: if linked, Telegram receives and delivers bot messages and exposes the chat identifier needed to reply.
- Email: our configured mail provider processes addresses and message content needed to deliver invitations, reminders and notifications.
- Calendar feeds: anyone holding your private feed URL may read the task information exposed by that feed. Regenerate or stop sharing the URL if it is disclosed.
- Real-time updates: where a hosted real-time provider is configured, it carries authenticated event data needed to update the interface.
- Public-site fonts: the marketing site may request font files from Google Fonts, which receives ordinary request information such as IP address and browser headers.
6. Who receives data
We disclose data only as needed to operate Projectly: to hosting, storage, email and real-time infrastructure providers acting for us; to the AI or messaging provider you choose; to workspace members you collaborate with; to professional advisers under confidentiality; or to authorities when the law requires it. We may transfer relevant records to a successor if Projectly or our business is reorganised or sold, subject to appropriate protections.
7. Transfers outside the EU/EEA
Projectly is operated by a Danish company. Some providers, particularly AI, cloud, email and messaging services, may process data outside the EU/EEA. Where GDPR requires it, transfers rely on an adequacy decision, the European Commission's standard contractual clauses or another lawful safeguard. Contact us for information about the safeguards used for a specific provider.
8. How long we keep information
- Account and workspace data: while the account or workspace is active, then deleted or anonymised within a reasonable period after closure, subject to shared-workspace ownership, backups and legal obligations.
- Deleted tasks: may remain recoverable for a limited operational period before permanent deletion and may persist temporarily in backups.
- Sessions and short-lived caches: until expiry, sign-out or clearing; the standard signed-in session expires after inactivity according to the deployed configuration.
- AI and Telegram context caches: generally between a few minutes and 12 hours, depending on the feature.
- Logs and delivery records: only as long as reasonably needed for security, reliability, support and accountability.
You can delete your account from Settings. Some content shared in a workspace may remain under another member's or organisation's control. We may retain records longer where necessary to establish legal claims, respond to an incident or comply with law.
9. Cookies and local storage
The signed-in service uses strictly necessary cookies for your session, sign-in persistence and protection against cross-site request forgery. Projectly also uses browser storage for interface preferences such as appearance. These technologies are needed for the service you request and are not used for third-party advertising. If you block them, sign-in and parts of the interface may not work.
10. Security
We use measures appropriate to the service, including password hashing, encryption of stored AI credentials, authenticated access controls, role-based workspace permissions, private attachment downloads, signed or secret integration URLs, rate limiting and transport encryption in production. No internet service is risk-free, so keep your credentials and private calendar links secure and tell us promptly about suspected misuse.
11. Your rights
Under the GDPR, you may have rights to access, correct or delete personal data; restrict or object to processing; receive portable data; and withdraw consent where processing is based on consent. Email [email protected]. We may ask you to verify your identity and will normally respond within one month.
You may complain to your local supervisory authority. In Denmark, the authority is Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark — datatilsynet.dk.
12. Changes to this policy
We update this policy when Projectly, our providers or applicable law changes. Material changes will be announced in the service or by email where appropriate. The current version and effective date are shown at the top.
13. Company details
Webkonsulenterne A/S
CVR 45330710
Hadsundvej 112, 9550 Mariager, Denmark
+45 54 62 54 21
[email protected] ·
webkonsulenterne.dk