Privacy Policy
Data controller: Vektor HQ (enkeltmandsvirksomhed), Denmark, CVR 46519779, Sandkaj 17, 2150 Nordhavn, Denmark, contact@vektorhq.ai. Effective date: June 23, 2026. Version: 3.0.
This policy explains how Vektor HQ ("Vektor", "we") handles personal data when you visit vektorhq.ai or use the Service. We comply with the GDPR and Danish data protection law.
1. Our two roles
- As controller, for data about you as a visitor, account holder and customer (your contact, account and billing data). This policy covers that role.
- As processor, for the personal data you put into the Service as content ("Customer Data"). There, your organisation is the controller and we process on your instructions under our DPA.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Account data | name, work email, hashed password, company | you, at signup |
| Billing data | billing name, address, VAT number, payment metadata | you / our payment provider |
| Usage data | features used, log and diagnostic data, device and IP-derived data (via consent-gated analytics) | automatically |
| Content you submit | prospect/company info, notes, and call transcripts and meeting notes you upload or paste | you (Customer Data, under the DPA) |
| Communications | support messages, emails | you |
3. Why we use it, and our legal basis (Art. 6 GDPR)
| Purpose | Legal basis |
|---|---|
| Provide and run the Service | Performance of contract |
| Billing, invoicing, tax compliance | Contract + legal obligation |
| Security, fraud prevention, debugging | Legitimate interests |
| Improve the Service (using aggregated, de-identified data, see §5) | Legitimate interests |
| Product analytics | Consent (see Cookie Policy) |
| Marketing emails to customers | Legitimate interests; opt-out always available |
| Support | Contract / legitimate interests |
4. Call transcripts and deal memory
You can upload or paste call transcripts and meeting notes to a deal. We store them so your brief can be generated and improved across meetings ("deal memory"). These may contain personal data about other people on the call, which you submit as Customer Data. Your organisation is the controller and is responsible for having a lawful basis and any required consents to upload it (see your obligations in the Terms and DPA). We store this content in our EU database and send it to our AI sub-processor (Anthropic) to extract a structured summary that informs the brief. It's deleted when you delete the deal or close your account (see §7).
5. How we use data for AI and product improvement
- We send your inputs to our AI sub-processor (Anthropic) to generate output and the structured "deal memory" summary.
- We do not use your Customer Data to train third-party AI models, and we do not build our own AI models from your raw data.
- We may create aggregated and de-identified information (which cannot identify you, your organisation or any individual) and use it to operate, secure and improve the Service.
- AI output may be inaccurate and is decision-support only.
6. Sharing and sub-processors
We share data with the providers in our Sub-processor List (AI, hosting, database, payments, email), each under a data processing agreement. We don't sell personal data. We may disclose data if required by law or to protect our rights.
Our bank (Lunar) and bookkeeping software (Dinero) process our own company's financial records, not Customer Data, so they aren't customer sub-processors. If we issue you a manual invoice, your billing contact details are kept in our bookkeeping for accounting/legal reasons.
7. How long we keep data
We keep account and Customer Data for the life of your subscription and delete or anonymise it within 30 days of account closure, except where the law requires longer, in particular Danish bookkeeping law, under which invoices and accounting records are kept for 5 years.
8. International transfers
Our core infrastructure is in the EU (Render EU, Supabase EU). Where a provider processes data outside the EEA (mainly our AI provider, Anthropic) we rely on EU Standard Contractual Clauses and appropriate safeguards.
9. Your rights (GDPR)
You can access, correct, erase, restrict, object to processing of, and port your data, and withdraw consent. Email contact@vektorhq.ai. You can also complain to the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk). For Customer Data, send rights requests to your organisation (the controller).
10. Cookies
We use essential cookies and, only with your consent, analytics cookies, see our Cookie Policy. No advertising or cross-site tracking.
11. Security
We use measures including encryption in transit, access controls and EU hosting. No system is perfectly secure; we'll notify you and Datatilsynet of a personal data breach as required by law.
12. Children
The Service is for business users and isn't directed at anyone under 18.
13. Changes
We may update this policy and will post the new version with an updated date; we'll notify account holders of material changes.
14. Contact
Vektor HQ, CVR 46519779, Sandkaj 17, 2150 Nordhavn, Denmark, contact@vektorhq.ai.