Privacy Policy
How Saras IT, an IT consultancy and software company in Denmark, handles personal data about clients, business contacts, website visitors and users of our apps.
Last updated: 29 September 2026
1. Who we are
Saras IT is a Danish IT company providing software development, DevOps, cloud and hybrid-infrastructure services and publishing software applications.
Saras IT (sole proprietorship), CVR 38960393
Guldbjergvej 10, 8270 Højbjerg, Denmark
Email: contact@saras-it.co · Phone: +45 21 34 58 56
We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Danish Data Protection Act (databeskyttelsesloven).
2. Our two roles: controller and processor
As data controller, we decide how personal data is used when we run our own business: communicating with clients and prospects, invoicing, operating this website and publishing our own apps. This policy covers that processing.
As data processor, we may handle personal data on behalf of our clients when we develop, host, operate or support their systems. In those cases the client is the data controller, and we only process the data on their documented instructions under a data processing agreement (databehandleraftale) in line with GDPR article 28. Questions about such data should be directed to the relevant client.
3. Personal data we process as controller
- Clients and business contacts: name, job title, company, work email, phone number, and our correspondence, contracts and project communication.
- Invoicing and accounting: company details, contact person, invoices and payment information.
- Enquiries: the information you give us when you contact us by email, phone or WhatsApp.
- Website visitors: technical data such as IP address, browser and pages requested, recorded in server logs by our hosting provider for security and operation.
- App users: the data needed to provide the app’s features, as described in the app’s App Store or Google Play listing and in the app itself.
- Public company information: we may use publicly available information from the Danish Central Business Register (CVR) about companies we work with.
We do not intentionally collect sensitive personal data (special categories under GDPR article 9) or Danish CPR numbers as controller.
4. Purposes and legal basis
- Entering into and performing contracts with clients (GDPR art. 6(1)(b)).
- Answering enquiries and maintaining business relationships (legitimate interest, art. 6(1)(f)).
- Bookkeeping and tax, as required by the Danish Bookkeeping Act (bogføringsloven) and tax legislation (art. 6(1)(c)).
- Operating and securing our website, systems and apps (legitimate interest, art. 6(1)(f)).
- Providing app functionality you have requested (art. 6(1)(b)).
5. Marketing
We only send marketing emails or newsletters with your prior consent, in line with the Danish Marketing Practices Act (markedsføringsloven). You can withdraw your consent at any time.
6. Cookies
This website uses cookies that are strictly necessary for it to function. With your consent, we also use Google Analytics to understand how the website is used. You can accept, reject or change your choice at any time via the cookie banner.
7. Who we share data with
We never sell personal data. We share it only when necessary with:
- IT service providers acting as our data processors, such as web hosting, email, cloud and backup providers, under data processing agreements;
- Google, for website statistics with Google Analytics, only if you consent to statistics cookies;
- our accountant and bank, for bookkeeping and payments;
- public authorities such as the Danish Tax Agency (Skattestyrelsen), where the law requires it;
- Apple and Google, when you download or use our apps through their stores, under their own privacy terms.
8. Transfers outside the EU/EEA
We prefer providers that store data within the EU/EEA. If data is transferred to a country outside the EU/EEA, we ensure a valid transfer basis, such as an EU adequacy decision (including the EU–US Data Privacy Framework) or the EU Standard Contractual Clauses.
9. How we protect data
As an IT company, security is part of how we work. Our measures include:
- encryption in transit (TLS/HTTPS) and, where supported, at rest;
- multi-factor authentication and least-privilege access to systems;
- keeping software and systems up to date and monitored;
- regular backups and separation of client environments;
- confidentiality obligations for anyone working with personal data.
If a personal data breach occurs that is likely to result in a risk to individuals, we notify the Danish Data Protection Agency (Datatilsynet) within 72 hours and, where required, the people affected. When we act as processor, we notify the client without undue delay.
10. How long we keep data
- Accounting records: five years from the end of the financial year, as required by the Bookkeeping Act.
- Client and contract data: for the duration of the relationship and up to five years afterwards, for documentation and legal claims.
- Enquiries that do not lead to a contract: normally up to two years.
- Server logs: for a short period, normally no longer than 90 days.
- App data: for as long as you use the app or until you ask us to delete it.
11. Your rights
You have the right to access your personal data, to have it corrected or deleted, to restrict or object to processing, to data portability, and to withdraw consent at any time. To use your rights, email contact@saras-it.co. We respond within one month.
12. Complaints
You can complain to the Danish Data Protection Agency: Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, datatilsynet.dk. We would appreciate the chance to resolve your concern first.
13. Changes to this policy
We update this policy when our services or the law change. The current version is always available on this page.