★ FEATUREDBuild your BI dashboard from scratch — faster than taming Power BIRead →
Legal

Privacy policy

Last updated 5 October 2026.

broberg.ai is an open website: you can read everything without logging in, we show no advertising, and we do not follow you around. We count visits anonymously so we can see which pages are read. There are therefore only a few places where we process personal data about you at all. This page explains which, why, and how to have them removed again.

If you hold an account in our customer portal, the section on the portal below applies in addition to the rest.

Data controller

WEB HOUSE ApS
Riberhusvej 9
9492 Blokhus, Denmark
Company reg. (CVR): 21221198
Contact: legal@broberg.ai

What we process

  • Support enquiries. When you write to us — through the form or through the Aidan chat — we process the name and the email address or phone number you provide, together with the text of your message. A name and at least one way to reach you are required: without them we cannot answer you.
  • Conversations with Aidan. What you write to our AI assistant is sent to a language model so it can be answered. We do not use these conversations to train models.
  • Technical data. Ordinary server logs (IP address, time, which page was requested) for operations and security.
  • Anonymous visitor statistics. When you open a page, we record which page it is, which page you came from, how fast it loaded, and which country the visit comes from. The country is derived from your IP address, which is not stored. We use no cookies for this and store nothing in your browser. Your IP address is not stored; to count unique visitors we use an anonymous code that changes every day, so we cannot recognise you from one day to the next.

We do not build profiles, and we do not track you across websites.

Why we process them

  • Legitimate interest (GDPR art. 6.1.f) — answering an enquiry you sent us, keeping the site safe from abuse, and understanding which pages are read (the anonymous visitor statistics).
  • Performance of a contract (art. 6.1.b) — if your enquiry leads to us working together.
  • Legal obligation (art. 6.1.c) — bookkeeping under Danish law, should an invoice be involved.

How long we keep them

  • Support cases: while the case is open, and afterwards for as long as it is needed to make sense of an earlier enquiry.
  • Bookkeeping records: 5 years, as Danish law requires.
  • Server logs: briefly, for operations and security only.
  • Visitor statistics: only as anonymous counts, with no IP address and nothing that could lead back to you.

Who we share data with

We never sell data. We use these processors:

  • broberg.ai HelpDesk — our own support system, where your enquiry becomes a case.
  • Mistral AI (France, EU) — the language model behind Aidan, chosen precisely because it runs inside the EU.
  • Resend (USA, EU-approved) — sending email, such as a receipt for your enquiry.
  • Cloudflare (USA, EU-approved) — Turnstile, the check that keeps bots away from the contact form.
  • Fly.io (Stockholm, EU) — hosting of the site itself.
  • Upmetrics (Stockholm, EU) — our own service for operations monitoring and the anonymous visitor statistics.

Trust & security: See Where your data lives for the full, measured overview of suppliers, security and our data processing agreement.

The customer portal

If you are a client, you can be given an account in our customer portal, where you can follow your own cases, agreements and solutions in one place. Accounts are created by arrangement only — you cannot sign yourself up.

  • What we store: your name, your email address, your role at the client, and the content belonging to your own engagement with us.
  • What you see: only your own company's data. An account never gives sight of another client's data.
  • For how long: for as long as the engagement lasts. When it ends the account is closed and the data deleted, except what Danish bookkeeping law requires us to keep.
  • Legal basis: performance of a contract (GDPR art. 6.1.b).

The portal is being built. If it gains features that process more data than the above, this section is updated before that feature opens.

When we process data on behalf of our clients

When we build and operate a website, a webshop or a platform for you, you are the data controller for your own users' data and we are the data processor. That relationship is put in writing in a data processing agreement before we touch any data — it sets out what we may do, which sub-processors are involved, and what happens when the engagement ends.

This privacy policy covers broberg.ai as a company. It does not cover the sites we operate for others; there, the client's own policy applies.

Job applications

If you send us an application — solicited or not — we process what you write, solely in order to assess it. We delete the material no later than six months after the process ends, unless you have agreed that we may keep it longer.

When you connect an account from another platform

Some of our solutions can — only when you ask them to — be connected to a third-party account, for example LinkedIn, so that content can be published on your behalf.

  • We request only the permissions required for the feature you chose, and we never ask for access to your messages or to your network's personal data.
  • We store the access token the connection requires, and the profile identifier needed to know whose account it is. The token is stored encrypted.
  • We do not resell platform data, do not use it for advertising, and do not use it to train AI models.
  • You can disconnect at any time — in the solution itself or in the platform's own settings. We delete the token and the associated data when the connection is revoked.

Our use of the LinkedIn API complies with the LinkedIn API Terms of Use and Platform Guidelines.

Transfers outside the EU/EEA

Aidan and the hosting stay inside the EU. Two of our providers — Resend and Cloudflare — are US-based. Those transfers rely on the European Commission's Standard Contractual Clauses and the providers' certification under the EU-US Data Privacy Framework.

Security

All traffic to and from broberg.ai is encrypted (HTTPS). Access to the support system requires authentication, and access keys are stored encrypted and separately from the code. We do not collect data we do not need — the cheapest security there is.

Your rights

You have the right of access, rectification, erasure, restriction, objection and data portability. Write to legal@broberg.ai and we will help you — including if you simply want an enquiry deleted again.

If you disagree with how we handle your data, you may complain to the Danish Data Protection Agency (Datatilsynet).

Cookies

broberg.ai currently sets no cookies for tracking, analytics or advertising — neither our own nor any third party's.

The first time you visit, a cookie box asks for your choice. Your answer is kept in one necessary cookie, broberg-consent, for up to 12 months, so we do not ask again on every visit. Our visitor statistics use neither cookies nor storage in your browser, so the box does not ask about them. You can change your choice at any time under «Cookie settings» at the bottom of every page.

If you log in to the customer portal, one technical cookie is set, solely to keep you signed in. It is required for the portal to work, it is used for nothing else, and it disappears when you log out.

Changes

If this policy changes, the date at the top is updated.

Hi — I'm Aidan