Data processing agreement

When you sign up, we enter into a data processing agreement - whether you are a freemium user or a paying customer - as it is important to us that you feel comfortable that orderstep protects your data.

Cookie and privacy policy

1. General information

1.1 The Cookie and Privacy Policy in this section describes how orderstep ApS, Aldersrogade 6E, 2nd floor, 2100 Copenhagen Ø, CVR number 39107457 collects and processes your personal information when you use the systems on orderstep.dk to prepare offers, manage information and collect data for statistical purposes.

1.2. orderstep is the data controller and you can always contact orderstep's data controller, currently Lars Olafsson, regarding questions about the processing of your personal data at either persondata@orderstep.dk or telephone 4110 9090.

2. What personal data is collected and what is the data used for

2.1 Processing the information we receive about you as a user of the system

2.1.1 Your name, company or organisation name, job title, phone number and email will be registered in orderstep's systems.

2.1.2 The information provided is used for processing and delivery of the ordered subscription. It is also used for communication about updates to the systems and expected system downtime, etc.

2.1.3 The legal basis for the processing of the information provided about you as a user of the systems is Article 6(1)(b), (c) and (f) of the EU Data Protection Regulation.

2.2 Processing of data when you visit the orderstep.dk website

2.2.1. orderstep.dk uses cookies. A cookie is a small text file that many websites use to recognise your computer each time you visit the website. A cookie is a passive file and cannot spread viruses or other harmful programmes. The cookies used do not identify the individual user, but rather the user's computer.

orderstep's use of cookies depends on which pages you visit on the website.
When you visit www.orderstep.dk, and not secure.orderstep.dk, you are visiting the parts of the website whose purpose is sales and customer care for customers and potential customers of orderstep. Here orderstep uses cookies to improve your experience on the website, assess the use of the individual elements on the website and to improve the marketing of our products and services. See further information under section 7 "Cookies".

2.2.2 When you use orderstep.dk, your actions on the pages are registered in a log. The log stores data about all activities you perform on the website. What information is logged depends on the pages you visit on the website.

On all pages you visit on the website, orderstep logs:

Which IP address you are using
which user ID you are logged in with
which pages you have visited

In addition, orderstep logs most of what you do in the systems, e.g. which offers, customers etc. you have created, edited, viewed, deleted etc. including what you have entered along the way.

orderstep uses the information in the log to document what you have done, improve user-friendliness, target marketing and as a documentation basis for the resolution of any discrepancies.

2.2.3 If you write to us, we process the personal data you provide us with in order to respond to your enquiry.

2.2.4 The legal basis for the processing of data when you visit the orderstep.dk website is Article 6(1)(b), (c) and (f) of the EU General Data Protection Regulation.

3. Recipients of personal data

3.1. orderstep does not sell the personal data you have entered when ordering the subscription to third parties.

3.2. orderstep does not disclose the registered personal data to third parties unless expressly stated in these terms and conditions.

3.3 In order to administer and improve your subscription, personal data will be passed on to external partners. The external partners that may be used include payment providers, a web hosting provider, a newsletter provider, a provider of an evaluation system and a provider of a CRM system. For telephone enquiries, a telephone service provider will also be used.

3.4. orderstep also uses external partners to improve the website and targeted marketing, including retargeting. See further information in section 7 "Cookies".

4. Erasure of personal data

4.1 The data is stored for 5 years from the end of the financial year to which the material relates.

4.2 Deletion of information as a result of you having an activity on orderstep.dk (does not apply to secure.orderstep.dk) occurs two years after the activity.

5. Safety and security

5.1. orderstep maintains appropriate technical and organisational security measures against accidental or unlawful destruction, loss or deterioration of personal data and against unauthorised access or misuse.

5.2 Only employees who have a genuine need to access your personal data in order to perform their work will have access to it.

5.3 The data is not stored encrypted, but is transferred encrypted.

6. Your rights

6.1 As a data subject, you always have the right to access and object to a registration in accordance with the rules of the General Data Protection Regulation.

6.2 The GDPR gives you as a data subject the following rights:

6.2.1 The right to access your own personal data

You are at any time entitled to receive information about how your personal data is processed, including, for example, what data is registered about you, what purpose the registration serves, the category of personal data, recipients of personal data, etc. If you wish to gain insight into the processing of your personal data, you must send a written request to the data controller at orderstep. You may be asked to document that you are who you claim to be.

6.2.2 The right to rectification

You have the right to have incorrect personal data about yourself corrected. If you become aware that there are errors in the information registered about you, orderstep may have made it possible for you to correct the information you have provided directly in the system. If it is not possible to change the information directly in the system, you are encouraged to contact orderstep so that the information can be corrected.

6.2.3 Right to erasure

In certain cases, you have the right to have all or some of your personal data deleted by orderstep. To the extent that continued processing of your data is necessary, e.g. due to compliance with legal obligations or for the establishment, exercise or defence of legal claims, orderstep is not obliged to delete your personal data.

6.2.4. The right to restriction of processing

In certain cases, you have the right to have the processing of your personal data restricted to storage only, for example if you believe that the data processed about you is inaccurate or the processing in question is believed to be illegal.

6.2.5 The right to data portability (provision of data in a commonly used format)

In certain cases, you have the right to have personal data that you have provided in a structured, commonly used and machine-readable format and transferred to another controller.

6.2.6. The right to object

You have the right to object to the processing of your personal data at any time.

You can exercise your rights, including objecting to the processing, by contacting the data controller at orderstep, currently Lars Olafsson at persondata@orderstep.dk or 4110 9090. Following your enquiry, we will investigate whether the conditions for your enquiry have been met and then implement the requested changes or deletion as soon as possible.

6.3 You can complain about the processing of your personal data to:

Danish Data Protection Agency, Borgergade 28,5
1300 Copenhagen K, Denmark
Tel: +45 33 19 32 32 00
Fax: 33 19 32 18
Email: dt@datatilsynet.dk

7 Cookies

7.1 Cookies are used to improve your experience on our website, to assess the use of the individual elements on the website and to improve the marketing of our products and services. How orderstep uses cookies depends on the pages you visit on the website.

7.2 Technical cookies

7.2.1. Technical cookies are used on the website for the purpose of making the website work. The cookies used for technical reasons are necessary for the website to function and you will therefore not be able to use the website if you choose to reject the use of technical cookies. On the pages where videos are shown, technical cookies from the video hosting service Vimeo are set to enable video playback.

7.2.2 Technical cookies become obsolete 30 minutes after you have clicked away from the website. Your browser will then delete them according to its procedure for deleting obsolete cookies.

7.2.3 Technical cookies are used on all pages you visit on the orderstep.dk website.

7.3 Statistics cookies and marketing cookies

7.3.1 The website allows the web analytics tools Google Analytics to register cookies on your computer for tracking purposes. The tracking is used for analyses to optimise the design, usability and efficiency of the website.

7.3.2. The website also allows the advertising tools Google Analytics, LinkedIn and Facebook to register cookies so that they can track what your computer does on the website. The tracking is done in order to offer you relevant adverts about our products and services on their media and on third-party networks where they have an agreement to show adverts. The tracking does not allow orderstep to identify your name, contact details or other personal details.

7.3.3 Tracking is stored indefinitely and is not automatically deleted when you click away from the website.

7.3.4. The above-mentioned statistics cookies and marketing cookies used on www.orderstep.dk are intended to help with sales and customer care for customers and potential customers of orderstep.

7.3.5 The statistics cookies mentioned above are also used on the systems at secure.orderstep.dk. The purpose here is to see how many users use the system, at what times and which pages are used. This is done so that orderstep can ensure that the system runs stably at all times and can ensure better hardware if overload is detected during certain periods, etc.

7.4. Reject or delete cookies

7.4.1. If you do not want your computer tracked, you need to configure your browser to reject cookies from 3rd party websites. Where to find the settings depends on which browser you use.
Cookies that you have previously accepted can subsequently be deleted. If you use multiple browsers, remember to delete cookies in all of them.

See how to delete cookies and configure your browser in the guide http://minecookies.org/cookiehandtering/.

7.4.2 If you delete these cookies, you may experience that the systems and the website will not function as intended. orderstep cannot help you get the system to work for you in this case.

7.5. Guarantees for data transfers to the US

7.5.1 Google Analytics, Vimeo, LinkedIn and Facebook are established in the USA. The necessary guarantees for the transfer of data to the United States are ensured through the data processor's certification under the EU-U.S. Privacy Shield, cf. Article 45 of the EU General Data Protection Regulation.