Privacy Policy
Effective date: 18 May 2026 — Version 1.9 (updated 3 October 2026)
This policy applies to PennaSystems and all products under the platform (PennaPay, PennaSchedule, PennaConnect, PennaShare, PennaWelcome, PennaProfit, PennaVentory, PennaFolio, PennaClock). It explains what data we collect, why and your rights under the GDPR. The full scope is set out in §2 below.
Short version: We collect what's needed to run PennaSystems (your account info, your invoices, your client data on your behalf). We don't sell data. We don't profile you for advertising. You can export or delete your data anytime. We're a Danish sole trader operating under EU GDPR — this policy is short, specific and binding.
1. Who we are, how to contact us and DPO
PennaSystems is operated by a sole trader (Personligt ejet Mindre Virksomhed / PMV) based in Denmark, registered with Erhvervsstyrelsen under CVR number 46522036. References to "we", "us", or "PennaSystems" in this policy refer to that registered sole trader, whose statutory operator details (including the operator’s name) are set out in our Impressum.
We are the data controller for personal data we collect about you directly (your account data, your usage of the platform, your interactions with our marketing site and emails) — and we act as a controller strictly for the data necessary for billing, account administration and security and audit logging. Where you use the platform to send invoices, messages, files or bookings to your own clients, you are the data controller for your clients' personal data and we are your data processor under GDPR Art. 28. The Data Processing Agreement governing that relationship is incorporated into our Terms of Service and the data flows are described in §3 below.
Contact:
PennaSystems (CVR 46522036)
privacy@pennasystems.com
We respond to ordinary enquiries within 5 business days and to GDPR data subject requests within one month as required by GDPR Art. 12(3).
Data Protection Officer: PennaSystems has not appointed a Data Protection Officer. Under GDPR Art. 37(1), a DPO is mandatory only where an organisation's core activities consist of regular and systematic monitoring of data subjects on a large scale (Art. 37(1)(b)) or large-scale processing of special-category data (Art. 37(1)(c)). As a micro-enterprise (PMV) we do neither — we do not process personal data, special-category or otherwise, on a large scale — and so do not meet the Art. 37(1) thresholds. All privacy enquiries are handled directly by the operator at privacy@pennasystems.com. We will reassess this position as the platform grows.
2. Scope of this policy
This Privacy Policy covers personal data we process across:
- the public website at pennasystems.com — including the free invoice maker, FAQ, pricing pages, template pages, the PennaSystems suite pages and any "notify me when X launches" forms. Our former marketing domain, pennapay.com, now only redirects to pennasystems.com;
- the authenticated application at app.pennasystems.com and all included modules (PennaPay, PennaSchedule, PennaConnect, PennaShare, PennaWelcome, PennaProfit, PennaVentory, PennaFolio, PennaClock);
- the PennaSystems mobile application;
- transactional emails we send to you and to your clients on your behalf — account, invoice, booking, message, contract, welcome-package and platform notifications;
- the cookie banner and cookie-consent records on the sites listed above.
This Privacy Policy does not cover:
- websites and services operated by your clients or by other third parties that link to or from PennaSystems pages;
- payment-page surfaces operated by Stripe — Stripe's own privacy policy applies once you are on Stripe Checkout;
- third-party authenticator apps you use for two-factor authentication, or password managers you use to store PennaSystems credentials.
For the specific cookies and similar technologies set in your browser, see §9 below and our separate Cookie Policy.
3. Personal data we collect and why
Account data (you, the freelancer who signs up):
- Name, email address, password hash — to create and secure your account.
- CVR number (Danish Central Business Register) or equivalent EU VAT identification number — optional. You can create and use an account without one, and you can add or change it at any time in Settings → Business profile. When you do provide one, we use it to populate the invoices you send to your clients with the correct tax information and to enable the features that depend on a business identity: business-to-business VAT handling, including EU reverse-charge invoicing, and Danish e-invoicing (not yet available). We validate the value only when one is supplied — Danish CVR numbers against the public CVR API (cvrapi.dk) and EU VAT numbers against the European Commission's VIES service. If you leave the field blank, nothing is sent to either service. See Terms of Service §3 for the account terms that apply to business accounts.
- Business name, logo, billing address, business email, phone, tax/VAT numbers, OSS registration details — to populate invoices you send to your clients.
- Payment method — handled entirely by Stripe. We never see or store your card number.
- Two-factor authentication credentials: a TOTP secret if you enable an authenticator app and the public key plus credential metadata for any passkey/WebAuthn device you register. Private keys never leave your device.
- Last-login IP address — captured to send you a security alert when a new IP address logs in to your account. We store only the most recent login IP, not a history.
- Mobile push token — only if you install the PennaSystems mobile app and enable push notifications.
These categories of personal data: identity data (name), contact data (email, address, phone), business identifiers (CVR/VAT, business name, logo), authentication data (password hash, 2FA secrets, passkey credentials, session tokens), technical data (last-login IP, push token).
Client data (data about your clients and other end-recipients, entered by you or submitted to you through the platform):
- Client name, email, address, phone, VAT number — to create invoices, quotes and messages.
- EU VAT-number validation at invoice time: when you issue a zero-rated reverse-charge invoice to a business in another EU country, your client's (the buyer's) VAT number is transmitted to the European Commission's VIES service (VAT Information Exchange System) so we can confirm it is registered for cross-border trade. The VIES consultation reference and result returned by the Commission are then stored on the invoice as a contemporaneous good-faith audit trail and retained for 5 years under the Danish Bookkeeping Act (Bogføringsloven § 12). This is a distinct processing operation from the one-time validation of your own business's VAT number, carried out only if and when you supply one, described in the account-data section above; the recipient (the EU Commission) is a public authority operating a statutory verification registry, not a commercial subprocessor.
- Invoices, line-item descriptions, payment status and the immutable "client snapshot" captured at invoice-send time — to provide invoicing and bookkeeping continuity.
- Bookkeeping integration — only if you connect your own Billy, Dinero or e-conomic account (see §5): the invoice and client details you choose to send are transmitted to that account. From the bookkeeping system we receive and store only what the integration needs: the identifier of your account there (for example your e-conomic agreement number or your Billy or Dinero organisation ID), its company name, the few settings a transfer needs (such as the base currency, and the customer group and product to use), the reference numbers that system gives to the customers, contacts, invoices and drafts we create there, and any error message it returns when a transfer fails. The access token for the connection is encrypted before it is stored and is deleted when you disconnect.
- PennaSchedule booking data: client name, email, phone, the date/time of the booking and the answers to any custom intake fields you have defined. Important: if you define custom fields that ask about health, religion, sexual orientation, or other categories listed in GDPR Art. 9, the answers are special-category personal data and you must have an Art. 9 lawful basis (typically explicit consent) before collecting them. The platform does not gate Art. 9 collection technically — that judgement is yours as the controller.
- PennaConnect conversation data: message bodies and attachments exchanged between you and your clients through the platform.
- PennaShare deliverable files: files you upload to share with clients. Download links are time-limited (see Terms of Service §2).
- PennaWelcome client-onboarding data: project briefs, the questions you ask clients during onboarding and the answers clients submit, agreement-acceptance flags and timestamps.
- PennaProfit expense records: vendor name, amount, currency, description and any receipt image you upload.
- Contract e-signature evidence: the signatory's name, email, IP address and timestamp captured at the moment of signing — for non-repudiation.
- Audit log entries: the IP address captured when a client views a public invoice portal, downloads a deliverable file, or signs a contract — to give you an audit trail of client interactions with the platform.
- You are the data controller for your clients' personal data. We process it as your data processor, on your documented instructions, in accordance with GDPR Article 28. The Data Processing Agreement between us is incorporated into the Terms of Service.
These categories of personal data about your clients: identity data (name), contact data (email, address, phone), transactional data (invoices, payment status), content data (messages, files, brief answers), evidence data (IP addresses captured for e-signature and portal-access audit trails) and — only if you choose to collect them via custom booking fields — special-category data under GDPR Art. 9.
Usage data (automatically collected when you use the service):
- Log data: IP address, browser type, pages visited, timestamps — for security monitoring and debugging.
- Session tokens — to keep you logged in.
- Security alert emails: when a login from an unrecognised IP address is detected, that IP address is included in the notification email sent to you via Resend (see §5).
- Audit records of past AI-feature use: while PennaSystems offered AI features (until 2 October 2026), each use was logged with which feature was invoked, when, token count, cost and the input/output payload — for cost monitoring and abuse prevention. No new records are created. Retention is disclosed in §7.
- Income records: when you mark an invoice or a deposit as paid, we record the amount, currency, the exchange rate to DKK and a short description, for your profit-and-loss overview. Your clients pay you directly, using the payment details you put on the invoice, so their payments never pass through accounts controlled by PennaSystems and we receive no payment data from them. When you pay for your own subscription through Stripe, Stripe sends us the amount, currency and your billing country, and we keep a record of the payment, with the exchange rate to DKK, for our own bookkeeping.
These categories of personal data: technical data (IP, browser, timestamps, session tokens), audit data (records of past AI-feature use, income records).
Marketing list (only if you opt in):
- If you submit a "notify me when X launches" form on pennasystems.com, we store the email address you provided plus the IP address and browser user-agent captured at submission for abuse prevention. Retention is disclosed in §7. We do not buy, sell, or rent marketing lists.
4. Why we process your data (legal basis under GDPR Article 6)
- Contract performance (Art. 6(1)(b)): We process your account data and your clients' data (on your instructions as our controller) to deliver the PennaSystems service you signed up for — invoicing, scheduling, messaging, file delivery, contract signing and the related platform operations.
- Legal obligation (Art. 6(1)(c)): We retain certain financial records (subscription invoices we issue to you and the records of the subscription payments you make to us) for 5 years as required by the Danish Bookkeeping Act (Bogføringsloven § 12) and we apply equivalent retention to records required under EU VAT Directive 2006/112/EC where applicable.
- Legitimate interests (Art. 6(1)(f)): We process log data, security audit data, audit records of past AI-feature use and abuse-prevention metadata (e.g. notify-signup IP/user-agent) to protect the platform, our users and our subprocessors from abuse, fraud and misuse. We have weighed these interests against your privacy rights and consider them not to override your reasonable expectations.
- Consent (Art. 6(1)(a)): We use consent for non-essential cookies and analytics identifiers (loaded only after you accept analytics through the cookie banner — see §9), and for any optional marketing communications you opt into.
5. Who we share your data with (subprocessors)
We do not sell your data. We share it only with the following subprocessors, each bound by a Data Processing Agreement that incorporates the EU Standard Contractual Clauses (or, where applicable, the EU–US Data Privacy Framework) and limits processing to the purposes specified below. For full details — exact data categories, retention behaviour, transfer mechanism and link to each vendor's privacy policy — see our Subprocessors page, which is the authoritative always-current list.
- Stripe, Inc. (USA) — payment processing and subscription billing. EU–US Data Privacy Framework.
- Resend, Inc. (USA) — transactional email delivery. Standard Contractual Clauses.
- Railway Corp. (USA) — cloud application hosting and managed PostgreSQL database. Standard Contractual Clauses.
- Cloudflare, Inc. (USA) — CDN, DDoS protection and R2 object storage for user-uploaded files. Standard Contractual Clauses.
- Functional Software, Inc. / Sentry (USA) — application error tracking. Standard Contractual Clauses. PII is scrubbed from error payloads before transmission.
- Expo Technology, Inc. (USA) — mobile push notification delivery. Standard Contractual Clauses.
- PostHog, Inc. (EU Cloud — Frankfurt, DE) — product and web analytics. Data stored in EU (AWS eu-central-1); no transfer outside the EEA.
- Ghost Foundation (Ghost Pro, USA) and Mailgun (USA, via Ghost) — newsletter platform and its email-delivery subprocessor, used only for users who opt in to PennaSystems newsletters. Standard Contractual Clauses.
We will notify you by email at least 30 days before adding any new subprocessor that will process your personal data, giving you the opportunity to object and terminate your account before the change takes effect.
Optional integrations. If you connect a third-party account (for example, a Meta / Facebook Messenger or Instagram account) to PennaConnect, we process the resulting messages solely on your behalf, as your processor, to operate the integration you enabled — subject to that third party's own privacy terms, under which the third party acts as an independent (or joint, with you) controller rather than as a PennaPay subprocessor. These integrations are off by default and listed, with their controller relationships and transfer basis, on our Subprocessors page.
Bookkeeping integrations. If you connect your own Billy, Dinero or e-conomic account, we send the invoice and client data you choose to that account on your instruction: when you send an invoice there, or automatically when an invoice is sent if you switch that on. You choose these bookkeeping providers and contract with them directly. They process the data for you under your own agreement with them, not as PennaSystems subprocessors. Data that has reached your bookkeeping account is governed by that agreement and stays there if you disconnect the integration or delete your PennaSystems account. These integrations are off until you connect one and are listed on our Subprocessors page. What we receive back from the bookkeeping system is listed in §3.
5.1 No AI features; how we use AI tools (Anthropic)
PennaSystems has no AI features. The AI-assisted features we offered earlier (drafting, suggestions and receipt scanning, provided through Anthropic's Claude API) were switched off on 2 October 2026. No feature of the service sends your data, or your clients' data, to an AI provider.
- Anthropic is a former subprocessor. It is listed under former subprocessors on our Subprocessors page. Content sent to Anthropic while the features were available was processed under Anthropic's Commercial Terms and Data Processing Addendum (Standard Contractual Clauses). Under those terms Anthropic does not train models on that content, and it deletes it after a standard retention period of 30 days.
- Our own records of past AI-feature use are kept and deleted as described in §7.
- How we build the service. Our operator uses AI tools, including Anthropic's Claude, as an assistant for writing and maintaining the PennaSystems software. These tools work on our source code and on information that does not identify anyone, such as the structure of our database and aggregate counts. We do not give them your personal data, your clients' personal data or data from a connected bookkeeping account, so Anthropic is not a subprocessor for this use.
6. International data transfers
Most of our subprocessors are based in the United States. Personal data is transferred under one of the following GDPR-recognised mechanisms:
- EU–US Data Privacy Framework (DPF): Stripe is DPF-certified.
- Standard Contractual Clauses (SCCs): Resend, Railway, Cloudflare, Sentry, Expo, Ghost (and via Ghost, Mailgun). We have signed SCCs with each.
- No transfer: PostHog operates from EU servers (Frankfurt, AWS eu-central-1); no transfer outside the EEA occurs.
Cloudflare R2 storage region: deliverable files (PennaShare) and receipt images (PennaProfit) stored in our Cloudflare R2 buckets are pinned to Cloudflare's European Union jurisdiction, so the objects are held at rest on infrastructure located within the EU (owner-verified 2026-07-04). Cloudflare, Inc. remains a US-incorporated provider whose personnel may in principle access the data for support and operational purposes; that residual transfer is safeguarded by the Standard Contractual Clauses cited above under GDPR Art. 46. We will update this disclosure if the storage region changes.
Transfers to the US are safeguarded by mechanisms such as the EU-US Data Privacy Framework or Standard Contractual Clauses incorporated into our vendor agreements, and we assess transfer risks on an ongoing basis.
We monitor for changes in adequacy decisions and transfer mechanisms (for example, if a subprocessor obtains DPF certification, loses it, or the framework is invalidated by the CJEU) and will update this disclosure within a reasonable period of any material change. Registered users will be notified by email if a change materially affects how their data is transferred.
If you have specific concerns about a particular transfer or want to receive a copy of the relevant SCCs, contact us at privacy@pennasystems.com.
7. Data retention
- Account data: retained while your account is active. When you request deletion we soft-delete your account immediately so you can no longer log in or use the service; the underlying user record is then held in a restorable state for 30 days. After the 30-day grace period your account is permanently erased: the data you created on the platform (your invoices, contacts, messages, conversations, uploaded files and similar records) is deleted and the underlying user record is reduced to an anonymous tombstone — your email address, password hash, security credentials, last-login IP address, push token and similar identifiers are nulled, leaving only an internal anonymous identifier, the account-creation timestamp, the deletion timestamp and the timestamp of your acceptance of our Terms retained for audit and legal-defence purposes. This final erasure runs automatically once the grace period has passed and cannot be reversed. We fulfil erasure requests by permanently erasing your personal data, except for records we are legally required to retain — notably our own subscription-billing records under the Danish Bookkeeping Act (Bogføringsloven § 12), kept for 5 years under GDPR Art. 17(3)(b). You can request an immediate manual purge before the 30 days elapse by emailing privacy@pennasystems.com; we will action manual purges within 30 days of receipt.
- Inactive accounts: if your account remains inactive for an extended period, we may close it. Closure follows the same soft-delete process described above — your login credentials and personal identifiers are removed — while any records we are legally required to keep (e.g. bookkeeping records under Danish Bogføringsloven § 12) are retained for their full mandated period and never deleted early.
- Links you have shared with your clients: deleting your account does not, by itself, send any message to your clients. Links you have already shared with them — an invoice portal link, a PennaConnect thread link, a PennaShare download link — stop working no later than the permanent erasure at the end of the 30-day grace period, and you can close any of them sooner by revoking, expiring or deleting the individual invoice, thread or file. Telling your clients that a link will stop working is your responsibility, not ours — we do not contact your clients on your behalf when you close your account.
- Conversations, projects and orders you delete on their own: deleting a PennaConnect thread moves it to Trash, and the client link for that thread stops working immediately. The thread stays restorable for 30 days, after which it is permanently erased together with all of its messages. The same 30-day Trash window applies to projects and orders you delete.
- Invoices and bookkeeping records you create for your clients: deleted within 30 days of your account deletion request, in line with our role as data processor (GDPR Art. 28). As the data controller for these records, you are responsible for retaining them in your own bookkeeping system for the 5-year period required by Danish Bogføringsloven § 12. Use the data export tool in Settings to download and store a copy before deletion.
- Subscription invoices PennaSystems issues to you (for your platform subscription) are retained for 5 years from the end of the financial year to which they relate, as required by Danish Bogføringsloven § 12 governing our own bookkeeping records.
- Server logs: kept for 90 days then rotated and deleted, except where a security incident under investigation requires longer retention. In that case, only the logs relevant to the incident are preserved, and only for as long as the investigation requires.
- Encrypted backups: we keep encrypted off-site copies of the platform database for about five years, the retention period the Danish Bookkeeping Act (Bogføringsloven) sets for bookkeeping records; the same backups let us restore the service after a technical failure. Each backup is deleted automatically when that period ends. This means that data erased from the live service — including the data of a deleted account — can remain inside older backups until those backups expire. Backups are encrypted before they leave our servers, the key needed to open them is kept offline rather than on our servers, and they are used only to restore the service or records and to meet that retention obligation; we do not read or process the data in them for any other purpose.
- Content sent to Anthropic by the former AI features: deleted by Anthropic after its standard 30-day retention period under its Commercial Terms (see §5.1). PennaSystems kept no separate copy of AI inputs or outputs apart from the audit records described below.
- Marketing "notify me" signups: if you sign up to be notified when a forthcoming module launches, your email address and the abuse-prevention metadata captured at sign-up (IP address and browser user-agent) are retained for 18 months and then automatically deleted, in line with GDPR Art. 5(1)(e) storage limitation. Email privacy@pennasystems.com at any time to unsubscribe and erase the record immediately.
- Support correspondence: retained for 2 years from the close of the matter, then deleted, unless required longer for legal-defence purposes.
- Audit records of past AI-feature use: each use of an AI feature before they were switched off on 2 October 2026 left a structured audit record (which feature, when, token count, cost and the input/output payload). We keep each record for up to 12 months from the date of use, to monitor cost and abuse, then delete it. No new records are created. If your account is deleted before that window, the user ID on the audit row is nulled but the row itself is retained as part of the organisation's billing audit until the organisation is fully purged.
8. Your rights under GDPR
As a data subject in the EU/EEA you have the following rights regarding personal data we hold about you:
- Right of access (Art. 15): you can request a copy of the personal data we hold about you and information about how we process it.
- Right to rectification (Art. 16): you can request that we correct inaccurate personal data or complete incomplete data.
- Right to erasure (Art. 17): you can request that we delete your personal data, subject to legal obligations that may require us to retain certain records (notably the 5-year retention under Danish Bogføringsloven § 12 for our own subscription invoices to you, and the deletion-delay disclosed in §7 above).
- Right to restriction of processing (Art. 18): you can request that we restrict how we process your data in certain circumstances (e.g. while you contest the accuracy of the data).
- Right to data portability (Art. 20): you can receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller. PennaSystems provides a data export tool in Settings; you can also request the data by emailing us.
- Right to object (Art. 21): you can object to processing based on legitimate interests; we will assess your objection and stop the processing unless we demonstrate compelling legitimate grounds that override your interests.
- Right to withdraw consent (Art. 7(3)): where we rely on consent (for example, non-essential cookies or analytics identifiers — see §9), you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- Rights regarding automated decision-making (Art. 22): PennaSystems does not make decisions about you based solely on automated processing, and it has no AI features.
To exercise any of these rights, email privacy@pennasystems.com with the words "GDPR request" in the subject line. We will respond without undue delay and in any event within one month of receipt of your request as required by GDPR Art. 12(3); if your request is complex we may extend this by a further two months and will tell you why in writing. There is no fee for ordinary requests; only manifestly unfounded or excessive repeated requests may be subject to a reasonable fee or refusal, in accordance with Art. 12(5).
9. Cookies and similar technologies
PennaSystems uses a minimal set of strictly-necessary cookies (your authenticated-session token and your language preference) and one consent-gated analytics identifier (the PostHog visitor ID, stored in browser localStorage rather than as a cookie). We do not set retargeting or cross-site tracking cookies of any kind, and the only advertising cookies that can appear are the consent-gated Google Ads conversion cookies described below.
For the complete table — every cookie and similar identifier set by pennasystems.com and app.pennasystems.com (pennapay.com only redirects to pennasystems.com), with name, domain, purpose, lifetime and which party sets it — see our separate Cookie Policy.
Consent: non-essential analytics identifiers (currently only the PostHog visitor ID) are loaded only after you grant analytics consent through the cookie banner shown on first visit. The banner offers Accept all and an equally prominent Reject all, plus a per-category control under Manage preferences; nothing optional is granted until you choose, and nothing is pre-ticked. You can withdraw consent at any time from that preferences dialog, by clearing your browser's localStorage for our domains, by using your browser's cookie controls, or by emailing privacy@pennasystems.com. Withdrawing consent does not affect the lawfulness of processing that took place before withdrawal.
Advertising measurement (Google). A second, separate consent category governs a Google Ads conversion tag, which tells us whether someone who clicked one of our advertisements went on to create an account. It is declined by default; while it is declined, no Google script is requested and no Google cookie is set. It is additionally gated by a server setting, so consent alone does not load it. Granting it lets Google set the _gcl_* / _gac_* cookies described in our Cookie Policy. For that measurement Google acts as an independent controller under its own terms rather than as a PennaSystems subprocessor — the same relationship described for optional integrations in §5 — so its processing is governed by Google's privacy terms. We do not use Enhanced Conversions and send Google no email address, hashed or otherwise; ad personalisation and remarketing stay disabled even after consent. Withdrawing the permission deletes those cookies. Full detail, including what happens in each state, is in §6 of the Cookie Policy.
Cloudflare Web Analytics sets no cookies and creates no client-side identifiers, and operates without consent under the ePrivacy strictly-necessary exemption.
Anonymous usage counts in the free invoice builder. When you download an invoice PDF or switch template in the free builder without an account, our own server records a count of that action together with the template name, the page language and — if it is in the page address — the name of the template page you arrived from (for example src=faktura-freelancer). This count contains no IP address, browser details, cookies, local-storage values or any other identifier, so it cannot be linked to you; it is only a number per template that tells us which template pages are useful. It is stored in our EU-hosted database, is never shared with PostHog, Google or anyone else, and does not require consent because it neither stores nor reads anything on your device.
10. Security and breach notification
We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit (TLS; current browsers connect using TLS 1.3) and at rest, restricted administrative access secured with two-factor authentication, segregated production credentials and continuous logging. We rely on industry-standard practices from our subprocessors (Railway, Cloudflare, Stripe) for the underlying infrastructure security.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify Datatilsynet without undue delay and, where feasible, within 72 hours of becoming aware of the breach (GDPR Art. 33). If the breach is likely to result in a high risk, we will also notify you directly without undue delay (GDPR Art. 34).
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our processing activities, the subprocessors we use, or applicable law. Material changes will be communicated to registered users by email or in-app notification at least 30 days before they take effect, except where shorter notice is required to address a security or legal issue. The current version is always available at pennasystems.com/privacy.html.
12. Complaints to the supervisory authority
If you believe we have not adequately handled your request or that our processing of your personal data violates GDPR, you have the right to lodge a complaint with a data protection supervisory authority. The competent supervisory authority for PennaSystems is:
Datatilsynet (the Danish Data Protection Agency)
Carl Jacobsens Vej 35
2500 Valby, Denmark
datatilsynet.dk · dt@datatilsynet.dk
You may also lodge a complaint with the supervisory authority in your EU/EEA country of residence or place of work, or in the country where the alleged infringement took place (GDPR Art. 77(1)).