Privacy Policy

Effective date: 18 May 2026 — Version 1.1 (updated 20 May 2026)

This policy applies to PennaSystems and all products under the platform (PennaPay, PennaSchedule, PennaConnect, PennaShare, PennaVentory). It explains what data we collect, why, and your rights under the GDPR.

Short version: We collect what's needed to run PennaSystems (your account info, your invoices, your client data on your behalf). We don't sell data. We don't profile you for advertising. You can export or delete your data anytime. We're a Danish sole trader operating under EU GDPR — this policy is short, specific, and binding.

1. Who we are

PennaSystems is operated by Rune Rævdal Walther, a sole trader (Personligt ejet Mindre Virksomhed / PMV) based in Denmark, registered with Erhvervsstyrelsen under CVR number 46426061. References to "we", "us", or "PennaSystems" in this policy refer to Rune Rævdal Walther.

Contact: rrwalther@pm.me — Banevænget 5C, 5270 Odense N, Denmark

2. What data we collect and why

Account data (you, the freelancer who signs up):

These categories of personal data: identity data (name), contact data (email, address), authentication data (password hash), business data (logo, business name).

Client data (data about your clients, entered by you):

These categories of personal data about your clients: identity data (name), contact data (email, address, phone), transactional data (invoice history), content data (messages, file uploads).

Usage data (automatically collected):

These categories of personal data: technical data (IP, browser, timestamps), authentication data (session tokens).

3. Legal basis for processing (GDPR Article 6)

4. Who we share your data with

We do not sell your data. We share it only with the following sub-processors, each bound by a Data Processing Agreement. For full details including data categories and transfer mechanisms, see our Subprocessors page.

We will notify you at least 30 days before adding any new sub-processor.

5. AI-assisted features

PennaSystems includes optional AI-assisted features that help you draft invoice line items, compose emails, and generate proposals. These features use the Anthropic Claude API.

6. International data transfers

Most of our subprocessors are based in the United States. Personal data is transferred under one of the following GDPR-recognised mechanisms:

We document Transfer Impact Assessments (TIAs) for each US-based transfer to evaluate whether the receiving country's legal regime offers adequate protection. These TIAs are available on request.

If you have specific concerns about a particular transfer or want to receive a copy of the relevant SCCs, contact us at rrwalther@pm.me.

7. Data retention