In short: we collect as little as possible, we never sell your data, and we use no tracking or advertising cookies. Here's exactly what happens with data on soge.dk.
- 🔒 No tracking cookies, no ad networks, no Google Analytics.
- 📊 Visitor stats are measured anonymously on our own server — your raw IP is never stored.
- 💳 Card details never touch our servers (handled 100% by Stripe).
- 🤝 We never sell or rent personal data.
1. Data controller
LynBro ApS, CVR 46321499, Rødovre, Denmark ("we") is the data controller for personal data processed on soge.dk and in the Soge API. Contact: info@lynbro.dk.
2. What we process
- Account: email, password (hashed), optionally phone number and CVR number.
- Billing: handled by Stripe — we never store card details, only subscription and invoice status.
- Operations & security: IP address, browser/User-Agent and request logs — used to keep the service up, prevent abuse and meter API quota. See section 4.
3. Purposes and legal bases
We process data to provide the account, the API and billing (contract, GDPR art. 6(1)(b)); for security and abuse prevention — rate limiting, key/device/IP binding (legitimate interest, art. 6(1)(f)); and for bookkeeping (legal obligation, art. 6(1)(c)).
4. Analytics, operations and security
Visitor analytics (cookieless): we don't use Google Analytics or any third party. Statistics are kept on our own server as anonymous totals (pageviews, an approximate unique-visit count via a daily salted hash, country, browser type). Your raw IP address is never stored in analytics, and no cookie is set — so no consent is required.
Operations and security: to keep the service running and stop abuse (bots, scraping, attacks), the server briefly processes IP address and request details in operational and security logs. The legal basis is legitimate interest (art. 6(1)(f); recital 49: processing for network and information security is a legitimate interest). These logs are deleted on a rolling basis.
5. Data from public registries
Site content (vehicles, companies) comes from public registries — the Danish Motor Registry (DMR) and CVR/Virk. Information about persons (e.g. company ownership) is shown as it appears in CVR, which is public by law. Advertising protection (reklamebeskyttelse) is respected. Corrections must be made in the source registry (Virk/Motorregistret); for questions about how data is displayed here, contact us.
6. Recipients
Stripe (payments), hosting and email providers in the EU/EEA. We do not sell personal data.
7. Cookies
We only use strictly necessary cookies: login session, CSRF protection, language choice and light/dark theme. No tracking, analytics or marketing cookies. That's why there's no cookie banner.
8. Retention
Account data is kept for as long as the account exists. Invoice data is kept for 5 years (Danish Bookkeeping Act). Operational and security logs are deleted on a rolling basis (typically within a few weeks).
9. Your rights
You have the right of access, rectification, erasure, restriction, data portability and objection. Write to info@lynbro.dk. You may complain to the Danish DPA, Datatilsynet.