Scriboflow Privacy

Privacy Policy

Version 1.0Effective 21 August 2026

How Scriboflow handles personal data for its website, accounts, business relationship, and service operations.

1Who we are

Scriboflow ApS
Denmark
Legal: legal@scriboflow.com
Privacy: privacy@scriboflow.com

This Privacy Policy explains when Scriboflow ApS acts as an independent controller. When a customer organisation uses Scriboflow to process contract, contact, signing, or uploaded data for its own purposes, that organisation is normally the controller and Scriboflow is its processor under the public Data Processing Agreement. Contact the organisation first about those records.

2Data we collect as controller

We may collect account and profile data; organisation, role, plan, and relationship data; billing contacts and transaction references; sign-in, device, network, security, and usage events; support and sales correspondence; website interactions and analytics identifiers; and records of consents, notices, legal acceptance, privacy requests, complaints, and disputes.

Legal-acceptance evidence contains the organisation, accepting user identifier, exact Terms, DPA, and Privacy Policy versions shown, acceptance revision, selected locale, acceptance context, and server timestamp. It does not contain an IP address.

We receive data from you, your organisation, other users who invite or transact with you, identity and sign-in providers, payment providers, security and infrastructure providers, public business sources where relevant, and your device or browser.

3Our purposes and legal bases

We process data to create and administer accounts and the customer relationship, authenticate users, provide requested support, coordinate billing and regulated payments, communicate service and security information, keep acceptance and transaction evidence, protect Scriboflow and users, prevent fraud and abuse, diagnose and improve the Service, comply with law, and establish or defend legal claims.

Depending on the activity, our basis is performance of a contract or steps requested before a contract; our legitimate interests in secure and effective service operations, relationship management, improvement, and protection of legal rights; compliance with legal obligations; or consent where law requires it. You may withdraw consent prospectively. You may object to processing based on legitimate interests, and we will assess your circumstances and applicable overriding grounds.

4Processor activities for customers

Customer-controlled contract content, contacts, signers, workflows, files, and related events are processed on the customer's instructions under the DPA. The customer decides purposes, recipients, retention choices, and lawful basis. Scriboflow uses that data only to provide, secure, support, and maintain the Service or as law requires.

Limited controller processing can coexist with the processor role, for example account security, billing records, fraud prevention, mandatory legal records, and handling a privacy request. We do not use customer contract content for our own advertising and do not sell personal data.

5Sharing and providers

We disclose data to authorised members of your organisation and recipients you or the organisation direct; infrastructure, communications, identity, security, analytics, support, and professional providers; payment providers and financial institutions; public authorities or counterparties where law or legal claims require it; and a buyer or successor in a genuine corporate transaction subject to appropriate safeguards.

Our public subprocessor register distinguishes providers that process customer data on Scriboflow's behalf from other service providers and independent controllers. Stripe, for example, determines purposes required for regulated payment and fraud services. Provider roles can depend on the activity and governing terms.

6International transfers

Scriboflow uses services that may process data in the United States and other locations outside Denmark or the EEA. We do not describe the Service as Europe-only. Where required, we rely on an adequacy decision, the EU–US Data Privacy Framework for eligible recipients, EU Standard Contractual Clauses, or another lawful mechanism and assess supplementary safeguards as appropriate.

7Retention

We retain account and relationship data while the account or organisation is active and afterwards for limited support, security, billing, legal, dispute, and deletion periods. Acceptance and transaction evidence may be retained for the applicable limitation period. Security and operational logs are retained according to their purpose and configuration. Marketing and analytics data is retained until its purpose expires, consent is withdrawn where applicable, or a shorter configured period applies.

Deleting an individual user account does not by itself delete data owned by an organisation and may leave the organisation without that profile for support recovery. An authorised organisation administrator should export or request deletion of organisation data. This operational behavior is under review and must not be treated as an immediate organisation-wide erasure guarantee.

8Security

We use organisational and technical measures including TLS in transit, provider-supported encryption at rest for the production database and object storage, authentication and optional MFA, role and membership controls, row-level security, restricted service credentials, event records, deployment checks, monitoring, and incident handling. No internet service is risk-free.

9Cookies and analytics

The website and application use necessary storage for sign-in, locale, security, and service operation. Current deployments may also load Google Analytics and PostHog analytics without a complete consent gate. The Cookie Information describes the observed storage, providers, purposes, mechanisms, and durations. That implementation must be resolved or expressly approved before official launch where consent is required; this disclosure does not replace a required consent mechanism.

You may use browser controls and supported provider opt-outs, but blocking storage or scripts can affect functionality. We will update the available consent controls and this notice when the launch configuration is final.

10Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or information; object to certain processing; withdraw consent; and complain to the Danish Data Protection Agency (Datatilsynet) or your local supervisory authority. Rights can be limited where exemptions apply, identity cannot be verified, or retention is legally required.

For customer-controlled workspace data, contact the relevant organisation. We will assist that organisation under the DPA. For Scriboflow controller data, contact privacy@scriboflow.com. We may ask for information needed to verify identity and scope.

11Children

Scriboflow is a business service and is not directed to children. Organisation administrators must not create accounts for children or intentionally submit children's data unless the use is lawful, appropriate for the Service, and expressly agreed where required.

12Changes and contact

We may update this Policy. Editorial changes may keep the same legal acceptance revision; material changes associated with organisation use will be identified through the acceptance process described in the Terms. The version and effective date above identify this text.

Questions and rights requests: privacy@scriboflow.com. Legal notices: legal@scriboflow.com.

Scriboflow ApS · Privacy Policylegal@scriboflow.com