Legal
Privacy Policy
Sonardeck is a CRM and recruitment system developed and operated from Denmark. We collect only the information needed to provide and secure the service, and we want to make it clear who decides how information is used.
When an organisation uses Sonardeck for information about its own customers, contacts, employees or candidates, that organisation is the data controller and Sonardeck is its processor. Requests about that information should generally be directed to the relevant organisation.
1. Who is responsible for the information?
Sonardeck is operated by Redefine v/Morten Bang Justesen, Danish company registration no. 30270444, Denmark ("Sonardeck", "we" or "us"). We are the controller for information about visitors to sonardeck.com, our contacts and service users where we determine the purposes of processing.
For content a customer places in its workspace — such as information about contacts, candidates, applicants and employees — we act on the customer's documented instructions as a processor. Our Data Processing Agreement describes these roles in more detail.
2. What information do we process?
The specific information depends on how you and your organisation use Sonardeck.
- Account and organisation data: name, email address, organisation, role, workspace, language, login identifier and email-verification status.
- CRM data: customer organisations, registration or tax identifiers, addresses, locations, contacts, telephone numbers, email addresses, notes, activities and follow-ups.
- Recruitment data: jobs, applications, candidate profiles, contact details, CVs, profile images, links, tags, notes, assessments, pipeline history, communications and consent status.
- Operational and security data: IP address, time, device and browser information, requests, error logs, audit records and actions within the service.
- Communications: content and contact details when you contact support or receive account, invitation, verification or consent messages.
- Time and call data where those features are used: time entries, telephone numbers, call time and duration, related records and notes.
3. Purposes and legal bases
We process account and subscription information to create and administer your account, provide the service and perform our contract with you or your organisation. Necessary security, operational and change communications are sent as part of that contract or our legitimate interest in operating a secure service.
We process technical logs, audit trails and limited usage data based on our legitimate interests in preventing abuse, troubleshooting and improving Sonardeck. We do not use your information for behavioural advertising and do not sell it.
Where a customer is the controller, the customer determines the legal basis for CRM and recruitment data. Consent recorded in Sonardeck is the customer's documentation and is not, by itself, Sonardeck's legal basis.
5. Recipients and transfers
We grant access only where needed to provide the service, follow a lawful instruction or meet a legal obligation. Providers may include hosting and object storage, authentication, email delivery, operational notifications and anonymised analytics. The current description of subprocessors appears in our Data Processing Agreement.
We aim to store customer data in the EU/EEA. If a provider processes information outside the EU/EEA, we use a valid GDPR Chapter V transfer mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses, and supplementary measures where necessary.
6. Retention and deletion
Account and customer data are retained while the account or customer relationship remains active and afterwards only for as long as needed for wind-down, documentation, security or legal requirements. The customer determines retention periods for information Sonardeck processes on its behalf.
Candidate data without an active legal basis is generally scheduled for deletion or anonymisation 30 days after a job process closes. Where a candidate has validly consented to continued retention, the profile and CV may be kept for up to 24 months or any shorter period set by the customer. Consent and audit records may be retained for up to 24 months as documentation.
Deleted information may remain in encrypted backups for a limited period and is overwritten according to the backup schedule. It is not restored to ordinary operations unless required for incident recovery.
7. How we protect information
We use technical and organisational measures appropriate to the risk. These include encrypted transmission using TLS/HTTPS, role- and workspace-based access, logging of security-relevant actions, separation between customers, system component updates and controlled backups.
Uploaded CV files are encrypted before they are stored in object storage. No internet service can guarantee absolute security, but we review and improve our measures continuously.
8. Your rights
Depending on the processing, you may have rights of access, rectification, erasure, restriction, portability and objection, and a right to withdraw consent. You may also complain to the Danish Data Protection Agency at datatilsynet.dk or your local supervisory authority.
If your request concerns information a Sonardeck customer placed in its workspace, please contact that customer directly. We assist the customer with its response. Where we are the controller, use the email address below. We normally respond within one month and may request information needed to verify your identity.
Sonardeck does not make solely automated decisions about individuals that produce legal or similarly significant effects.
9. Changes to this policy
We may update this policy when the service, providers or applicable rules change. The date above identifies the latest version. For material changes, we notify relevant users through the service or by email before they take effect where required.