TransformRadar

Privacy policy

Last updated: 3 July 2026

This privacy policy explains how ThejnValue Best Focus ApS ("we", "us", "our") processes personal data when you visit transformradar.eu, create an account, or use the TransformRadar application (together, the "Service").

We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Danish data protection law.

1. Data controller

ThejnValue Best Focus ApS

Ornekulsvej 8, DK-2920 Charlottenlund, Denmark

VAT no. DK36028394

Email: hello@transformradar.eu

2. Scope

This policy covers personal data we process as data controller when you use our website, sign up, sign in, or use TransformRadar as a user.

When your organisation uses TransformRadar, your organisation is typically the controller of personal data about its employees, contractors, and programme stakeholders entered into the Service. We process that data as a processor on your organisation's instructions, as described in section 8.

3. Personal data we collect

Depending on how you use the Service, we may process:

  • Identity and contact data — name, work email address, organisation name, country, role, and similar details you provide at sign-up or in your profile;
  • Account and security data — authentication identifiers, session tokens, sign-in timestamps, and security logs;
  • Usage and technical data — pages viewed, features used, device and browser type, IP address, and diagnostic logs;
  • Billing data — subscription status, trial dates, and payment-related identifiers when you add a payment method (card details are handled by our payment provider, not stored by us);
  • Communications — messages you send to us and emails we send to you (for example sign-in links, invitations, and service notices);
  • Customer content — project data you enter that may contain personal data about third parties (for example stakeholder names and contact details).

4. Purposes and legal bases

We process personal data for the following purposes:

  • Providing and operating the Service — performance of a contract (Art. 6(1)(b) GDPR) or steps prior to entering a contract;
  • Account security, fraud prevention, and abuse detection — legitimate interests (Art. 6(1)(f) GDPR);
  • Service communications (sign-in links, invitations, billing notices) — performance of a contract or legitimate interests;
  • Product analytics to understand usage and improve the Service — legitimate interests, with privacy-respecting configuration where possible;
  • Compliance with legal obligations — legal obligation (Art. 6(1)(c) GDPR);
  • Marketing to business contacts where permitted — consent or legitimate interests, with opt-out where required.

5. Cookies and analytics

We use essential cookies and similar technologies required for authentication and security.

We may use privacy-oriented analytics (Matomo) hosted in the EU to understand aggregate usage. Where required, we will request consent before non-essential cookies or tracking. You can adjust browser settings to limit cookies.

6. AI processing

When you use AI-assisted features, relevant Customer content may be sent to EU-resident or EU-hosted AI providers (currently Mistral) to generate responses. We configure providers not to use Customer data to train general models where such options are available.

Do not submit special category data or unnecessary personal data to AI features unless your organisation has a lawful basis to do so and accepts the associated risk.

7. Recipients and sub-processors

We use carefully selected service providers who process personal data on our instructions. Key categories include:

  • Hosting and infrastructure — Clever Cloud (France), EU data centres;
  • Email delivery — Brevo (EU);
  • AI inference — Mistral (EU-resident processing);
  • Analytics — Matomo hosted via Clever Cloud (Paris);
  • Payment and subscription management — billing provider when you subscribe (to be confirmed when billing goes live).

We may also disclose data where required by law, to protect rights and safety, or in connection with a merger or acquisition subject to appropriate safeguards.

A current sub-processor list can be provided on request to organisation administrators.

8. Processing on behalf of customers

For personal data your organisation enters about its programme participants and stakeholders, your organisation is the data controller and we act as processor. Processing is governed by these Terms, this policy, and, where required, a data processing agreement (DPA).

Organisation administrators control user access and may export or delete data subject to product functionality. Contact us if you need a DPA or sub-processor information for vendor due diligence.

9. International transfers

We design the Service for EU data residency. Primary hosting and analytics are in the EU. If we transfer personal data outside the European Economic Area, we will implement appropriate safeguards such as Standard Contractual Clauses and transfer impact assessments where required.

10. Retention

We retain personal data only as long as needed for the purposes above, including while your account is active and for a reasonable period afterwards for backups, billing records, and legal compliance.

Security logs and analytics may be kept for shorter or longer periods depending on operational need. Organisation administrators may request deletion of an organisation's Customer data when closing an account, subject to legal retention duties.

11. Security

We implement technical and organisational measures appropriate to the risk, including access controls, encryption in transit, role-based permissions, and monitoring. No online service can guarantee absolute security.

12. Your rights

If we process your personal data as controller, you may have the right to access, rectify, erase, restrict, or object to processing, and to data portability where applicable. Where processing is based on consent, you may withdraw consent at any time.

You may lodge a complaint with Datatilsynet (Denmark) or your local supervisory authority.

For data your employer or organisation controls in TransformRadar, contact your organisation administrator first; we will assist them as processor where required.

To exercise rights against us: hello@transformradar.eu. We may need to verify your identity.

13. Children

The Service is intended for business use and is not directed at children under 16. We do not knowingly collect personal data from children.

14. Changes to this policy

We may update this policy from time to time. We will post the revised version on our website and update the "Last updated" date. Material changes will be communicated to organisation administrators where appropriate.

15. Contact

Privacy questions: hello@transformradar.eu

ThejnValue Best Focus ApS, Ornekulsvej 8, DK-2920 Charlottenlund, Denmark.

← Back to homepage