Privacy Policy

Last updated: December 2025

1. Introduction

Prowi ApS ("Prowi", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our commission and variable salary management platform (the "Service").

We process your personal data in compliance with the General Data Protection Regulation (GDPR) and applicable Danish data protection laws.

2. Data Controller

Prowi ApS
CVR: 43243977
Klamsagervej 35
8230 Åbyhøj
Denmark

Phone: +45 70604554
Email: legal@prowi.io

Prowi is the data controller for personal data collected via our website (prowi.io). When we process personal data on behalf of our customers through the Prowi platform, we act as a data processor and our customers act as data controllers.

3. Information We Collect

Information you provide directly:

• Contact information (name, email address, phone number)

• Company information (company name, job title)

• Account credentials

• Communications with us (support requests, feedback)

Information collected automatically:

• Device information (browser type, operating system)

• IP address

• Usage data (pages visited, features used, time spent)

• Cookies and similar tracking technologies

Information processed on behalf of customers:

When our customers use the Prowi platform, we process personal data about their employees on their behalf, including names, email addresses, salary information, and commission data. This processing is governed by our Data Processing Agreement with each customer.

4. Legal Basis for Processing

We process your personal data based on several legal grounds.

We rely on contractual necessity to fulfill our contractual obligations to you and provide our services.

We also process data based on our legitimate interests for improving our platform and services, monitoring usage, and protecting our platform's security.

For certain activities such as marketing communications, we may process your data based on your consent, where required.

5. How We Use Your Data

We may use your personal data for various purposes related to providing and improving our services for the following purposes.

• Providing and maintaining the Prowi platform

• Managing your account and user registration

• Processing transactions and calculating commissions

• Communicating with you about your account and our services

• Providing customer support

• Improving our platform and developing new features

• Analyzing usage patterns and platform performance

• Ensuring security and preventing fraud

• Sending marketing communications (with your consent)

• Complying with legal obligations

6. Cookies and Tracking Technologies

How We Use Cookies

Prowi uses cookies and similar tracking technologies to provide, improve, and secure our services. Below is a detailed overview of the cookies we use.

Types of Cookies We Use

3Essential Cookies (Required)

These cookies are necessary for the website and platform to function properly. They cannot be disabled.

session_id - Maintains your login session (Session, Prowi)

csrf_token - Security - prevents cross-site request forgery (Session, Prowi)

cookie_consent - Stores your cookie preferences (1 year, Prowi)

Analytics Cookies

These cookies help us understand how visitors interact with our website by collecting and reporting information anonymously.

_ga - Distinguishes unique users (2 years, Google Analytics)

_ga_* - Maintains session state (2 years, Google Analytics)

_gid - Distinguishes unique users (24 hours, Google Analytics)

_gat - Throttles request rate (1 minute, Google Analytics)

Google Analytics: We use Google Analytics to analyse website traffic and usage patterns. Google Analytics uses cookies to collect information about your use of our website, including your IP address (anonymised), pages visited, time spent, and referral source. This data is transmitted to and stored by Google. For more information, see Google's Privacy Policy.

You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

Marketing and Tracking Cookies

These cookies are used to track visitors across websites and display relevant advertisements.

__hssc - Tracks sessions for analytics (30 minutes, HubSpot)

__hssrc - Determines if user has restarted browser (Session, HubSpot)

__hstc - Tracks visitors over time (13 months, HubSpot)

hubspotutk - Tracks visitor identity (13 months, HubSpot)

HubSpot: We use HubSpot for marketing automation and to understand how visitors engage with our content. For more information, see HubSpot's Privacy Policy.

unctionality Cookies

These cookies allow the website to remember choices you make and provide enhanced features.

language - Remembers your language preference (1 year, Prowi)

timezone - Stores your timezone setting (1 year, Prowi)

Managing Your Cookie Preferences

You can control and manage cookies in several ways:

Browser settings: Most web browsers allow you to control cookies through their settings. You can typically:

• Delete existing cookies

• Block all or certain cookies

• Set your browser to notify you when cookies are set

• Browse in "private" or "incognito" mode

Please note that if you disable cookies, some features of our services may not function properly.

Browser-specific instructions:

• Google Chrome: support.google.com/chrome/answer/95647

• Mozilla Firefox: support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer

• Safari: support.apple.com/guide/safari/manage-cookies-sfri11471/mac

• Microsoft Edge: support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge

Third-Party Cookies

Some cookies are placed by third-party services that appear on our pages. We do not control these third-party cookies. Please refer to the relevant third party's website for more information about their cookies:

• Google: policies.google.com/technologies/cookies

• HubSpot: legal.hubspot.com/cookie-policy

7. Sharing Your Information

We may share your personal data with:

Service providers: Third-party vendors who help us operate our platform, including cloud hosting (Heroku/AWS), analytics providers, and business tools.

Legal requirements: When required by law, regulation, or legal process.

Business transfers: In connection with a merger, acquisition, or sale of assets.

We do not sell your personal data to third parties.

For a complete list of our sub-processors, see our Sub-processors page.

8. International Transfers

Your personal data is stored and processed within the European Union (AWS EU region, Frankfurt, Germany). We do not transfer personal data outside the EU/EEA unless appropriate safeguards are in place, such as EU Standard Contractual Clauses or the EU-US Data Privacy Framework.

9. Data Retention

We will retain your personal data for as long as necessary to provide our services or as required by law. Upon termination of your account or at your request, your data will be deleted, except where retention is required for legal or legitimate business purposes:

Active account data: Duration of your account plus 1 year

Transaction/commission records: 5 years (legal requirement under Danish law)

Marketing data: Until you withdraw consent

Support correspondence: 3 years after last contact

Upon termination of your account or at your request, your data will be deleted unless retention is required by law.

10. Your Rights

Under GDPR, you have the following rights regarding your personal data:

Right of access: Request a copy of the personal data we hold about you.

Right to rectification: Request correction of inaccurate or incomplete data.

Right to erasure: Request deletion of your personal data (subject to legal exceptions).

Right to restriction: Request that we limit how we use your data.

Right to data portability: Receive your data in a structured, machine-readable format.

Right to object: Object to processing based on legitimate interests or for direct marketing.

Right to withdraw consent: Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, please contact us at legal@prowi.io. We will respond within 30 days.

11. Security

We implement appropriate technical and organisational measures to protect your personal data, including:

• Encryption of data in transit (TLS) and at rest (AES-256)

• Two-factor authentication (2FA)

• Role-based access controls

• Regular security reviews and monitoring

• Secure cloud infrastructure (Heroku/AWS EU-North-1, Stockholm. with SOC 2 and ISO 27001 certifications)

While we strive to protect your data, no method of transmission or storage is 100% secure.


12. Children's Privacy

Our Service is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on our website and updating the "Last updated" date. We encourage you to review this policy periodically.

14. Contact the Supervisory Authority

If you have concerns about our processing of your personal data, you have the right to lodge a complaint with the Danish Data Protection Agency:

Datatilsynet
Carl Jacobsens Vej 35
2500 Valby
Denmark

Phone: +45 33 19 32 00
Email: dt@datatilsynet.dk
Website: www.datatilsynet.dk

We encourage you to contact us first so we can try to resolve any issues together.

15. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:

Prowi ApS
Klamsagervej 35
8230 Åbyhøj
Denmark

Email: legal@prowi.io
Phone: +45 70604554