Skip to content

Persondata policy.

How we collect, use and protect your personal information — and what rights you have.

In short

Last updated: August 2026

This policy describes how Discebo processes personal data about you when you create a profile and use the platform. We only process the data that is necessary to run a professional learning and work platform for craftspeople.

If you use the platform through a school or company, there are two layers: your own information, where we are the data controller, and the school or company's information about you — hours, absences, pay, matters — where they are the data controller and we process on their instructions. It is marked along the way where it makes a difference for who you should contact.

Data controller

The data controller for the processing of your personal data is Discebo. If you have questions about this policy or wish to exercise your rights, you can contact us:

  • Camsilo (v/ Casper Madsen)
  • Address: Ørstedvej 15, 6560 Sommersted
  • Company reg. no.: 45925145
  • Contact (e-mail): kontakt@camsilo.dk

What personal data do we process?

We process the information you provide yourself and the data that arises when you use the platform:

  • Profile information — name, email address (login), password (stored securely as scrypt hash, never in plain text), and optional fields such as role, company, school, phone number, region, experience, education, brief bio, profile picture, and qualifications/certificates.
  • Trade activity — quiz and test answers, projects and material calculations, saved items and your subject/membership.
  • Active learning time — how much time you are active on professional content (calculators, articles, videos, quizzes etc.), totalled in days per subject. This drives your own time overview, your streak and your achievements (badges). If you are a student in a class, your teacher can see your active time as part of the teaching (never other students or classes). You can turn off the measurement in your settings, and you always see exactly the same as the teacher.
  • Social data — feed posts, likes and comments, friendships, user-to-user messages, forum threads and posts, calendar/shifts, class and team memberships.
  • Work & market — job posts and applications, marketplace ads and buy/sell inquiries.
  • Uploads — images and files you share (profile picture, feed and marketplace images, message attachments).
  • Technical data — a secure, signed session cookie and certain technical information such as IP address, used temporarily to protect against abuse (e.g. rate limiting on login).
  • Work data in a company — registered working hours and shifts, absence with type and period, driven kilometres and routes, expenses with receipt photos, wage basis and wage statement, employment date, employee number and your role and rights in the company. If you work in a company on the platform, the company is the data controller for this information, and we process it on the company's instruction according to a data processing agreement. The time card can also contain a start time and an end time if you fill them in yourself — they are voluntary, and a time card without them is just as valid. Finally, an hour can be marked as billable and carry an hourly charge-out rate; that is information about the work and about the company's invoicing to its customer, not about you.
  • Working environment: accidents and near misses — if you are injured at work, the company can record who was injured, the type of injury from a fixed list, what happened, your days off work, and the date and reference number of the report the company itself submitted. This is health information — see the separate section on sensitive personal data below. A near-miss incident never bears a name.
  • Jobs, customers and documents — cases and tasks with photos, notes and time spent, the company's customer directory with contacts, quotes, invoices and credit notes, form submissions, drive files and digital signatures with name, time and technical traces. If you are a customer of a company on the platform, your contact information can be stored here even if you have not created a profile yourself — the company is the data controller for it.
  • Your own finances — if you use «My finances», it is information about YOU and not about an employer: deductions, rates you have chosen to calculate with, and eventually figures about transport, student grant and income you yourself enter. We are data controllers for them, and no company, foreman or school can see them — there is no right to assign. The basis is your consent (art. 6(1)(a)), and you can withdraw it by deleting the information or your account; there is no record-keeping obligation that binds us to keep them. We NEVER ask for your CPR number, and we retrieve nothing from your tax return or from the Danish Tax Agency. We also don't know your salary payments — that's why it says 'possible deduction' and never 'your deduction'. The calculations are a basis for your own conversation with SKAT or an advisor; they are not a ruling.
  • What you send to the AI features — see the section on AI features below. Briefly: what you yourself write, dictate or photograph when using one of them.
  • Activity and audit log — in order to detect errors and misuse, we log which actions are performed, by whom and when, together with the path and any error message. The log is retained for a maximum of 180 days. Administrative actions — including when a support employee views the platform as a user in order to help — are logged separately and cannot be deleted by the administrator who performed them.
  • Enquiries to us — if you write to us via the contact form or support, we process your name, your e-mail address and the contents of your enquiry, even if you don't have an account. The email is held by our e-mail provider (see the list of data processors below).
  • Consents we have received from you — when you give consent, we save the consent itself along with the time and where it was given, because we must be able to document it. This applies to consent to newsletter and consent when purchasing a subscription to start delivery immediately.

Sensitive personal data (special categories)

If you use the platform's absence module in a company, we process absence recorded as 'sickness'. It is health information under article 9, and it is included in the payroll data because sick leave is handled differently than holiday. The processing is necessary to fulfil employment and employment law obligations and is based on art. 9, section 2, letter b, cf. the data protection act § 12 — together with performance of contract, art. 6, section 1, letter b. We record only that the absence is illness, never a diagnosis, and you should not provide one. The employer is the data controller for the information; we process it on the employer's instruction.

Workplace accidents and near misses

If your company registers a work accident in the work environment module, we treat another health information about you: who was injured, the type of injury selected from a fixed list, what happened, how many days you could not perform your usual work, and the date and record number if the accident was reported. The processing is based on the same grounds as sick leave — Art. 9, para. 2, litra b, cf. the Data Protection Act § 12 — together with the employer's legal obligation under the Working Environment Act and the Workers' Compensation Insurance Act, Art. 6, para. 1, litra c. We store no diagnosis, no treatment, no doctor's name and no medical record; there are no fields for it. Only the person in the company who has decision-making authority over users and staff can read the register — your colleagues cannot. You can always see your own records, and they are deleted when you delete your account. Discebo does not report the accident; the employer does it themselves in EASY at virk.dk, and the Working Environment Authority and the Danish Working Injury Insurance Association are independently responsible for that report. A near-miss incident is never linked to a named person.

Apart from the two categories mentioned, the platform has no fields for sensitive personal information. But free text can in practice come to contain them — a note about work clothes can, for example, reveal an allergy. Therefore avoid writing health or other sensitive information in free text fields (bio, posts, messages, notes), and certainly never write them about anyone other than yourself. Access to colleagues' body measurements and equipment notes is limited to the roles that have been given decision-making rights for the equipment module.

Purpose and legal basis

We process your information for these purposes with the following legal basis under the Data Protection Regulation (GDPR):

  • To create and operate your account and provide the platform's features (profile, learning, feed, messages, jobs, marketplace etc.) — fulfillment of contract, art. 6, para. 1, litra b.
  • To protect operations against abuse and fraud (e.g., login protection and logging) — legitimate interest, art. 6, sec. 1, lit. f.
  • To measure your active learning time so you can track your own progress, and — if you are a student in a class — so your teacher can follow the teaching. It is a core function in the learning platform (and thus not marketing statistics, which only runs with cookie consent) — performance of contract, art. 6, para. 1, lit. b. You can turn off the measurement in your settings.
  • Handling payment and subscription where relevant — fulfillment of contract and legal obligation (accounting).
  • To handle optional information you choose to add to your profile (e.g. job search status) — consent art. 6 para. 1 lit. a. You give consent by filling in the field yourself and can withdraw it at any time by removing the information in your settings. Your job search status is used ONLY for job searching — to make you visible to employers and match you with listings. We do not use it to select recipients of newsletters or other marketing; that would be a different purpose than the one you gave consent for (art. 5, para. 1, lit. b).
  • To record working time, shifts, absences, mileage, expenses and payroll basis for a company you work for, and to manage the company's cases, customers and documents — the company is the data controller, and we are the data processor under art. 28. The company's basis is typically fulfilment of the employment contract (art. 6, para. 1, lit. b), legal obligation (art. 6, para. 1, lit. c — e.g. accounting and working time rules) and for sick leave art. 9, para. 2, lit. b.
  • Sending you newsletters and other marketing about the platform — your explicit consent, art. 6, para. 1, lit. a, and marketing law § 10. We save the time of consent and where you gave it so we can document it. You can unsubscribe from each individual email — even without logging in — and the unsubscribe takes effect immediately. Necessary messages about your account and subscription (receipts, password reset, service notices) are not marketing and are sent regardless of your consent, because they are part of the agreement.
  • To log actions on the platform, so errors and abuse can be discovered and verified, and so a company can see who has changed what — legitimate interest, art. 6, para. 1, lit. f. The log is kept for a maximum of 180 days.
  • To answer your enquiry to us — legitimate interest, art. 6, section 1, letter f, or performance of contract, if the inquiry concerns your subscription.

AI features — what is sent out, and when

The platform's AI functions are powered by language models from Anthropic PBC in the USA. They send something only when you use the function yourself — there is no AI running in the background, and no content is sent on its own. Specifically:

  • The trade assistant — the entire conversation with the assistant and which trade or which qualification you are asking about within.
  • The job assistant — in addition to your questions, hidden context about the case you are in is sent: the case name, customer name, address, case status and an overview of materials with an estimated material price. The context is not shown in the chat window, but it is sent along so the answer fits the case. If the customer is a private person, the customer's name and address thus leave the EU when you use the function.
  • Translating a message — the entire text in the message you choose to translate, plus the language you want it translated to. This also applies to a PRIVATE message from another user: when you press translate, the entire content of the message leaves the platform. We do not save the translation.
  • Dictating a task — the text you dictate about a task. The actual conversion from speech to text happens in your own browser; it is the finished text that is sent on to be split into title, description and priority.
  • Reading a receipt — the actual IMAGE of the receipt. Everything that is in the image frame is transmitted: supplier, amount, VAT, date, possible mileage — and everything else that happens to be there. Therefore, include only the receipt in the image. We only save the fields that are read.
  • Travel plan suggestions — your free text about the trip: destination, dates and number of people.
  • Quote lines from a description — your description of the task, and if you choose, a PICTURE of the task. Everything in the picture frame is sent, so photograph only what the work is about. In addition, three fields are sent from each line in your company's previous quotes: the service text, the unit and the unit price — so the proposal can use the company's own prices instead of guessing. No customers, addresses, quote numbers or totals are sent; but the line text is a field you write yourself, so if you write a customer or person name into a quote line, it follows the next time the function is used. We save nothing from the answer until you yourself place the lines in the quote.

We have agreed with the supplier that your content is not used to train models, and the transfer to the USA is based on a valid legal basis — see the section on third countries below, where the basis is stated for each individual supplier. If your employer or school does not want data sent to any country outside the EU/EEA, AI functions can be disabled for the organization.

Minors

Discebo is used in a professional and educational context. If you are under 15, you may only create a profile and give consent with the permission of a parent or guardian. Schools and teachers who invite students are responsible for obtaining necessary parental consent for students under 15. Contact us if a profile has been created for a minor without proper consent — we will remove it.

Payment

If you subscribe to a paid subscription, the payment itself is handled by our payment provider Stripe. We do not store your full card details — only a reference to your subscription and its status. Stripe has two roles: when the payment is processed on our instructions, Stripe is our data processor; for their own fraud prevention and legally required payment control, Stripe is an independent data controller according to their own policy. If you have questions about the latter part, they should be directed to Stripe.

If you buy a subscription, we ask you at the same time to confirm that delivery of the digital content may begin immediately, and that your 14-day right to withdraw thus expires (Consumer Contracts Act § 18, section 2, no. 13). We save that confirmation together with the time and the version of the text you were shown, because we must be able to document exactly what you said yes to. If you do not confirm, the purchase is not completed.

Who sees your information?

Other users can see the information you share publicly or with your connections: your profile, your feed posts (according to the visibility you choose), your marketplace and job postings, and messages you send. Messages between two users are only shown to sender and recipient, and we use them for nothing else. If the sender or recipient chooses to have a message translated, the message's text is sent to our translation provider — see the section on AI functions. We do not sell your personal data.

If you block another user, we store the block to enforce it. When you request access to your data, we only provide YOUR own blocks — i.e. who you have blocked, never who has blocked you. That would reveal another person's choice, and the right of access may not violate others' rights (art. 15, para. 4).

In addition to other users, we share data with the processors who help us run the platform. Here are all of them — the list comes from one place in the code, so it cannot fall behind when we add a function:

Recipients of your data

10
HostStack[udfyldes af den dataansvarlige]Data processor for usHosting af selve platformen: applikationsserver, database og fillager.Alle data på platformen, fordi de fysisk ligger på leverandørens diske.Altid — hele platformen kører hos leverandøren.
StripeIrland (EU) og USAData processor for usKortbetaling og abonnementsstyring for både personlige abonnementer og firma-pladser.Navn, e-mailadresse, betalingsoplysninger og abonnementets status. Vi gemmer selv kun en reference til abonnementet — aldrig fulde kortoplysninger.Kun hvis du tegner eller administrerer et betalt abonnement.
Claude (AI-assistent, oversættelse, diktat, kvitteringsscan)USAData processor for usAlle AI-funktioner: fag-assistenten, sags-assistenten, oversættelse af beskeder, diktat af opgavetekst, aflæsning af kvitteringsfotos og rejseplan-forslag.Det indhold du selv sender til funktionen. Konkret: hele samtalen i assistenten; sags-assistenten sender desuden en skjult kontekst med sagens navn, kundens navn, adresse, status og materialeoverblik inkl. anslået materialepris. Oversættelsen sender hele teksten i den besked du oversætter. Diktatet sender din dikterede tekst. Kvitteringsscanningen sender selve FOTOET af kvitteringen — altså leverandør, beløb, moms, dato, eventuel kilometerstand og alt andet der er med i billedet. Rejseplanen sender destination, datoer og antal personer.Kun når du selv bruger en af AI-funktionerne. Der sendes intet i baggrunden.
PostStack[udfyldes af den dataansvarlige]Data processor for usAl udgående e-mail (kvitteringer, nulstilling af adgangskode, afmeldingslink, nyhedsbreve) og den indgående postkasse som henvendelser til platformen lander i.Modtagerens navn og e-mailadresse samt mailens fulde indhold. For indgående post desuden afsenderens adresse og eventuelle vedhæftninger.Hver gang der sendes eller modtages en e-mail.
Bunny Stream / bunny.netSlovenien (EU)Data processor for usLagring, transkodning og levering af video du uploader.Selve videofilen og dens indhold, samt IP-adressen på den der ser eller uploader videoen.Kun når du uploader eller afspiller en video.
Google Analytics 4Irland (EU) og USAData processor for usStatistik over hvordan sitet bruges.Besøgs-id i en cookie, hvilke sider du ser, hvor du kom fra og dit browsersprog.Kun hvis du selv vælger «Accepter alle» i cookie-banneret. Vælger du «Kun nødvendige», indlæses Google aldrig.
Log ind med GoogleIrland (EU) og USAIndependent data controllerGodtgør over for os at du er indehaver af en Google-konto, så du kan logge ind uden en ekstra adgangskode.Vi modtager dit navn, din e-mailadresse og et konto-id. Google ser at du logger ind på Discebo.Kun hvis du selv vælger at logge ind med Google.
Log ind med FacebookIrland (EU) og [udfyldes af den dataansvarlige]Independent data controllerGodtgør over for os at du er indehaver af en Facebook-konto, så du kan logge ind uden en ekstra adgangskode.Vi modtager dit navn, din e-mailadresse og et konto-id. Meta ser at du logger ind på Discebo.Kun hvis du selv vælger at logge ind med Facebook.
MobilePayNorge (EØS)Data processor for usBetaling med MobilePay, hvor en virksomhed har slået det til.Beløb, betalingsreference og betalerens MobilePay-oplysninger.Kun hvis din virksomhed har aktiveret MobilePay som betalingsmåde.
Browserens push-tjenesteUSA — hvilken af dem, afgøres af din browser, ikke af osIndependent data controllerAt levere notifikationer til din telefon eller computer, når nogen skriver til dig eller der sker noget der vedrører dig.Det endpoint din egen browser har udstedt (en unik adresse til netop den browser-installation) samt selve notifikationen — men KUN i krypteret form. Indholdet krypteres ende-til-ende til din browsers egne nøgler efter RFC 8291, så push-tjenesten videresender en blob den ikke selv kan læse. Den kan altså se AT der blev sendt noget til din enhed og hvornår, men ikke hvad der står.Kun hvis du selv har slået notifikationer til i den enkelte browser. Slår du dem fra igen, sendes der intet.

In addition, you can have the platform create a file yourself — for example a payroll export for the payroll system or a ledger file for the accounting software. You download the file yourself, and what happens to it afterwards is your or your employer's responsibility. We do not forward it for you.

Transfer to third countries

We aim to process your data within the EU/EEA. Some of our data processors process it outside the EU/EEA, and for each there must be a specific transfer mechanism under art. 44-49. Here they are — and the basis for each one, with the source we have verified it from:

Processors outside the EU/EEA

8
  • HostStack ([udfyldes af den dataansvarlige]) — [udfyldes af den dataansvarlige]Source: [udfyldes af den dataansvarlige] — driftaftalen og leverandørens databehandlervilkår findes ikke i kodebasen, og hverken region eller juridisk enhed kunne bekræftes 2026-08-05.
  • Stripe (Irland (EU) og USA) — Stripe oplyser selv at overførsler til USA hviler på BÅDE en certificering under EU-U.S. Data Privacy Framework OG EU-Kommissionens standardkontraktbestemmelser (SCC).Source: stripe.com/legal/privacy-center — afsnittene «Is Stripe certified under the EU-U.S Data Privacy Framework?» og «How to get a copy of the SCCs or UK Addendum?», læst 2026-08-05.
  • Claude (AI-assistent, oversættelse, diktat, kvitteringsscan) (USA) — EU-Kommissionens standardkontraktbestemmelser (SCC, modul 2 og 3) via Anthropics databehandleraftale, der automatisk indgår i deres erhvervsvilkår. Anthropic påberåber sig IKKE en certificering under EU-U.S. Data Privacy Framework: deres egen privatlivspolitik nævner udelukkende SCC og adgangsafgørelser.Source: anthropic.com/legal/privacy (senest opdateret 8. juli 2026): «We rely on standard contractual clauses to transfer information … to certain affiliates and third parties in countries without an adequacy decision». DPA'ens indarbejdelse: privacy.claude.com/en/articles/7996862. Begge læst 2026-08-05. ⚠️ Offentlige kilder er UENIGE om Anthropics DPF-status — derfor er SCC anført som grundlaget, fordi det er det leverandøren selv skriver.
  • PostStack ([udfyldes af den dataansvarlige]) — [udfyldes af den dataansvarlige]Source: [udfyldes af den dataansvarlige] — ⚠️ EFTERPRØVET 2026-08-05: poststack.dev offentliggør hverken juridisk enhed, hjemland, privatlivspolitik, databehandleraftale eller behandlingssted. Uden dem er art. 28, stk. 1's krav om «tilstrækkelige garantier» ikke dokumenteret, og hjemlandet kan derfor heller ikke oplyses her.
  • Google Analytics 4 (Irland (EU) og USA) — Googles databehandlervilkår anvender en «Alternative Transfer Solution» med EU-Kommissionens standardkontraktbestemmelser (SCC) som den udtrykkelige tilbagefaldsordning, hvis den løsning ikke er i kraft. Selve behandlingen sker for europæiske kunder hos Google Ireland Limited.Source: business.safety.google/adsprocessorterms — «if Google has not adopted, or informs Customer that Google is no longer adopting an Alternative Transfer Solution for any Restricted European Transfers, then … the SCCs … will apply». Læst 2026-08-05.
  • Log ind med Google (Irland (EU) og USA) — Google fastlægger selv formål og midler for sin egen konto-behandling og er dermed selvstændig dataansvarlig efter sin egen politik. Vi overfører ingen data til Google ud over den forespørgsel du selv udløser.Source: policies.google.com/privacy — Googles egen politik gælder for kontoen. Læst 2026-08-05.
  • Log ind med Facebook (Irland (EU) og [udfyldes af den dataansvarlige]) — [udfyldes af den dataansvarlige]Source: [udfyldes af den dataansvarlige] — ⚠️ Metas overførselsgrundlag for login-flowet er IKKE efterprøvet 2026-08-05, og posten skal derfor udfyldes eller integrationen fjernes, før politikken udleveres.
  • Browserens push-tjeneste (USA — hvilken af dem, afgøres af din browser, ikke af os) — [udfyldes af den dataansvarlige]Source: [udfyldes af den dataansvarlige] — ⚠️ Overførslen sker til den push-tjeneste DIN BROWSER har valgt (Googles FCM, Apples APNs eller Mozillas autopush). Vi har intet kundeforhold til nogen af dem og kan derfor hverken indgå en aftale eller fremvise et grundlag; den dataansvarlige må tage stilling til om overførslen kan hvile på art. 49, stk. 1, litra b (nødvendig for at opfylde en aftale den registrerede selv har anmodet om — brugeren slår notifikationer til aktivt) eller om funktionen skal begrænses. Forholdet der taler for: indholdet er krypteret ende-til-ende til brugerens egne nøgler (RFC 8291), så det der reelt overføres i klartekst, er endpointet og tidspunktet. Teknisk kilde: RFC 8291 + RFC 8292 (VAPID); afsendelsen sker i src/lib/push/send.ts via web-push-pakken.

Our other sub-processors process your data within the EU/EEA, and for them there is no third-country transfer to rely on a basis.

How long do we store data?

We store your information as long as you have an active account. If you delete your account, we remove or anonymize your personally identifiable data across the platform — including profile, posts, messages you have sent, ads, job postings, projects, exam answers and uploads. Certain information may be stored for a shorter period if law requires it (e.g. accounting materials for payments).

Beyond this, three fixed limits apply: the activity log is deleted automatically after 180 days, and those lines in it that point to you as the acting person are removed at the same time your account is deleted. Our own visit statistics are anonymised when the account is deleted, so the figures remain but the link to you does not. If you have given consent to the newsletter, we keep the consent itself and the time as long as it is valid, and after withdrawal only as long as we may need to document that we had it.

If you work at a company on Discebo, the company owns its own business data — for example customer records, quotes and invoices. These data are therefore not deleted together with your personal account, even if you created them: the company is the data controller, and invoices are also accounting material that must be kept for 5 years. If you want them deleted, you must contact the company.

Sletter du en sag eller et projekt, bliver det arkiveret: det forsvinder fra listerne, men sagen, dens filer og alt, hvad der peger på den, bevares og kan gendannes. En personlig sag eller et projekt slettes endeligt sammen med din konto. En virksomheds sag slettes endeligt, når virksomheden slettes — medmindre den, der oprettede sagen, stadig har en konto; så overgår sagen til vedkommende og slettes sammen med den konto.

Your rights

Under the data protection rules you have, among other things, the right to:

  • Insight into the personal information we process about you.
  • Correction of incorrect information.
  • Deletion of your information ("the right to be forgotten").
  • Data portability — getting a copy of your data in a machine-readable format.
  • Making objection to and limiting certain treatments.
  • To withdraw consent without affecting the legality of previous processing.

You can exercise several of these rights directly on your settings: here you can edit your profile, download a complete copy of your data, and delete your account. You are also always welcome to contact us.

The right of access has one natural limit: we provide your own data, but not data that would reveal another person's choice or data (art. 15, para. 4). Therefore you can see who you have blocked, but not who has blocked you.

Are you a school or a company?

If your organisation uses the platform for students or employees, the organisation is the data controller for the information, and we are the data processor. Then there must be a data processing agreement under art. 28. Our draft — with annex on sub-processors and security measures — can be read here: data processing agreement. If you have your own standard agreement, we'd rather look at that instead.

Complaint

If you are dissatisfied with how we handle your personal information, you can complain to: Danish Data Protection Authority (datatilsynet.dk). However, we would appreciate it if you contacted us first so we can help.

Cookies

We use necessary and functional cookies and local storage — and only with your consent anonymous statistics about how the site is used (our own first-party measurement and Google Analytics). No tracking across sites or marketing. Read the details in our cookiepolicy.