Privacy Policy

Last updated: 21.07.2025

This website is operated as a student-led project in collaboration with DTU Entrepreneurship. We take your privacy seriously and are committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR) and Danish data protection laws.

1. Who We Are (Data Controller)

Responsible for data processing:
Prof. Carina Lomberg
DTU Entrepreneurship
Technical University of Denmark (DTU)
Akademivej, Building 34
22800 Kongens Lyngby,
Denmark
Email: calom@dtu.dk

2. What Personal Data We Collect

We only collect personal data when you sign up for a membership on this website. This may include:

-> Full name
-> Email address
-> Login credentials
-> Other voluntarily provided information (e.g. profile info)

We do not collect sensitive data such as health information, political views, or biometric data.

3. Why We Collect and Process Your Data

We process your personal data solely for the following purposes:

-> To manage your membership access
-> To provide content or services that are available only to members
-> To communicate with you, if needed
-> To improve the functionality and security of the website

We do not sell or rent your data to third parties.

4. Legal Basis for Processing

According to GDPR Article 6, we rely on the following legal bases:

-> Consent – you voluntarily provide data during sign-up
-> Legitimate interest – to operate and improve our membership platform
-> Contract performance – managing your account if services are provided

You may withdraw your consent at any time by contacting us at calom@dtu.dk

5. Third-Party Tools and International Transfers

To run this website, we use trusted third-party providers. Some of your data may be transferred to and stored in the United States. These transfers are legally permitted under GDPR due to adequate safeguards:

Our service providers:

Webflow, Inc. (Website hosting & CMS)
➤ DPF-certified & uses Standard Contractual Clauses (SCCs)
Privacy Policy

Memberstack, Inc. (User authentication & membership management)
➤ Uses SCCs & provides a GDPR-compliant Data Processing Addendum (DPA)
Privacy Policy

Make (formerly Integromat)
➤ Offers SCCs and EU-based data centers for workflows
Privacy Policy

OpenAI, Inc. (Used for selected AI-generated content)
➤ Uses SCCs and complies with GDPR through data minimization.
Privacy Policy

We ensure all third-party providers offer appropriate safeguards under Article 46 of GDPR.

6. Cookies

This site may use cookies to enable core functionality and analyze performance. Where required by law, you will be asked for explicit cookie consent. You can also manage cookies via your browser settings.

7. Data Storage and Retention

Your data is stored securely by our providers and is only retained:

-> As long as your membership is active
-> Or until you request deletion of your data

We implement industry-standard technical and organizational measures to protect your data from unauthorized access.

8. Your Rights Under GDPR

As a data subject, you have the right to:
-> Access your data
-> Correct inaccurate or incomplete data
-> Request deletion (“right to be forgotten”)
-> Restrict or object to processing
-> Withdraw consent at any time
-> File a complaint with Datatilsynet (Danish Data Protection Agency): https://www.datatilsynet.dk

9. Contact

If you have questions about how we process your data or want to exercise your rights, contact:
Prof. Carina Lomberg
Email: calom@dtu.dk