Privacy Policy
Last updated: 17 September 2026
This privacy policy describes how Storebook processes personal data in connection with the customer portal at app.storebook.dk. The policy applies to the users your company creates in the portal, and to any personal data that may be contained in the accounting records we process on your behalf.
Data controller
Storebook ApS, Grønnegade 1, 1., 1107 København K, CVR 46721519, is the data controller for the personal data described under "Our two roles" below.
Questions about this policy or about our processing of personal data can be sent to philip@storebook.dk.
Storebook has not appointed a data protection officer (DPO). Our processing does not meet the conditions in Article 37 of the GDPR (the General Data Protection Regulation) for when appointing one is mandatory. Data protection enquiries can be sent to philip@storebook.dk.
Our two roles
Storebook is the data controller for the data we process to provide and operate the portal: contact details for your users, login and security data, and log data about use of the platform.
Storebook is a data processor for the personal data contained in your accounting and bookkeeping records. Here we process the data exclusively on your documented instructions. The terms for this processing are set out in the data processing agreement (DPA) that forms part of your agreement with us.
In the event of any inconsistency between this policy and the data processing agreement, the data processing agreement governs the processing we carry out as data processor.
What personal data we process
User data: name, email address, phone number and role for the users your company creates in the portal.
Login and security data: authentication data handled via a dedicated identity service, including two-factor authentication. We do not store passwords in plain text.
Usage and log data: login timestamps, actions taken in the portal, IP address and technical information about browser and device, used for operation, troubleshooting and security.
Accounting and bookkeeping data: vouchers, invoices, bank transactions and postings that you upload, or that are retrieved from the integrations you connect yourself in the portal. Today that covers the accounting system e-conomic, the commerce platform Shopify, the payment platforms Adyen and Airwallex, and the Gmail or Outlook mailbox you give access to, from which attachments are retrieved and processed as vouchers. The list of integrations in force at any given time is shown in the portal. This material may contain personal data about your employees, customers and business partners.
Commerce data from Shopify, where that integration is enabled: order, payment, refund, product, inventory and delivery data. We do not import a customer's name, email, phone number, address, IP address, notes or tracking number. Where repeat-purchase metrics require an identifier, a customer-specific pseudonymous reference is used.
Purpose and legal basis
Providing the portal and performing the agreement with your company, including creating users and managing access. Legal basis: GDPR Article 6(1)(b), and GDPR Article 6(1)(f) with respect to data about employees of a business customer.
Processing accounting records on your behalf. Legal basis: GDPR Article 6(1)(b) and (f), Storebook acting here as data processor under your instructions.
Compliance with legal obligations, including bogføringsloven's (the Danish Bookkeeping Act's) requirements on retaining accounting records. Legal basis: GDPR Article 6(1)(c).
Operation, troubleshooting, security and abuse prevention, including logging. Legal basis: GDPR Article 6(1)(f). Our legitimate interest is keeping the platform stable and secure, and we have assessed that this interest is not overridden by the rights of the data subjects.
Receiving a name and email address is a precondition for creating a user. Without this data, access to the portal cannot be granted.
Automated suggestions and human control
The platform uses automated models to suggest coding of vouchers and bank transactions and to extract data from vouchers.
The suggestions are preparatory only. No posting is completed automatically: a suggestion must be approved by an employee before it takes effect. No decisions are therefore made based solely on automated processing within the meaning of GDPR Article 22.
Responsibility for the bookkeeping being correct remains with your company and your responsible bookkeeper or accountant.
Where the data comes from
We receive user data from your company when a user is created or invited.
We receive accounting and commerce data from you or from the systems you connect yourself in the portal — today e-conomic, Shopify, Adyen and Airwallex — and from the Gmail or Outlook mailbox you give access to, from which we retrieve attachments as vouchers. That list is not exhaustive for all time: the list of integrations in force at any given time is shown in the portal. We receive account and bank transaction data from your bank via an account information service, once you have given the bank authorisation to do so.
Personal data about third parties — for example a supplier's contact person on an invoice — therefore originates from your own material and not from that person directly.
Recipients and data processors
We use the following categories of data processors to provide the platform: cloud infrastructure, storage, authentication and running AI models, frontend hosting, document recognition, sending transactional emails, obtaining account and bank transaction data via an account information service once you have connected a bank, access to the email mailbox you connect and retrieval of its attachments as vouchers, and delivery of notifications to the Slack workspace you connect.
Your own connected business systems are not data processors for Storebook. That applies to the accounting integration your company has chosen — today e-conomic — and to commerce platforms such as Shopify and payment platforms such as Adyen and Airwallex. The system is your own, under your own agreement with the provider, and we access it as your agent under your instructions. See Annex C of the data processing agreement.
We use data processors only under a written agreement imposing data protection obligations equivalent to our own.
An up-to-date overview of sub-processors is available in Annex C of the data processing agreement. Material changes to the set of sub-processors are notified in accordance with the data processing agreement.
We do not sell personal data and do not disclose it for marketing purposes.
Transfers to third countries
Our primary infrastructure is located in the EU. Processing and storage of your data take place within the EU/EEA with established cloud providers. After activation and verification, the planned recovery configuration will store encrypted rotating backups of protected production data in another EU region. AI models are run within the EU, distributed across several EU regions rather than in one named region.
Frontend hosting, the sending of transactional email and the machine reading of vouchers may involve transferring data to countries outside the EU/EEA. These transfers take place on the basis of the European Commission's Standard Contractual Clauses (SCCs), supplemented by the EU-US Data Privacy Framework where the recipient is certified. The processors concerned are named in Annex C of the data processing agreement, and a copy of the relevant safeguards can be requested from philip@storebook.dk.
For the account information service, the email integration and the Slack integration, no data is transferred to a third country without a valid transfer basis. The processors concerned are named in Annex C of the data processing agreement, and the specific basis is disclosed on request. The email integration is accessed via the service's EU endpoint.
Retention
Accounting records are retained for 5 years from the end of the financial year to which they relate, in accordance with bogføringsloven (the Danish Bookkeeping Act).
User data is retained for as long as the agreement with your company is active. On termination, the data is deleted or anonymised unless continued retention is required by law.
Log and security data is retained for three months in production.
When the Shopify app is uninstalled, synchronisation stops immediately and access credentials are deleted. Configuration and operational data is deleted upon Shopify's deletion request. Only material we are legally required to retain is kept, for the required period.
Security
We have implemented appropriate technical and organisational measures to protect personal data against accidental or unlawful loss, alteration, unauthorised access and disclosure.
The measures are described in more detail on the Security page.
If we become aware of a personal data breach concerning data for which we are ourselves the data controller, we notify Datatilsynet (the Danish Data Protection Agency) within 72 hours where the GDPR requires it, and notify the affected individuals without undue delay where the breach entails a high risk.
Where we act as your data processor, we notify you without undue delay after becoming aware of the breach. In that situation we do not report the breach to Datatilsynet and do not notify data subjects on your behalf; that responsibility rests with you as data controller, unless otherwise separately agreed. See the personal data breach section of the data processing agreement.
Your rights
Under the GDPR, data subjects have the right to access their own data, the right to rectification of inaccurate data, the right to erasure, the right to restriction of processing, the right to data portability, and the right to object to processing carried out on the basis of a legitimate interest.
These rights are not absolute. We may be required to continue retaining data where the law requires it — typically accounting records under bogføringsloven (the Danish Bookkeeping Act).
Enquiries about your rights can be sent to philip@storebook.dk. We respond without undue delay and no later than one month after receipt.
If your enquiry concerns data we process as a data processor for a customer, we will refer you to that company, which is the data controller for the material.
Complaints to Datatilsynet
If you are dissatisfied with our processing of personal data, we would welcome hearing from you first at philip@storebook.dk, so we can try to resolve the matter.
You always have the right to lodge a complaint with Datatilsynet (the Danish Data Protection Agency), Carl Jacobsens Vej 35, 2500 Valby, Denmark, phone +45 33 19 32 00, dt@datatilsynet.dk, www.datatilsynet.dk.
Changes to this policy
We update this policy when the platform, the law, or the set of sub-processors changes. The date at the top of the page shows the most recent update.
For material changes, we notify you via the portal or by email before the changes take effect.