Consitus

Transparency about data and security

Consitus Trust Center

One place for privacy, technology and agreements. Find the documents, understand our providers' roles and ask questions about your solution.

Updated 1 October 2026

A clear basis for working together

We bring together information about consitus.dk and show where to request documentation for Consitus Intranet and your other solutions. Specific data-processing and operational requirements are addressed in the agreement for each solution.

Privacy

Read about information, purposes, retention and your rights when you visit the website or contact us.

Read the privacy policy

Cookies and consent

Read the cookie policy and change your choices in iubenda's preference panel. Submitting a form does not subscribe you to a newsletter.

Read the cookie policy

Agreements

Find our B2B terms of sale. Contact us about specific requirements for data processing, access or operation of your solution.

Read the terms of sale

Data and access in Consitus Intranet

This describes the shared intranet platform. Your chosen modules, integrations and agreement determine which information is processed in your solution.

Responsibilities and contact
Consitus ApS is the controller for its own customer and contact information. Anne Lehd Jepsen is the responsible contact at Consitus. When we process information on your behalf in the intranet, you are generally the controller and Consitus is the processor.
Database in Ireland
The shared intranet platform's Supabase database is located in AWS region eu-west-1 in Ireland. This describes the database location; email, integrations and other providers may involve processing elsewhere.
Users and support access
Access is managed through users, company membership and roles. The platform's support function supports time-limited access to a particular company with read-only or extended access. Consitus administrators may therefore have access for operation and support.
Backup and recovery
Uploaded files are backed up daily in the EU. A full file restore has been completed and verified in the EU, and email alerts for failed and missed backups have been tested. File backup and database backup have separate scopes; retention and agreed recovery objectives are set out in the operational schedule.

Data processing agreement for your intranet

Enter your company details and download a completed draft with schedules covering processing, security and subprocessors. The agreement is completed with you before signing.

Create your data processing agreement

Enter your company details to generate a personalised PDF draft. The agreement is in Danish and uses Consitus' draft v0.2.

The PDF is created in your browser. This form does not send your details to Consitus or save them between visits.

Create your data processing agreement

For example: Intranet, documents, time tracking or festival/volunteers. For companies outside Denmark, contact alj@consitus.dk.

Your processing and integrations

Fill in the details you know. Describe categories and purposes, not actual personal records. These fields are optional in the draft and reviewed before signing.

Company details are filled in automatically. Complete the remaining customer schedules and operational terms with Consitus before signing. Generation is not a signature or acceptance of the agreement.

Download blank draft agreement (PDF, Danish)

Danish · Draft v0.2 · 7 pages · 1 October 2026

From draft to signed agreement

  1. Download the draft and identify your company, modules and contact person.
  2. Work with us to specify data types, groups of users, integrations and operational terms in the customer-specific schedules.
  3. Review the complete agreement and schedules before signing. Downloading does not constitute acceptance.

The dynamic website privacy policy hosted by iubenda explains website processing. It does not replace the data processing agreement between you and Consitus.

Responsible privacy contact

Anne Lehd Jepsen

alj@consitus.dk

Subprocessors in the shared intranet platform

When Consitus processes personal data on your behalf, the following providers support the shared service. The scope depends on your features and agreement. Customer-specific integrations must be added to the schedule of your data processing agreement.

Supabase Pte. Ltd.

Purpose and information
Database, authentication, file storage and backend. Processes user and contact details and the information and files you add to your selected modules.
Location and transfers
The intranet database is in Ireland (AWS eu-west-1). Supabase also has processing and subprocessors outside the EEA; its data processing terms include EU Standard Contractual Clauses. The database location does not guarantee that all processing takes place in the EU.

Cloudflare, Inc.

Purpose and information
Hosting, delivery and protection of the web application, plus separate file backup. Processes web traffic, IP addresses, technical information and data passing through the application.
Location and transfers
The separate file backup is restricted to the EU. The web application uses a global network; other processing may take place outside the EEA. Its data processing terms describe international transfers and the relevant transfer mechanisms.

Resend — Plus Five Five, Inc.

Purpose and information
Delivery of system emails, invitations and other emails from the solution. Processes recipient addresses, email content, any attachments and delivery information.
Location and transfers
The verified sending domains use the Ireland region (eu-west-1). Resend's data processing terms describe primary processing in the USA and EU Standard Contractual Clauses. The sending region therefore does not mean that all email data stays in the EU.

The providers' own lists describe the next level of the processing chain. For example, AWS provides infrastructure to Supabase and Resend. Which of their subprocessors are relevant depends on the service used.

Push and integrations depend on your solution

When push notifications are enabled, the browser's push provider is used. Subscriptions with Apple and Google have been observed. Delivery involves a technical subscription identifier and encrypted message content. The relevant providers and terms are set out in the schedule for your solution.

The platform’s integration overview includes Relatel, Google Calendar, Microsoft Outlook, Dinero, e-conomic, GLS, SmartWeb, Shopify, United Tickets, Eventpos and CoreGo. Support does not mean an integration is active for you. Your own providers are not automatically Consitus subprocessors; the contracting party, data flow and responsibilities must be set out in your customer-specific schedule.

Terms for the website's other providers

iubenda and Google Analytics support website consent and measurement. GitHub is used for development and publishing. These roles are separate from processing customer operational data in the intranet.

Data return, deletion and termination

Contact us to request the return or deletion of data or to end the service. The handling of your request is based on your agreement and instructions.

  1. 01

    Define the request

    Identify your company, contact person, solution and the data or modules concerned. Do not include personal data registers, passwords or sensitive attachments in your first email.

  2. 02

    Arrange data return

    For data return, we clarify the contact person's authority, scope, format and secure transfer. State whether you also need uploaded files and data from connected integrations.

  3. 03

    Clarify deletion and termination

    At termination, we clarify return or deletion according to your instructions, applicable deadlines and any statutory retention requirements. Deletion from the active service and expiry of backup copies must be addressed separately in the agreement.

Contact us about data return or deletion

The technology behind this website

Our providers have different roles. This overview covers consitus.dk and is not a complete list of subprocessors for every customer solution.

Cloudflare
Website delivery, hosting and web analytics.
Provider privacy policy
Supabase
Database and backend, including website form enquiries.
Provider privacy policy
Resend
Sending emails from website form workflows.
Provider privacy policy
iubenda
Cookie choices, the consent interface and legal documents.
Provider privacy policy
Google Analytics 4
Measuring website visits and usage, governed by the measurement choice.
Provider privacy policy
GitHub
Source code, version history and automated code checks for changes.
Provider privacy policy

Data location and any international transfers depend on the particular service. Refer to the privacy information and contact us for documentation concerning your solution.

Ask about what matters to your business

A Trust Center should make it easier to get specific answers. We help clarify documentation and requirements before you choose or extend a solution.

01

Access and responsibilities

Which users need access, what roles do they have and who manages access in your solution?

02

Operation and recovery

What are your needs for availability, backups, recovery and handling service disruptions? Specific terms should be set out in your agreement.

03

Data processing

What data is processed, where is it processed and which providers are involved? Ask for the relevant data processing agreement and provider overview.

Documents and agreements

Direct access to information about this website and our working relationship.

Frequently asked questions

Does this page also cover our intranet?

The linked privacy and cookie information describes the public website. Processing data on behalf of your business and the terms for your intranet should be assessed against your specific service and data processing agreements.

Can we request a data processing agreement?

Yes. Download the Danish draft agreement as a PDF on this page. We complete the agreement and customer-specific schedules with you before signing. Contact Anne Lehd Jepsen at alj@consitus.dk.

Where can I find evidence for specific security requirements?

Send us your requirements, such as a security questionnaire or certification requirements. We will clarify what documentation is available for the particular solution. This page is not itself a certification.

How do I request access to or deletion of my data?

Email Anne Lehd Jepsen at alj@consitus.dk and explain your request without including passwords or sensitive information. If it concerns data in a customer's solution, we can help identify the appropriate contact.

Have a security question or found an issue?

Tell us which page or solution is affected and describe what you observed. Do not include passwords, tokens or personal data as evidence in your first email.

Contact Consitusinfo@consitus.dk