Scope
EU, DK-facing service, Polish operator
Version
24 June 2026
Operator
Nova Group Sp. z o.o.
This Policy explains how CVR360 processes personal data in connection with Danish company search, reports, source provenance, accounts, payments, support and analytics.
1. Controller
The controller is Nova Group Sp. z o.o., ul. Żurawia 6/12 lok. 745, 00-503 Warszawa, Poland, VAT ID PL7011215529.
Contact: the contact form
Privacy contact: the privacy contact form
2. Data categories
CVR360 may process account data, billing data, support messages, technical logs, consent records, product usage data and public-source company information. Public-source company information may include names and roles of individuals when those facts are lawfully published in Danish company sources.
3. Danish public sources
Company profiles may reference CVR/Datafordeler, Virk, Regnskabsdata, VIES, SKAT and Statstidende. CVR360 aims to minimize personal data and present source provenance, retrieval status and limitations.
4. Purposes and legal bases
Processing may be necessary to provide the service, perform a contract, answer support requests, handle payments, comply with legal duties, secure the platform, improve the product and pursue legitimate interests in operating a source-backed business information service.
5. AI processing
AI summaries must be based only on facts available in source-backed profile data. AI output is informational and may be reviewed, corrected, disabled or regenerated as the product evolves.
6. Recipients
Data may be processed by hosting, authentication, payment, email, analytics, security, AI and storage providers. Providers must be configured under appropriate contractual and security controls before production use.
7. Retention
Retention periods depend on the data type. Account and billing records may be kept as required by law. Logs and analytics are kept only as long as needed for security, diagnostics and product operation.
8. Rights
Individuals may request access, correction, deletion, restriction, portability or objection where applicable under GDPR. Requests can be sent to the privacy contact form.
9. Source data corrections
If a fact originates from an official Danish source, the official source may need to be corrected first. CVR360 can update or annotate its own display after review.
10. International transfers
Where providers process data outside the EEA, appropriate safeguards such as standard contractual clauses should be used.
This Policy is a product-localization draft and should be reviewed by counsel before production launch.