Last updated
Privacy Policy
What personal data StandardOS processes, why, where it lives, and the rights you have. Short version: EU-hosted, no tracking, no selling of data, export and deletion on demand.
1. Who is responsible
The data controller for this website and for account data is RMS Systems (CVR 34282668), Nyvangsvej 29, 5000 Odense C, Denmark. privacy@getstandardos.com. For the compliance records your organization keeps inside StandardOS, your organization is the controller and we act as its processor under our Data Processing Agreement (Art. 28 GDPR), which applies to every customer and is published in full.
2. What we process, and why
| Data | Purpose | Legal basis |
|---|---|---|
| Account data: name, work email, password hash or OAuth identity | Sign-in, workspace membership, security notifications | Contract (Art. 6(1)(b)) |
| Organization & billing data: company name, billing country, VAT number, payment status | Subscription management, invoicing, tax compliance | Contract; legal obligation (Art. 6(1)(b), (c)) |
| Content you store: policies, risks, evidence, audit records (may contain personal data your organization controls) | Providing the service to your organization | Processor on your organization's instructions (Art. 28) |
| Service logs: IP address, timestamps, actions | Security, abuse prevention, tamper-evident audit trail | Legitimate interest (Art. 6(1)(f)) |
| Emails we send: delivery and bounce metadata | Transactional notifications and digests you control | Contract (Art. 6(1)(b)) |
| Marketing consent: the wording you agreed to, when, and from which screen | Email about StandardOS itself, only if you asked for it, and proof that you did | Consent (Art. 6(1)(a)); legal obligation to document it (Art. 6(1)(c)) |
That last row is opt-in and stays opt-in. Nothing is pre-ticked, declining changes nothing about your trial or your account, and you can withdraw with one click in any such email or from your notification settings, with no sign-in needed for the link. Notices about your own workspace are separate and are not marketing. We keep the consent record after you withdraw, because Danish marketing law requires us to be able to show what you agreed to for two years after we last relied on it.
We do not run advertising or cross-site tracking, we do not sell or share personal data for marketing, and our marketing site sets no analytics cookies. See the Cookie Policy.
3. Where your data lives
Customer data is stored in databases located in the European Union. We choose EU regions for our infrastructure providers wherever the service touches customer records.
4. Subprocessors
We use a deliberately short list of subprocessors. This is the same list published on our Trust page: one source, rendered in both places, last changed 2026-07-28.
| Provider | Role | Location of processing |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (Ireland) |
| Vercel | Application hosting & delivery; cookieless traffic analytics (no cookies, no cross-site identifiers) | EU serving; global CDN for static assets |
| Sentry | Error monitoring, diagnostics only; email addresses, IP addresses and record identifiers are stripped before events leave our servers | EU region (Frankfurt) |
| Paddle | Merchant of record: checkout, payment, VAT & invoicing (card data never touches our servers) | UK, under the EU adequacy decision |
| Resend | Transactional email | EU region |
Where a provider processes data outside the EU/EEA, transfers rest on an adequacy decision (such as the EU-US Data Privacy Framework) or Standard Contractual Clauses. We announce subprocessor changes on our Trust page with prior notice to customers.
5. How long we keep data
- Account and organization data: for the life of the account.
- Workspace content after a subscription ends: read-only and exportable for 90 days, then scheduled for deletion.
- Invoices and accounting records: 5 years (Danish Bookkeeping Act).
- Security logs: up to 12 months, unless needed for an ongoing investigation.
6. Your rights
Under the GDPR and the Danish Data Protection Act you can request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. Write to privacy@getstandardos.com. We answer within a month. You can also complain to the Danish supervisory authority, Datatilsynet (datatilsynet.dk), or your local EU authority.
7. Security
Encryption in transit and at rest, row-level access isolation between organizations, least-privilege access for our own staff, daily backups with automated alerting and a weekly encrypted copy held outside our database provider, and a tamper-evident, hash-chained audit log, described in detail on the Trust page. We run StandardOS on StandardOS: the same ISMS discipline we sell is the one we operate under, and we notify affected customers of personal-data breaches without undue delay as the GDPR requires.
8. Changes
We update this policy as the service evolves; the date above always reflects the current version, and material changes are announced by email to account owners.