Last updated
What personal data StandardOS processes, why, where it lives, and the rights you have. Short version: EU-hosted, no tracking, no selling of data, export and deletion on demand.
The data controller for this website and for account data is RMS Systems (CVR 34282668), Nyvangsvej 29, 1. tv., 5000 Odense C, Denmark — privacy@getstandardos.com. For the compliance records your organization keeps inside StandardOS, your organization is the controller and we act as its processor under a Data Processing Agreement (Art. 28 GDPR), available to every customer.
| Data | Purpose | Legal basis |
|---|---|---|
| Account data — name, work email, password hash or OAuth identity | Sign-in, workspace membership, security notifications | Contract (Art. 6(1)(b)) |
| Organization & billing data — company name, billing country, VAT number, payment status | Subscription management, invoicing, tax compliance | Contract; legal obligation (Art. 6(1)(b), (c)) |
| Content you store — policies, risks, evidence, audit records (may contain personal data your organization controls) | Providing the service to your organization | Processor on your organization's instructions (Art. 28) |
| Service logs — IP address, timestamps, actions | Security, abuse prevention, tamper-evident audit trail | Legitimate interest (Art. 6(1)(f)) |
| Emails we send — delivery and bounce metadata | Transactional notifications and digests you control | Contract (Art. 6(1)(b)) |
We do not run advertising or cross-site tracking, we do not sell or share personal data for marketing, and our marketing site sets no analytics cookies — see the Cookie Policy.
Customer data is stored in databases located in the European Union. We choose EU regions for our infrastructure providers wherever the service touches customer records.
We use a deliberately short list of subprocessors:
| Provider | Role | Location of processing |
|---|---|---|
| Supabase | Database, authentication, file storage | EU region |
| Vercel | Application hosting and delivery | EU serving; global CDN for static assets |
| Stripe | Payment processing (card data never touches our servers) | EU/US — EU-US Data Privacy Framework & SCCs |
| Resend | Transactional email | EU region |
Where a provider processes data outside the EU/EEA, transfers rest on an adequacy decision (such as the EU-US Data Privacy Framework) or Standard Contractual Clauses. We announce subprocessor changes on our Trust page with prior notice to customers.
Under the GDPR and the Danish Data Protection Act you can request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. Write to privacy@getstandardos.com — we answer within a month. You can also complain to the Danish supervisory authority, Datatilsynet (datatilsynet.dk), or your local EU authority.
Encryption in transit and at rest, row-level access isolation between organizations, least-privilege access for our own staff, tested backups, and a tamper-evident, hash-chained audit log — described in detail on the Trust page. We run StandardOS on StandardOS: the same ISMS discipline we sell is the one we operate under, and we notify affected customers of personal-data breaches without undue delay as the GDPR requires.
We update this policy as the service evolves; the date above always reflects the current version, and material changes are announced by email to account owners.