Privacy Policy
This privacy policy explains which personal data Ampleo ApS processes when you visit ampleocrm.com, create a trial account, use AmpleoCRM in a browser or on a mobile device, or contact us for support. It also explains what we do with the data, who it is shared with, how long it is kept, and what rights you have.
1. Data controller
Ampleo ApS
Hestetorvet 7, 1. th.
4000 Roskilde
Denmark
Company reg. no. (CVR) 39640708
Email: info@ampleo.dk
We are not required to appoint a Data Protection Officer and have not appointed one. All enquiries about personal data go to the address above and are answered by Ampleo.
2. We act in two different roles
AmpleoCRM is a CRM system that companies use to record their own customers, leads and employees. That gives us two roles, and keeping them apart matters:
- We are the controller of the data we process for our own purposes: website visitors, trial sign-ups, user accounts and logins, subscription and billing details, support enquiries, and operational and security logs. That is the processing this policy describes.
- We are a processor of the data a customer records in their own CRM: contacts, leads, companies, activities, emails, documents, time entries and HR records. There, the customer is the controller and decides what is recorded and for how long. We process that data only on the customer's instructions and under the data processing agreement entered into at sign-up. We do not use it for our own purposes, do not sell it, and do not use it to train AI models.
If you are recorded in a company's AmpleoCRM - for example as a contact at one of their customers - please direct your request to that company, as they are the controller. If you contact us instead, we will forward the request to the customer and tell you that we have done so.
3. When you visit ampleocrm.com
Statistics. We measure visits with Plausible Analytics, a cookie-free analytics service hosted in the EU. Nothing is stored on your device, your IP address is not retained, and no profile of you is built across websites. We only see aggregate figures: which pages are viewed, which page you arrived from, browser and operating system type, and country. The legal basis is our legitimate interest in knowing which content is being used (GDPR article 6(1)(f)).
Forms. If you write to us through the contact form, request a demo or book an onboarding meeting, we process the details you provide: typically name, email, phone number, company and your message. We use them only to answer the enquiry and for the conversation that follows. The legal basis is article 6(1)(b) (steps prior to entering a contract) or 6(1)(f) (legitimate interest in answering an enquiry). The enquiry is deleted no later than 24 months after the last contact, unless it has become part of a customer relationship.
Spam protection. The forms are protected by Altcha, which runs on our own server. Your browser solves a small computational puzzle before the form can be submitted. No data is sent to third parties and nothing is stored on your device.
4. Cookies and local storage
We do not use cookies for analytics, marketing or tracking. That is also why we do not show a cookie banner. The cookies and local storage we do use are necessary for the service to work:
| Name | Purpose | Lifetime |
|---|---|---|
AmpleoCRM.Auth | Keeps you signed in. Only set once you log in. | The session |
ampleo_locale | Remembers your language choice. | Up to 1 year |
ampleo_date_format | Remembers your chosen date format. | Up to 1 year |
ampleo_support_access | Only set if an Ampleo support employee has been granted time-limited access to your environment (see section 7). | The session, at most the duration of the grant |
ampleo_density (local storage) | Remembers how compact you want the interface. Never leaves your browser. | Until you clear browser data |
The mobile app and the installable web app additionally store your session and a local data cache on the device so the app can start and show data quickly. It is cleared when you log out or uninstall the app.
5. When you create a trial account or become a user
At sign-up we process: name, work email, phone number, company name and company registration number, the one-time code we send to verify the email address, and your password. The password is stored only as a cryptographic hash in our identity system (Keycloak) and cannot be read by us.
When you accept the terms of service and the data processing agreement, we also record which document versions you accepted, your name and email, the timestamp, and the IP address and browser user agent. This is the evidence that the agreement was entered into, and we cannot omit it.
While you use the service we process your user profile (name, email, role, business unit and team membership) as well as logins and timestamps.
The legal basis is article 6(1)(b) (performance of the contract with the company you are a user at), and for the acceptance record also 6(1)(f) (documenting that an agreement was concluded) and 6(1)(c) (legal obligation).
The user profile is deleted or anonymised when the subscription ends, under the terms of the data processing agreement. The acceptance record is kept for up to 5 years after the agreement ends as evidence.
6. Subscription and accounting
For invoicing we process the company's name, address and registration number, plus the name and email of a billing contact. Subscriptions and invoices are handled in Fenerum. We neither receive nor store full card numbers.
The legal basis is article 6(1)(b) (the contract) and 6(1)(c) (the Danish Bookkeeping Act). Accounting records are kept for the current financial year plus 5 years, as the law requires.
7. Support, operations and troubleshooting
Support enquiries. When you contact support we process your enquiry with the content you send, including any screenshots. Please do not send more personal data than the case requires.
Access to your environment. Our staff do not have standing access to customer data. To help you inside the system, an explicit, time-limited grant is required; it is issued per case, expires by itself, and is logged with who, when and which environment. The log is available to us as evidence.
Operational and security logs. The system writes technical logs that may contain IP address, user id, timestamp and the action performed. They are used for troubleshooting, operational monitoring and security. The legal basis is article 6(1)(f). Logs are deleted automatically after 30 days.
8. Mobile app and installable web app
AmpleoCRM is available as an app for iOS and Android and as an installable web app. The app is a work tool for companies that are already customers. You cannot create an account in the app - it is created by your company's administrator - and you sign in with the same credentials as in the browser.
The app requests only the following access on your device, and only when you use the feature that needs it:
- Microphone. Used solely when you start a meeting recording yourself. The recording is sent to Ampleo's own transcription service on our server in Finland, converted to text, and analysed once to produce a meeting summary with follow-up items. The audio recording and the raw transcript are not stored - neither on our servers nor with any sub-processor. Only the summary you save remains in the CRM, and you can edit or delete it like any other note. Only record meetings where you are permitted to do so under the rules that apply to you and the other participants.
- Location. Used only while you are actively using a feature that needs your position, such as finding nearby customers or registering a visit. The app does not track your position in the background, and we build no location history.
- Notifications. If you enable notifications, we process a device token so the message can be delivered to your device. The token is not used for anything else and is deleted when you turn notifications off or uninstall the app.
Every permission can be withdrawn at any time in your device settings. The feature stops working, but the rest of the app keeps functioning.
What the app does not do: it contains no advertising, no advertising identifier, no third-party analytics or tracking SDKs, and no tracking across apps or websites. We do not sell personal data and do not share it with data brokers or for marketing purposes. We do not use your data for automated decisions with legal effect for you.
Deleting your account and data. Your user account belongs to the company you are a user at. To have it deleted, ask your AmpleoCRM administrator, or write to info@ampleo.dk from your work email address - we will then delete the account within 30 days and confirm it in writing. To have an entire company's data deleted, the request must come from the company as controller. See also section 12 on retention.
9. AI features
Some features use a language model, for example to summarise a meeting or suggest follow-up items. For that we send the specific text the feature needs to Mistral AI, a European provider that processes data in the EU. We send no more than the task requires, and the text is not used to train models. This processing only happens when you or your company actively use the feature.
10. Processors and recipients
We use the following providers. They process data only on our instructions and under a data processing agreement:
| Provider | Function | Location |
|---|---|---|
| Hetzner Online GmbH | Servers, database and encrypted backup | Finland (EU) |
| Plausible Analytics | Cookie-free website statistics | EU |
| Lettermint | Delivery of system and service emails | EU |
| Mistral AI | Language model for summaries and suggestions | EU |
| MapTiler | Maps and address geocoding | Switzerland (covered by the European Commission's adequacy decision) |
| Fenerum | Subscriptions and invoicing | Denmark |
The identity system (Keycloak) and the transcription service run on our own servers and involve no third party.
In addition, an individual customer may choose to connect their CRM to services they already use - for example Microsoft 365 or Google Workspace for mail and calendar, or tools for website tracking and digital signatures. Where that happens, it is the customer's decision, and the data is then also processed under that provider's terms. We do not enable such integrations on our own initiative.
Otherwise we disclose personal data only where we are legally required to, or where it is necessary to establish or defend a legal claim.
11. Transfers outside the EU/EEA
Operations, database and backup are located in the EU. The providers we have chosen ourselves process data in the EU/EEA or in a country the European Commission has found to provide an adequate level of protection. Where a transfer to a third country is necessary, it takes place on the basis of the European Commission's Standard Contractual Clauses supplemented by the necessary safeguards. If a customer chooses to connect their CRM to a service outside the EU/EEA, that transfer is made on the customer's decision and responsibility as controller.
12. Retention and deletion
We keep personal data for as long as there is a legitimate purpose for doing so:
- Enquiries via the website: no more than 24 months after the last contact.
- User accounts and CRM data: for as long as the subscription runs. After that, data is deleted or returned under the data processing agreement.
- Evidence of acceptance of the terms: up to 5 years after the agreement ends.
- Accounting records: the current financial year plus 5 years, as required by the Danish Bookkeeping Act.
- Operational and security logs: 30 days.
About backups. We take encrypted backup copies and keep them separate from the production environment so data can be restored after a failure, a mistake or an attack. A deletion is carried out in the live system. Backup copies are not edited, but they rotate, so a deleted record disappears by itself within 12 months at the latest. We consider this necessary and proportionate in order to be able to restore the system, and any restore from backup always includes re-applying the deletions made in the meantime.
13. Security
We have implemented technical and organisational measures appropriate to the risk, including:
- All traffic to and from the service is encrypted (TLS/HTTPS).
- Backup copies are encrypted, both in transit and at rest.
- Each customer's data is isolated from every other customer's, and that isolation is covered by automated tests that run on every change to the system.
- Passwords are stored only as hashes in the identity system.
- Access is role-based, and support access to customer data requires a time-limited and logged grant (see section 7).
- Access and events are logged, and logs are monitored.
If a personal data breach occurs, we handle it under articles 33 and 34 of the GDPR: we notify affected customers without undue delay, and we report to the Danish Data Protection Agency within 72 hours where we are the controller and the breach is notifiable.
14. Your rights
Under the GDPR you have the right to:
- Access the data we process about you, and why (article 15).
- Rectification of incorrect or incomplete data (article 16).
- Erasure of your data once we no longer have a basis for processing it (article 17).
- Restriction of processing (article 18).
- Data portability - to receive the data you provided to us in a machine-readable format (article 20).
- Object to processing based on our legitimate interest (article 21).
- Withdraw consent where processing is based on consent. This does not affect the lawfulness of processing before the withdrawal.
Write to info@ampleo.dk to exercise a right. We respond within one month. If the request is complex we may extend the deadline by up to two further months, and will tell you within the first month if we do. We may ask for information that lets us establish that the request comes from you.
If your request concerns data held in a customer's CRM, that customer is the controller. We forward the request and assist them in answering it.
15. Children
AmpleoCRM is a business tool for professional use. The service is not directed at children, and we do not knowingly collect data about children under 15. If we become aware that we have, we delete the data.
16. Changes to this policy
The policy is versioned, and the version number and date appear at the top of this page. If we change anything material, we notify customers by email or in the application before the change takes effect. Earlier versions can be requested at info@ampleo.dk.
17. Contact and complaints
Questions about this policy or about our processing of personal data go to info@ampleo.dk.
If you are unhappy with how we process your personal data, we hope you will contact us first. You always have the right to complain to the Danish Data Protection Agency:
Datatilsynet
Carl Jacobsens Vej 35
2500 Valby
Denmark
dt@datatilsynet.dk · www.datatilsynet.dk