Last updated: October 2, 2026
Hours (CVR: 34 97 22 81) is the controller for the processing of your personal data. Hours has not appointed a data protection officer (DPO). The privacy contact is Martin Kristensen. Contact him at msk@hours.dk with questions about how we process your data.
We collect the following categories of personal data:
We process your personal data for the following purposes:
The legal basis for the processing is performance of a contract (GDPR Art. 6(1)(b)) and legitimate interest (GDPR Art. 6(1)(f)).
We retain your personal data for as long as you are an active user of Hours. Upon cancellation, your data is deleted within 30 days, unless the law requires longer retention.
The database and file archive are hosted by Supabase in the EU (Frankfurt) and encrypted at rest by the provider (AES-256). The application runs on Hostinger in the EU; encryption at rest of the application server's disk is not documented, but Hours encrypts access tokens for banking, accounting and mailboxes with AES-256-GCM before storing them. All communication between your browser and Hours is encrypted in transit (TLS 1.2+). When the AI assistant Amber is enabled, document content is sent to Anthropic (USA) under Standard Contractual Clauses (SCC).
You have the following rights under the GDPR:
To exercise your rights, contact Martin Kristensen at msk@hours.dk. You can also complain to the Danish Data Protection Agency at dt.dk.
Hours uses necessary cookies to maintain your session and ensure the platform's functionality. We do not use third-party tracking cookies without your consent.
Hours currently uses no statistics cookies and no web analytics. If we introduce web analytics, we will ask for your consent first and update this policy. Your language choice is stored only when you click a language yourself. Without a choice the page is shown in Danish.
You choose which services to connect to Hours, for example Google, Microsoft 365 or your accounting system. For each connection Hours receives only the access you explicitly grant on the service's own consent screen, and uses it only to provide the features you turn on. Data from connected services is not sold, not used for advertising and not used to train generalised AI models. You can disconnect any service under Settings → Integrations; Hours then stops using it and removes the access tokens.
This describes how Hours accesses, uses, stores, shares, protects and deletes data it receives from Google APIs. For Google user data this section takes precedence over any general statement elsewhere in this policy.
Data we access, and why
What we store. From Gmail we store the documents you import (PDF attachments and the records created from them, such as invoices, contracts and receipts), supplier replies to your negotiations, the subject and a short excerpt of detected price notices, and a fingerprint (hash) of each imported file to avoid duplicates. We do not store the full text of other emails. Attachments you send to Amber in Gmail are stored in your Hours account.
Sharing. We share Google user data only as needed to provide the features you use:
We do not sell Google user data or transfer it for advertising, to data brokers, or for credit assessment or lending.
AI and machine learning. Google user data is used by AI only to provide the features you use. Any learning, such as remembering how your organisation classifies a supplier, is stored and used only within your own organisation and is never shared with or used for other customers. Google Workspace data is not used to develop, improve or train generalised or non-personalised AI or machine learning models, by Hours or by our providers.
How we protect it. All traffic is encrypted with TLS. Google access and refresh tokens are encrypted by Hours with AES-256-GCM before they are stored, in a database that is also encrypted at rest. Access is restricted to the server functions that provide the features, and every record is scoped to your organisation and user. Backups are encrypted.
Storage and deletion
Limited Use. Hours' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Clarified on October 2, 2026.
Before we use your Google data in a new way or for a purpose other than what was previously disclosed to and accepted by you, we update this policy, notify you in Hours or by email, and ask for your affirmative consent to the changed processing. The notice explains the affected data and features, the purpose and any new recipients, and links to the updated policy.
The new processing may only begin after you give consent. If you decline or do not respond, we do not use your Google data for the new processing. You can still disconnect under Settings → Integrations. Continued use of Hours, an updated date or an existing Google permission does not by itself constitute consent to a new purpose. If the feature requires additional Google permissions, we also request them on Google's consent screen.
To request deletion of data from a connected service, write to kontakt@hours.dk. We complete it without undue delay and within 30 days.
If you have questions about our privacy policy, feel free to contact us:
Hours v/ Martin Kristensen, sole proprietorship, CVR no. 34 97 22 81
Privacy contact: Martin Kristensen, msk@hours.dk
Other enquiries: kontakt@hours.dk