Dataansvarlig
Hours (CVR: 34 97 22 81) er dataansvarlig for behandlingen af dine personoplysninger. Kontakt os på hej@hours.dk ved spørgsmål om vores behandling af dine data.
Indsamling af personoplysninger
Vi indsamler følgende kategorier af personoplysninger:
- Kontaktoplysninger (navn, e-mail, telefonnummer)
- Virksomhedsoplysninger (virksomhedsnavn, CVR-nummer, branche)
- Brugsdata (loginaktivitet, funktioner brugt, sessionsdata)
- Betalingsoplysninger (håndteres af tredjepart, vi gemmer ikke kortoplysninger)
- Kontraktdata og leverandøroplysninger du uploader til platformen
Opbevaring og sletning
Vi opbevarer dine personoplysninger så længe du er aktiv bruger af Hours. Ved opsigelse slettes dine data inden for 30 dage, medmindre lovgivning kræver længere opbevaring.
Databasen og filarkivet ligger hos Supabase i EU (Frankfurt) og er krypteret i hvile af leverandøren (AES-256). Applikationen kører hos Hostinger i EU; applikationsserveren er ikke omfattet af en dokumenteret kryptering i hvile, og adgangstokens til bank og indbakke lagres uden særskilt feltkryptering. Al kommunikation mellem din browser og Hours er krypteret under transport (TLS 1.2+). Når AI-assistenten Amber er aktiveret, sendes dokumentindhold til Anthropic (USA) under standardkontraktbestemmelser (SCC).
Dine rettigheder
Du har følgende rettigheder i henhold til GDPR:
- Ret til indsigt i dine personoplysninger
- Ret til berigtigelse af ukorrekte oplysninger
- Ret til sletning ("retten til at blive glemt")
- Ret til begrænsning af behandling
- Ret til dataportabilitet
- Ret til indsigelse mod behandling
For at udøve dine rettigheder, kontakt os på hej@hours.dk. Du kan også klage til Datatilsynet på dt.dk.
Cookies
Hours anvender nødvendige cookies til at opretholde din session og sikre platformens funktionalitet. Vi anvender ikke tredjeparts tracking-cookies uden dit samtykke.
Bruger du kategorien "Statistik" overføres anonymiseret data til Google LLC i USA. Overførselsgrundlag: EU's standardkontraktbestemmelser (SCC) iht. Kommissionens afgørelse 2021/914 + EU-US Data Privacy Framework.
Google-integrationer og behandling af Google-data
Dette afsnit gælder de data, Hours modtager fra Google, når du forbinder Gmail, Google Drive eller tilføjelsen Amber i Gmail. For Google-data går dette afsnit forud for generelle formuleringer andre steder i politikken. Den fulde, bindende beskrivelse står på engelsk i afsnittet Google user data herunder.
- Afsendelse (gmail.send): Hours sender kun mails fra din Gmail-adresse, når du selv bekræfter dem: forhandlingsmails til leverandører, invitationer til dit team og delingslinks.
- Læsning (gmail.readonly), kun hvis du slår det til: Når du aktiverer automatisk import eller svarfinding, læser Hours afsender, emne, dato, tekst og vedhæftninger i de relevante mails for at finde fakturaer, kontrakter, prisvarsler og leverandørernes svar på forhandlinger, du har startet.
- Google Drive (drive.file): kun filer og mapper, Hours opretter, eller som du vælger i Googles mappevælger, til at gemme kopier af dine dokumenter.
- Amber i Gmail: kun den åbne mail og de dele, du selv vælger. Vedhæftninger, du sender til Amber, gemmes i din Hours-konto. Amber kan oprette et svarudkast, men sender aldrig selv.
Dokumenter analyseres af vores AI-leverandør Anthropic, og ved genanalyse af kontrakter kan teksten behandles af Groq. Vælger du din egen AI-nøgle (fx OpenAI eller Google) i Amber, sendes indholdet til den leverandør, du har valgt. Google-data bruges aldrig til reklame, sælges ikke, bruges ikke til kreditvurdering eller udlån og bruges ikke til at træne generelle AI-modeller.
Hours' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data
This section describes how Hours accesses, uses, stores, shares, protects, retains and deletes data it receives from Google APIs. For Google user data it takes precedence over any general statement elsewhere in this policy. Hours is operated by Hours v/ Martin Sarvio, CVR 34 97 22 81, Denmark (kontakt@hours.dk).
Data we access, and why
- Your Google email address (userinfo.email, openid): to show which Google account is connected and match it to your Hours account.
- Sending email (gmail.send): to send email from your own address when you confirm it in Hours: negotiation emails to suppliers (in the original thread, sometimes with a redacted contract attached), invitations to your team and share links. Hours never sends email you have not confirmed.
- Reading email (gmail.readonly), only after you turn on automatic import or reply finding: Hours reads the sender, subject, date, text and attachments of messages that match invoice and contract searches (for example messages with attachments and words such as invoice or contract, by default from the last 30 days) to import invoices, contracts and price notices; and it reads messages tagged with your Hours negotiation reference to find supplier replies to negotiations you started. Hours asks Google for this permission separately, at the moment you turn the feature on.
- Google Drive (drive.file): only files and folders Hours creates or that you choose in Google's picker, to store copies of your documents. Hours cannot see other files in your Drive.
- Amber in Gmail add-on (gmail.addons.execute, gmail.addons.current.message.readonly, gmail.addons.current.action.compose): only the message you have open and the parts you select, so you can ask Hours about it, and a reply draft when you press the button. The add-on never sends email.
What we store
From Gmail we store the documents you import (PDF attachments and the records created from them, such as invoices, contracts and receipts), supplier replies to your negotiations, the subject and a short excerpt of detected price notices, and a fingerprint (hash) of each imported file to avoid duplicates. We do not store the full text of other emails. Attachments you send to Amber in Gmail are stored in your Hours account.
Sharing
We share Google user data only as needed to provide the features you use:
- Supabase (database and file storage, EU) and Hostinger (application servers, EU).
- Anthropic (USA, EU Standard Contractual Clauses): analyses documents and selected email content to extract suppliers, amounts, dates and terms, and powers Amber. Anthropic does not use the data to train its models.
- Groq (USA, EU Standard Contractual Clauses): may process the text of a stored contract when you ask Hours to analyse it again.
- An AI provider you choose yourself (for example OpenAI or Google) if you connect your own API key in Amber; content is then sent to that provider under your own agreement with it.
- Notification channels you set up (Slack, Telegram or WhatsApp) receive short notices such as the supplier name and email subject.
We do not sell Google user data or transfer it for advertising, to data brokers, or for credit assessment or lending.
AI and machine learning
Google user data is used by AI only to provide the features you use. Any learning, such as remembering how your organisation classifies a supplier, is stored and used only within your own organisation and is never shared with or used for other customers. Google Workspace data is not used to develop, improve or train generalised or non-personalised AI or machine learning models, by Hours or by our providers.
How we protect it
All traffic is encrypted with TLS. Google access and refresh tokens are encrypted by Hours with AES-256-GCM before they are stored, in a database that is also encrypted at rest. Access is restricted to the server functions that provide the features, and every record is scoped to your organisation and user. Backups are encrypted.
Retention and deletion
- Disconnect: when you disconnect Gmail or Google Drive in Hours (Settings, Integrations), we ask Google to revoke Hours' access, delete the stored tokens and remove the stored Gmail address. If Google does not confirm the revocation, Hours tells you, and you can remove access at myaccount.google.com/permissions.
- Imported data: documents and records you imported stay in your Hours account until you delete them or your account. There is no automatic expiry.
- Account deletion: after a 30-day grace period we delete your account, revoke Hours' Google access and delete Google-derived data, including Amber attachments, negotiation emails and file fingerprints. Accounting records that Danish bookkeeping law requires us to keep (invoices, receipts and contracts registered as vouchers) are kept for 5 years, anonymised and separated from your identity, and then deleted.
- Backups: encrypted nightly backups are kept for up to 30 days and then deleted.
- Requests: you can ask us to delete Google-derived data at any time by writing to kontakt@hours.dk.
Limited Use
Hours' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Forbundne tjenester
Du vælger selv, hvilke tjenester du forbinder til Hours. For hver forbindelse får Hours kun den adgang, funktionen kræver, og bruger den kun til at levere funktionen til dig. Adgangsnøgler gemmes i Hours' database i EU, som er krypteret i hvile. Data fra forbundne tjenester bruges ikke til reklame, sælges ikke og bruges ikke til at træne generaliserede AI-modeller. Du kan afbryde enhver forbindelse under Opsætning → Integrationer; så stopper Hours med at bruge den og fjerner adgangsnøglerne.
- Microsoft Outlook, OneDrive og SharePoint (Microsoft Graph): e-mails og vedhæftninger til import af fakturaer og kontrakter, afsendelse af forhandlingsmails, du selv bekræfter, og filer i de mapper eller biblioteker, du vælger, til lagring af kopier af dine dokumenter. Amber i Outlook læser kun den mail, du har åben, og de dele, du vælger.
- Slack: filer og beskeder i de kanaler, Hours-botten er inviteret i, så delte fakturaer og kontrakter kan importeres, og notifikationer fra Hours.
- Dropbox: filer i den Hours-mappe eller den mappe, du vælger, til lagring af kopier af dine dokumenter.
- Telegram og WhatsApp: de dokumenter og beskeder, du selv sender til Hours, så Amber kan analysere dem. Grupper holdes adskilt pr. virksomhed.
- e-conomic, Dinero, Billy, Uniconta og Business Central: leverandører, fakturaer, bilag og posteringer fra dit regnskabsprogram, så Hours kan vise og afstemme dem.
- Bookingformularen på hours.dk (Web3Forms): når du bestiller en gennemgang, sendes dit navn, din e-mail, din virksomhed, din besked og det valgte tidspunkt gennem formulartjenesten Web3Forms, som videresender henvendelsen til Hours. Vi bruger oplysningerne til at svare dig. Placering og aftale med tjenesten er ved at blive verificeret.
- Stripe Financial Connections: hvis funktionen er slået til, kan Hours hente de konto-, saldo- og transaktionsoplysninger, du godkender gennem Stripe og din bank, så Hours kan vise likviditet og afstemme bankbevægelser med fakturaer og udgifter. Forbindelsen er read-only, bruges ikke til kreditvurdering og kan afbrydes igen. Se dokumentet Financial Connections & Open Banking under Dokumenter på docs.hours.dk, hvor det kan hentes.
- Enable Banking (open banking): med dit udtrykkelige samtykke kan du dele konto-, saldo- og transaktionsoplysninger med Hours til bankafstemning og økonomioverblik. Enable Banking håndterer bankadgangen under sin egen AISP-autorisation, mens Hours er ansvarlig for den efterfølgende brug og lagring. Samtykket udløber efter bankens regler og kan trækkes tilbage når som helst. Se dokumentet Financial Connections & Open Banking under Dokumenter på docs.hours.dk, hvor det kan hentes.
Connected services (English)
You choose which services to connect to Hours. For each connection Hours requests only the access the feature needs and uses it only to provide that feature to you. Access tokens are stored in Hours' database in the EU, which is encrypted at rest. Data from connected services is not used for advertising, not sold, and not used to train generalised AI models. You can disconnect any service under Settings, Integrations; Hours then stops using it and removes the tokens.
- Microsoft Outlook, OneDrive and SharePoint (Microsoft Graph): email and attachments to import invoices and contracts, sending negotiation emails you confirm, and files in the folders or libraries you choose to store copies of your documents. Amber in Outlook only reads the email you have open and the parts you select.
- Slack: files and messages in channels the Hours bot is invited to, to import shared invoices and contracts, and notifications from Hours.
- Dropbox: files in the Hours folder or the folder you choose, to store copies of your documents.
- Telegram and WhatsApp: documents and messages you send to Hours yourself, so Amber can analyse them. Groups are kept separate per company.
- e-conomic, Dinero, Billy, Uniconta and Business Central: suppliers, invoices, vouchers and entries from your accounting system, so Hours can show and reconcile them.
- Booking form on hours.dk (Web3Forms): when you book a walkthrough, your name, email, company, message and chosen time are sent through the form service Web3Forms, which forwards the request to Hours. We use the data to reply to you. The location of the service and the agreement with it are being verified.
- Stripe Financial Connections: where the feature is enabled, Hours can retrieve the account, balance and transaction data you approve through Stripe and your bank, so Hours can show liquidity and reconcile bank movements with invoices and expenses. The connection is read-only, is not used for credit assessment and can be disconnected again. See the document Financial Connections & Open Banking under Documents on docs.hours.dk, where it can be downloaded (Danish).
- Enable Banking (open banking): with your explicit consent you can share account, balance and transaction data with Hours for bank reconciliation and financial overview. Enable Banking handles bank access under its own AISP authorisation, while Hours is responsible for the subsequent use and storage. Consent expires under your bank's rules and can be withdrawn at any time. See the document Financial Connections & Open Banking under Documents on docs.hours.dk, where it can be downloaded (Danish).
To request deletion of data from a connected service, write to kontakt@hours.dk. We complete it without undue delay and within 30 days.
Kontakt
Har du spørgsmål til vores privatlivspolitik, er du velkommen til at kontakte os:
Hours v/ Martin Sarvio, enkeltmandsvirksomhed, CVR-nr. 34 97 22 81
E-mail: kontakt@hours.dk