Privacy Policy

How Estaid collects, uses, and protects your personal data under GDPR.

Privacy Policy

Last updated: August 20, 2026


1. Data Controller

  • ESTAID ApS, a company registered under Danish law
  • Store Kongensgade 65A, ST., 1264 Copenhagen K, Denmark
  • CVR: 46213998
  • Email: info@estaid.com

We are the controller of your personal data. No Data Protection Officer is appointed (GDPR Art. 37 not triggered).


2. Personal Data We Collect (GDPR Arts. 13–14)

Provided by you:

  • Name
  • Email address
  • Company name
  • Investment data (property addresses, financial figures, portfolios — may contain personal data)

Payment data:

  • Handled by a third-party processor
  • We store only the transaction ID

Technical data:

  • IP address
  • Browser type
  • Device information
  • Usage logs

Analytics & marketing:

  • Google Analytics 4 and Microsoft Clarity — only if you accept the Analytics cookie category
  • Meta Pixel and Meta Conversions API, and Google Ads conversion tracking — only if you accept the Marketing cookie category
  • Campaign parameters from the link you arrived through (utm_*, gclid, fbclid)

Cookies & trackers:

  • Each one is named, with its purpose and retention, in our Cookie Policy

Special categories:

  • None collected

Providing data is necessary for the performance of a contract; refusal may prevent account creation or use of the Service.


Perform contract

  • Deliver the platform
  • Manage subscriptions

Legitimate interests

  • Improve the Service
  • Prevent fraud
  • Security measures (balanced against your rights)
  • Analytics and marketing cookies and similar technologies (see Cookie Policy)
  • Nothing in either category loads until you accept it
  • Bookkeeping and tax compliance (Danish Bookkeeping Act)

No automated decision-making or profiling (GDPR Art. 22).


4. How We Use Your Data

  • Operate the platform
  • Process subscriptions
  • Send transactional emails
  • Analyse usage
  • Comply with legal obligations

5. Recipients (GDPR Art. 13)

  • Processors: EU hosting providers, third-party payment processors (SCCs)
  • Analytics & advertising providers, where you have consented: Google Ireland Limited (Analytics, Ads), Microsoft Ireland Operations Limited (Clarity), Meta Platforms Ireland Limited (Pixel, Conversions API). Contact details sent to Meta are SHA-256-hashed before they leave our server
  • Affiliates: under GDPR-compliant agreements
  • Public authorities: when required by law

We do not sell personal data.


6. International Transfers (GDPR Chapter V)

Primary storage and processing occur within the EU/EEA.
Any transfers outside the EU/EEA rely on:

  • Standard Contractual Clauses (SCCs)
  • Adequacy Decisions, including the EU–U.S. Data Privacy Framework, which the analytics and advertising providers above rely on
  • Binding Corporate Rules

7. Retention Periods

  • Account & investment data: until deletion request + 30 days (or longer if in dispute)
  • Financial transactions: 5 years from end of fiscal year (Danish Bookkeeping Act § 10)
  • Analytics data: up to 26 months; individual cookie lifetimes are listed in the Cookie Policy
  • Security logs: 12 months

Data is securely deleted after retention expires.


8. Your Rights (GDPR Chapter III)

  • Access (Art. 15)
  • Rectification (Art. 16)
  • Erasure (Art. 17)
  • Restriction (Art. 18)
  • Data portability (Art. 20)
  • Objection (Art. 21)
  • Withdraw consent (Art. 7)

Consent to cookies is withdrawn through Cookie settings in the site footer, which reopens the consent dialog. Exercise your other rights free of charge at privacy@estaid.com.
We respond within 1 month (extendable to 3 months for complex requests).

You may also complain to Datatilsynet (https://www.datatilsynet.dk) or your local supervisory authority.


9. Security Measures (GDPR Art. 32)

  • TLS encryption in transit
  • Encryption at rest where appropriate
  • Pseudonymisation (hashed passwords)
  • Strict access controls
  • Regular security audits
  • Backups
  • Vulnerability scans
  • Staff training

10. Data Breach Notification (GDPR Arts. 33–34)

  • We notify Datatilsynet within 72 hours unless the breach is unlikely to pose a risk.
  • If a breach poses high risk to your rights, we notify you without undue delay, describing:
    • The nature of the breach
    • Likely consequences
    • Measures taken

11. Children

The Service is not intended for individuals under 18.
We do not knowingly process children’s data. Any discovered data is deleted immediately.


12. Changes to this Policy

Material changes will be notified via email or in-app at least 30 days in advance.
Continued use of the Service constitutes acceptance of the updated policy.


13. Contact