Legal

Privacy policy

What we collect, why, and what we refuse to do. Short, because we collect very little.

Version 1.0Effective 1 June 2026No tracking cookies

Who we are

Wildfire ApS, Smedevej 1, 5800 Nyborg, Denmark. CVR 18101580. We build and operate the Wildfire platform. For questions about this policy or about personal data we hold, write to privacy@wildfire.business.

Controller or processor

Two different relationships, with different rules, and it matters which one you are in.

  • We are the controller for the small amount of data we collect in our own right: people who email us, book a call, apply for a job, or read this website.
  • We are the processor for everything inside a customer workspace. That data belongs to the customer, who decides what we may do with it. Our instructions come from them, and the terms are in the DPA.

Data we collect ourselves

Website visitors

Nothing beyond what a web server necessarily sees to deliver a page. No analytics product, no tracking pixels, no advertising identifiers, no session recording. We do not build a profile of you and we could not sell one if we wanted to.

People who contact us

Your name, email address, employer if you mention it, and what you wrote. We keep it so we can reply and so the next conversation does not start from scratch.

Job applicants

Whatever you send us. We delete unsuccessful applications after six months unless you ask us to keep them on file.

Customer administrators

Names, work email addresses and role, so we can operate your workspace and know who is allowed to authorise a change to a tier policy.

Customer content

Everything your agents read, draft and remember is customer content. We process it only to provide the service, only on the customer’s instructions, and never to train models. That last point is contractual, not a preference.

We do not train on your data

Not our own models, not a provider’s. Where a third-party model is used, it is used under an agreement that excludes training on inputs and outputs.

Personal memory is inaccessible to us. There is no support override that lets an employee of ours read what a user told their own agent. Support works from what you choose to share in a channel.

Legal bases

  • Contract — operating a workspace for a customer and administering the agreement.
  • Legitimate interests — replying to enquiries, securing our systems, keeping records of what our platform did.
  • Legal obligation — accounting records, and the logging duties that come with the EU AI Act and GDPR.
  • Consent — only where we ask for it explicitly, such as keeping a job application on file. Withdrawable at any time.

Cookies

This website sets no cookies beyond those strictly necessary to serve it, and it runs no analytics. That is why you were not asked to dismiss a banner. The product itself uses a session cookie to keep you signed in; that is strictly necessary and cannot be switched off without signing you out.

Sub-processors

The current list is maintained in Annex III of the DPA. Customers are notified before a new sub-processor is added and may object on reasonable data-protection grounds.

Tools you connect yourself — your CRM, your file store, your ad accounts — are not our sub-processors. They are your systems, and your relationship with those vendors is unchanged.

International transfers

Regulated workloads stay inside European jurisdiction by design, enforced at our gateway rather than promised in a policy. Where a transfer outside the EEA is unavoidable, it rests on an adequacy decision or on Standard Contractual Clauses with a transfer impact assessment on file. Customers can request a copy.

Retention

  • Evidence ledger — 3 to 7 years, configurable per DPA. This is deliberately long: it is the audit trail.
  • Customer content — for the term of the agreement, then deleted or returned on request.
  • Enquiries — 24 months from last contact.
  • Applications — 6 months, longer only with consent.
  • Accounting records — 5 years, as Danish bookkeeping law requires.

Your rights

Access, rectification, erasure, restriction, portability, objection, and the right not to be subject to a decision based solely on automated processing. Write to privacy@wildfire.business and we will respond within one month.

If the data sits inside a customer workspace, we are the processor and will refer you to that customer, who is the controller — we will tell you who, and we will help them answer you.

You may complain to the Danish Data Protection Agency (Datatilsynet) or to your local supervisory authority. We would rather you told us first.

Security

Encryption in transit and at rest, per-tenant network isolation, least-privilege access, audited hardware in European data centres, and an append-only log of what happened. Detail is in Annex II of the DPA and on the compliance page.

If we suffer a personal data breach affecting customer content, we notify the affected customer without undue delay and in any case within 24 hours of becoming aware.

Contact

Wildfire ApS, Smedevej 1, 5800 Nyborg, Denmark. CVR 18101580.
Email privacy@wildfire.business.

We update this policy when our processing changes. Material changes are announced in the changelog and, for customers, by email.

Need the signed
version for procurement?