Legal
Privacy Policy
This policy explains how Tradebird collects, uses, shares, retains, and protects personal data and describes the rights available to individuals.
- Effective date:
- 7 September 2026
- Version:
- 2026-09-07
1. Scope and our roles
This Privacy Policy applies when Tradebird determines why and how personal data is processed, including when operating the public website and platform, administering accounts and customer relationships, maintaining security, providing support, and communicating about the service. For that processing, the Tradebird entity identified below is the controller.
A customer organization is generally the controller for personal data it chooses to submit to Tradebird as private customer content. When Tradebird processes that data only to provide the service under the customer's instructions, Tradebird acts as a processor under the Data Processing Agreement. This policy does not replace the customer's own privacy notice to the people whose data it controls.
Our role depends on the processing activity, not merely where data appears. Tradebird may act as controller for account, security, billing, service-usage, and public-source processing while acting as processor for private customer content.
2. Personal data we process
The personal data depends on how a person or organization uses Tradebird. It may include:
- Account and organization data: name, business email, sign-in identifier, profile image, role, organization membership, preferences, and authentication information.
- Customer content: files, text, messages, instructions, business records, communications, and other information submitted by or for a customer. Customer content may contain personal data about users, employees, suppliers, customers, or other people.
- Public and business information: company information, professional roles and contact details, public statements, source links, publication history, corrections, and information submitted for public display.
- Commercial and support data: plan, invoice and payment status, business contact information, support communications, feedback, and privacy correspondence. Payment-card details are handled by our payment provider rather than stored by Tradebird.
- Device, usage, and security data: IP address, browser and device information, timestamps, authentication and security events, service interactions, performance, errors, consent choices, and diagnostic data.
- Derived data: classifications, summaries, connections, and other information generated while providing, protecting, or improving requested services.
3. Sources of personal data
We receive personal data:
- directly from individuals and customer organizations;
- from users who submit information about other people;
- automatically from devices and use of the service;
- from service providers involved in authentication, billing, communications, security, and support; and
- from public sources such as company websites, business registries, professional publications, public catalogues, and other publicly accessible business material.
Where personal data was not obtained directly from the individual, we provide the information required by applicable law within the relevant period unless a lawful exception applies. We record source information where appropriate so public information can be checked, corrected, or removed.
4. Customer content and Restricted Data
Customers decide what customer content to submit and are responsible for having the notices, rights, permissions, consents, and lawful bases needed for Tradebird to process it under their instructions.
Tradebird is not designed for the categories of Restricted Data identified in the Terms of Service, including special-category data under Article 9 of the GDPR, criminal-offence data, children's data, complete payment-card data, authentication secrets, government identifiers, or highly sensitive personal information unrelated to a legitimate business use. Customers and users must not submit Restricted Data unless Tradebird has expressly agreed otherwise in writing.
This contractual restriction does not remove Tradebird's obligations if Restricted Data is submitted. If we become aware of it, we may restrict access, suspend the affected processing, preserve information where legally necessary, notify the relevant customer, and delete or otherwise handle the data in accordance with law and the applicable agreement. Please report suspected Restricted Data using the contact below.
5. Public information
Tradebird processes public and business information to provide business discovery, maintain accurate public information, prevent fraud and duplication, explain sources, and allow relevant organizations and individuals to request corrections or removal.
Depending on the circumstances, our legal basis is our legitimate interest in operating an accurate and transparent business platform, performance of a requested service, consent, or a legal obligation. We consider the nature of the information, its source, the person's professional context, reasonable expectations, potential impact, and available controls before relying on legitimate interests.
Public information may be indexed by search engines, accessed through public interfaces, copied by other people, or remain available in caches outside Tradebird's control. You can object to processing, report a problem, or request correction or removal using our content reporting process or the privacy contact below.
6. Why we process personal data
We process personal data to:
- provide, administer, personalize, and support the service;
- create and secure accounts, control access, and prevent abuse, fraud, and security incidents;
- process purchases, subscriptions, invoices, and customer relationships;
- store, retrieve, transform, communicate, publish, or otherwise handle information as requested by users and customers;
- operate and improve public business information and respond to corrections, objections, and removal requests;
- monitor reliability, diagnose errors, understand service use, and improve usability;
- communicate service, legal, security, and support information;
- establish, exercise, or defend legal claims and enforce agreements; and
- comply with legal, accounting, tax, sanctions, law-enforcement, and regulatory obligations.
7. Legal bases
The applicable legal basis depends on the activity:
- Contract: where processing is necessary to provide an account, requested service, support, or paid subscription.
- Legitimate interests: where necessary to operate, secure, support, and improve a useful business service; maintain accurate public business information; prevent abuse; and protect Tradebird, customers, and others. We balance these interests against the affected person's rights.
- Consent: for optional analytics and another use where we specifically request permission. Consent can be withdrawn at any time.
- Legal obligation: where processing is required by law.
- Legal claims: where necessary to establish, exercise, or defend claims.
When Tradebird acts as processor, the customer determines the legal basis for the processing it instructs.
8. Automated processing
Tradebird may use automation and artificial intelligence to retrieve, organize, classify, transform, summarize, generate, and assist with information as part of requested services. Depending on the request, relevant customer content may be sent to an approved model provider acting under contract.
Automated output may be incorrect and should be reviewed before it is relied on or shared. Tradebird does not use automated output by itself to make decisions about individuals that produce legal or similarly significant effects.
9. Who receives personal data
We disclose personal data only as needed for a requested service, customer instruction, business operation, or lawful requirement. Recipients may include:
- members and administrators of the relevant customer organization;
- people or organizations with whom a user intentionally shares or publishes information;
- hosting, database, storage, authentication, communications, billing, analytics, security, support, and artificial-intelligence providers;
- professional advisers, auditors, insurers, and parties to a corporate transaction; and
- courts, regulators, law-enforcement bodies, and other authorities where lawfully required.
Providers acting as subprocessors for customer content are listed on our Subprocessors page. We require providers to protect personal data and use it only for agreed purposes.
10. International transfers
Some providers or authorized personnel may process personal data outside the European Economic Area. Where an adequacy decision does not apply, we use an appropriate transfer mechanism, such as the European Commission's standard contractual clauses, together with supplementary safeguards where required. Contact us for information about safeguards relevant to a particular transfer.
11. Retention and closure
We retain personal data only for as long as needed for the relevant purpose, customer instructions, security and business requirements, legal obligations, or legal claims. Retention depends on the data and context.
- Data needed to provide an active account or organization is retained while the service is active.
- Closing an account revokes access immediately. A 30-day support-assisted recovery period follows, during which ordinary account processing stops except for recovery, security, legal obligations, and privacy requests.
- After 30 days, the external sign-in identity is deleted and direct account identifiers such as name, email, profile image, and sign-in identifier are irreversibly anonymized. A neutral internal user record remains so relational and shared records are not broken.
- Closing an organization makes it inaccessible and unpublished without automatically deleting its relational records. We delete or anonymize personal data when it is no longer necessary and assess erasure requests under applicable law.
- Lawful shared business records may remain available to another participant after an account closes. Personal attribution is removed or neutralized when it is no longer needed.
- Public information and source evidence are corrected, refreshed, suppressed, or removed when no longer accurate or necessary. A limited suppression record may be retained to prevent removed information from being republished.
- Security, application, and infrastructure logs have limited periods appropriate to investigation and reliability. Backups expire on a rolling schedule and are not restored for ordinary service use after deletion.
- Billing, accounting, dispute, and legal records are retained for periods required by law or reasonably needed for legal claims, with access restricted when no longer needed for normal service delivery.
An authenticated user can close their account directly from Settings. Closing an account does not automatically delete organization-controlled or shared records, but an individual may still request erasure using the contact below.
12. Security
Tradebird uses technical and organizational safeguards designed for the nature and risk of the service, including access controls, authentication, encryption in transit, encryption at rest for hosted data, organization boundaries, logging, backups, provider controls, and incident procedures. No internet service can promise absolute security. Please report suspected unauthorized access or a personal-data incident promptly.
13. Your rights
Depending on the circumstances, you may have the right to access, correct, erase, restrict, or receive a portable copy of personal data; object to processing based on legitimate interests; and withdraw consent. You may also complain to the Danish Data Protection Agency or the supervisory authority where you live or work.
We normally respond within one month. We may need information to verify identity and may extend the period for a complex or numerous request where law permits. A right may be limited by another person's rights, legal obligations, legal claims, or another lawful exception. We will explain a refusal or limitation.
If a customer organization controls the relevant data, we may direct the request to that customer or assist it in responding under the DPA.
14. Children
Tradebird is a business service and is not intended for children. Users must be at least 18 years old. Do not submit personal data about children.
15. Changes to this policy
We may update this policy as our processing or the law changes. We will publish the new version and effective date. If a change materially affects how we process personal data, we will provide a dedicated email or in-product notice where appropriate and explain the nature and likely effect of the change.
Where we intend to process personal data for a new incompatible purpose, we will provide required information before that processing begins. Where consent is required, we will request new consent first.
Contact
Contact us to exercise a privacy right, correct or remove public personal information, report Restricted Data, or ask a question about this policy.
Tradebird ApS
Company registration number: 46753313
Overgaden Oven Vandet 58A, 2. 1415 København K Danmark