Sitenyx ApS ("Sitenyx", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our website builder platform and related services. This policy applies to all users of sitenyx.com and websites created through our platform.
Sitenyx ApS, registered in Denmark, is the data controller responsible for your personal data. We process your data in accordance with the EU General Data Protection Regulation (GDPR) and Danish data protection legislation. For any data protection inquiries, you can reach our data protection contact at [email protected].
We collect several categories of personal data to provide and improve our services:
Under the GDPR, we process your personal data based on the following legal grounds:
We use the collected data to provide and maintain our website builder service, process transactions and send related information, respond to your requests and provide customer support, send you technical notices and security alerts — transactional service messages, not marketing — monitor and analyze usage patterns to improve our platform, detect and prevent fraud and abuse, comply with legal obligations, and personalize your experience based on your preferences. Marketing messages are sent only on the bases described in section 4: your per-channel consent or, for existing customers, email about similar services under markedsføringsloven § 10, stk. 2.
We do not sell your personal data. We may share your information with the following categories of recipient: payment processors (Stripe, EU) for transaction processing, cloud infrastructure and security providers (Cloudflare) for hosting, content delivery and bot protection, email providers (Resend, EU) for transactional email, SMS providers (Twilio, US) for notifications, AI service providers in the United States for processing prompt content in the platform's AI features, and law enforcement or regulatory authorities when required by law. We use no third-party analytics services. All third-party processors are bound by data processing agreements that ensure GDPR compliance.
Your application database, file storage and backups are kept within the EU/EEA. Two transfers to the United States happen systematically: prompt content from the platform's AI features is processed by our AI service provider in the US, and SMS notifications are processed by Twilio in the US. Both transfers run under the EU Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework. For providers that serve from the EU (Stripe, Cloudflare, Resend), control-plane metadata may transit the US under the same clauses. You can obtain a copy of the safeguards in use by writing to [email protected].
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy. Account data is retained for the duration of your account and up to 30 days after deletion. Billing records and other accounting material are retained for 5 years from the end of the financial year they relate to, under section 12 of the Danish Bookkeeping Act. Usage statistics and technical event logs are retained for a maximum of 90 days and are then deleted automatically. Support correspondence is retained only for as long as necessary to handle and document your enquiry, and is deleted thereafter.
As a data subject under the GDPR, you have the following rights:
You can request deletion of your account and your personal data at any time. Accounting and billing material is exempt, see section 8, and if you are the only administrator of a workspace you must first give someone else administrator access. Use any of the following methods:
We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit (TLS 1.2/1.3), encryption at rest for files and media at our storage provider and for particularly sensitive database fields, regular security assessments, access controls and authentication requirements, and incident response procedures. While we strive to protect your data, no method of transmission over the internet is 100% secure.
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us immediately, and we will take steps to delete such information.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the "Last updated" date. We encourage you to review this policy periodically. Continued use of our services after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at [email protected]. You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) at [email protected] or your local supervisory authority.
We accept