Privacy Policy
Last updated · 16 April 2026
1. Who we are (Data Controller)
This website (automents.ai) and the Automents product are operated by Actual Intelligence ApS, a Danish private limited company and the data controller for the personal data described in this policy.
Actual Intelligence ApSBorgmester Jakob Jensens Gade 7
8000 Aarhus C, Denmark
CVR: 32820301
privacy@automents.ai
For any privacy enquiry — including to exercise your rights under the GDPR — write to privacy@automents.ai.
2. What data we collect
We keep data collection to the minimum needed to run the site and waitlist:
- Waitlist submissions. Your work email address and the timestamp of submission, collected when you request access on the homepage.
- Technical data. IP address, user agent, referrer and pages viewed — processed by our hosting and analytics providers for security, abuse prevention and aggregate traffic analytics.
- Communications. Any message you send us via email.
We do not knowingly collect data from children under 16, nor do we process special categories of personal data (GDPR Art. 9).
3. Why we process it (lawful basis)
- Consent — Art. 6(1)(a). You opt in to the waitlist to receive product updates and invitations. You can withdraw consent at any time by emailing us.
- Legitimate interests — Art. 6(1)(f). Running and securing the website, preventing fraud, and understanding aggregate usage. We balance these interests against your rights and keep the footprint minimal.
- Legal obligation — Art. 6(1)(c). Where we must retain records (e.g. accounting, responding to lawful requests from authorities).
4. Who we share data with (processors)
We use a small, vetted set of processors, each bound by a data processing agreement (GDPR Art. 28):
- Vercel Inc. — website hosting and privacy-friendly analytics. Data may be processed in the United States under the EU Standard Contractual Clauses and the EU–US Data Privacy Framework.
- Supabase Inc. — managed Postgres database (EU region) storing the waitlist records. Controller–processor data processing agreement in place.
- Resend Inc. — transactional email delivery for waitlist notifications. Data may be processed in the United States under the EU Standard Contractual Clauses.
We do not sell your personal data and we do not share it for cross-context behavioural advertising.
5. International transfers
Some of our processors are established outside the EU/EEA. Where this is the case we rely on the European Commission's Standard Contractual Clauses and, where applicable, adequacy decisions (e.g. the EU–US Data Privacy Framework) to ensure an equivalent level of protection.
6. How long we keep your data
- Waitlist email: until you unsubscribe or the waitlist is closed, whichever is earlier.
- Analytics logs: up to 90 days in identifiable form.
- Email correspondence: up to 24 months after our last exchange.
- Records required by law: for the retention period required by that law (e.g. 5 years under Danish bookkeeping rules).
7. Your rights under the GDPR
You can exercise the following rights at any time, free of charge:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure / "to be forgotten" (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21), including to direct marketing
- Right to withdraw consent at any time (Art. 7(3))
- Right not to be subject to solely automated decision-making (Art. 22)
To exercise any of these, email privacy@automents.ai. We respond within one month (GDPR Art. 12(3)).
If you are unhappy with how we handle your data, you can complain to your local supervisory authority — in particular:
- Denmark: Datatilsynet
- Norway: Datatilsynet
8. Cookies & similar technologies
The homepage does not set any non-essential cookies unless you consent. See our Cookie Policy for the full list and how to manage your preferences.
9. Security
We apply appropriate technical and organisational measures, including encryption in transit (TLS), access controls, infrastructure hardening and the principle of least privilege. No system is 100% secure — if we become aware of a personal data breach that is likely to result in a risk to you, we will notify the relevant authority and, where required, you directly (GDPR Art. 33–34).
10. Changes to this policy
We may update this policy as the product evolves. Material changes will be announced on this page with a new "last updated" date. Please review it periodically.