Privacy policy

This privacy policy sets out how Continia Software A/S and its affiliates (“Continia”) will process any personal information that we may collect about you as a visitor to our websites, premises or events, or as one of our customers or potential customers, suppliers or potential suppliers, shareholders, or other business partners or in any other cases where we specifically state that this policy will apply.

This privacy policy also sets out how we protect your privacy and your rights in respect of our use of your personal information.

Continia may also have a privacy policy or statement specific to particular local laws, solutions, services, events or collaborations in which case such policy or statement shall supplement, and where there is a conflict supersede, this privacy policy.

This policy does not cover cookies and similar technologies on our websites. Those are described in our separate Cookie Policy, which also explains how to change your cookie choices.

We handle personal data in two fundamentally different ways
This is the section worth reading first. Continia processes personal data in three distinct capacities, and our responsibilities - and yours, if you are the person the data is about - differ in each.

We are the controller for everything we do in our own name
We decide why and how personal data is used when we run our websites, market our solutions, host events and webinars, sell to and administer customers and partners, handle support requests, issue licences and invoices, recruit, and operate our whistleblower scheme. This policy apply to that data and describes our processing. You can exercise your rights over it directly with us.

We are a processor for the personal data our customers put into our solutions
Our solutions run inside a customer's Microsoft Dynamics 365 Business Central environment. The customer decides what goes in and what the solution does with it. In practice, invoices, expense claims, payment files, reminders and approval flows routinely contain personal data about the customer's own employees, suppliers, customers and contacts - and a scanned or received document can contain anything at all, including sensitive information that neither we nor the customer selected in advance.

For all of that data, the customer is the controller and Continia is the processor. We act only on the customer's documented instructions, under our standard Data Processing Agreement, which is available in the Continia Trust Center. Where a customer uses our solution through service provider and that service partner is itself acting as a processor, we act as a sub-processor on the same terms.

This policy does not apply to such data where Continia is a processor. If your personal data has reached us because an organisation used a Continia solution, that organisation is the one to contact about access, correction or deletion. If you approach us instead, we will tell you so and we will support our customer in responding to you, but we cannot act on that data on our own initiative.

A limited set of data inside our solutions is still ours to control
Providing a solution is not the same as only storing a customer's content, and there is a narrow band of data we determine the use of even while a customer is using our solutions. We set it out plainly rather than leaving it implied:

  • account and sign-in data for named users of our solutions, our mobile apps and the partner portal - the identifiers we need to give a person access and keep that access secure;
  • licence and entitlement records, including which organisation a user belongs to and which modules and features they are licensed for;
  • telemetry and operational data about how our solutions perform, which errors occur and which features are used, which we use to keep the solutions running and to improve them;
  • security and audit logs, including sign-in records, administrative actions and events we need in order to detect, investigate and document misuse;
  • support tickets, together with the correspondence, screenshots, logs and diagnostic files attached to them;
  • contract, billing and administration records relating to the customer relationship.

We are the controller for that data. We rely on our legitimate interest in operating, securing, supporting and developing our services, and on the contracts with the customer and partner organisations. We do not use it to profile individual end users or to market to them, and we do not sell it. This policy applies to such data where Continia is the controller.

When you visit our website
When you browse continia.com and our related sites, we record technical information including your IP address and the approximate location derived from it, your device and browser type, the pages you look at, and the site or campaign that referred you.

We use this to keep the site available and secure and to understand which content is useful, relying on our legitimate interest in operating and improving our own website, and on your consent where the collection happens through cookies or similar technologies that require it. How those technologies work and how to change your choices is set out in our separate Cookie Policy.

When you sign up for newsletters, events and webinars
If you subscribe to a newsletter, register for a webinar, book a demonstration, download a guide or sign up for an event, we collect the details you give us - typically name, business email, company, job role and country - along with what you registered for and whether you attended.

We send marketing on the basis of your consent, and, where you already are a customer or partner, on our legitimate interest in telling you about products and updates similar to the ones you use. We record whether our emails are opened and which pages are visited afterwards, so that we can stop sending material that is of no use to you. Every email contains an unsubscribe link, and you can withdraw consent or object at any time, with no effect on anything you have received already.

When you are a contact at a customer, partner or prospective customer
Most of the people we deal with are contacts at businesses: customers, suppliers, partners/resellers and prospective customers. For them we hold name, job title and business contact details, the organisation they work for, records of our meetings and correspondence, and the quotes, licences, orders and invoices that relate to their organisation.

We process this because it is necessary for the contract with your organisation and because we have a legitimate interest in maintaining the business relationship, administering licences and running our sales and partner operations. Alongside what you tell us yourself, we may obtain contact details from your employer, from the partner you work with, and from public professional sources such as company websites, trade registers and professional networks.

When you use our solutions and portals
If you sign in to our solutions, a Continia mobile app or the partner portal (Partner Zone), we process the account, licence, telemetry, log and support data described above, for which we are the controller.

The business content you work with in those tools - the invoices you approve, the expenses you submit, the payments you release - belongs to your organisation, which decides what happens to it. For that content we are a processor, and questions about it go to your organisation.

When you contact our support team as a Continia Partner
As a Continia Partner you can request support via our support platform. We keep your request, your correspondence with us, your contact details, and the environment information, log files, screenshots and sample documents needed to reproduce and resolve the problem. We rely on our legitimate interest in supporting our solutions and on the contracts with the partner and customer organisations.

Material sent to us in a support case sometimes contains personal data about other people - a scanned invoice attached to illustrate a problem, for example. We ask partners to send only what is necessary and to mask or anonymise where they can. Where such material forms part of the customer's own data, we handle it as a processor under our standard Data Processing Agreement.

When you apply for a job with us
We process the application, CV, certificates and any assessments or references that form part of the recruitment process, in order to evaluate your application and take steps towards a possible contract of employment.

When you report a concern under our whistleblower scheme
Continia operates a whistleblower scheme under the Danish Whistleblower Act. Reports are handled confidentially by a restricted group, and the identity of a reporter is protected as the Act requires. The scheme has its own information page setting out how reports are received, who sees them, how long they are kept and what rights a reporter and a reported person have: see our Whistleblower Scheme.

Cookies and similar technologies
Cookies, pixels, tags and similar technologies on our websites are not covered by this policy. They are described in our separate Cookie Policy, which lists the technologies we use, what each is for, how long it lasts and how to give or withdraw your consent.

Who we share personal data with
We share personal data only where there is a reason to, and we do not sell it.

  • Within the Continia group. Our companies share customer, partner and prospect information so that the person closest to you can serve you and share administrative systems.
  • Suppliers acting on our behalf. These include the various providers of our IT-systems, e.g. our CRM and marketing automation platform, our support platform, and our finance and HR systems. They act on our instructions under a data processing agreement and may not use the data for their own purposes.
  • Continia partners. Our solutions are usually bought and implemented through a Continia Partner / Microsoft Dynamics partner. Where you work with one, we share the contact, licence and case information needed for them to sell to and support your organisation.
  • Sub-processors used in our solutions. When we act as a processor, we only use sub-processors in accordance with the data processing agreement. The currently used sub-processors are always published at our Trust Center. Customers can subscribe to notifications of changes to that list.
  • Advisers and authorities. Auditors, lawyers and insurers where needed, and public authorities and courts where we are legally required to disclose.
  • In a corporate transaction. If we sell or reorganise part of our business, personal data may transfer with it, subject to the protections in this policy.

How we share and transfer personal data
When we need to share or transfer your personal data within the Continia group or with third parties, we put in place appropriate technical and organisational measures, including international transfer safeguards (unless an Adequacy Decision is in place), to ensure a secure and compliant processing.

Data we hold as a processor is only shared and transferred as the customer/controller instructs, under our standard Data Processing Agreement.

How long we keep personal data
We keep personal data for as long as we need it for the purpose we collected it for and then delete or anonymise it.

Data we hold as a processor is kept and deleted as the customer/controller instructs, under our standard Data Processing Agreement.

How we protect personal data
We have put in place appropriate technical and organisational measures to ensure a secure and compliant processing. We monitor, scan for vulnerabilities, run intrusion detection, restrict access to those who need it, use encryption, and have an incident management process for responding to and reporting personal data breaches. We enter into data processing agreements with every supplier that handles personal data for us.

Data we hold as a processor is protected in accordance with our standard Data Processing Agreement.

Your rights
You have the right to ask us for a copy of the personal data we hold about you; to have inaccurate data corrected; to have data deleted; to have processing restricted; to object to processing we base on legitimate interests; and to receive data you gave us in a portable format. You can object to direct marketing at any time, and we will stop. Where we rely on consent, you can withdraw it at any time, which does not affect what we did before you withdrew it.

Write to legal@continia.com to exercise any of these rights. We answer within one month and will tell you if we need longer because the request is complex. We may need to verify your identity first.

One important limit: if your personal data is in a Continia solution because an organisation put it there, we act only as that organisation's processor and cannot give you access to it or change it on our own. Contact the relevant organisation. If you are not sure which one, tell us what you can and we will try to point you in the right direction.

If you want to complain
If you believe that we have handled your personal data in a way that infringes applicable data protection law, you have the right to complain directly to us. You can submit your complaint emailing us at legal@continia.com. We will acknowledge your complaint within 30 days and investigate it without undue delay. We will keep you informed of the process and tell you the outcome of our investigation.

If you are not satisfied with our response, you can escalate your complaint to the relevant data protection authority. In Denmark that is Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, telephone +45 33 19 32 00, dt@datatilsynet.dk. If you live or work elsewhere in the EU or EEA, you can complain to your local authority instead.

Children
Our solutions and our marketing are directed at businesses, not at children, and we do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us at legal@continia.com and we will delete it.

Changes to this policy
We update this policy when our processing changes or the law requires it. The current version and its date are always shown at the top. If a change materially affects how we use personal data about you, we will draw it to your attention rather than rely on you noticing it here.