Privacy Policy
1. Introduction and Data Controller
This Privacy Policy explains how Everyday Dzign (“we,” “us,” or “our”) collects, uses, and protects your personal data when you use Gript, our project management platform at gript.app.
We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and applicable Danish data protection law.
Data Controller: Ben Korez, Everyday Dzign, Copenhagen, Denmark
Privacy contact: [email protected]
This policy is effective as of April 1, 2026.
2. What Data We Collect
We collect and process the following categories of personal data:
Identity and account data
- Name, email address, and profile avatar
- Password hash (bcrypt) for email/password authentication
- OAuth tokens (AES-256-GCM encrypted) for Google and Microsoft sign-in
- Session data for maintaining your login state
Usage data
- Login timestamps and user preferences (language, theme)
- Board, item, and document activity within the platform
File data
- Files you upload as attachments, including file metadata (name, size, type)
Time tracking data
- Start and stop times, durations, and notes associated with time entries
Notification data
- Notification content and read status
Audit and security data
- User ID, action performed, IP address, and user agent (retained for 90 days)
Consent records
- Type of consent, version, IP address, and timestamp (retained for 5 years)
Billing data
- Subscription plan, billing cycle, and payment status. Payment details (card numbers, bank information) are processed exclusively by Stripe and are never stored on our servers.
3. How We Use Your Data
We process your data for the following purposes:
To provide the service (Legal basis: Contract performance — Art. 6(1)(b) GDPR)
- Creating and managing your account
- Authenticating your identity
- Enabling project management features (boards, items, documents, time tracking)
- Processing payments and managing subscriptions
- Sending transactional emails (invitations, password resets, notifications)
To maintain security and compliance (Legal basis: Legitimate interest — Art. 6(1)(f) GDPR)
- Maintaining audit logs for security monitoring and incident response
- Detecting and preventing unauthorized access or abuse
With your consent (Legal basis: Consent — Art. 6(1)(a) GDPR)
- Push notifications (if enabled in future)
- Analytics (if implemented in future)
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
4. Cookies
Gript uses only strictly necessary cookies required for the service to function. These include:
- Session cookie: Maintains your authenticated session
- Locale preference cookie: Stores your language preference
We do not use analytics cookies, advertising cookies, or third-party tracking cookies. If this changes in the future, we will update this policy and obtain your consent where required.
5. Data Sharing and Sub-processors
We do not sell your personal data. We share data only with the following categories of sub-processors, all of which are contractually bound to protect your data:
- Hetzner Online GmbH (Germany, EU) — infrastructure for running the platform
- Hetzner Online GmbH (Germany, EU, S3-compatible object storage) — storage of uploaded files
- Google — OAuth authentication (only if you choose Google sign-in)
- Microsoft — OAuth authentication (only if you choose Microsoft sign-in)
- Stripe — Payment processing for subscriptions and billing
We may also share data if required by law, court order, or to protect our legal rights.
6. International Data Transfers
Your data is stored and processed within the European Union. Our hosting infrastructure is provided by Hetzner Online GmbH and located in their data centers in Germany.
Some sub-processors (Google, Microsoft, Stripe) may process limited data outside the EU. Where this occurs, transfers are protected by Standard Contractual Clauses (SCCs) or adequacy decisions approved by the European Commission.
7. Data Retention
We retain your data as follows:
- Account and usage data: For the duration of your account, plus 30 days after deletion request
- Uploaded files: For the duration of your account, plus 30 days after deletion request
- Audit logs: 90 days from creation
- Consent records: 5 years from the date of consent (legal compliance requirement)
- Billing records: As required by applicable tax and accounting laws
When your account is deleted, a 30-day grace period applies during which you may request your data. After this period, your personal data is permanently deleted from our systems.
8. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): Request a copy of the data we hold about you. You can export your data directly from your account settings.
- Right to rectification (Art. 16): Correct inaccurate data. You can update your profile information directly in your account.
- Right to erasure (Art. 17): Request deletion of your personal data. Upon request, your account enters a 30-day grace period, after which all data is permanently deleted.
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format. We provide data export in JSON format, with files as a ZIP archive.
- Right to restrict processing (Art. 18): Request that we limit how we use your data in certain circumstances.
- Right to object (Art. 21): Object to processing based on legitimate interest.
- Right to withdraw consent (Art. 7): Withdraw any consent you have given, without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at [email protected]. We will respond to your request within 30 days.
9. Data Security
We take the security of your data seriously and implement appropriate technical and organizational measures, including:
- Encryption of data in transit (TLS/HTTPS)
- Encryption of sensitive data at rest (AES-256-GCM for OAuth tokens, bcrypt for passwords)
- Invite-only account creation to prevent unauthorized access
- Role-based access controls within the platform
- Audit logging of security-relevant actions
- Regular backups and infrastructure monitoring
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Danish Data Protection Authority (Datatilsynet) within 72 hours and inform affected users without undue delay.
10. Children’s Privacy
Gript is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take steps to delete that data promptly. If you believe a child has provided us with personal data, please contact us at [email protected].
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will notify you by email or through the service at least 30 days before the changes take effect.
The date at the top of this policy indicates when it was last updated. We encourage you to review this policy periodically.
12. Contact and Complaints
If you have questions or concerns about this Privacy Policy or how we handle your data:
- Privacy inquiries: [email protected]
- General support: [email protected]
- Data Controller: Ben Korez, Everyday Dzign, Copenhagen, Denmark
If you are not satisfied with our response, you have the right to lodge a complaint with the Danish Data Protection Authority:
- Datatilsynet
- Carl Jacobsens Vej 35, 2500 Valby, Denmark
- Website: datatilsynet.dk
- Email: [email protected]
- Phone: +45 33 19 32 00