Legal
Privacy policy
Last updated: 19 September 2026
This policy explains what Apply in Denmark does with your personal data, what we do with the information we receive from Google, how long we keep it, and what you can ask us to do about it.
Who we are
Apply in Denmark (applyindenmark.dk) is operated by LEV Systems ApS, a company registered in Denmark. LEV Systems ApS is the data controller for the personal data described here.
- Company: LEV Systems ApS
- CVR: 46070070
- Address: Rådhusstræde 15, 1466 København K
- Email: support@applyindenmark.dk
Write to that address about anything in this policy. It reaches the people who decide how data is handled here, not a queue.
What the service does
You sign in with Google, upload your CV, answer seven short questions about your situation, and approve one application text. We then adapt that text to each company on your list and send it from your own email address, a few each day, across the week.
Recipients always come from our own database of companies in Denmark. You cannot upload your own list of recipients, and you cannot add an address by hand. Nothing is sent that you have not approved.
How we access, use, store and share Google user data
What we ask for
We use Google Sign-In. When you sign in, Google asks you to grant two things: openid, email and profile, which tell us who you are, and https://www.googleapis.com/auth/gmail.send, which lets an application hand a finished message to Gmail for sending.
How we access it
We reach your Google account only through Google's official APIs, using the token Google issues after you grant permission. We never ask for your Google password, and we never sign in as you in a browser.
The gmail.send scope does one thing: it sends. It gives no access to your mailbox. We never read your mail, we never search it, we never list it, we never download it, and we never delete anything in it. The scope we hold cannot do any of that, and we do not request a scope that can.
How we use it
We use the permission for one purpose: to send the applications you have approved, from your own address, to the companies on your list for the week you have paid for. The name and email address on your Google profile are used to sign you in and to sign the application. We never send marketing from your account, and we never send anything on your behalf that you have not approved.
How we store it
The refresh token Google issues is stored encrypted, never in clear text. We use envelope encryption: the token is encrypted with a data key, and that data key is itself encrypted with a key kept separately from the database. Tokens never appear in logs, error messages or support tickets.
If you disconnect Google inside your account, or delete your account, we erase the stored token straight away and sending stops there and then.
If you instead remove our access from your Google account, the token stops working immediately, so we can no longer send anything on your behalf. Google does not tell us that it happened, so we find out at the next attempt, and we erase the stored token when we see that it has been revoked.
How we share it
We do not share Google user data with anyone for advertising, for sale, or for any other purpose of our own. We do not pass it to data brokers, we do not build advertising profiles from it, and we do not use it to develop, improve or train generalised models.
Two things deserve to be said precisely. First, the name and email address on your Google profile are used to create your account and as the sender of your applications. Second, the application itself is written from your CV and from your own answers by the text generation provider listed under who we share data with, and your name can appear in that material, because an application is signed. Beyond that, your email address is handed to the providers listed under who we share data with, so that they can deliver our system emails to you and run your subscription. Those are the only transfers, they happen only to deliver what you asked for, and they are limited to what that takes.
Nothing from your mailbox is sent anywhere, to that provider or to anyone else, because we have no access to your mailbox in the first place.
Who can read it
People do not read your Google user data. There are three narrow exceptions, and they are the ones Google's policy allows: with your explicit consent, for example when you ask support to look at a send that failed; where it is necessary for security purposes, such as investigating abuse or a suspected breach; and where we are required to do so by law.
Limited Use
Apply in Denmark's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The policy that statement refers to is here: Google API Services User Data Policy.
How to take the access away
- Disconnect Google inside your account. The stored token is erased and sending stops.
- Or remove our access at https://myaccount.google.com/permissions. Google revokes the token, and every further send fails at once.
Taking the access away does not by itself delete the rest of your data. Use delete now in your account, or write to us, if you want everything erased.
What we process, why, and for how long
| What we process | Why | Legal basis | How long we keep it |
|---|---|---|---|
| Your CV, and any extra file you attach | WhyTo write the applications you approve, and to attach your CV to every application we send for you. | Legal basisArticle 6(1)(b), performance of our contract with you. A CV can hold special categories of data, and those rest on your separate explicit consent, Article 9(2)(a). | How long we keep itErased 90 days after your last active week, or as soon as you ask us to. |
| Google account information: your name, your email address, and the permission to send mail from your address | WhyTo sign you in, and to send the applications you approved from your own address. | Legal basisArticle 6(1)(b), performance of our contract with you. The permission itself is granted through Google and can be withdrawn at any time. | How long we keep itKept while your account is open. The stored token is erased the moment you withdraw the permission or delete your account. |
| Payment data: subscription status, amount, date, and the card brand and last four digits Stripe reports back to us | WhyTo take payment for your subscription, and to handle refunds and disputes. | Legal basisArticle 6(1)(b), performance of our contract with you, and Article 6(1)(c), our legal obligation to keep accounting records. | How long we keep itAccounting records are kept 5 years from the end of the financial year, as Danish bookkeeping law requires. We never receive or store your full card number. |
| Send log: the company, the time, the delivery status, and the exact text that went out | WhyTo show you what has been sent, to make sure no company is written to twice, and to document delivery if it is ever disputed. | Legal basisArticle 6(1)(b), performance of our contract with you, and Article 6(1)(f), our legitimate interest in being able to document what we sent. | How long we keep itErased 90 days after your last active week, or as soon as you ask us to. |
| Profile fields and your answers to our questions: field of work, experience, languages, availability, notice period, and anything you asked us not to mention | WhyTo write applications that match what you actually told us, and to pick companies in the right category. | Legal basisArticle 6(1)(b), performance of our contract with you. | How long we keep itErased 90 days after your last active week, or as soon as you ask us to. |
| Citizenship group and work permit answer: one of three groups (Denmark or the Nordic countries, the EU, the EEA or Switzerland, or anywhere else), plus yes or no to holding a Danish work and residence permit | WhyTo check whether we can send applications for you at all. We only send for people who are already allowed to work in Denmark. | Legal basisArticle 6(1)(b), steps taken at your request before entering into our contract. | How long we keep itErased 90 days after your last active week, or as soon as you ask us to. |
We never store your nationality, your country of origin, or any free text about where you are from. The citizenship answer is one of the three groups above and nothing more. We do not give advice about immigration or residence rights, we only point you to the authorities who do.
Beyond the table, our servers keep short technical logs (IP address, time, and the page requested) for security and troubleshooting, for up to 30 days. Emails you send to support are kept for as long as it takes to close your case.
Giving us this data is not a legal requirement, but it is necessary to use the service. Without a CV, your answers and the permission to send, there is nothing we can deliver, and there is no way to subscribe.
Sensitive information in your CV
A CV often holds more than work history. It can say something about your health, a period of parental leave, a union, a religious school, or where you were born. Under Article 9 that is a special category of personal data, and it needs a legal basis of its own.
So we ask for it separately. Before you upload a CV you tick a box that is not pre-ticked and is not buried in the terms, giving your explicit consent for us to process the CV, including any special categories it happens to contain, for the single purpose of writing and sending the applications you approve.
You can withdraw that consent whenever you like. Withdrawing it stops further sending and lets you have the CV erased. It does not make what we lawfully did before unlawful.
We never ask you for health data, union membership, religion, political views, sexual orientation or criminal record, and none of it is ever used to select companies for you.
How long we keep your data
The rule is 90 days after your last active week. In detail:
- Your CV, your drafts and your send log are erased automatically 90 days after your last active week, without you having to ask.
- Delete now: one click in your account erases your CV, your drafts, your send log and the account itself, and disconnects Google. We act on it straight away, not within a month.
- Accounting records we are required by Danish bookkeeping law to keep are the one exception. They are kept 5 years from the end of the financial year.
- Our internal audit and access records are kept for security and documentation, in a form that no longer points at you once your account is erased.
Transfers outside the EU and the EEA
Some of the processing happens outside the EU and the EEA. Anthropic processes in the United States, Stripe does so in part, and Meta transfers to the United States if, and only if, you have accepted marketing cookies. Those transfers rest on the European Commission's standard contractual clauses, which come with the agreements we hold, on the supplementary measures described in them, and for Meta also on its Data Privacy Framework certification.
You can ask for a copy of the safeguards that are in place. Write to support@applyindenmark.dk and we will send what we are allowed to send.
Automated text generation, and decisions
Your application is drafted by an automated text generation service provided by Anthropic, from your CV and from the answers you gave us. You read and approve one master text before anything is sent. Each company then receives a version of that text where only the marked parts change: the greeting, the company name, one sentence about the company, and the closing.
We do not make automated decisions that produce legal effects concerning you, or that affect you in a similarly significant way. We do not score you, rank you or screen you, and we decide nothing about your employment. The companies that receive an application decide for themselves what to do with it.
One automated rule does decide something: if your answers say you are not already allowed to work in Denmark, we cannot send applications for you, and there is no way to subscribe. That is a decision about what we can deliver, not a judgement about you, and if the answer was recorded wrongly you can write to us and have a person look at it.
If your company received an application
If you received an application sent through Apply in Denmark and you do not want more of them, write to support@applyindenmark.dk with the address you want removed. We put it on a permanent exclusion list within 24 hours, and no user of the service can reach it again. You do not have to give a reason.
That address stays on the exclusion list permanently, and it is deliberately not erased with everything else. Keeping it is the only way we can be sure the request is honoured.
The company contact details we use come from public business sources. Companies registered with advertising protection in the Danish Central Business Register are filtered out, always. If you want to know what we hold about your company, or have it corrected or erased, write to the same address.
How we protect your data
- Data is encrypted in transit. Refresh tokens and uploaded CV files are encrypted at rest with the same envelope pattern, and CV files are stored outside the web root, so no address on this site leads to one.
- Every read of CV data and of the send log is logged with who, when and what.
- Uploaded files are checked for type and size, and scanned for malware before they are attached to anything.
- Access to production data is limited to the people who need it to run the service.
If a breach happens and it is likely to put your rights at risk, we tell you, and we report it to the Danish Data Protection Agency within the deadline the law sets.
Your rights
These rights are yours, they are free to use, and we answer within one month.
- Access: a copy of the personal data we hold about you, and what we do with it.
- Rectification: anything wrong or incomplete corrected.
- Erasure: your data deleted, which for most of it is one click in your account.
- Restriction: processing paused while a disagreement is sorted out.
- Data portability: a copy of the data you gave us in a structured, commonly used, machine readable format, and sent straight to another provider where that is technically possible.
- Objection: you can object to processing we base on our legitimate interest, and we stop unless we have compelling grounds that override yours.
- Withdrawal of consent: the consent you gave for your CV, and the permission you gave Google, can both be withdrawn at any time, without affecting what was lawful before.
- Complaint: you can complain to a supervisory authority, see the next section.
Most of this is one click: your account page shows what we hold, lets you download it, and lets you erase it. For anything else, write to support@applyindenmark.dk.
Complaints
If you think we handle your data wrongly, tell us first. We would rather fix it than read about it. You can complain to the Danish Data Protection Agency at any time:
- Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark
- Email: dt@datatilsynet.dk
- Website: www.datatilsynet.dk
Changes to this policy
When we change this policy we change the date at the top. If a change materially affects how we handle your data, we tell you by email before it takes effect.