Skip to content
Apply in Denmark

Legal

Privacy policy

Last updated: 19 September 2026

This policy explains what Apply in Denmark does with your personal data, what we do with the information we receive from Google, how long we keep it, and what you can ask us to do about it.

Who we are

Apply in Denmark (applyindenmark.dk) is operated by LEV Systems ApS, a company registered in Denmark. LEV Systems ApS is the data controller for the personal data described here.

Write to that address about anything in this policy. It reaches the people who decide how data is handled here, not a queue.

What the service does

You sign in with Google, upload your CV, answer seven short questions about your situation, and approve one application text. We then adapt that text to each company on your list and send it from your own email address, a few each day, across the week.

Recipients always come from our own database of companies in Denmark. You cannot upload your own list of recipients, and you cannot add an address by hand. Nothing is sent that you have not approved.

How we access, use, store and share Google user data

What we ask for

We use Google Sign-In. When you sign in, Google asks you to grant two things: openid, email and profile, which tell us who you are, and https://www.googleapis.com/auth/gmail.send, which lets an application hand a finished message to Gmail for sending.

How we access it

We reach your Google account only through Google's official APIs, using the token Google issues after you grant permission. We never ask for your Google password, and we never sign in as you in a browser.

The gmail.send scope does one thing: it sends. It gives no access to your mailbox. We never read your mail, we never search it, we never list it, we never download it, and we never delete anything in it. The scope we hold cannot do any of that, and we do not request a scope that can.

How we use it

We use the permission for one purpose: to send the applications you have approved, from your own address, to the companies on your list for the week you have paid for. The name and email address on your Google profile are used to sign you in and to sign the application. We never send marketing from your account, and we never send anything on your behalf that you have not approved.

How we store it

The refresh token Google issues is stored encrypted, never in clear text. We use envelope encryption: the token is encrypted with a data key, and that data key is itself encrypted with a key kept separately from the database. Tokens never appear in logs, error messages or support tickets.

If you disconnect Google inside your account, or delete your account, we erase the stored token straight away and sending stops there and then.

If you instead remove our access from your Google account, the token stops working immediately, so we can no longer send anything on your behalf. Google does not tell us that it happened, so we find out at the next attempt, and we erase the stored token when we see that it has been revoked.

How we share it

We do not share Google user data with anyone for advertising, for sale, or for any other purpose of our own. We do not pass it to data brokers, we do not build advertising profiles from it, and we do not use it to develop, improve or train generalised models.

Two things deserve to be said precisely. First, the name and email address on your Google profile are used to create your account and as the sender of your applications. Second, the application itself is written from your CV and from your own answers by the text generation provider listed under who we share data with, and your name can appear in that material, because an application is signed. Beyond that, your email address is handed to the providers listed under who we share data with, so that they can deliver our system emails to you and run your subscription. Those are the only transfers, they happen only to deliver what you asked for, and they are limited to what that takes.

Nothing from your mailbox is sent anywhere, to that provider or to anyone else, because we have no access to your mailbox in the first place.

Who can read it

People do not read your Google user data. There are three narrow exceptions, and they are the ones Google's policy allows: with your explicit consent, for example when you ask support to look at a send that failed; where it is necessary for security purposes, such as investigating abuse or a suspected breach; and where we are required to do so by law.

Limited Use

Apply in Denmark's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The policy that statement refers to is here: Google API Services User Data Policy.

How to take the access away

  • Disconnect Google inside your account. The stored token is erased and sending stops.
  • Or remove our access at https://myaccount.google.com/permissions. Google revokes the token, and every further send fails at once.

Taking the access away does not by itself delete the rest of your data. Use delete now in your account, or write to us, if you want everything erased.

What we process, why, and for how long

Categories of personal data, purpose, legal basis and retention
What we processWhyLegal basisHow long we keep it
Your CV, and any extra file you attachWhyTo write the applications you approve, and to attach your CV to every application we send for you.Legal basisArticle 6(1)(b), performance of our contract with you. A CV can hold special categories of data, and those rest on your separate explicit consent, Article 9(2)(a).How long we keep itErased 90 days after your last active week, or as soon as you ask us to.
Google account information: your name, your email address, and the permission to send mail from your addressWhyTo sign you in, and to send the applications you approved from your own address.Legal basisArticle 6(1)(b), performance of our contract with you. The permission itself is granted through Google and can be withdrawn at any time.How long we keep itKept while your account is open. The stored token is erased the moment you withdraw the permission or delete your account.
Payment data: subscription status, amount, date, and the card brand and last four digits Stripe reports back to usWhyTo take payment for your subscription, and to handle refunds and disputes.Legal basisArticle 6(1)(b), performance of our contract with you, and Article 6(1)(c), our legal obligation to keep accounting records.How long we keep itAccounting records are kept 5 years from the end of the financial year, as Danish bookkeeping law requires. We never receive or store your full card number.
Send log: the company, the time, the delivery status, and the exact text that went outWhyTo show you what has been sent, to make sure no company is written to twice, and to document delivery if it is ever disputed.Legal basisArticle 6(1)(b), performance of our contract with you, and Article 6(1)(f), our legitimate interest in being able to document what we sent.How long we keep itErased 90 days after your last active week, or as soon as you ask us to.
Profile fields and your answers to our questions: field of work, experience, languages, availability, notice period, and anything you asked us not to mentionWhyTo write applications that match what you actually told us, and to pick companies in the right category.Legal basisArticle 6(1)(b), performance of our contract with you.How long we keep itErased 90 days after your last active week, or as soon as you ask us to.
Citizenship group and work permit answer: one of three groups (Denmark or the Nordic countries, the EU, the EEA or Switzerland, or anywhere else), plus yes or no to holding a Danish work and residence permitWhyTo check whether we can send applications for you at all. We only send for people who are already allowed to work in Denmark.Legal basisArticle 6(1)(b), steps taken at your request before entering into our contract.How long we keep itErased 90 days after your last active week, or as soon as you ask us to.

We never store your nationality, your country of origin, or any free text about where you are from. The citizenship answer is one of the three groups above and nothing more. We do not give advice about immigration or residence rights, we only point you to the authorities who do.

Beyond the table, our servers keep short technical logs (IP address, time, and the page requested) for security and troubleshooting, for up to 30 days. Emails you send to support are kept for as long as it takes to close your case.

Giving us this data is not a legal requirement, but it is necessary to use the service. Without a CV, your answers and the permission to send, there is nothing we can deliver, and there is no way to subscribe.

Sensitive information in your CV

A CV often holds more than work history. It can say something about your health, a period of parental leave, a union, a religious school, or where you were born. Under Article 9 that is a special category of personal data, and it needs a legal basis of its own.

So we ask for it separately. Before you upload a CV you tick a box that is not pre-ticked and is not buried in the terms, giving your explicit consent for us to process the CV, including any special categories it happens to contain, for the single purpose of writing and sending the applications you approve.

You can withdraw that consent whenever you like. Withdrawing it stops further sending and lets you have the CV erased. It does not make what we lawfully did before unlawful.

We never ask you for health data, union membership, religion, political views, sexual orientation or criminal record, and none of it is ever used to select companies for you.

How long we keep your data

The rule is 90 days after your last active week. In detail:

  • Your CV, your drafts and your send log are erased automatically 90 days after your last active week, without you having to ask.
  • Delete now: one click in your account erases your CV, your drafts, your send log and the account itself, and disconnects Google. We act on it straight away, not within a month.
  • Accounting records we are required by Danish bookkeeping law to keep are the one exception. They are kept 5 years from the end of the financial year.
  • Our internal audit and access records are kept for security and documentation, in a form that no longer points at you once your account is erased.

Who we share data with

A small number of providers process data on our instructions, under a data processing agreement. They may not use it for their own purposes.

The first four in the table below are processors in that sense. Meta is not: it is a recipient that uses what it receives for its own purposes, under its own terms, and only after you have accepted marketing cookies.

For the collection and transmission of the pixel data itself, we and Meta are likely to be joint controllers, following the Court of Justice's reasoning in the Fashion ID case. What Meta then does with that data afterwards is its own responsibility alone.

Providers and recipients, what they do, and where they do it
WhoWhat they do for usWhere they process dataSafeguard
AnthropicWhat they do for usRuns the text generation service that drafts your application from your CV and your answers.Where they process dataUnited StatesSafeguardData processing agreement with the European Commission's standard contractual clauses. Under that agreement the content we send is not used to train their models.
StripeWhat they do for usTakes the payment and runs the subscription. Card details go straight to Stripe.Where they process dataEuropean Union and United StatesSafeguardData processing agreement with standard contractual clauses. Stripe answers for card data in its own right, and we never see your card number.
Email providerWhat they do for usDelivers the system emails we owe you: the receipt, the week reminders and service notices. Your applications do not go through it, they go through your own Gmail.Where they process dataEuropean Union, or the United States for some providersSafeguardData processing agreement, with standard contractual clauses where data leaves the EU or the EEA.
HetznerWhat they do for usHosts the servers and the database that run the service.Where they process dataGermanySafeguardData processing agreement. The data stays inside the European Union.
Meta Platforms Ireland, only if you accept marketing cookiesWhat they do for usMeasures which advertisements bring people to this site, using the cookie identifiers that are set after you accept marketing cookies. It receives cookie identifiers, the pages you looked at here, and your IP address. It never receives your CV, an application, or anything we received from Google.Where they process dataIreland, with transfer to the United StatesSafeguardYour consent, Article 6(1)(a), which you can withdraw at any time under Cookie settings. Transfers to the United States rest on the EU US Data Privacy Framework and on standard contractual clauses.

Meta is the odd one out on that list. It receives nothing at all unless you accept marketing cookies. If you never accept them, or you withdraw your consent under Cookie settings, nothing about you reaches Meta. What it can receive is limited to the cookie and browsing data in the row above.

One more party belongs in the picture, and it is not on that list: Google. An application leaves through Gmail on your instruction, because it is your mailbox and your address. Google handles that mail under its own agreement with you, not as our processor.

We do not sell personal data. Your Google user data, your CV and your applications are never given to advertising networks, in any circumstances. The only advertising network in the picture is Meta, it is there only if you accept marketing cookies, and it only ever receives the cookie and browsing data described above. Authorities receive data only where the law requires it, and lawyers or courts only where we have to defend or enforce a legal claim.

Transfers outside the EU and the EEA

Some of the processing happens outside the EU and the EEA. Anthropic processes in the United States, Stripe does so in part, and Meta transfers to the United States if, and only if, you have accepted marketing cookies. Those transfers rest on the European Commission's standard contractual clauses, which come with the agreements we hold, on the supplementary measures described in them, and for Meta also on its Data Privacy Framework certification.

You can ask for a copy of the safeguards that are in place. Write to support@applyindenmark.dk and we will send what we are allowed to send.

Automated text generation, and decisions

Your application is drafted by an automated text generation service provided by Anthropic, from your CV and from the answers you gave us. You read and approve one master text before anything is sent. Each company then receives a version of that text where only the marked parts change: the greeting, the company name, one sentence about the company, and the closing.

We do not make automated decisions that produce legal effects concerning you, or that affect you in a similarly significant way. We do not score you, rank you or screen you, and we decide nothing about your employment. The companies that receive an application decide for themselves what to do with it.

One automated rule does decide something: if your answers say you are not already allowed to work in Denmark, we cannot send applications for you, and there is no way to subscribe. That is a decision about what we can deliver, not a judgement about you, and if the answer was recorded wrongly you can write to us and have a person look at it.

If your company received an application

If you received an application sent through Apply in Denmark and you do not want more of them, write to support@applyindenmark.dk with the address you want removed. We put it on a permanent exclusion list within 24 hours, and no user of the service can reach it again. You do not have to give a reason.

That address stays on the exclusion list permanently, and it is deliberately not erased with everything else. Keeping it is the only way we can be sure the request is honoured.

The company contact details we use come from public business sources. Companies registered with advertising protection in the Danish Central Business Register are filtered out, always. If you want to know what we hold about your company, or have it corrected or erased, write to the same address.

Cookies

We set the cookies the site needs to work, and nothing else without your consent. What we set, why, and how to change your mind is on the cookie policy page.

How we protect your data

  • Data is encrypted in transit. Refresh tokens and uploaded CV files are encrypted at rest with the same envelope pattern, and CV files are stored outside the web root, so no address on this site leads to one.
  • Every read of CV data and of the send log is logged with who, when and what.
  • Uploaded files are checked for type and size, and scanned for malware before they are attached to anything.
  • Access to production data is limited to the people who need it to run the service.

If a breach happens and it is likely to put your rights at risk, we tell you, and we report it to the Danish Data Protection Agency within the deadline the law sets.

Your rights

These rights are yours, they are free to use, and we answer within one month.

  • Access: a copy of the personal data we hold about you, and what we do with it.
  • Rectification: anything wrong or incomplete corrected.
  • Erasure: your data deleted, which for most of it is one click in your account.
  • Restriction: processing paused while a disagreement is sorted out.
  • Data portability: a copy of the data you gave us in a structured, commonly used, machine readable format, and sent straight to another provider where that is technically possible.
  • Objection: you can object to processing we base on our legitimate interest, and we stop unless we have compelling grounds that override yours.
  • Withdrawal of consent: the consent you gave for your CV, and the permission you gave Google, can both be withdrawn at any time, without affecting what was lawful before.
  • Complaint: you can complain to a supervisory authority, see the next section.

Most of this is one click: your account page shows what we hold, lets you download it, and lets you erase it. For anything else, write to support@applyindenmark.dk.

Complaints

If you think we handle your data wrongly, tell us first. We would rather fix it than read about it. You can complain to the Danish Data Protection Agency at any time:

Changes to this policy

When we change this policy we change the date at the top. If a change materially affects how we handle your data, we tell you by email before it takes effect.