Legal
Privacy Policy
This policy explains which personal data LISTDIR processes, why it is needed, and the choices available to you.
Last updated: 30 July 2026
Controller and contact
The Danish business identified below is the controller for account, billing, support, and product-usage data. Directory operators are separate controllers for information you choose to submit to their services.
Data we process
We process account and workspace details, product profiles and submission content, support communications, security and audit events, and transaction references supplied by our payment provider. We collect only the information needed to provide, secure, and improve the service.
Purposes and legal bases
We process data to perform our contract, protect the service and prevent misuse, comply with accounting and legal duties, and—with consent where required—measure or market the service. Consent can be withdrawn at any time without affecting prior lawful processing.
Service providers and transfers
We use vetted hosting, authentication, storage, payment, email, monitoring, and support providers. Where data leaves the EEA, we use an applicable transfer mechanism and assess the safeguards offered by the provider. A current subprocessor list will be made available before commercial launch.
Retention and security
Product profiles and workspace content are kept while the account is active and are removed through the account-deletion process unless continued retention is legally required. By default, security audit events are kept for 365 days, completed operational jobs for 90 days, and unused expired invitations for 30 days. Billing, tax, refund, and dispute records may be retained for the statutory period that applies. Encrypted backup copies age out on the hosting provider's backup schedule rather than being used as active product data.
We use least-privilege access, database-enforced tenant isolation, encryption in transit, private object storage, file-signature inspection, abuse controls, audit logging, backups, restore tests, and incident procedures.
Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability, or object to processing. You may also complain to Datatilsynet or your local EEA supervisory authority. Contact us using the email below; identity verification may be required before fulfilling a request.
Cookies
Strictly necessary cookies support authentication and security. Optional analytics or marketing technologies will remain disabled until valid consent has been collected, and rejecting them will be as easy as accepting.