Online Erhverv
Security & GDPR

Your data is yours. Full stop.

You put your customers’ names, addresses, invoices and photos into the system — and you are the one responsible for them to your customers. That’s why more work has gone into security than into everything you see on screen. Data in the EU, separated per company, encrypted end to end.

See the platform live in the demo
Protected
Your data and your customers’ data
Built watertight from the ground up
Data in the EU
Hosted in Ireland — never sold on
Separated per company
Row-Level Security locks your data
Encrypted end to end
All traffic over TLS
Deleted after 90 days
The AI phone’s recordings remove themselves
EU
Your database is hosted in the EU (Ireland) — never sold on
Per company
Row-Level Security locks your data to your business
TLS
All traffic encrypted end to end
90 days
Then the AI phone’s recordings are deleted automatically
How we look after it

Six things that keep your data watertight

Not a logo with “security” on it. The actual stack, explained plainly.

Your data stays in the EU

The database is hosted with Supabase in the EU (Ireland). Your data and your customers’ data is never sold on to third parties.

Separated per company

Row-Level Security on every table in the database. Your company’s data is locked to your business — no one else on the platform can see it.

Encrypted end to end

All traffic runs encrypted over TLS, incoming webhooks are signature-validated, and double actions are blocked with idempotency keys.

You can always delete

Export all your data as a file (GDPR Art. 20), and delete a customer’s details across the whole system (Art. 17). Recordings from the AI phone are deleted automatically after 90 days.

Audit log on everything

Every change to customers, jobs, invoices and users is logged with the time and who did it. You can always see what happened.

We watch the uptime

Health checks run continuously and backend errors are caught automatically, so we spot problems fast — often before you notice them.

For your customers too

You’re the data controller — we make it easy to comply

When you store a customer’s details, it’s your responsibility under GDPR. We’re your data processor and give you the tools to hold up your end — without being a lawyer.

Data processing agreement in the app

You accept it inside the system — so the paperwork is in place, no lawyer needed.

Delete a customer across the system

A customer asks to be forgotten? One click removes them from the whole system (Art. 17).

Pull everything out

Export a customer’s data as a file if they ask for access (Art. 20).

Consent is managed

SMS only goes to customers who’ve said yes — so you stay on the right side of the law.

GDPRData export + deletion
Data in the EUSupabase, Ireland
TLSAll traffic encrypted
eIDAS signatureSMS code + tamper check
Audit logWho did what, when

We are the data processor for your customer data. You accept the data processing terms inside the app and can pull all your data out as CSV or JSON straight from the portal at any time.

FAQ

Questions about security

What you should know before you put your customers’ data somewhere new. If your answer isn’t here, call or write.

A question about something specific?

Call us and we’ll answer honestly — including the technical side.

Where is my data kept — and my customers’ data?

In the EU. Your database is hosted with Supabase in Ireland. We never sell or share your data with third parties, and you can pull everything out as CSV or JSON straight from the portal at any time.

Can other companies on the platform see my customers?

No. Every table in the database is protected by Row-Level Security that locks your data to your business. It is technically impossible for another company to read it.

Is it GDPR-compliant to have my calls recorded?

Yes. The AI phone’s calls are transcribed and deleted automatically after 90 days. Your database is in the EU, and you can always export or delete a customer’s data. You are the data controller, we are the data processor — it’s set out in the data processing agreement inside the app.

What happens to my customers’ data if a customer asks to be deleted?

You delete the customer across the whole system with one click (GDPR Art. 17 — the right to be forgotten). So you can always meet your own obligations to your customers.

Are signatures on quotes legally valid?

Yes. The digital signature follows eIDAS (simple electronic signature) with a one-time SMS code and a tamper check that detects if the document is altered after signing. The whole process is logged, so it holds up if it’s ever disputed.

What if I leave Online Erhverv — do you keep my data?

No. You own your data. You export everything (customers, invoices, photos, history) as a file whenever you like. The product should keep you — not a locked door.

Try it — your data comes back out with you if you change your mind

90 days free, no commitment. You own your data the whole way, and you can export everything with one click.

90 days free