Legal

Hawn hija l-politika tal-privatezza tagħna

How SolvencyTool collects, uses, and protects your data — written in plain language, backed by GDPR.

Last updated: 7 August 2026

This policy is provided in English. In case of any conflict with a translated version, the English text prevails.

Introduction

SolvencyTool (“we”, “us”, “our”) builds insurance software for Solvency II compliance, XBRL reporting, and regulatory calculations. This policy explains what personal data we collect when you visit solvencytool.com and any of its localised versions, why we collect it, how we use it, and the rights you have under the EU General Data Protection Regulation (GDPR) and other applicable laws.

If anything below is unclear, contact us — we’ll answer in plain language.

Who we are

The data controller for this website is:

SolvencyTool (Alpina) Høje Taastrup Boulevard 52, 1. floor DK-2630 Taastrup, Denmark Email: info@SolvencyTool.com Phone: +45 7023 2016

Data we collect

We keep data collection to the minimum needed to run the site and answer requests.

Information you give us directly

  • Contact and demo requests. When you email or call us, we store your name, email, phone number, employer, and the content of the message. This lets us reply and follow up.
  • Newsletter and product updates. If you subscribe to a mailing list, we store your email address and language preference until you unsubscribe.

Information collected automatically

  • Server logs. Our hosting provider records standard request metadata (IP address, user agent, timestamp, requested URL, referrer) for a short retention window. This is used for security, debugging, and abuse prevention.
  • Cookies and similar technologies. See Cookies below. No cookies that collect personal data are set before you give consent.
  • Analytics. If you accept the Analytics category in our cookie banner, Google Analytics 4 collects anonymised usage statistics (pages visited, session duration, approximate region). We use Google’s IP-anonymisation setting so full IP addresses are never stored.

We do not collect special categories of data (health, ethnic origin, political opinions, etc.) through this site.

Under GDPR Article 6, we rely on:

  • Consent (Art. 6(1)(a)) — for non-essential cookies and analytics. You can withdraw consent at any time via cookie preferences.
  • Contract or pre-contract steps (Art. 6(1)(b)) — when you request a demo, quote, or trial.
  • Legitimate interest (Art. 6(1)(f)) — to operate a secure website (server logs), respond to unsolicited enquiries, and communicate with existing customers about product updates. We weigh this against your rights and only rely on it where the impact on you is minimal.
  • Legal obligation (Art. 6(1)(c)) — where retention is required by tax, accounting, or regulatory rules.

How we use your data

  • Respond to enquiries, demos, and support requests.
  • Deliver newsletters and product updates you’ve opted into.
  • Improve the site’s content, navigation, and speed based on aggregated analytics.
  • Keep the site secure and prevent abuse (rate-limiting, bot detection).
  • Comply with legal obligations that apply to us as a Danish company operating across the EU.

We do not sell your personal data. We do not use your data for automated decision-making or profiling that produces legal effects.

Cookies

Cookies are small text files stored in your browser. This site uses three categories, and only the first is on by default:

  • Necessary. Region preference, dismissed banners, and your own cookie-consent choice. These do not track you across sites and cannot be disabled — without them the site can’t remember basic settings.
  • Analytics. Google Analytics 4 with IP anonymisation. Off by default. Turns on only if you press Accept all or enable it in Cookie preferences.
  • Marketing. Reserved for future advertising and remarketing pixels. Off by default. Currently unused — no data is collected even when enabled.

You can review and change your cookie choices at any time via Manage cookie preferences at the bottom of this page, or by clearing the st_consent cookie in your browser and reloading.

Google Consent Mode v2 is in effect, meaning Google tags are present on the page but sit in denied state until you consent. If you never consent, no analytics identifiers are stored.

Third parties who process data on our behalf

We rely on a small number of external processors, each bound by data-processing agreements consistent with GDPR:

  • Hosting and content delivery — for serving the website worldwide with reasonable latency. Server logs stay within the EU where possible.
  • Google Analytics (Google Ireland Ltd.) — only after Analytics consent. Anonymised at collection.
  • Ahrefs Analytics — first-party, cookie-less analytics on aggregated traffic patterns. No personal data leaves your browser to Ahrefs.
  • Email delivery — for replying to enquiries and sending opt-in newsletters.

We do not transfer personal data outside the EEA unless the recipient is covered by the EU Standard Contractual Clauses or an adequacy decision by the European Commission.

Data retention

  • Enquiries and demo requests — kept for up to 24 months after the last contact, then deleted unless the exchange resulted in a customer relationship.
  • Newsletter subscribers — kept until you unsubscribe, then deleted within 30 days.
  • Server logs — 30 days.
  • Analytics data — Google Analytics 4 default (up to 14 months at event level, then aggregated).
  • Cookie-consent record — 6 months, after which we ask again.

Your rights under GDPR

You have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data (“right to be forgotten”).
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Portability — receive your data in a machine-readable format.
  • Objection — object to processing based on legitimate interest.
  • Withdraw consent — for anything we process on the basis of consent.
  • Lodge a complaint with the Danish Data Protection Agency (datatilsynet.dk) or your local supervisory authority.

To exercise any of these, email info@SolvencyTool.com. We’ll respond within one month.

Security

We use encryption in transit (HTTPS across the entire site), access controls on internal systems, and periodic security reviews. No system is perfectly secure — if a breach ever affects your data, we will notify you and the relevant supervisory authority within the timeframes required by GDPR.

Children

This site is intended for professional audiences (insurers, actuaries, compliance officers) and is not directed at children under 16. We do not knowingly collect data from children.

Changes to this policy

We may update this policy to reflect changes in law, our services, or feedback. When we make material changes, we’ll update the “Last updated” date at the top and — where the change affects your rights — notify you directly if we have your email.

Contact

For any privacy-related question:

Please write “Privacy” in the subject line so your request reaches the right team quickly.

Questions about your data?

Reach us any time — our data protection team responds within one business day.