Privacy

Privacy policy

This page is about you as a customer: what we record, why we are allowed to, who gets to see it, and when it is deleted. We have written it so you can read it without a lawyer beside you.

Last updated:

Contents
  1. Who is the data controller
  2. What data we process
  3. Where the data comes from
  4. What we use the data for — and on what legal basis
  5. Who sees the data
  6. Transfers to countries outside the EU/EEA
  7. How long we keep the data
  8. Cookies
  9. Automated decisions and profiling
  10. Security
  11. Your rights
  12. Complaining to the Danish Data Protection Agency
  13. Changes to this policy
  14. Contact

In short

The short answer to the questions we are asked most often. The rest of the page is the full policy.

We do not sell your data
Not to anyone, for any purpose. Nor do we use it for marketing without your consent.
We never see your card number
The card is held by Stripe. We can see the last four digits and the expiry date, and nothing else.
Necessary cookies only
Login, language choice and payment security. If you have asked for help, we also store a marker in the browser’s storage for 30 days so the contact form can be resumed — and Zendesk may itself set a cookie once the form has loaded. Visits are counted with Plausible, which neither sets cookies nor can recognise you — hence no cookie banner. No ad tracking.
The cleaner sees what they need to
Your name, your address, your phone number and what you have said about the job. Not your payment history and not your other bookings.
You can have it all deleted
Write to us and we delete your account — and we clear out accounts that are not in use ourselves. Invoices we have to keep for five years by law; everything else goes.
No machine decides anything about you
We make no decisions about you by automated means alone that you cannot have a human being look at.

Who is the data controller

Hilfr.dk ApS is the data controller for the personal data we process about you as a customer.

Company
Hilfr.dk ApS
CVR no.
45805360
Address
Brødeskovvej 36, 3400 Hillerød
Email
support@hilfr.dk
Phone
+45 92 45 32 29

This policy applies to you as a user of hilfr.dk as a customer. If you are employed by Hilfr as a cleaner, we process more data about you, and more sensitive data — among other things your CPR number, bank account number and pay details — and that is described in a separate privacy policy for employees.

If you are both a customer and an employee, both policies apply — each to its role.

What data we process

We process only ordinary personal data about you as a customer. We do not ask you for a CPR number, and we do not collect sensitive data such as health, religion or political opinion.

Your account

  • Name, email address and phone number.
  • Password, which is stored encrypted and can never be read by us.
  • Profile picture, if you choose to upload one.
  • Language choice and the settings you have made on your profile.

Your phone, if you use the app

  • A device token, which Apple or Google gives the app. It points to the phone, not to you, and we use it solely to send you the notifications you have turned on yourself.
  • Which kind of phone it is (iPhone or Android), so the message is sent the right way.

You decide. The app asks for permission the first time it makes sense, and you can always turn notifications off again in your phone’s own settings. If you turn them off there, the phone does not show them, and the next time you are in the app, we delete the token — until then, a message can still appear as a banner inside the app if it is open on Android. Otherwise the token is deleted when you sign out or delete your account, and on its own after 270 days.

If you report content or block someone

  • What you write when you report a conversation, a listing, a profile or a review. The text is usually about another person, and it is read by us — not by the person you report.
  • Who you have blocked. The list is your own, and the person you block is not told.

Your home and your bookings

  • The address where the cleaning is to be carried out.
  • Information about the home that you enter yourself: square metres, number of bedrooms and bathrooms. We use it to suggest a realistic number of hours.
  • What you write about the job — wishes, pets, how the cleaner gets in.
  • Date, time, number of hours and which cleaner you have booked.
  • Whether the booking is a one-off or part of a recurring agreement.

Your communication

  • Messages between you and your cleaner on the platform.
  • Your correspondence with our support team by email, chat and phone.
  • Reviews you write of a cleaner.

Payment and invoices

  • The last four digits of the card, the card type and the expiry date. The card number itself is held by Stripe and never enters our systems.
  • The course of the payment: when the amount was reserved, charged, retried or refunded.
  • Your invoices with amounts, the VAT breakdown, the deductible wage share and a sequential invoice number.

Technical data

  • IP address, browser and device type, and login times.
  • Error logs when something goes wrong in the app. The log automatically masks the fields that carry name, address, email address, phone number, card details and free text such as a cancellation reason or a note, and email addresses wherever in the text they appear, before it leaves your browser.

Where the data comes from

By far the most of it we get from you, when you create an account, book a cleaning or write to us.

If you were a customer on Hilfr’s previous platform, we have transferred your basic details, your booking history and the reviews you have written to the new platform, so that you can pick up where you left off. The basis is our agreement with you and our legitimate interest in a customer relationship not being lost because we change systems.

What we use the data for — and on what legal basis

We process your data for the purposes set out below, and for those only. The legal basis is stated next to each purpose.

Carrying out your booking
Creating your account, passing the details to the cleaner and performing the cleaning. Performance of the contract with you (Article 6(1)(b)).
Taking payment
Reserving, charging and where relevant refunding the amount, and issuing an invoice. Performance of the contract (point (b)) and a legal obligation under the Danish Bookkeeping Act (point (c)).
Communicating with you
Confirmations, reminders, messages about the payment and invitations to write a review. Performance of the contract (point (b)).
Customer service and complaints
Answering enquiries and handling complaints and damage claims. Performance of the contract (point (b)) and our legitimate interest in being able to document the course of a case (point (f)).
Safety and misuse
Preventing fraud, misuse of the platform and harassment of our employees. Our legitimate interest in a platform that is safe for both parties (point (f)).
Operations and debugging
Keeping the platform running and finding faults. Our legitimate interest in a service that works (point (f)).
Accounting and tax
Keeping accounting material for the statutory period. Legal obligation (point (c)).
Legal claims
Establishing, exercising or defending a legal claim if a dispute arises. Our legitimate interest in doing so (point (f)).

Who sees the data

Your cleaner

So that the cleaning can be carried out, the cleaner you have booked receives your name, your address, your phone number and what you have said about the job and the home. They do not receive your payment details, your invoice history or information about your bookings with other cleaners.

Our processors

We use a number of suppliers who process data on our behalf and on our instructions. They may not use it for their own purposes. A data processing agreement has been entered into with each of them.

Sharetribe
The platform itself — accounts, bookings, messages and reviews are held in their system, which runs on AWS.
Stripe
Payment cards, payments, refunds and card security.
Postmark
Sending the emails you receive about your bookings.
Zendesk
Support enquiries through the contact form in the corner and by email. The form loads only once you open it yourself — and again on later visits for up to 30 days if you have opened it. When you are signed in, it receives your name, your email address and which pages you visit.
Sentry
Error logs from app and server, in masked form. Runs on Sentry’s EU installation.
Google Firebase
Delivery of notifications to the app on your phone. Firebase receives the device token that points to the phone, and the message text itself — which never contains names, addresses, dates or amounts. If you do not use the app, nothing is sent.
Plausible
Cookie-free visit statistics: which pages are viewed, and whether a search or a booking was completed — never who. Runs from the EU.
Google Workspace
Our own email, including correspondence with you.
Google Maps
The map and the address suggestions. The script loads on every page — not only where a map is shown — so Google receives your IP address on every visit. What you TYPE when you search is not sent: the postcode lookup happens locally on our side, and the address field on your profile is an ordinary text field. Google’s address suggestions are only used when a cleaner types the address for their listing.
Simply.com
Hosting and operation of the servers behind hilfr.dk. Danish provider.

Other recipients

  • IF, if a damage claim arises. IF is an independent data controller for its handling of the case.
  • Public authorities, including the tax authorities and the police, to the extent we are obliged to under the law.
  • Our accountant and any advisers, if a matter requires it.

We do not sell your personal data, and we do not pass it on to third parties for marketing purposes. There are no ad networks or data brokers involved in hilfr.dk.

Transfers to countries outside the EU/EEA

Some of our suppliers are American and may process data outside the EU/EEA — that applies in particular to Stripe, Zendesk and Google, including Firebase, which delivers the notifications to the app. Where that happens, we require a valid transfer basis: the European Commission’s standard contractual clauses, or the supplier’s certification under the EU-US Data Privacy Framework.

If you want to see the specific basis for a particular supplier, you can ask for a copy by writing to support@hilfr.dk.

How long we keep the data

Your account
For as long as you have an active account. We review accounts that have not been in use on an ongoing basis and delete them when they are no longer necessary.
Bookings and messages
Together with the account — they are deleted when the account is deleted.
The app’s device token
Deleted when you sign out or delete your account — and when you turn notifications off in your phone’s settings, the next time you are in the app (until then, a banner can still appear inside the app on Android). If a phone has not opened the app for 270 days, the token disappears on its own.
Reported content
Two years. The limit exists because a report is about another person, and it has to be usable for understanding a pattern — but not to sit there forever.
Who you have blocked
For as long as the block stands. If you lift it, the entry disappears; if you delete your account, the whole list goes with it.
Invoices and accounting material
Five years after the end of the financial year they relate to. That follows from the Danish Bookkeeping Act, and we cannot delete them earlier, not even if you ask us to.
Reviews you have written
They remain on the cleaner’s profile, but are no longer linked to an active profile once your account is deleted. They are part of the cleaner’s reputation.
Damage claims and complaints
For as long as the case is open, and thereafter for as long as a claim can be brought — as a rule three years.
Error logs
Deleted automatically after 90 days.

You can have your account deleted at any time by writing to support@hilfr.dk from the address the account was created with. If you have upcoming bookings, we cancel them at the same time, and that costs nothing.

Cookies

Hilfr.dk uses only the cookies that are necessary for the site to work. That is why you do not meet a cookie banner — there is nothing to decide.

Login
Keeps you signed in between pages and visits.
Language choice
Remembers whether you want to see the site in Danish or English.
Payment
Stripe’s script loads across the whole site — that is how Stripe requires it in order to detect fraud — and sets two cookies that recognise your browser. Without them, no payment can be made.

We measure how the site is used with Plausible: an analytics tool that sets no cookies, stores nothing on your device and cannot recognise you from one visit to the next. It counts page views and a few actions — that a search returned results, that a booking was completed — without name, address, postcode, email or payment details. Plausible runs from the EU. We use no ad tracking and no social media cookies. Should that change, we will obtain your consent first — and then it will say so here.

The help button in the corner is provided by Zendesk. It opens a contact form, and it loads only at the moment you press it — until then Zendesk has not been on the page at all. If you have opened the form yourself within the past 30 days, it does load again on your next visits, so that an enquiry in progress is not lost when you change page or reload. Once loaded, it stores an id on your device so that an enquiry in progress can be followed — in the browser’s own storage and possibly in a cookie from Zendesk. It stays there until you clear your browsing data. If you are signed in, Zendesk also receives your name and your email address, so that an enquiry can be linked to your account, along with which pages you visit. The page address is sent in masked form, so that a single-use password reset link never travels with it.

Automated decisions and profiling

We make no decisions about you that have legal effect or similarly significant consequences based solely on automated processing.

Two things in the system do run automatically, and you should know about them: the order of cleaners in the search results is the age of their listings, newest first, unless you choose a different sort yourself — your postcode is a FILTER, not a distance ranking, and neither ratings nor the number of cleanings enters into the order. And a booking is cancelled automatically if the payment is not in place 12 hours before it was due to start. The latter can always be undone — call or write, and we restore the booking if the cleaner is still available.

Security

All traffic to and from hilfr.dk is encrypted. Passwords are stored encrypted and cannot be read by us. Card details are held by Stripe, which is PCI DSS certified, and never pass through our own systems.

Access to customer data is limited to those staff at Hilfr who need it in order to do their job. Our error log automatically masks the fields that carry name, address, email address, phone number, card details and free text such as a cancellation reason or a note, and email addresses wherever in the text they appear, before anything leaves your browser or our server.

If a security breach nevertheless occurs that involves a high risk to you, we notify you, and we report the breach to Datatilsynet, the Danish Data Protection Agency, within 72 hours.

Your rights

The General Data Protection Regulation gives you a number of rights towards us. You can use all of them by writing to us — it costs nothing, and you do not have to give a reason.

Access
You can be told what data we process about you, and receive a copy.
Rectification
You can have incorrect data about you corrected.
Erasure
In many cases you can have data about you deleted before we would have done so ourselves.
Restriction
In certain cases you can require us to only store the data and not use it for anything else.
Objection
You can object to processing we base on a legitimate interest, and to direct marketing.
Data portability
You can receive the data you have given us yourself in a machine-readable format and have it sent on.
Withdrawal of consent
If you have given a consent, you can withdraw it at any time. That does not affect the lawfulness of the processing up to that point.

Write to support@hilfr.dk from the email address your account was created with, or call +45 92 45 32 29. We reply within a month. If a matter becomes so extensive that we need longer, we tell you within that month and explain why.

Complaining to the Danish Data Protection Agency

If you are dissatisfied with how we process your personal data, we would very much like to hear from you first — but you always have the right to complain to Datatilsynet, the Danish Data Protection Agency, Carl Jacobsens Vej 35, 2500 Valby. You will find the complaints guidance at datatilsynet.dk.

Changes to this policy

We update the policy when the platform, the law or our suppliers change. The version in force is always shown here with a date and a version number at the top.

If we change something material — a new purpose, a new category of recipients — we notify you by email before the change takes effect.

Contact

If you have questions about this policy, about what we hold on you, or if you want to use one of your rights, write or call. You get an answer from a human being.

Email
support@hilfr.dk
Phone
+45 92 45 32 29
Post
Hilfr.dk ApS, Brødeskovvej 36, 3400 Hillerød

We are not required to have a data protection officer (DPO) and have not appointed one. Data protection enquiries go to our support team, who pass them on internally.