Privacy information - platform draft
Draft — company details and operational annexes remain to be confirmed.
LEGAL-DRAFT-20261008-1 · B2B · EN
Identity and contact
Platform operator: Welcom, registration [TO CONFIRM: registration_number], address [TO CONFIRM: address]. Privacy contact: [TO CONFIRM: privacy_email]. These company details and the operational rights-request channel are pending confirmation. A reseller may provide an additional notice for its own customer relationship.
Data handled by this platform
The application can store account names and email addresses, roles and support actions, SIM identifiers (ICCID, IMSI, MSISDN where available), device labels, usage and network observations, customer and reseller contracts, quotes, invoices and integration identifiers. Tracking can include GPS positions and geofence events when that paid service is enabled. Such records may relate to employees or other individuals. Payment integration is being prepared; full card numbers and security codes must remain with the payment provider, not in platform business tables.
Purposes and proposed legal bases
Account and contractual administration support service delivery. Access controls and audit support security and incident investigation. Billing records support settlement and applicable accounting obligations. Tracking is purpose-limited and requires a customer-defined lawful deployment. Contract necessity, legal obligation or legitimate interests may be relevant depending on the person and processing; a contract with a company is not automatically a legal basis for all employee data. Optional analytics or marketing would require a separate documented basis and cookie choice. The final basis register is pending.
Roles and recipients
Welcom, a reseller, the customer, a connectivity supplier and a payment provider may have different roles for different data flows. Do not assume that every supplier is a processor or that a single data-processing agreement covers all flows. The controller/processor allocation, instructions, recipients and approved subprocessor register must be completed before production services are contracted. Sure and Stripe integrations are being prepared; this notice does not claim that live personal-data transfers or agreements are already in place.
Storage, retention and international transfers
The planned primary infrastructure is Danish colocation; this is not a claim that every processing operation, supplier or backup is located in Denmark. Retention schedule: [TO CONFIRM: retention_schedule]. Define periods and deletion/export procedures for account, traffic/location, audit, contract, billing and backup data separately. The location and transfer safeguards for each external service must be documented before use. There is no blanket promise of indefinite retention or EU-only processing.
Rights and complaints
Depending on the applicable basis and circumstances, individuals can request access, correction, deletion, restriction, portability or object to processing, and withdraw consent. Contact [TO CONFIRM: privacy_email]; identity verification must be proportionate. Complaints can be addressed to the Danish Data Protection Agency (Datatilsynet). Requests and responses must be recorded and handled within applicable deadlines. Do not email copies of sensitive identifiers unnecessarily.
Security and changes
The application uses scoped access and audit for the newer commercial modules; full delegated support/RBAC and network-provider enforcement remain implementation gates. Complete the operational security controls, incident procedure, backups, restore tests and deletion jobs before claiming compliance. This notice is a versioned draft; changes must reflect actual data flows rather than marketing assumptions.