Legal
Privacy policy
This policy explains how KURS handles personal data. Last updated: 14 August 2026.
Who is responsible
Hpcreators I/S, CVR 42979228, operates KURS and is the data controller for account, billing, security, support, and marketing data described in this policy. Contact us at n.hpcreators@gmail.com. Our business address is Hiort Lorenzens Gade 11, 2200 Copenhagen N, Denmark.
Data we collect
- Account data: email address, account identifier, confirmation and security status, and basic profile data you choose to add.
- Workspace data: project, task, milestone, risk, equipment, owner, and collaboration data created in KURS. Workspace data may contain personal data if users enter it.
- Invitation data: invitee email address, role, status, and related workspace metadata.
- Billing data: selected plan, subscription status, Stripe customer and subscription identifiers, and billing-related records. Payment-card details are collected and processed by Stripe, not by KURS.
- Security and technical data: information needed to secure the service, such as authentication/session information, request metadata, and fraud-prevention signals.
- Marketing preference data: whether you opted in to product updates and the related consent metadata.
Why we use personal data
- To provide KURS: to create accounts, operate workspaces, process invitations, and provide requested subscription features. This is necessary to perform our contract with you.
- To protect the service: to prevent abuse, protect accounts, investigate security incidents, and maintain reliable operation. This is based on our legitimate interests in running a secure service.
- To meet legal obligations: to maintain records required by applicable tax, accounting, or other law.
- To send marketing: only where you have opted in. You can withdraw consent at any time.
Service providers and recipients
We use carefully selected providers to operate KURS. They receive only the data needed for their service.
- Supabase: authentication, database storage, and workspace data hosting.
- Vercel: hosting, application delivery, and operational infrastructure.
- Stripe: subscription checkout, payment processing, tax calculation, invoices, and billing portal services.
- Resend: transactional account and invitation emails, and marketing contact services where you opted in.
- Cloudflare: Turnstile security checks that help protect signup, login, and recovery flows from automated abuse.
Some providers may process data outside the EU/EEA. Where a transfer occurs, we rely on the safeguards required by applicable data-protection law, such as an adequacy decision or standard contractual clauses.
Retention and deletion
- Account and workspace data are retained while the relevant account or workspace is active.
- When you request deletion, we delete or anonymise personal data when it is no longer needed, subject to legal obligations, security needs, and technically necessary backup retention.
- Invitation and security records are retained only for as long as needed to operate, secure, and defend the service.
- Billing and accounting records are retained for the period required by applicable law.
- Marketing contact data is retained until you withdraw consent or ask us to remove it, unless another lawful basis requires limited retention.
Cookies and security checks
KURS uses necessary session and authentication cookies to sign users in, keep sessions active, and protect the workspace. Cloudflare Turnstile may process technical information needed to distinguish people from automated abuse. KURS does not currently use optional advertising or analytics cookies. If that changes, this policy and any required consent mechanism will be updated first.
Your rights
Subject to applicable law, you can request access to, correction of, deletion of, restriction of, or portability of your personal data. You may object to processing based on legitimate interests and may withdraw marketing consent at any time. Contact us at n.hpcreators@gmail.com. We normally respond within one month.
You also have the right to complain to the Danish Data Protection Agency (Datatilsynet) or your local data-protection authority.
Changes to this policy
We may update this policy when KURS, our providers, or applicable law changes. The current version is published here with its update date.