Privacy Policy

Introduction

PixelPai ApS (“PixelPai,” “we,” “us,” or “our”) is committed to protecting your personal data and ensuring your privacy rights are upheld. This Privacy Policy covers how we collect, use, share, protect, and retain your personal information—whether you’re browsing our website, using our services, applying for a role, or engaging with our Legal Expert Network.

1. Who We Are

PixelPai ApS, registered in Denmark, company number 44479397, and located at Applebys Plads 7,2, 1411 Copenhagen K, is registered as a Virtual Asset Service Provider (“VASP”) with the Danish Financial Supervisory Authority. We are also preparing for CASP operations and certifications including ISO 27001, SOC 2, GDPR, and the EU AI Act.

2. Scope of This Policy

This Policy applies to all personal data we collect about:
– Website visitors
– Customers & users of our services
– Applicants (e.g., Counsel, Careers)
– Suppliers & business partners

3. Personal Data We Collect

Depending on your interaction with us, we may collect:
1. Website Visitors: IP address, device/browser information, cookies, and analytics data.
2. Service Users: Name, contact details, account credentials, profile data, payment information, and usage logs.
3. Applicants: Professional data such as resumes, CVs, LinkedIn profiles, contact details, and other application information.
4. Suppliers & Partners: Company contact information, contractual data, invoicing details.

We may also obtain data from third parties—like analytics tools, payment processors, or social media platforms.

4. How and Why We Use Your Data

We process data in line with GDPR principles and undertake only lawful, transparent, and necessary processing.

Purposes and Legal Basis include:
– Providing, administering, and improving services (Contract performance)
– Customer support and communication (Contract performance / legitimate interest)
– Processing payments (Contract performance)
– Compliance with AML, KYC, regulatory obligations (Legal obligation)
– Marketing (Consent)
– Enhancing user experience via analytics (Legitimate interest)
– Application review and communication (Legitimate interest / consent)

5. How We Share Your Data

We may share personal data with:
– Service providers (for data hosting, analytics, payment processing, etc.)
– Regulatory or law enforcement authorities, if required by law
– Auditors, lawyers, or professional advisors for compliance and audit purposes
– In anonymized form for statistical or research uses

Where data is transferred outside the EEA, we rely on Standard Contractual Clauses or equivalent safeguards.

6. Data Security

We implement security controls across technical, organizational, and physical layers:
– Encryption (in transit and at rest)
– Multi-factor authentication, access controls (least privilege)
– Secure data centers with environmental safeguards
– Monitoring, audits, and vulnerability assessments
– Incident response protocols

While we aim for the highest levels of protection, no system is entirely risk-free.

7. Data Retention & Deletion

Data Type | Retention Period
———-|—————-
Customer data | Minimum 5 years post-relationship (AML compliance)
Tax/Financial data | 6 fiscal years + current year (legal requirement)
Applicants | Up to 2 years, unless extended by consent
Suppliers & partners | Duration of engagement + usual accounting retention period
Anonymized data | Indefinite use for analytics/statistics

Data Deletion Requests & Policy:
– Scope: Applies to all personal and related data (logs, backups, metadata).
– Request Process: Email data@pixelpai.com to request deletion.
– Response Timeline: Acknowledge within 5 business days; complete deletion within 30 calendar days unless legal retention applies. Confirmation will be provided.
– Secure Deletion Methods: Crypto-shredding, secure wiping, or equivalent. Request proof if needed.
– Exceptions: If legal obligations (e.g., AML/KYC) override deletion, data will be retained for permitted duration.
– Audit Readiness: Deletion events are logged and available for audits (ISO 27001, SOC 2).

8. Your Rights Under GDPR

You have the right to:
– Access your personal data
– Correct inaccuracies
– Request erasure
– Restrict processing
– Receive data portability
– Object to processing (e.g., for marketing)

To exercise your rights, contact: data@pixelpai.com. We respond within one month, extendable if needed.

9. Cookie and Tracking Policy

We use cookies and similar technologies (e.g., tracking pixels) for site functionality, analytics, and marketing. For details and cookie management, see our Cookie Policy. Note cookies may be optional but can improve your site experience.

10. Children’s Privacy

Our services are not intended for persons under 18. If we learn we’ve collected a minor’s data in error, we swiftly delete it.

11. Policy Updates

We may update this Policy to reflect changes in services or laws. Updates will be posted on this page, and you’ll be notified when appropriate.

12. Contact

Have questions? Reach us at:

Email: data@pixelpai.com
Address: Applebys Plads 7,2, 1411 Copenhagen K, Denmark