Skip to content

Privacy policy for identityden.com

How IdentityDen processes personal data: what we collect, why, how long we keep it, who we share it with, and the rights you have under the GDPR.

Last updated

This privacy policy describes what personal data IdentityDen processes, why we process it, how long we keep it, and the rights you have under the General Data Protection Regulation (GDPR). It covers both this website and the account-based service.

1. Data controller

bon.do ApS
Company registration: 43473425
Svendborg, Denmark
Email: hello@identityden.com

bon.do ApS is the controller for the personal data processed in connection with the use of IdentityDen.

2. What we process

Account details

Name, email address and, if you provide them, company name and phone number. They are used to create and administer your account.

Content you provide

The description of the company you write in the brief, the choices you make along the way, and any files you upload if you want tokens derived from an existing logo. It is processed to deliver the service and kept for as long as your account exists.

Payment details

Subscription and payments are handled by our payment provider. We receive information about which subscription is active and whether a payment went through, but we do not store card numbers or other complete payment details in our own systems.

Usage data

Each run records which actions were performed, how many credits they cost, and what the AI consumption behind them was. That record is the basis for the usage report you can see in your account.

Technical data

When you visit this website, your request is handled by our hosting provider, and technical log data such as IP address and user agent may be recorded as part of that. The site sets no analytics or marketing cookies. See the cookie policy.

3. Purposes and legal bases

  • Delivering the service. Account creation, running the chain from brief to brand kit, and delivering the files. Legal basis: Article 6(1)(b) GDPR, performance of a contract.
  • Payment and bookkeeping. Administering subscriptions and meeting accounting obligations. Legal basis: Article 6(1)(b) and (c).
  • Operations and troubleshooting. Monitoring errors, security and performance. Legal basis: Article 6(1)(f), legitimate interest in running a stable and secure service.
  • Enquiries. Answering questions you send us. Legal basis: Article 6(1)(f), or (b) where the enquiry concerns your contract.
  • Product notices. Messages about changes to the service or the terms. Legal basis: Article 6(1)(b), information necessary for the contract.

We do not send newsletters or marketing without your consent. If you withdraw consent, we stop using the data for that purpose.

4. AI processing

The chain uses language models to generate name proposals, reasoning and concept directions. The content you write in the brief is sent to a model provider in order to generate the answer. We do not send account details with it, and we do not use your content to train models.

The quality control of the logos is deterministic code running with us, it sends nothing onward.

5. Who we share data with

We do not sell personal data. We use the following categories of processors:

  • Hosting and network. Cloudflare for this website; other infrastructure with our hosting provider. Processing takes place within the EU/EEA where the provider offers it.
  • Model provider. OpenRouter brokers calls to language models. Only the content needed for the specific generation is sent.
  • Payments. Stripe handles payments and subscription administration.
  • Logging and monitoring. Datadog is used for operational logging. Personal data is not part of normal logging, but an error message can in rare cases contain a fragment of a request.
  • Email. Our mail provider sends transactional email such as account activation and receipts.

All processors are covered by data processing agreements with appropriate technical and organisational measures. Where data is transferred outside the EU/EEA, it is on the basis of the European Commission's standard contractual clauses or an equivalent approved mechanism.

6. Retention and deletion

  • Account and content data is kept while your account is active and deleted no later than 30 days after you close it.
  • Accounting records are kept for 5 years after the end of the financial year, as required by Danish bookkeeping law.
  • Usage data is kept for up to 24 months, so you can see the history of your consumption, and deleted after that.
  • Enquiries are kept for up to 2 years after the case is closed.

When the retention period ends, the data is deleted or anonymised.

7. Your rights

You have the right to access the data we process about you, to have it corrected, and in certain cases to have it deleted or the processing restricted. You also have the right to object to processing based on legitimate interest, and to receive the data you provided in a machine-readable format.

Write to hello@identityden.com to exercise your rights. We reply within 30 days.

Complaints. If you believe our processing breaches the rules, you may complain to the Danish Data Protection Agency, Datatilsynet. We would prefer the chance to resolve the matter first.

8. Security

We use appropriate technical and organisational measures to protect the data: encryption in transit, access control and operational logging. If a breach involving a high risk to you is identified, we will notify you as soon as possible in accordance with Article 34 GDPR.

9. Changes

We update the policy when the processing changes. The date at the top shows when it was last changed. For material changes we will give you notice before they take effect.

10. Contact

Questions about this policy go to hello@identityden.com or the address above.