Last updated: 2026-09-14
Privacy policy
This policy explains how LynBro ApS processes personal data in connection with the BKG.dk booking service. The Danish version is the authoritative one.
1. Who is the data controller
LynBro ApS, CVR 46321499, Denmark. Contact: hello@lynbro.dk.
2. Our two roles
BKG.dk is used by businesses — salons, clinics and other service providers — that take bookings from their own customers. That creates two distinct roles:
- Controller for data about the businesses that subscribe to BKG.dk and the people who create and administer an account with us.
- Processor for the data a business enters about its own customers and bookings. There the business is the controller, and we process the data only on its instructions, under a data processing agreement.
If you are a customer of a salon and want access to or deletion of your data, contact the salon. We assist the salon in meeting the request.
3. What we process
- Account data: name, email, phone number, company name, CVR number, address, chosen plan.
- Booking data: name, email, phone number and any notes about the person booking, plus time, service and staff member.
- Payment data: amount, status and Stripe references. We never receive or store full card numbers — card data is handled by Stripe.
- Technical data: IP address, browser and device type, pages and actions requested, time and outcome, and sign-in events.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the service, accounts, bookings, reminders | Contract, Art. 6(1)(b) |
| Payments and invoicing | Contract, Art. 6(1)(b) |
| Bookkeeping and accounting | Legal obligation, Art. 6(1)(c), Danish Bookkeeping Act |
| Security, abuse prevention, operations and debugging | Legitimate interest, Art. 6(1)(f), cf. Art. 32 |
| Aggregate statistics and product improvement | Legitimate interest, Art. 6(1)(f) |
Security and service quality
To protect the service and its users from abuse we process technical data about each request: IP address, browser and device type, pages and actions requested, time and outcome, and sign-in events. The legal basis is our legitimate interest (Art. 6(1)(f)) in network and information security, preventing abuse and keeping the service running, together with the duty to ensure appropriate security of processing (Art. 32). This data is not sold, not passed on for advertising and not published. Analytics and marketing are switched on only with your consent, which you can withdraw at any time.
5. How long we keep it
| Category | Retention |
|---|---|
| Account and subscription data | While the account is active, then 90 days |
| Accounting and invoice records | 5 years after the end of the financial year |
| Booking and customer data inside a salon's account | Per the salon's own instruction; deleted with the account |
| Request and security logs containing IP | 90 days, then aggregated without IP for up to 13 months |
| Sign-in and authentication events | 12 months |
| Audit log of administrative actions | 1–3 years |
| Raw request payloads | Not stored |
6. Who we share with (sub-processors)
| Provider | Purpose | Location |
|---|---|---|
| Contabo GmbH | Server hosting and operations | EU (Germany/France) |
| Stripe Payments Europe, Ltd. | Card payments, if the salon enables them | EU (Ireland), group in the US |
| Twilio Ireland Limited | SMS reminders, if enabled | EU (Ireland), group in the US |
| Google Ireland Limited | Calendar sync, only if the user connects a calendar | EU (Ireland), group in the US |
Email is sent from our own mail server in the EU. We do not sell personal data and do not use it for third-party profiling.
7. Transfers outside the EU/EEA
Data is stored in the EU. Some providers have group companies in the US where support or security functions may access data. Such transfers rely on the European Commission's Standard Contractual Clauses and the provider's own supplementary measures.
8. Security
Passwords are stored hashed, never in clear text. All traffic uses HTTPS. Access to production data is limited to those who need it, and administrative actions are written to an audit log. Each business's data is logically isolated from every other. Two-factor authentication is available for accounts with access to sensitive functions.
9. Your rights
You have the right of access, rectification, erasure, restriction, data portability, and to object to processing based on legitimate interest. Write to hello@lynbro.dk; we respond within one month.
You may complain to the Danish Data Protection Agency, Carl Jacobsens Vej 35, 2500 Valby, datatilsynet.dk.
10. Changes
If this policy changes materially we give notice in the service or by email before the change takes effect. The date at the top shows the current version.