GDPR & Cookies

Privacy Policy

Information related to GDPR and the handling of personal data at Morten Deurell

In short: From 25 May 2018, all businesses are required to comply with the General Data Protection Regulation (GDPR). This document describes how I handle your data — as responsibly and with as much consideration as possible. Once you give consent, your data may be handled as described below.

Introduction

When sending an enquiry, quote, contract or invoice, and in the context of ongoing email correspondence and possible invitations to leave a Google review, Morten Deurell will handle various personal data. This document describes how that data is processed, with whom it is shared, where it is stored, and how you can request that your information be deleted.

What data is collected?

The client

  • Name(s)
  • Address(es)
  • Phone number(s)
  • Mobile phone number(s)
  • Email address(es)
  • Optionally, first names of colleagues or family members

The contact person (often identical to the client)

  • Name(s)
  • Address(es)
  • Phone number(s)
  • Mobile phone number(s)
  • Email address(es)

The venue

  • Name of the venue (e.g. restaurant)
  • Address
  • Phone number
  • Mobile phone number
  • Email address

Where is data stored?

Online client system

For security reasons, the specific system is not named here. It is hosted with a reputable and secure provider, uses an encrypted connection (SSL/https), and only Morten Deurell has access.

Email system and digital messaging services

Data may appear in emails (as text, encrypted links or attachments). Only Morten Deurell has access. Morten Deurell does not take responsibility for how the client handles their own part of the correspondence — but discretion is encouraged.

Computer and backup

There is a local hard drive backup as well as a backup with a reputable cloud service — both accessible only by Morten Deurell.

Mobile devices and messaging apps

Correspondence via SMS/MMS or services such as Messenger or WhatsApp is stored on those platforms. The client can at any time see their own messages and threads.

Accounts

All invoices are printed and stored in paper form. The accounts are under Morten Deurell's personal supervision. The following may have access to the accounts:

  • Accountant / bookkeeper / Dinero
  • SKAT (Danish Tax Authority)
  • Morten Deurell
  • Danish Artists' Association (DAF)
  • Danish Actors' Union (DSF)
  • Any future employees of the business

Review platforms

Clients are invited to review Morten Deurell on Trustpilot and Google. The invitation is sent as a link — the client decides for themselves whether they wish to use the service.

How long is data stored?

Data may be stored for as long as it could be relevant in order to provide the best possible service — typically indefinitely, assumed to be proportionate in the specific context. Should a client wish to have data deleted or corrected, Morten Deurell can be contacted and will act on this manually — unless doing so would prevent compliance with legal documentation requirements.

Sharing and disclosure of information

When preparing accounts

An accountant or bookkeeper may have access to documents, but without the right to collect personal data from them. SKAT may receive documents upon request.

When seeking advice

In connection with contracts, advice from DAF or DSF may be necessary.

When making a referral

With oral or written consent, Morten Deurell may pass a client's enquiry on to a recommended colleague — including all relevant data listed above.

Cookies

When visiting this site, necessary cookies are used for Google Analytics. The sole purpose is to optimise campaigns based on what works. Google will know you visited the site and whether you submitted a booking enquiry. You can change your consent at any time via the cookie banner.

Deletion and correction

Should you wish to have information deleted or corrected, contact Morten Deurell — he will act on this manually, unless it would be contrary to legal requirements.

Procedure in the event of a data breach

  • The security breach will be closed as quickly as possible.
  • Anyone whose data may have been compromised will be informed.

Are there particular risks?

Overall, there is no particular risk of personal data leakage, because:

  • This is a sole trader business
  • Information is shared with practically no one other than Morten Deurell and those directly involved
  • Proportionate security measures have been taken
  • The information is not of a particularly sensitive nature

The main risks are:

  • A break-in at the address where paper accounts are stored
  • Data theft (hacking) from emails or a computer

Is data protection built into the processing of personal data?

Yes.

Physical

Paper copies are stored sensibly, inaccessible to unauthorised persons.

Digital

  • Email access is secured with strong passwords
  • The website's client system uses https
  • Only Morten Deurell has access
  • All data transmission is encrypted
  • FTP access uses SFTP/SSH
  • Two-factor login is used wherever possible

Questions about your data?
Contact Morten Deurell at tryl@mortendeurell.dk or call (+45) 3050 9036.