Skip to content

1. About this policy

This privacy policy explains how Windfeld Jensen Co. processes personal data in connection with LCAB (Life Cycle Assessment Beacon) on lcab.app.

LCAB is a B2B platform for collecting, structuring, and documenting product information. The policy is written so visitors, users, and customer organisations can understand what happens with data.

Related documents:

More about the company: www.windfeldjensen.com

2. Data controller

Windfeld Jensen Co. CVR: 46591054 Address: Lyngbyvej 83A, 2100 Copenhagen, Denmark Email: info@windfeldjensen.com Phone: +45 23 97 94 91

When you visit lcab.app or create an account directly with us, Windfeld Jensen Co. is typically the controller for personal data we collect to operate the service (for example account, login, support, and billing).

When a customer organisation uses LCAB to process data about its own employees, supplier contacts, or other data subjects, the customer organisation is generally the controller for the content it uploads, and Windfeld Jensen Co. is the processor. This is described further in the DPA (/dpa).

3. GDPR

We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and Danish data protection law.

This means, among other things, that we:

• Process data only for clear purposes • Limit collection to what is necessary • Apply appropriate security measures • Inform about rights and complaint options • Enter into processor agreements where we process data on behalf of customers • Document processing activities to the relevant extent

Legal bases under GDPR Article 6 may be contract (b), legal obligation (c), legitimate interest (f), or consent (a), depending on the situation.

4. Personal data

We may process the following types of personal data:

• Identity and contact details (name, email, phone, job title) • Company and organisation details • Account and login details (including roles and access rights) • Support and inquiry content • Billing and subscription status (card details are handled by Stripe) • Technical log data (for example IP address, time, browser/device, security logs) • Content you upload to LCAB if it contains personal data (for example supplier contacts) • Haddock conversations you choose to save in your account

Please do not upload special-category personal data (GDPR Article 9) or unnecessary data about third parties in free-text fields, documents, reports, or chat.

We do not sell personal data and do not use it for spam.

5. Purposes of processing

Personal data is used to:

• Deliver and operate LCAB • Create and manage accounts, organisations, and access • Provide support and respond to inquiries • Handle subscriptions, payment, and billing • Secure the service (abuse prevention, rate limiting, audit) • Answer questions in Haddock and generate AI-assisted text when you use those features • Comply with legal requirements

If you apply as a Founding Partner, application data is used to assess and follow up on the application.

6. Haddock and AI

Haddock is LCAB's built-in consultant in the signed-in platform. It is not an external chatbot brand.

Haddock only uses the context the user already has access to in their dashboard and organisation. That can include the current page, products, materials, and documents the session is already allowed to see. Haddock does not pull data from other customers' dashboards.

To produce an answer, messages and necessary context may be sent to a cloud language model (Google Gemini) when that service is enabled. If it is unavailable, Haddock answers from LCAB's own document library. Data therefore leaves the LCAB server when the cloud model is used.

Messages are processed to answer. They are not used to train an LCAB language model, and they are not shared into other customers' dashboards.

Saved conversations stay in your LCAB account until you delete them. Temporary chat is not stored in the database. Conversations you delete, or that you leave as temporary chat when you sign out, are not kept as permanent chats with us.

The full explanation is on /haddock.

7. Cookies

LCAB sets necessary cookies for login, CSRF security, language, consent recording, and theme in the signed-in platform.

We do not set Google Analytics, and we do not set other analytics or marketing cookies today. The other banner categories are reserved if we later add a named tool. Until then, no analytics scripts run, even if the category is accepted.

You can change your choice under Cookie settings in the footer. The full cookie policy is at /cookies.

8. Processors and sub-processors

When Windfeld Jensen Co. processes personal data on behalf of a customer organisation, it acts as a processor under GDPR Article 28. The terms are set out in the DPA (/dpa).

To operate LCAB we use technical sub-processors, including:

• Render (hosting, application, and database) • Stripe (payment and subscription; independent controller for card details) • Resend (sending email, for example invites and verification) • Google Gemini (cloud language model for Haddock and other AI-assisted text when the feature is enabled)

We enter into agreements and use providers with appropriate security. See also /security.

9. Retention

We keep personal data only as long as needed for the purpose, the contract, or legal requirements.

Typical periods:

• Accounts and platform data: while the account/organisation is active, and for a reasonable period after it ends • Saved Haddock conversations: until you delete them, or the account ends • Support and application messages: while the dialogue is relevant, then a reasonable time • Security and audit logs: for a period that supports security and debugging • Invoice and accounting data: according to bookkeeping and tax rules • Cookie choice: typically up to 6 months (see /cookies)

When data is no longer needed, it is deleted or anonymised, unless longer retention is required.

10. Security

We apply appropriate technical and organisational measures, including:

• HTTPS and security headers • Access control and organisation isolation • CSRF protection and rate limiting • Audit logging of relevant events • Secure cookies in production • Optional 2FA and idle logout in the signed-in platform • Limited internal access to customer data

No system is 100 percent secure. We keep improving. See also /security and /dpa.

11. Rights

Under the GDPR you typically have the right to:

• Access • Rectification • Erasure (where the law allows it) • Restriction of processing • Objection • Data portability • Withdraw consent where processing is based on consent

If you are a user under a customer organisation, some requests may need to go through the organisation as controller.

Contact: info@windfeldjensen.com

You also have the right to complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, www.datatilsynet.dk.

12. Transfers outside the EU/EEA

If personal data is transferred to countries outside the EU/EEA, we ensure a lawful transfer basis (for example the European Commission's standard contractual clauses) when that is relevant.

Primary application hosting is aimed at the EU when practical. Google Gemini is a cloud service. When Haddock or other AI is enabled, messages may be processed by that provider to produce an answer.

13. Changes

We may update this privacy policy when law, technology, or LCAB changes. The current version is published on this page with an update date. For material changes we inform you in the platform or by email when that is reasonable.

14. Contact

Windfeld Jensen Co. Email: info@windfeldjensen.com CVR: 46591054 Address: Lyngbyvej 83A, 2100 Copenhagen, Denmark Phone: +45 23 97 94 91

We believe in transparency. Ask rather once too often than once too little.

Questions about privacy and personal data can be sent to info@windfeldjensen.com

Windfeld Jensen Co. · CVR 46591054 · 23 97 94 91
Lyngbyvej 83A, 2100 København Ø