SES Group

Privacy policy

How SES Group processes personal data as controller for visitors, enquiries and clients across sesspace.com, sesgrp.org, insight.sesnas.com, quality.sesnas.com and games.sesnas.com. Processing a client's own data inside the products happens as a processor under a separate agreement, described at the foot of this page.

Last updated 25 August 2026.

1. Data controller

Business SES Group
Owner Sigurður Eggert Sveinsson
CVR 46651596
Based in Odense, Denmark
Email ses@sesspace.com

Write to the address above about anything to do with your personal data. There is only one person to write to, so there is no enquiry that can fall between two departments.

2. What is processed, why, and on what basis

DataPurposeLegal basis
Name, email, any telephone number, and the content of what you writeTo answer the enquiry and give a quoteGDPR art. 6(1)(b) or 6(1)(f)
Contact and client details attached to a jobTo enter into and perform the agreement and deliver the serviceArt. 6(1)(b), performance of a contract
Invoicing and bookkeeping dataTo issue invoices and meet the bookkeeping obligationArt. 6(1)(c), legal obligation under the Danish Bookkeeping Act

No sensitive personal data about you is processed, and there is no profiling and no automated decision making. There is no newsletter, so no marketing consents are collected either.

3. Who else touches it

Data is not passed to third parties for their own purposes, and it is never sold. A small number of suppliers process data on instruction under a data processing agreement in order to keep things running:

  • Zoho, for email.
  • Dinero, for bookkeeping and invoices.
  • Cloudflare, which delivers this site and protects it from abuse. Cloudflare sees the IP address a request comes from, as an unavoidable part of delivering a web page.
  • Microsoft, where a job is built inside your own Microsoft environment. There you are the controller for that environment yourself.

Data is held in the EU or the EEA, or on a valid transfer basis. The websites and the products run on our own infrastructure in Denmark.

4. Cookies and tracking

No cookies, no tracking, no third parties
The websites set no cookies, run no analytics and embed nothing from anyone else. The typefaces are served from the site itself rather than from a font library, precisely so that reading a page does not pass your IP address on to anybody. That is also why there is no cookie banner: there is nothing to consent to. Inside the products, where users sign in, only what is technically necessary to keep a user signed in is used; no cross-service tracking happens there either.

5. How long it is kept

  • Enquiries that do not turn into a client relationship are deleted no later than six months after the last contact.
  • Client and accounting material is kept for five years from the end of the financial year it belongs to, because the Danish Bookkeeping Act requires it, and is deleted afterwards.
  • A copy of your own data made in order to build a solution is deleted or returned when the job is finished, in line with the data processing agreement.

6. Your rights

Under data protection law you have the right to:

  • obtain access to the data processed about you
  • have inaccurate data corrected
  • have data erased in the cases where the rules give that right
  • have the processing restricted
  • object to the processing
  • receive your data in a common format (data portability)
  • withdraw a consent, where processing rests on consent

Write to ses@sesspace.com to use any of them. You get an answer as quickly as possible and within one month at the latest.

7. Complaints

If you are not satisfied with how your data is handled, you can complain to the Danish Data Protection Agency, Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, dt@datatilsynet.dk. Do say so here first, so there is a chance of putting it right straight away.

8. When we process your customers' data

Where a solution is built on your data and that data contains personal information, you are the controller and SES Group is the processor. That relationship is governed by a data processing agreement under article 28 of the GDPR, which is signed before any data moves, not afterwards.

The agreement sets out what is processed, where it sits, which security measures are actually in place, which sub-processors are used, and how data is deleted or returned when the job ends. Ask for it before you decide: it is part of the quote and costs nothing to read.