This policy explains how Onlime ApS processes personal data when you use our public website, buy or use the cloud-storage service, contact support or receive messages from us.
1. Controller and contact
Onlime ApS is the data controller for the account, subscription, billing, support, communication and public-site processing described here. Our address is Spinderigade 11, 7100 Vejle, Denmark, and our CVR number is DK40831193. Questions and requests about personal data can be sent to kundeservice@onlime.dk or privacy@onlime.dk.
The cloud-storage service lets you store, back up, synchronise and share files. For consumers, Onlime is also the controller for personal data in stored content. Where a business customer uses the service to process personal data, that customer is the controller and Onlime acts as processor under the applicable data-processing agreement. The underlying storage provider processes stored files on Onlime’s behalf.
2. Data we process
Depending on how you use Onlime, we may process:
- account and contact details, such as name, e-mail address, telephone number and postal address;
- subscription, order, invoice and payment-status information;
- support messages and the information you choose to provide in them;
- security and technical data needed to operate, protect and troubleshoot the service;
- consent records and communication preferences;
- country and evidence metadata needed to calculate and document VAT; and
- files and other content that you choose to store in the service.
Payment instrument details are handled by Frisbii. Onlime does not store your card details.
3. Why we process data
We process personal data to create and administer accounts, deliver and secure the service, take payment, issue invoices, provide support, fulfil legal and accounting duties, document consumer requests, and improve the reliability of the service. Where processing is necessary to enter into or perform your contract, it does not depend on marketing consent.
We process marketing only on the consent basis described below. We do not treat account creation, a purchase or existing-customer status as marketing consent.
4. Service messages and onboarding
Welcome messages, receipts, payment reminders, renewal reminders, password messages and cancellation confirmations are contract-necessary service messages. They are sent when relevant to delivering or administering your subscription and do not depend on a newsletter or marketing preference.
The six product-guidance onboarding messages cover installing a client, making the first backup, verifying the backup, restoring, sharing and using the service securely. They are contract-based product guidance and do not require marketing opt-in.
Service messages contain no offers, upselling, referral promotion or campaign content. A campaign series is marketing and is sent only after prior marketing consent. If a message mixes service information with marketing, we do not classify it as contract-necessary.
5. Newsletter and marketing consent
Onlime uses one broad consent for newsletters and marketing. There is no separate onboarding preference, and we do not use the soft-opt-in exception in version 1. You can use the service without giving marketing consent.
For each marketing consent, we record the purpose, channel, wording version, timestamp and locale. Intercom is the runtime source of truth for whether marketing may be sent. The preference centre is the customer-facing control that writes the change to Intercom; it is not a second source of truth.
You may withdraw marketing consent at any time. We suppress marketing immediately after withdrawal. Withdrawal does not stop contract-necessary service messages, and consent to marketing is separate from consent to load the support chat or store campaign attribution in your browser.
6. Service providers and international transfers
We use service providers where they are needed to operate Onlime. They include storage infrastructure, Frisbii for checkout and payment, FusionAuth Cloud for identity, Google Workspace for e-mail, and Intercom for support chat and customer communications.
Intercom Inc. is based in the United States, and Onlime’s Intercom workspace is hosted there. If you consent to load the support chat, what you write is processed by Intercom for Onlime. Onlime has a data-processing agreement with Intercom. Intercom states that its transfers use the EU-US Data Privacy Framework, with EU standard contractual clauses as a fallback. Your files are not moved to Intercom by using the chat.
FusionAuth Cloud provides identity from a service hosted in the United States, and Google Workspace handles e-mail. These systems may process account, authentication or communication data outside the EEA. They are separate from the file-storage chain.
We may also disclose personal data where a public authority or court lawfully requires us to do so.
7. Where your files are stored
Your files are stored in Norway or in a country with equal or stricter data-protection law. File storage is subject to Norwegian law and EEA data-protection rules. The file-storage chain is separate from support chat through Intercom, identity through FusionAuth Cloud and e-mail through Google Workspace, which may process other personal data outside the EEA.
8. VAT location evidence
For a completed transaction, the OSS record held through Frisbii covers the service and transaction identifiers, supply, payment and invoice dates, country evidence and decision metadata, taxable amount, VAT rate and VAT amount, currency, refunds or corrections, and the export and reconciliation trail. For any IP-derived location evidence, Onlime retains only the country, data source and version, lookup time and integrity proof, not the raw IP address. This does not mean that an IP address is never processed transiently when a network request is made.
The VAT evidence for a completed transaction is retained through Frisbii for ten years from the end of the calendar year in which the transaction took place. This is separate from ordinary bookkeeping records and remains subject to verification of the Frisbii setup.
Evidence from a checkout attempt that does not become a transaction does not inherit the ten-year period. It is kept for a fixed short period and then deleted automatically. The exact duration and access rule must be approved before this clause is released; no duration is implied here.
9. Retention and deletion
We keep personal data only for as long as needed for the purpose for which it was collected, or for a longer period where the law requires it. Certain bookkeeping records are kept for five years. VAT evidence for completed transactions follows the separate ten-year rule above.
After an ordinary subscription ends, files are deleted 30 days after the paid period expires, and other account data is deleted no later than 90 days after expiry, except for records that must be kept longer by law. The 30-day period after expiry is a deletion buffer, not an additional access period.
Marketing consent evidence is retained as needed to document the consent and its withdrawal. Marketing delivery stops immediately when you withdraw consent.
10. Your rights
Subject to the conditions in data-protection law, you may ask us for access to your personal data, correction of inaccurate data, deletion, restriction, data portability or information about the processing. You may also object where the law gives you that right and withdraw a consent without affecting processing that was lawful before withdrawal.
You may complain to the Danish Data Protection Agency or another competent supervisory authority. Contacting us first is welcome but is not a condition for making a complaint.
Cookie and browser-storage policy
No cookies before you say yes
This public Onlime site sets no cookies before you say yes. The support chat is click-to-load: the Intercom script is fetched, and its cookies are set, only after you accept the chat on the permission card. If you decline, no refusal preference is stored, and you can contact us by e-mail instead.
The site does use necessary or function-triggered first-party Web Storage. Web Storage is data on your device, but it is not sent with every request in the way a cookie is. We therefore do not claim that nothing is stored in your browser.
Support chat consent
Consent to load the support chat is separate from marketing consent. You can withdraw chat consent through the same permission control. Withdrawal removes Onlime’s chat-consent flag, shuts down Intercom without a reload and expires the Intercom cookies that our site can reach. The chat is not fetched again unless you consent again.
After you consent, Intercom uses the following browser data on this public site:
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| intercom-id-<app-id> | Cookie | Recognises the browser so an ongoing conversation can be shown again. | Set by Intercom; approximately 9 months. |
| intercom-session-<app-id> | Cookie | Keeps the chat session open. | Set by Intercom; approximately 1 week. |
| intercom-device-id-<app-id> | Cookie | Links the conversation to the device used for the chat. | Set by Intercom; approximately 9 months. |
| intercom.intercom-state-<app-id> | Local Storage | Remembers the state of the chat window. | Until consent is withdrawn or browser data is cleared. |
Campaign measurement consent
Campaign measurement is shown only when a landing URL contains a supported, non-empty advertising parameter. The eight parameters that can show the choice are gclid, gbraid, wbraid, paid, pacid, addrevenueClickId, addrevenueClickRef and addrevenueChannelId. A referral code on its own does not show the choice. If you consent, the consent flag is stored in Local Storage and supported campaign values are stored in Session Storage for the current tab. They may then be sent with an order for attribution.
If you decline, campaign values are neither stored nor sent for measurement, and the refusal is not stored as a preference. The supported parameters are removed from the reported analytics URL. A referral code may still be held separately for the checkout discount because it is part of the purchase function, not campaign-measurement consent.
First-party Web Storage
| Key | Type | Purpose | Lifetime |
|---|---|---|---|
| onlime.chat.consent | Local Storage | Remembers that you accepted the support chat. A refusal stores nothing. | Until you withdraw consent or clear browser data. |
| onlime.attr.consent | Local Storage | Remembers that you accepted campaign measurement. A refusal stores nothing. | Until you withdraw consent or clear browser data. |
| onlime.attr.<parameter> | Session Storage | Stores the eight advertising values and ref only after consent. | Until you close the tab or withdraw consent. |
| onlime.checkout.ref | Session Storage | Holds a referral code so a checkout discount can be applied; a referral code alone does not trigger campaign consent. | Until you close the tab. |
| onlime.checkout.intro | Session Storage | Holds details for an order in progress and a key that prevents duplicate creation. | Until you close the tab. |
| onlime.checkout.plan | Session Storage | Holds the selected plan for an order in progress. | Until you close the tab. |
| hf-theme | Local Storage | Remembers the light, dark or automatic theme choice. | Until you delete it; choosing automatic removes the key. |
| hf-cta-min | Session Storage | Remembers whether you minimised the bottom action bar. | Until you close the tab. |
| frigoer-demo-played-v1 | Local Storage | Remembers that the archiving demo has played. | Until you delete it. |
| deling-demo-played-v1 | Local Storage | Remembers that the sharing demo has played. | Until you delete it. |
| onlime.vk.pending | Local Storage | Marks that the receipt page is waiting for payment confirmation. | Deleted automatically after 6 hours. |
| onlime.vk.settled | Local Storage | Keeps receipt details available across a reload. | Deleted automatically after 48 hours. |
| onlime.vk.pv.<value> | Local Storage | Prevents the same purchase from being recorded twice. | Until you delete it. |
| onlime.vk.ab.<sha256> | Local Storage | Prevents the same analytics beacon from being sent twice. | Until you delete it. |
| onlime.obs.<error-signature> | Session Storage | Prevents the same technical error from being reported repeatedly in one tab. | Until you close the tab. |
Details entered during an order may be held temporarily in your browser so a reload does not lose the order. A technical error report may include the error message, file name, line number, current page and referrer. The browser also sends an IP address with the request. We do not use these reports to recognise you across websites.
Onlime does not use cookies or Web Storage to read, analyse or resell the contents of files stored in the service.
Analytics without cookies
This public site uses Plausible Analytics to measure traffic without cookies. It reports a URL stripped of the supported campaign parameters, uses no identifier across websites and hosts the analytics data in the EU.
Necessary login cookies
The signed-in service at cloud.onlime.dk and login.onlime.dk uses strictly necessary first-party session and login cookies, including AUTH_SESSION_ID, KC_RESTART and fusionauth.*. They are required to keep you securely signed in and are outside the public-site click-to-load chat rule.
Changes to this policy
We update this policy when our processing or the applicable requirements change. The current version and revision date are shown on this page.