GDPR-aligned handling

Privacy Policy

How INSTRAT360 collects, uses, and protects personal data - with clear policies for secure, GDPR-aligned handling.

Last updated: March 2026

Privacy at a glance

Key information.

Controller

INSTRAT Technology ApS

Region

GDPR-aligned handling

Contact

ale@instrat360.com

AI policy

Customer data not used for AI training

Enterprise

DPA available where applicable

01

Who we are

INSTRAT360 is the platform brand of INSTRAT Technology ApS, a company registered in Denmark. We provide strategy operating systems and capability apps for enterprise organisations. This policy explains how we handle personal data collected through our website, platform, and related services.

02

What information we collect

We collect information you provide directly, such as name, email, and organisation when you request a demo, sign up for early access, or contact us. We also collect technical data including IP address, browser type, and usage patterns to improve our services. For platform users, we process data as defined in your service agreement.

03

How we use your information

We use your information to provide and improve our services, communicate about updates and opportunities, ensure platform security, and fulfill legal obligations. We do not sell personal data to third parties. For enterprise customers, data processing scope and purposes are governed by your specific service agreement.

04

Legal basis

We process personal data based on: (a) your consent where provided, (b) performance of a contract or service agreement, (c) our legitimate interests in operating and improving our services, and (d) compliance with legal obligations. You may withdraw consent at any time without affecting the lawfulness of prior processing.

05

Data sharing and processors

We may share data with trusted service providers who assist in operating our platform, such as hosting providers and analytics services. All processors are bound by data processing agreements and are required to handle data in accordance with GDPR. We do not share personal data with third parties for their own marketing purposes.

06

Data retention

We retain personal data only as long as necessary for the purposes for which it was collected, or as required by law. Contact and inquiry data is typically retained for up to 3 years after last interaction. Enterprise customer data retention is governed by your service agreement.

07

Security measures

We implement appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, access controls, regular security assessments, and staff training. Our platform is hosted on enterprise-grade infrastructure in AWS EU regions.

08

Your rights

Under GDPR, you have rights to access, rectify, erase, restrict processing, data portability, and object to processing of your personal data. You also have the right to lodge a complaint with a supervisory authority. To exercise any of these rights, contact ale@instrat360.com.

09

AI and customer data

Customer workspace data is not used to train external AI models. AI features within INSTRAT360 operate on your data only to provide the service as described, with human approval required for critical outputs. This commitment is fundamental to our platform design.

10

Enterprise and DPA

Enterprise customers may have a Data Processing Agreement (DPA) in place that governs the handling of customer data within the platform. Where a DPA exists, its terms take precedence over this general policy for the scope of data covered by that agreement.

11

Connected accounts

You may connect third-party accounts - Google, Microsoft, HubSpot, Slack, Meta, Atlassian - to let INSTRAT360 act on your behalf. Each connection is authorised by you through the provider's own consent screen, is stored encrypted and scoped to a single organisation, and grants only the narrowest permissions the connected capability needs. We never ask for a password: authorisation is held as an OAuth token that you can revoke at any time, either inside the platform or from the provider's own security settings. Revoking a connection immediately ends our access and deletes the stored authorisation.

12

Google user data

Where you connect a Google account, INSTRAT360 requests only these permissions, each spent by a single feature: send email as you (gmail.send), read and write events on your calendars (calendar.events), create and manage only the Drive files this app creates (drive.file), read your Google Ads reporting (adwords), and see your primary email address so the platform can show you which account is connected (openid, userinfo.email). We do not request permission to read your mailbox. Google data is retrieved live when a feature needs it, is used solely to perform the action you requested, is never sold, never used for advertising, and never used to train any AI model - ours or a third party's. Human approval is required before any external action, including sending mail or creating an event, is carried out.

13

Limited Use

INSTRAT360's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The same commitment applies to data received from every other connected provider.

Data controller

INSTRAT Technology ApS

INSTRAT360 is a protected trademark. Registered in Denmark. For privacy inquiries, contact ale@instrat360.com.

My AI CCO is a registered trademark of INSTRAT Technology ApS.

How we build for compliance

Privacy is one part of how My AI CCO is built for GDPR and the EU AI Act. See the full governance posture - approvals, audit trail, AI systems register, and your data rights - in the Trust Center.

Visit the Trust Center