Privacy Policy
Last updated: 28 July 2026
This privacy notice explains how BEST 4 PROJECT ApS (“we”, “us”) processes personal data when you visit ready4aiact.eu, take an AI Act readiness assessment, book a course, or contact us. We process personal data in accordance with Regulation (EU) 2016/679 (“GDPR”) and the Danish Data Protection Act.
1. Controller
BEST 4 PROJECT ApS, Grønningen 16, 7190 Billund, Denmark - CVR 44625148. Contact: info@ready4aiact.eu. We have not appointed a Data Protection Officer, as we are not required to under Art. 37 GDPR.
2. Categories of data we process
- Contact & identification data - name, work email, company, role, phone (when you submit a form, book a course, or contact us).
- Assessment data - answers you provide in the AI Act readiness assessment and the generated report.
- Account data - email and authentication credentials if you create an account.
- Technical & usage data - IP address, device and browser type, referrer, pages visited, timestamps. Stored in short-lived server logs and, where you consent, in analytics or marketing tools.
- Marketing data - email preferences and interactions with our newsletters or ads (only where you consented).
3. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the website and keeping it secure | Art. 6(1)(f) - legitimate interest in a functioning, secure service |
| Running the readiness assessment and generating your report | Art. 6(1)(b) - performance of a (pre-)contract at your request |
| Responding to enquiries, quotes, course bookings | Art. 6(1)(b) / Art. 6(1)(f) |
| Sending service emails (report delivery, booking confirmations) | Art. 6(1)(b) |
| Marketing emails and lead nurturing | Art. 6(1)(a) - your consent; withdrawable at any time |
| Analytics, remarketing and conversion tracking (see §7) | Art. 6(1)(a) - your consent (and §9 of the Danish ePrivacy rules for cookie storage) |
| Compliance with legal obligations (accounting, tax) | Art. 6(1)(c) |
4. AI-generated content and the EU AI Act
The readiness report and certain explanatory content are generated with the help of large language models. We disclose this in line with Art. 50 of Regulation (EU) 2024/1689 (“AI Act”). Key points:
- Your answers are processed by our AI providers (see §8) solely to produce your report. They are not used to train foundation models.
- The report is decision-support, not legal advice. A human at your organisation remains responsible for any compliance decision.
- We do not carry out automated decision-making with legal or similarly significant effects on you within the meaning of Art. 22 GDPR.
5. Recipients and processors
We share personal data only with service providers acting as processors under Art. 28 GDPR, and only to the extent necessary:
- Cloud hosting and database - EU region.
- Maileroo - transactional email delivery (report delivery, booking confirmations, notifications). Provider: Maileroo SAS, France (EU). Personal data: email address, name, report content.
- Brevo - CRM and marketing email platform for opted-in recipients and lead management. Provider: Sendinblue SAS (Brevo), France (EU). Personal data: name, email, phone, company, engagement history.
- SimplyMeet.me - meeting scheduling. Provider: SimplyBook.me OÜ, Estonia (EU). Personal data: name, email, scheduling preferences.
- Mistral AI - AI model provider used to generate reports. Provider: Mistral AI SAS, France (EU). Personal data: your assessment answers (processed transiently for generation).
- Mouseflow - behavior analytics and session replay, only after your consent. Provider: Mouseflow ApS, Denmark (EU).
- Analytics and advertising tools listed in §7 - only after your consent
- Professional advisors, auditors, or authorities where legally required
6. International transfers
We prefer EU/EEA-based providers. Where a processor transfers data outside the EEA (for example, certain AI providers), the transfer is protected by an adequacy decision of the European Commission or, failing that, by the EU Standard Contractual Clauses (2021/914) and supplementary technical measures. A copy of the safeguards can be requested at the address in §1.
7. Cookies, analytics and marketing tags
We use only strictly necessary cookies by default. Analytics, remarketing, and advertising tools are loaded only after you give explicit consent through our cookie banner and can be withdrawn at any time.
Tools that we use or may activate after consent:
- Google Tag Manager - tag container used to load other tags only when consent is granted. Provider: Google Ireland Ltd.
- Mouseflow - session replay, heatmaps and behavioral analytics to understand how visitors navigate the site. Provider: Mouseflow ApS, Denmark.
- LinkedIn Insight Tag - conversion tracking and audience building for LinkedIn ads. Provider: LinkedIn Ireland Unlimited Company.
- Meta Pixel (Facebook) - conversion tracking for Meta ads, if activated. Provider: Meta Platforms Ireland Ltd.
Details of individual cookies, their duration and how to withdraw consent are set out in our Cookie Policy.
8. Retention
- Server logs: up to 30 days.
- Assessment answers & reports: for the duration of the customer relationship and up to 24 months thereafter, unless earlier deletion is requested.
- Contact and enquiry data: up to 24 months after the last interaction.
- Accounting records: 5 years, as required by the Danish Bookkeeping Act.
- Marketing consents and proof of consent: until withdrawal, plus statutory limitation periods.
9. Your rights
Under Articles 15–22 GDPR you have the right to access, rectification, erasure, restriction, data portability, and objection. Where processing is based on consent, you may withdraw it at any time with effect for the future. Requests can be sent to info@ready4aiact.eu.
Under Article 77 GDPR you also have the right to lodge a complaint with a supervisory authority - in particular in the EU/EEA Member State of your habitual residence, place of work or place of the alleged infringement. For Denmark, our lead authority is the Datatilsynet. A list of national supervisory authorities is maintained by the European Data Protection Board.
10. Security
We apply technical and organisational measures appropriate to the risk, including TLS in transit, encryption at rest for our database, role-based access control, least-privilege access for staff, and periodic reviews of processors.
11. Changes to this policy
We may update this notice to reflect changes in our services or the law. The current version is always available at this URL, with the “Last updated” date at the top.