Privacy Policy

Your Rights

Request access, correction, or deletion of your data

Submit GDPR Request

Cookie Settings

Manage your cookie and privacy preferences

Contact Us

Have questions about data processing?

Contact Us

Introduction

At TheMemorialStone, we protect your privacy. This privacy policy describes how we collect, use, share, and protect your personal information when you visit our website or use our services.

Data Controller and Contact Information

TheMemorialStone ApS is the data controller for the processing of your personal data in accordance with the GDPR (General Data Protection Regulation).

Contact Information:

TheMemorialStone ApS
CVR number: 46042387
Address: Skovmose Side Alle 2 3500 Værløse
Contact: Contact us here

Data Protection Officer (DPO)

We have appointed a Data Protection Officer (DPO) whom you can contact with questions about data processing:
Contact: Contact us via our contact page

What information do we collect?

  • Contact information (name, email, phone number, address)
  • Account information (username, password)
  • Payment information (processed securely through our payment provider)
  • Information about the deceased (name, date of birth, date of death, biography, images)
  • User behavior on our website (via cookies and similar technologies)

Purpose of processing

  • To create and manage your account with us
  • To provide our services, including the creation and maintenance of memorial pages
  • To process payments
  • To communicate with you about our services
  • To improve our website and services
  • To comply with legal obligations

Legal basis for processing

  • Your consent
  • Fulfillment of a contract with you
  • Compliance with legal obligations
  • Our legitimate interest in operating and developing our business

Storage and retention of personal data

We store your personal data according to specific retention periods based on the purpose of the processing:

Retention periods:

  • Account information: Active account + 5 years after account closure
  • Memorial data: As long as the memorial is active, or until deletion is requested
  • Payment data: 5 years (Bookkeeping Act)
  • Cookie consent: 13 months (requires renewal)
  • Marketing data: Until consent is withdrawn
  • Support inquiries: 3 years
  • Deleted profiles: 5 months recovery period, then permanent deletion

Upon a request for erasure (Right to be Forgotten), we will delete your data within 30 days, unless legislation requires longer storage.

Cookies and tracking technologies

We use cookies and similar technologies to improve your experience. We have implemented granular consent management in accordance with the Cookie Act and GDPR:

Cookie categories:

  • Necessary cookies: Ensures basic functionality (always active)
  • Analytics cookies: Helps us understand website usage (requires consent)
  • Marketing cookies: For targeted advertising (requires consent)
  • Performance cookies: Improves website speed (requires consent)
  • Social media cookies: Integrations with social media (requires consent)

You can always change your cookie preferences by clicking on 'Cookie settings' above. Consent to cookies is automatically renewed every 13 months as required by Danish law.

Disclosure and international transfers

We share your personal data with the following categories of recipients:

Third parties and their location:

  • Stripe (USA): Payment processing - adequacy decision and standard contractual clauses
  • SendGrid (USA): Email delivery - adequacy decision and standard contractual clauses
  • Google Cloud (EU): Hosting and storage - EU-based
  • Replit (USA): Platform hosting - adequacy decision and standard contractual clauses
  • Suno AI (USA): AI-generated music - standard contractual clauses
  • Spotify (EU/USA): Music integration - adequacy decision for USA transfers

For transfers to third countries without an adequacy decision, we use the EU's standard contractual clauses and supplementary measures to ensure an adequate level of protection.

Your GDPR rights and how to exercise them

Under the GDPR (General Data Protection Regulation), you have extensive rights over your personal data. Here is a detailed guide to your rights and how to exercise them:

Your rights under GDPR:

Article 15 - Right of access: You can request a copy of all personal data we hold about you, including purposes, categories, recipients, and storage periods.
Article 16 - Right to rectification: You can have inaccurate or incomplete information corrected or updated.
Article 17 - Right to erasure ('Right to be Forgotten'): You can request the deletion of your information under certain circumstances, for example, if the purpose is no longer relevant.
Article 18 - Right to restriction of processing: You can restrict the processing of your information under specific circumstances.
Article 20 - Right to data portability: You can obtain your information in a structured, machine-readable format for transfer to another service.
Article 21 - Right to object: You can object to processing based on legitimate interest or direct marketing.
Article 22 - Right against automated individual decision-making: You have the right not to be subject to automated decisions with legal or significant consequences.

How to exercise your rights:

  1. Online self-service: Use our GDPR data request page for quick processing of your requests.
  2. Contact: Contact us via our contact page with a detailed description of your request.
  3. Processing time: We process all requests within 30 days as required by GDPR.
  4. Identity verification: For your security, we verify your identity via email before processing.

Special notes for Danish users:

  • The minimum age for consent is 13 years in Denmark
  • We comply with Danish data protection law as a supplement to GDPR
  • You can complain to the Danish Data Protection Agency in Danish
  • All requests are processed in Danish or English at your request

Complaint

If you wish to complain about our processing of your personal data, you can contact the Danish Data Protection Agency:

Datatilsynet
Carl Jacobsens Vej 35
2500 Valby

dt@datatilsynet.dk
+45 33 19 32 00

Changes to this privacy policy

We may update this privacy policy from time to time. We encourage you to review this page regularly to stay informed of any changes.

Automated processing and profiling

We use limited automated processing for the following purposes:

  • Spam detection: Automatic filtering of spam in guestbooks and comments
  • Payment verification: Automatic processing of payments through Stripe
  • AI music generation: Automatic creation of memorial songs based on input

We do NOT carry out profiling that has legal consequences or significantly affects you. You always have the right to human intervention in automated decisions.

Security and data protection

We implement comprehensive technical and organizational measures to protect your data:

  • End-to-end encryption of sensitive data
  • Regular security updates and penetration tests
  • Limited access rights (principle of least privilege)
  • Incident response procedures for data breaches
  • Regular backup and disaster recovery

Important note on GDPR 2025:

This privacy policy has been updated to comply with the strengthened GDPR enforcement requirements for 2025, with a special focus on the Right to be Forgotten, consent management, and Danish data protection law.

Last updated: September 24, 2025
Version: 2.0 - GDPR 2025 Compliance
Effective from: September 24, 2025