Legal

Privacy Policy.

Version 1.7 · Last updated 1 October 2026

Staygood ApS, CVR no. 46639081, Rytterkær 2, DK-4000 Roskilde, Denmark (“Staygood”, “we”) provides a receivables platform to businesses. This policy covers personal data handled through the platform and on our website, staygood.ai.

Our role depends on the context:

ContextStaygood’s roleController
A creditor uses Staygood to contact you about an invoiceProcessorThe creditor named in the communication
You use the platform for your employer or businessController for account, security, support and billing dataStaygood
You visit our website, staygood.aiControllerStaygood

Questions about this policy can be sent to privacy@staygood.ai.

1. If you are contacted about an invoice

The creditor uses Staygood to manage its own receivables. It determines the purpose of the processing and the collection activity; Staygood processes personal data on its documented instructions under a Data Processing Agreement.

Sources and data. The creditor supplies data from its invoicing, accounting and customer records. We also process information generated through the service, such as replies, payment status, use of the payment portal and call outcomes. This can include:

The platform does not store Danish CPR numbers or payment card details. Card details are entered directly with Stripe. Calls handled by the AI voice assistant are recorded by our voice provider. The recording and transcript are kept for up to 90 days so that the creditor and Staygood can review the call, handle complaints and verify what was said, and are then deleted automatically. Staygood keeps its own copy of the transcript and of the instructions given to the assistant for the same 90 days, within the EU, and does not store the audio. Structured call outcomes remain in the platform. Limited backup or security-log retention may still apply under the provider’s terms.

AI-assisted processing. AI may assist with document extraction, drafting and classifying communications, prioritising work and voice interactions. Staygood does not use creditor or debtor data to train general-purpose AI models. The creditor controls the collection process and is responsible for decisions that have legal or similarly significant effects.

Your rights. The creditor is responsible for explaining its legal basis and handling requests for access, correction, deletion, restriction or objection. Its identity appears in the communication. If you contact Staygood, we will forward the request and assist the creditor. Rights are subject to the conditions and exceptions in the GDPR, including where information is needed to establish or defend a legal claim.

You may complain to the Danish Data Protection Agency, Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark, or to the supervisory authority where you live.

2. Platform users and business contacts

If you use the platform or deal with us on behalf of a customer, we may process your name, work contact details, role, language and notification preferences; sign-in identity; session information such as IP address and browser; support correspondence; and an audit log of actions taken in the platform. We receive this information from you, your employer or business, an identity provider you choose, and public company registers. When an account is created for a company, we may look up publicly registered information about the company and its management in the CVR register and public sources — with AI assistance — to prefill and personalise onboarding; you can ask us to delete this profile at any time.

We process it for the following purposes and legal bases:

Our legitimate interests are operating a secure service, performing and managing customer relationships, and improving the service without overriding the rights of the people concerned.

3. Who receives personal data

For the platform, we use service providers for hosting, storage, communications, digital post and AI processing. The current providers, processing locations and transfer safeguards are listed at staygood.ai/legal/subprocessors.

If a platform user chooses Google or Microsoft sign-in, that identity provider receives the authentication request under its own terms. Stripe is an independent controller for payment transaction data. Accounting systems and other integrations selected by a customer process data under that customer’s relationship with them.

We may also disclose limited data to professional advisers and public authorities where necessary or legally required. We do not sell personal data.

4. International transfers

Some providers process data outside the EEA, including in the United States. The sub-processor list states the current locations. Where Chapter V GDPR applies, transfers rely on an adequacy decision, the EU-U.S. Data Privacy Framework where the recipient is certified, and/or the European Commission’s Standard Contractual Clauses with supplementary measures where required.

5. Retention

Personal data processed for a creditor is returned or deleted under the Data Processing Agreement and the creditor’s instructions. Voice-call recordings and transcripts held by our voice provider, and the transcript copy held by Staygood, are deleted automatically 90 days after the call; structured call outcomes remain in the platform under the creditor’s instructions. Account and business-contact data is kept for the customer relationship and then only as needed for support, security, bookkeeping, limitation periods or other legal requirements. Technical and session records use shorter operational retention periods. Data is deleted or de-identified when the applicable purpose and retention requirement end; residual backup copies expire through the relevant backup cycle.

6. Security

Measures include tenant isolation, role-based access, restricted and logged administrative access, encryption in transit and at the infrastructure layer, one-way protection of credentials and tokens, encryption of integration credentials, environment separation, and monitored deployment and operating procedures. More detail is available in Annex C of the Data Processing Agreement.

7. Platform cookies and analytics

The platform uses a strictly necessary session cookie to keep users signed in and protect account security. It lasts for the session or a limited authentication period. The platform does not set analytics, preference or marketing cookies, and does not use third-party advertising or behavioural-tracking technologies.

Usage statistics (creditor dashboard). We use Pirsch Analytics (Emvi Software GmbH, Germany; hosted on servers in Germany) for aggregated, cookie-free statistics about how the creditor dashboard at app.staygood.ai is used — pages viewed, referrers, country and device type. Pirsch stores nothing on your device and can recognise a returning visitor only within a single day, by computing a salted, irreversible hash from the network address, browser signature and date; the IP address itself is never stored, query parameters are stripped before anything is sent, and the resulting statistics contain no personal data. It runs only on the creditor dashboard: the payment portal used by debtors carries no analytics. Legal basis: our legitimate interest in understanding how the platform is used (Article 6(1)(f)).

Cookies and similar technologies on the marketing website are covered in Section 8.

8. The staygood.ai website

This section covers visits to the marketing website, staygood.ai. Staygood is the controller for the processing it describes; it does not apply to the platform.

Enquiries. If you book a demo, email us or ask us to set up an account, we receive what you choose to share — typically your name, work email, company and message — and use it to respond and follow up. Legal basis: steps taken at your request and our legitimate interest in responding (Article 6(1)(b) and (f)).

Company-level visitor identification. We use Leadinfo (Leadinfo B.V., Netherlands), Snitcher (Snitcher, Netherlands; hosted in the EU) and Leadfeeder (Dealfront Group GmbH, Germany; hosted in the EU) to recognise the company behind a visit. These services look up visitors’ network (IP) addresses against business registries and firmographic sources and return company-level information such as company name and industry. They do not identify you as an individual, and we do not use them to build profiles of named people. An IP address can be personal data, which is why we disclose this here. Legal basis: our legitimate interest in understanding which businesses are interested in Staygood (Article 6(1)(f)). You can object at any time (Section 9).

Web analytics. We use Pirsch Analytics (Emvi Software GmbH, Germany; hosted on servers in Germany) for aggregated statistics about how the website is used: pages viewed, referrers, country and device type. It also counts what happens on a page: which sections come into view, which sample calls play and whether to the end, which agent descriptions are opened and which demo-booking or contact link is clicked. A sample call can start by itself as it scrolls into view; we record whether it did. Pirsch is cookie-free and built privacy-by-design: it stores nothing on your device, and it recognises a returning visitor only within a single day, by computing a salted, irreversible hash from the network address, browser signature and date. Your IP address is never stored, the statistics contain no personal data, and you are not tracked across other websites. Legal basis: our legitimate interest in understanding how our website is used (Article 6(1)(f)).

Technical operation. Our hosting provider records standard server logs (IP address, timestamp, page, browser information) to keep the site secure and available, and the site stores your language choice in a functional cookie. Legal basis: our legitimate interest in operating a safe service (Article 6(1)(f)).

Website service providers. Website data is handled by Leadinfo, Snitcher and Leadfeeder (above), Pirsch Analytics (web analytics, above), Railway (hosting), Attio (our CRM, where demo and account enquiries are recorded) and Google Workspace (email and scheduling), under data-processing agreements. Where a provider processes data outside the EEA, the safeguards in Section 4 apply.

Retention. We keep enquiry data for as long as we are in contact and as required by law. Visitor-identification and log data are kept for a limited period and then deleted or aggregated.

9. Your rights where Staygood is controller

Depending on the circumstances, you may have rights of access, correction, deletion, restriction, portability and objection — including the right to object to the visitor identification described in Section 8. To exercise them, write to privacy@staygood.ai. We normally respond within one month; the GDPR allows an extension for complex or numerous requests, in which case we will tell you.

You may also complain to Datatilsynet at the address in Section 1 or to your local supervisory authority.

10. Changes

We will post updates here. For a material change affecting platform users, we will also give appropriate notice by email or in the Service. The version and date above show the current text.


Staygood ApS · CVR 46639081 · Rytterkær 2, DK-4000 Roskilde, Denmark · privacy@staygood.ai