Privacy Policy
Last updated: 6 September 2026
On this page10 sections
This policy describes what personal data Sparro processes, what we use it for, and who we share it with — whether you're simply on the sparro.dk waitlist, or a customer using the bookkeeping platform itself.
Data controller
Ceero ApS (CVR 45 44 13 93), Njalsgade 21F, 2. sal, Copenhagen, is the data controller for personal data processed in connection with sparro.dk and the Sparro platform. You can contact us at nicklas@ceero.eu or on WhatsApp +45 31 33 25 99.
What we collect
Waitlist: your email address and the timestamp of your consent. Account: name, email, your company's CVR number and address, and a MitID-based identifier if you log in with MitID. Bookkeeping: invoices, receipts, and the documents you upload or send by email. Bank: transaction and account data from your bank via a PSD2-approved connection, when you connect your bank account yourself. Payroll: payroll-run data via Intect. Employees' CPR numbers are stored encrypted in Sparro so they can be registered with the payroll system; tax cards sit with our payroll provider. Communication: if you enable AI triage of your inbox, relevant emails are read to categorize them and suggest replies; CPR numbers in that text are automatically filtered out before it's sent to an AI model.
Purpose and legal basis
Waitlist sign-up relies on your consent (GDPR Article 6(1)(a)), given by actively checking the consent checkbox — not merely by submitting the form. As a customer, we process your data to perform the contract for the bookkeeping service (Article 6(1)(b)) and to comply with the Danish Bookkeeping Act's retention requirements (Article 6(1)(c)). Optional features such as AI categorization and the accountant marketplace rely on your active choice to use them. You can withdraw consent at any time by contacting us.
Staff and internal access
Sparro employees may, in limited circumstances, access your account and business data through our internal administration tool — for customer support, updating business details, opening/closing accounts, billing and subscription administration, and approving accountant partners on the marketplace. Access is restricted to employees who need it, and views of sensitive customer data are logged. We're building a feature that would let an employee get temporary, read-only access to view your account the way you see it, for troubleshooting a specific support case — never access to change or create anything on your behalf. This feature hasn't been taken into use yet; once it is, you'll always be able to tell: a visible notice will appear in your account while access is active, and the event will be recorded in your account's own activity log with the time and which employee had access. We're continuing to expand how detailed this logging is.
Retention
Waitlist emails are kept until the product launches or you ask us to delete them. Bookkeeping records (receipts, invoices, account statements) are kept for at least 5 years under the Danish Bookkeeping Act, counted from the end of the financial year the material relates to — we can't delete this earlier, even on request, while that period runs. Once the retention period expires, material is reviewed for deletion; automatic deletion isn't yet fully in place for all bookkeeping data, so the period may in practice run longer than 5 years until that manual review has happened. When you dismiss or reply to an email in the AI triage feature, the personal data in it is deleted 30 days later — unless the email has been booked as a receipt or invoice, in which case the sender and subject are instead kept as part of the ordinary 5-year retention. Emails you haven't yet acted on aren't covered by this 30-day deletion. Closing your account freezes it (read-only, and closing can be reversed) — it doesn't delete your data. If you want your data deleted, you need to separately request account deletion, which immediately removes non-statutory data (e.g. push notifications and sessions), while your bookkeeping itself continues to be retained until the statutory deadline has passed.
Your rights
Under the GDPR you have the right to access, rectify, and erase your data, as well as the right to restrict or object to our processing and the right to data portability. Note that the right to erasure is limited for bookkeeping material while the statutory retention period runs. Contact us at nicklas@ceero.eu to exercise your rights. You can also file a complaint with the Danish Data Protection Agency (datatilsynet.dk).
Security
All traffic to sparro.dk and the platform itself is encrypted (HTTPS). Data is stored encrypted at our database provider, and each company's data is logically separated from every other company's. Access to systems that process your data is limited to employees who need it, and certain sensitive views are logged (see "Staff and internal access" above).
Changes to this policy
We'll update this page whenever how we process personal data changes — for instance when we adopt a new processor or feature. Material changes are announced on the page or by email.