Privacy Policy
Last updated: 27 May 2026
This Privacy Policy explains how Regaco A/S ("Regaco", "we", "us" or "our") collects, uses, stores and protects personal data when you contact us, visit our website, request a quotation, place an order or otherwise interact with us. The policy is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Danish Data Protection Act.
1. Data controller
Regaco A/S is the data controller for the processing of your personal data:
Regaco A/S
Marielundvej 46E, 2730 Herlev, Denmark
CVR no. 27733166
Phone: +45 33 22 45 02
Email: info@regaco.eu
2. Categories of personal data we process
Depending on how you interact with us, we may process the following categories of personal data:
- Identification and contact data — name, employer, job title, business address, business email, business phone number.
- Communication data — emails, messages, meeting notes, offers, order history and any other correspondence between you and Regaco.
- Commercial data — quotations, orders, invoices, payment information, delivery information.
- Website and technical data — IP address, browser type, device type, operating system, language, pages visited, referring URL, timestamps and cookie identifiers (see the Cookie Policy).
- Visitor and access data — for visitors at our premises, we may register name, company and visit time for safety and access control.
3. Purposes and legal basis for the processing
We process your personal data for the following purposes and on the following legal bases under GDPR Article 6:
- To respond to enquiries and provide quotations — based on our legitimate interest in handling business enquiries (Article 6(1)(f)) or to take steps prior to entering into a contract at your request (Article 6(1)(b)).
- To enter into and perform contracts (orders, deliveries, services, warranty handling) — based on Article 6(1)(b) or our legitimate interest where the contract is with the company you represent (Article 6(1)(f)).
- To comply with legal obligations — including bookkeeping (Danish Bookkeeping Act), tax, product safety, export control and sanctions — based on Article 6(1)(c).
- To maintain customer relationships and provide service — including technical follow-up, training and after-sales support — based on Article 6(1)(f).
- To operate and improve our website — based on our legitimate interest in delivering a functional website (Article 6(1)(f)) and, for non-essential cookies, your consent (Article 6(1)(a)).
- To send relevant marketing communication (e.g. newsletters) — based on your consent (Article 6(1)(a)) or our legitimate interest in marketing to existing business customers within the conditions of the Danish Marketing Practices Act.
- To establish, exercise or defend legal claims — based on our legitimate interest (Article 6(1)(f)).
4. Recipients and disclosure of personal data
We share personal data only with parties that have a legitimate need to process it on our behalf or as independent recipients:
- Group companies and partners involved in delivering the requested products, services or projects.
- Data processors who process data on our behalf, including IT, hosting, e-commerce, email, CRM, analytics, accounting and customer service providers. Such processors are bound by data processing agreements pursuant to GDPR Article 28.
- Logistics and shipping partners when needed to deliver goods to the agreed address.
- Professional advisors (lawyers, auditors, insurers) where necessary.
- Public authorities where required by law (e.g. tax authorities, customs).
5. International transfers
Some of our suppliers are established outside the EU/EEA, e.g. in the United States. Where personal data is transferred to a country outside the EU/EEA, we ensure an adequate level of protection by relying on one of the transfer mechanisms permitted by Chapter V of the GDPR — typically the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. You may request a copy of the relevant safeguard by contacting us.
6. Retention periods
We store personal data only for as long as it is necessary for the purpose for which it was collected, or for as long as required by law:
- Enquiries and quotations that do not lead to a contract: typically up to 2 years after last contact.
- Customer master data and contract documentation: for the duration of the customer relationship and up to 5 years thereafter, to handle warranty, liability and legal claims.
- Accounting and bookkeeping material: 5 years from the end of the relevant financial year, as required by the Danish Bookkeeping Act.
- Marketing consents: until the consent is withdrawn, and subsequently for documentation of the withdrawal.
- Website logs and cookies: see the Cookie Policy.
7. Your rights as a data subject
You have the following rights regarding our processing of your personal data, subject to the conditions and exceptions of applicable law:
- Right of access — to obtain confirmation of whether we process your personal data and a copy of that data.
- Right to rectification — to have inaccurate or incomplete data corrected.
- Right to erasure ("right to be forgotten") — in certain situations, e.g. if the data is no longer necessary for the purpose.
- Right to restriction — in certain situations, e.g. while the accuracy of the data is being verified.
- Right to data portability — to receive data you have provided to us in a structured, commonly used, machine-readable format and to transmit it to another controller.
- Right to object — to processing based on our legitimate interest and to direct marketing at any time.
- Right to withdraw consent — where the processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights, contact us at info@regaco.eu. We will respond without undue delay and at the latest within one month, unless the request is particularly complex.
8. Right to complain
You have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) if you believe that our processing of your personal data does not comply with the GDPR or the Danish Data Protection Act. Contact details: www.datatilsynet.dk.
9. Security
We have implemented appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, including access controls, encryption in transit, secure backups, processor agreements and employee training. In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, we will notify the Danish Data Protection Agency and, where required, affected individuals.
10. Cookies
Our website uses cookies and similar technologies. Detailed information about which cookies we use, their purpose and how you can manage them is available in our Cookie Policy.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our processing activities or changes in applicable law. The current version is always available on this page, and the date of the latest update is indicated at the top.
12. Contact
If you have questions about this Privacy Policy or our processing of your personal data, please contact us at info@regaco.eu or by post at the address above.

