007 / Regulatory Framework

Legal Compliance

All regulatory documentation for GraniteOrbitForge, operating from Jægergårdsgade 44, 8000 Aarhus C, Denmark.

P

Privacy Policy

Effective Date: January 1, 2026

1. Data Controller Identity

GraniteOrbitForge ("Controller"), registered at Jægergårdsgade 44, 8000 Aarhus C, Denmark, is the data controller responsible for the processing of personal data as described in this Privacy Policy. For all data protection inquiries, contact: [email protected].

2. Categories of Personal Data Processed

We process the following categories of personal data in the course of delivering our digital engineering services:

  • Identity Data: Full name, job title, organizational affiliation provided through contact forms or project onboarding.
  • Contact Data: Email address, telephone number, physical address submitted for service delivery and invoicing purposes.
  • Technical Data: IP address, browser type and version, operating system, device identifiers, and access timestamps collected through standard web server logging.
  • Project Data: Technical specifications, system architectures, code repositories, and business documentation shared during service engagements under contractual NDA provisions.
  • Financial Data: Invoicing details and payment references processed exclusively through our Stripe payment infrastructure. We do not store card numbers, CVV codes, or banking credentials on our servers.

3. Legal Basis for Processing

All personal data processing operations are conducted under one or more of the following legal bases as defined in Article 6 of the EU General Data Protection Regulation (GDPR):

  • Contractual Necessity (Art. 6(1)(b)): Processing required for the performance of a contract to which the data subject is party, or for pre-contractual measures taken at the data subject's request.
  • Legitimate Interest (Art. 6(1)(f)): Processing necessary for the purposes of our legitimate interests in maintaining service quality, ensuring system security, and improving our engineering deliverables, except where overridden by the data subject's fundamental rights.
  • Consent (Art. 6(1)(a)): Where explicit consent is obtained for specific processing activities such as marketing communications or analytics cookie deployment.
  • Legal Obligation (Art. 6(1)(c)): Processing required to comply with applicable legal obligations under Danish and EU law, including tax record retention and anti-money laundering requirements.

4. Data Retention Periods

Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected:

  • Contact form submissions: 24 months from last interaction, or until consent is withdrawn.
  • Project documentation: Duration of the engagement plus 60 months, as required for warranty obligations and contractual claims under Danish limitation periods.
  • Financial records: 60 months from transaction date, in compliance with Danish Bookkeeping Act (Bogføringsloven) requirements.
  • Server logs: 90 days rolling window for security analysis and incident investigation.

5. Data Recipients and International Transfers

Your personal data may be shared with the following categories of recipients:

  • Stripe, Inc. (payment processing) — data transferred to the United States under Standard Contractual Clauses (SCCs) with supplementary technical measures including encryption at rest and in transit.
  • Cloud infrastructure providers (AWS/EU regions) — all project data is processed within European data centers with no transfer outside the EEA without explicit contractual authorization.
  • Subcontractors engaged for specific project phases — bound by data processing agreements (DPAs) ensuring equivalent GDPR compliance standards.

6. Data Subject Rights

Under the GDPR, you exercise the following rights by contacting [email protected]:

  • Right of Access (Art. 15): Obtain confirmation of processing and a copy of all personal data held.
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
  • Right to Erasure (Art. 17): Request deletion of personal data where no overriding legal retention obligation exists.
  • Right to Restrict Processing (Art. 18): Request limitation of processing in specific circumstances.
  • Right to Data Portability (Art. 20): Receive personal data in a structured, machine-readable format.
  • Right to Object (Art. 21): Object to processing based on legitimate interests, including profiling.
  • Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time without affecting the lawfulness of prior processing.

7. Right to Lodge a Complaint

If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the Danish Data Protection Authority (Datatilsynet):

Borgergade 28, 1300 Copenhagen K, Denmark
Tel: +45 33 19 32 00
Email: [email protected]

8. Data Security Measures

GraniteOrbitForge implements appropriate technical and organizational measures to protect personal data, including but not limited to: AES-256 encryption at rest, TLS 1.3 encryption in transit, role-based access control with multi-factor authentication, regular penetration testing, and automated vulnerability scanning across all production infrastructure.

C

Cookies Policy

Effective Date: January 1, 2026

1. Cookie Technology Overview

Cookies are small text files placed on your device when you access our website. They enable technical functionality, session management, and—where consent is provided—analytics measurement. This policy describes the specific cookies deployed by GraniteOrbitForge and their operational purposes.

2. Strictly Necessary Cookies

These cookies are essential for the website to function correctly and cannot be disabled:

  • session_id: Maintains your session state across page requests. Duration: 24 hours. Type: First-party, HTTP-only.
  • csrf_token: Prevents cross-site request forgery attacks on form submissions. Duration: Session. Type: First-party, HTTP-only.
  • gof_cookie_consent: Records your cookie preference selection (accept/decline). Duration: 365 days. Type: First-party, localStorage.

3. Analytics Cookies (Consent Required)

When you accept analytics cookies, we deploy the following measurement tools:

  • Performance monitoring: Aggregated, anonymized page load metrics and interaction patterns used to optimize system performance. No personally identifiable information is collected through analytics cookies.

4. Cookie Management

You can manage your cookie preferences at any time through the cookie consent banner displayed on your first visit, or by clearing your browser's cookie storage and revisiting the site. Disabling strictly necessary cookies may impair website functionality.

5. Third-Party Cookies

GraniteOrbitForge does not deploy third-party advertising cookies or social media tracking pixels. The only third-party cookie interaction occurs during the Stripe payment process, which is governed by Stripe's own privacy policy and cookie practices.

R

Refund Policy

Effective Date: January 1, 2026

1. Scope and Applicability

This Refund Policy governs all service engagements contracted with GraniteOrbitForge, operating from Jægergårdsgade 44, 8000 Aarhus C, Denmark. It applies to both fixed-scope service packages and custom enterprise engagements, subject to the specific terms outlined in each project's Statement of Work (SOW).

2. Milestone-Based Refund Structure

Refund eligibility is determined by the project milestone at which termination occurs:

  • Pre-Execution Phase (within 5 business days of contract signing): Full refund of any advance payments, minus administrative processing fees of 3% of the invoiced amount.
  • Discovery/Analysis Phase (after deliverable commencement): Refund calculated proportionally based on percentage of unbilled work remaining in the current phase. All completed analytical deliverables become the property of the client.
  • Execution/Development Phase: No refund for completed work units. Client retains all delivered code, documentation, and infrastructure configurations. Remaining unbilled phases may be terminated with 15 business days written notice.
  • Post-Deployment Phase: No refunds applicable. All support obligations continue as specified in the service agreement through their contractual term.

3. Non-Refundable Elements

The following are explicitly non-refundable under all circumstances:

  • Third-party licensing fees, API access charges, or cloud infrastructure costs already incurred on behalf of the client.
  • Work product delivered and accepted under formal sign-off procedures specified in the project SOW.
  • Consulting hours consumed during discovery, scoping, or architectural planning sessions.
  • Payments processed through the Stripe payment gateway after successful transaction confirmation, subject to Stripe's own dispute resolution mechanisms.

4. Refund Request Procedure

To initiate a refund request, contact [email protected] with the following information: project reference number, specific service engagement identifier, detailed justification for the refund request, and supporting documentation. All refund requests are reviewed within 10 business days. Approved refunds are processed within 30 days via the original payment method.

5. Dispute Resolution

Refund disputes that cannot be resolved through direct communication will be submitted to mediation under the rules of the Danish Mediation Institute (Danske Mediationsinstitut). This policy is governed by Danish law, with venue at the district court of Aarhus (Retten i Aarhus).

T

Terms of Service

Effective Date: January 1, 2026

1. Contractual Relationship

These Terms of Service ("Terms") constitute a legally binding agreement between GraniteOrbitForge ("Provider"), registered at Jægergårdsgade 44, 8000 Aarhus C, Denmark, and any individual or entity ("Client") that engages our services through written proposal acceptance, purchase order execution, or digital service registration. By engaging our services, the Client confirms legal capacity to enter into binding agreements.

2. Service Delivery Framework

  • All services are delivered according to the specifications defined in the applicable Statement of Work (SOW) or service proposal accepted by the Client.
  • Timeline commitments are estimated targets subject to reasonable adjustment for force majeure events, Client-caused delays (including delayed feedback, access provision, or content delivery), and scope modifications requested after project initiation.
  • The Provider reserves the right to engage qualified subcontractors for specific technical workstreams, provided that all subcontractors are bound by equivalent confidentiality and data protection obligations.

3. Intellectual Property Rights

  • Pre-Existing IP: All intellectual property owned by the Provider prior to or independent of the engagement (including proprietary frameworks, tools, methodologies, and code libraries) remains the exclusive property of the Provider. The Client receives a perpetual, non-exclusive license to use such components as integrated into the delivered work product.
  • Custom Development: Upon full payment of all applicable invoices, the Client receives full ownership of all custom code, designs, and documentation created specifically for the engagement. This transfer excludes any pre-existing Provider IP incorporated into the deliverables.
  • Portfolio Rights: The Provider retains the right to display completed work in professional portfolios, case studies, and marketing materials, unless the Client explicitly opts out in writing prior to project commencement.

4. Payment Terms

  • All invoices are payable within 14 calendar days of issuance unless alternative payment terms are specified in the SOW.
  • Late payments accrue interest at a rate of 1.5% per month (18% annually) from the due date, in accordance with the Danish Interest Act (RenteLov).
  • The Provider may suspend service delivery if payment is overdue by more than 15 calendar days, with written notice provided to the Client.
  • All prices are quoted in Euros (€) exclusive of applicable VAT. Danish VAT (25%) will be added to invoices for domestic clients unless a valid VAT registration number is provided for intra-EU reverse charge.

5. Confidentiality and Non-Disclosure

Both parties agree to maintain strict confidentiality regarding all proprietary information shared during the engagement. This obligation survives the termination of the service relationship for a period of 36 months. Confidential information includes, but is not limited to: technical architectures, business strategies, financial data, customer lists, source code, and any information marked as confidential or that a reasonable party would consider confidential.

6. Limitation of Liability

To the maximum extent permitted by applicable law, the Provider's total aggregate liability under any service engagement shall not exceed the total fees paid by the Client for the specific service giving rise to the claim. The Provider shall not be liable for indirect, incidental, consequential, special, or punitive damages, including but not limited to loss of profits, data, business opportunities, or goodwill.

7. Warranty and Quality Assurance

The Provider warrants that all deliverables will conform to the specifications defined in the applicable SOW at the time of delivery. A 30-day post-delivery warranty period is provided for defect remediation. Issues reported during the warranty period will be addressed at no additional cost. Issues arising from Client modifications, third-party integrations, or environmental changes outside the Provider's control are excluded from warranty coverage.

8. Termination

  • Either party may terminate the agreement with 30 calendar days written notice.
  • Immediate termination for cause is permitted in cases of material breach that remains uncured for 15 calendar days after written notice of the breach.
  • Upon termination, the Client is entitled to receive all completed work product and documentation for which payment has been made.

9. Governing Law and Jurisdiction

These Terms are governed by the laws of the Kingdom of Denmark, excluding its conflict of law provisions. Any disputes arising from or relating to these Terms or the services provided hereunder shall be submitted to the exclusive jurisdiction of the courts of Aarhus, Denmark (Retten i Aarhus).

10. Amendments

The Provider reserves the right to update these Terms with 30 calendar days written notice to the Client. Continued engagement of services after the notice period constitutes acceptance of the amended Terms. Material changes affecting existing engagements require explicit Client consent.