Contents
Privacy Policy Version: 2 Last Updated: September 7, 2026
Assembley is a platform used by companies, associations and other organisations to record, calculate and document general assemblies, member meetings, elections and other governance processes.
This Privacy Policy explains how personal data is collected, used, disclosed, retained and otherwise processed when you use Assembley, visit our website, take part in an Assembly conducted through Assembley, or otherwise interact with us.
It should be read together with the Assembley Terms of Service (“Terms”) and the Assembley Data Processing Agreement (“DPA”), which is concluded with every organisation that uses Assembley.
Section 2 explains what Assembley does and does not do. That distinction determines what personal data we hold, why we hold it, and who is responsible for it.
Assembley is operated by Assembley ApS, a private limited company incorporated in Denmark.
Assembley ApS Vesterbrogade 13, 4. th, 1620 København V, Denmark CVR no.: [•] Privacy: privacy@assembley.dk Security: security@assembley.dk General enquiries: hello@assembley.dk
Where Assembley determines the purposes and means of processing, Assembley is the data controller. Where Assembley processes personal data on behalf of an organisation using the platform, Assembley is a data processor. Section 5 sets out which applies to what.
Unless otherwise stated, references to “Assembley”, “we”, “us” or “our” mean Assembley ApS.
Assembley has assessed that it is not required to appoint a data protection officer under Article 37 GDPR. The contact point for data protection matters is privacy@assembley.dk.
Assembley performs three functions:
- Recording — the platform creates Records of what occurred through it: votes as submitted,
presence as registered, actions as performed, and the time of each.
- Calculation — the platform performs arithmetic on those Records in accordance with the
parameters the Organisation has supplied.
- Attestation — the platform produces tamper-evident material intended to make it detectable
if a Record has been changed after it was created.
Assembley does not decide whether an Assembly was validly convened, who was entitled to participate or vote, which majority rule or quorum requirement applies, or whether a resolution or election is valid. Those decisions belong to the Organisation and to the people who conduct its meetings.
This matters for privacy because it explains what we hold and why. We keep a record of what happened, not a judgement about it — and because that record may later be relied on as evidence, parts of it are kept in a form that cannot be altered. Section 13 explains what that means for the right to erasure.
This Privacy Policy applies to personal data processed in connection with:
-
the Assembley website;
-
Assembley user accounts;
-
organisation administration and Assembly configuration;
-
Assemblies conducted using Assembley;
-
participant, shareholder and member registers uploaded by an Organisation;
-
voting and election processes;
-
invitations, access links and other Assembly communications;
-
access and security logs;
-
Records, audit trails and Evidence Packages;
-
customer support and correspondence; and
-
billing and subscription administration.
It applies to several categories of individual, including organisation administrators, account holders, shareholders, members, participants, voters, proxy holders, candidates, chairs and others who record an outcome, people included in a register uploaded by an Organisation, and visitors to our website.
Not every section applies to every category of individual.
“Assembly” means a general assembly, annual or extraordinary general meeting, member meeting, board election or other governance or decision- making process in connection with which Assembley is used.
“Configured means a value, rule, threshold, definition, period, method or list entered, Parameter” selected or confirmed by the Organisation, including majority requirements, quorum definitions, notice periods, voting weights and eligibility lists.
“Evidence Package” means a technical export containing Records and Attestation data for an Assembly.
“Non-attributed ballot” means an agenda item configured so that Assembley does not store the association between an individual Participant and that Participant’s voting choice.
“Organisation” means the company, association or other legal entity using Assembley to conduct an Assembly. The Organisation is referred to as the “Customer” in the Terms and the DPA.
“Outcome Declaration” means a statement made by a person — typically the chair of the Assembly — as to the result of an agenda item, recorded through Assembley.
“Participant” means a person invited or authorised to take part in an Assembly through Assembley.
“Record” means an entry created by Assembley documenting an event that occurred through the platform, including a submitted vote, a registration of presence, an administrative action, a configuration change or a timestamp.
“GDPR” means Regulation (EU) 2016/679. The terms “controller”, “processor”, “processing”, “personal data” and “personal data breach” have the meanings given in the GDPR.
For personal data relating to Participants, shareholders, members, votes, presence and the conduct of an Assembly, the Organisation is the data controller and Assembley is the data processor.
The Organisation decides who is invited, what personal data is uploaded, who may vote and with what weight, which agenda items are voted on, whether a ballot is non-attributed, which quorum definition and majority requirement apply, how proxies are handled, and how the resulting records are used.
Assembley processes that data only on the Organisation’s documented instructions. Those instructions include the Configured Parameters entered through the platform.
This processing is governed by the DPA, which is concluded with every Organisation on acceptance of the Terms. In the event of conflict concerning processor activities, the DPA prevails over this Privacy Policy.
Assembley is an independent data controller for personal data relating to:
-
account registration and administration;
-
authentication and security of our own systems;
-
website operation;
-
customer and technical support correspondence;
-
billing and subscription administration;
-
prevention and investigation of misuse, and security monitoring;
-
compliance with legal obligations applicable to Assembley; and
-
direct marketing to our own business contacts.
Assembley may act as a processor for one activity and as a controller for another. We may, for example, process a Participant’s email address as a processor on behalf of an Organisation in order to send a voting invitation, while separately processing technical information as a controller in order to secure and operate the platform.
-
name and email address;
-
authentication credentials in protected form, where passwords are used;
-
organisation name and company registration number;
-
account role and permissions;
-
account creation, sign-in and status information;
-
the version of the Terms accepted, and the date and time of acceptance; and
-
correspondence with Assembley.
Passwords are never stored in plaintext. Where passwordless or link-based sign-in is used, credentials are handled through that mechanism rather than as a conventional password.
When an Organisation prepares an Assembly it may provide information about shareholders, members or other Participants, which may include:
-
full name and email address;
-
membership or shareholder status;
-
shareholding, share class or voting weight;
-
eligibility to vote;
-
proxy relationships;
-
candidate status in an election; and
-
other information the Organisation considers necessary for the Assembly.
The Organisation is responsible for the accuracy, relevance and lawfulness of the personal data it supplies, and for limiting it to what is necessary.
-
the agenda item voted on;
-
the option selected and the weight allocated, including split allocations;
-
whether a vote was cast;
-
the date and time of submission; and
-
the relevant Assembly and participant identifiers.
Because the platform documents how an Assembly was conducted, we also process information about the actions people take within it:
-
configuration changes, and who made them;
-
acknowledgement of an observation presented by the platform – for example, that the interval
between the recorded dispatch of notice and the Assembly is shorter than the configured notice period – including the identity of the acknowledging user and the time of acknowledgement; and
- Outcome Declarations, including the identity of the declaring individual, the time, and the
figures and Configured Parameters presented when the declaration was made.
-
access credential references and session identifiers;
-
authentication timestamps and sign-in information;
-
IP address, browser and device characteristics;
-
failed access attempts and security events; and
-
information concerning suspicious or potentially abusive activity.
Access links and one-time codes are designed to be short-lived and, where applicable, single-use.
-
timestamps and event sequence information;
-
participant and administrator identifiers;
-
voting and voting-window events;
-
quorum-related information and results;
-
cryptographic hashes, chain references and Merkle roots; and
-
the contents of Evidence Packages generated for an Organisation.
-
recipient name and email address;
-
the content of messages dispatched through the platform; and
-
dispatch and delivery status.
-
billing contact and organisation information;
-
subscription plan, invoices and payment status; and
-
transaction references and tax information.
Payment card details are handled by the applicable payment service provider and are not stored by Assembley.
-
IP address, browser type, device type and operating system;
-
pages or resources requested, and timestamps;
-
referring information and error information; and
-
technical logs necessary for security and operation.
We do not sell personal data, and we do not use participant or voting data for behavioural advertising.
-
creating and administering accounts;
-
verifying access credentials;
-
configuring Assemblies according to the Organisation’s instructions;
-
dispatching invitations and access links;
-
receiving and recording votes;
-
calculating totals and quorum figures from the Records;
-
recording Outcome Declarations;
-
generating draft documents and Evidence Packages; and
-
providing support.
-
detecting unauthorised access and preventing abuse;
-
preventing duplicate or unauthorised voting;
-
enforcing access controls;
-
investigating security incidents; and
-
protecting the confidentiality and integrity of the platform.
Because Assembley is used for governance processes that may later be relied on or challenged, we process certain information in order to preserve evidence of who performed an action, when it occurred, what occurred, in what sequence, and whether the resulting Records have been altered. This is an integral part of the service rather than an optional analytics function.
We use personal data to respond to requests and diagnose technical problems; to comply with applicable law and lawful requests from public authorities; to establish, exercise or defend legal claims; and to maintain legally required records.
Where permitted by law, we use limited information to understand performance, identify errors and improve the reliability and security of the platform. We use aggregated or anonymised information for this purpose wherever reasonably possible, and never voting choices.
Where Assembley acts as a controller, we rely on one or more of the following legal bases.
Creating and maintaining an account, verifying an account holder, providing support, administering a subscription and providing the contracted service.
Obligations relating to accounting, tax, corporate records, and responding to lawful requests from authorities.
Maintaining the security of our systems, preventing fraud and abuse, protecting the integrity of Records, investigating security incidents, defending legal claims, improving reliability and administering our business. Where we rely on legitimate interests, we consider whether they are overridden by the rights and freedoms of the individual concerned.
Where required by law, including for non-essential cookies and similar technologies. Consent may be withdrawn at any time; withdrawal does not affect processing carried out beforehand. We do not use consent as a substitute for another applicable legal basis.
Where Assembley acts as a processor, the legal basis for the processing is determined by the Organisation as controller.
Assembley is not designed to require special categories of personal data. Under the Terms, an Organisation must not submit special category data within the meaning of Article 9(1) GDPR, data relating to criminal convictions and offences, national identification numbers or payment card data, except as set out below.
Where the Organisation is an association, trade union, religious community, political party or similar body whose purpose is itself of a nature referred to in Article 9(1) GDPR, the fact of membership may itself constitute special category data. Such membership data may be processed through the platform where the Organisation relies on Article 9(2)(d) GDPR or another applicable exception, and does not submit further special category data beyond what follows from membership itself.
We apply the same security measures to such data as to all other personal data.
Agenda text, candidate descriptions and meeting materials uploaded by an Organisation may in some circumstances reveal information falling within Article 9 GDPR. The Organisation is responsible for establishing an appropriate legal basis and, where required, an exception under Article 9(2).
Unless electronic identification is enabled for a particular Assembly, Assembley verifies control of an access credential — such as an email address, an access link or a one-time code. It does not verify the identity of a natural person.
A Record therefore establishes that a submission was made using a given credential at a given time. It does not establish who used that credential.
The Organisation is responsible for deciding what level of assurance its Assembly requires, for the accuracy of the contact details to which credentials are sent, and for the consequences of a credential being forwarded or shared.
Assembley dispatches invitations, access credentials, notices and other messages submitted for sending by an Organisation.
We undertake to dispatch those messages. We cannot undertake that a message will be delivered, will reach an inbox rather than a spam or quarantine folder, or will be opened. Delivery depends on recipient mail systems, filtering rules and other factors outside our control.
Dispatch and delivery status is logged and made available to the Organisation, which is responsible for following up with Participants who have not received or acted on a message.
Where the platform supports non-attributed ballots and the Organisation configures an agenda item as such, Assembley does not store the association between an individual Participant and that Participant’s voting choice.
Availability of this functionality depends on the Organisation’s plan and is described in the Documentation. Where it is not available or has not been enabled, votes are recorded in attributed form.
Participation may still be recorded separately where necessary for quorum, attendance and audit purposes.
Anonymity is a property of the circumstances of a ballot, not a property that software can guarantee. Irrespective of how data is stored, an individual voting choice may be inferable from:
-
a small number of voters;
-
distinctive or uneven voting weights;
-
proxy arrangements;
-
turnout, timing or aggregate results;
-
information held by the Organisation; or
-
information obtained independently outside Assembley.
Assembley does not represent that a third party cannot infer an individual’s voting preference. Our undertaking is limited to the storage behaviour described in the Documentation for the functionality actually enabled. Organisations should configure non-attributed ballots with their own governance requirements in mind.
Certain Records are designed to be append-only and tamper-evident. Modification or deletion of such a Record is detectable and renders the associated Attestation material inconsistent.
Records are tamper-evident, not tamper-proof. The design makes modification detectable; it does not make modification impossible.
The Organisation instructs Assembley to maintain Records in append-only form for the period set out in section 18. This constitutes a documented limitation on erasure, applied for the purpose of establishing, exercising or defending legal claims within the meaning of Article 17(3)(e) GDPR.
Where a request for erasure concerns data held within an append-only Record, we will, on the Organisation’s instruction and so far as technically possible:
-
delete or anonymise associated data held outside the append-only structure;
-
suppress display of the identifying data in the user interface; and
-
retain within the append-only structure only the minimum required to preserve the integrity of
the Attestation material.
An Evidence Package demonstrates that the Records we hold for an Assembly are internally consistent and have not been modified since they were created. It does not demonstrate that votes were cast by the persons entitled to cast them, that Participants were correctly identified, that the Assembly was validly convened, or that any resolution or election is valid.
Authorised administrators and other authorised users of the Organisation may access personal data as configured by the Organisation, including participant information, voting eligibility and weights, attendance, aggregate results, attributed voting records, proxy information and Evidence Packages. For non-attributed ballots, the platform is designed not to expose an individual voting choice together with the voter’s identity.
We use selected technology providers to operate the platform, as described in section 15. Each is engaged under a written contract containing data protection obligations no less protective than those we are subject to.
We may disclose personal data to lawyers, accountants, auditors, insurers and other advisers where reasonably necessary for legal, accounting, compliance or corporate purposes.
We may disclose personal data where required by law or by a binding order from a competent authority or court, where necessary to establish, exercise or defend legal claims, or where necessary to protect the rights, property or safety of Assembley, our customers or others.
If we receive a binding request for personal data that we process on behalf of an Organisation, we will, unless legally prohibited, notify that Organisation without undue delay and give it a reasonable opportunity to respond. We disclose only what is legally required, and we will challenge requests that appear unlawful or excessive where it is reasonable to do so.
Where an Organisation, a court or another competent body asks Assembley to verify or explain an Evidence Package in connection with a dispute or investigation, personal data contained in the relevant Records may be disclosed for that purpose.
A current list of the sub-processors we use, together with the purpose of each and the location of processing, is published at assembley.dk/subprocessors. The categories are:
-
cloud infrastructure, database and authentication services;
-
application hosting and delivery;
-
transactional email dispatch;
-
electronic identification services, where enabled for an Assembly; and
-
AI-assisted functionality, where enabled — see section 20.
We may add or replace sub-processors. Notice of changes, and the Organisation’s right to object, are governed by the DPA.
Production data is hosted within the European Economic Area (“EEA”).
Certain technology providers may nevertheless involve corporate entities, support personnel or infrastructure located outside the EEA, even where primary production data is hosted within it. Where personal data is transferred outside the EEA, we ensure that a valid transfer mechanism under Chapter V GDPR is in place — an adequacy decision, the European Commission’s Standard Contractual Clauses with any necessary supplementary measures, or another legally recognised mechanism.
We do not claim that no provider entity, personnel or infrastructure is ever located outside the EEA. The position for each sub-processor, and the transfer mechanism relied on, is stated in the sub- processor list referred to in section 15.
We implement technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access. Depending on the data concerned, these may include:
-
encryption in transit and at rest;
-
row-level access controls isolating each Organisation’s data;
-
role-based permissions and access controls;
-
short-lived or single-use access credentials;
-
rate limiting on authentication endpoints;
-
logging, monitoring and security incident detection;
-
database-level protection of vote Records against modification;
-
hash-chained event records and Attestation material;
-
restricted access to production systems; and
-
regular backups and a documented incident response procedure.
We describe the measures we apply. We do not represent that the platform or any data is secure against all forms of attack, unauthorised access or compromise. No internet-based service can be.
You are responsible for the security of your own systems, devices and credentials. Suspected vulnerabilities may be reported to security@assembley.dk under the responsible disclosure process published at assembley.dk/security.
Where Assembley acts as a processor and becomes aware of a personal data breach affecting an Organisation’s data, we notify that Organisation without undue delay and in any event within 48 hours, and assist it in meeting its obligations under Articles 33 and 34 GDPR, as set out in the DPA.
Where Assembley acts as a controller, we assess and handle personal data breaches in accordance with applicable law, including notification to a supervisory authority and to affected individuals where legally required.
We retain personal data only for as long as necessary for the purposes for which it was collected, unless a longer period is required or permitted by law. Because Assembley is used for governance processes that may later be relied on or challenged, some records are retained longer than ordinary application data.
Category Retention period
Account data For as long as the account is active. Deleted or anonymised within 90 days of closure of the account.
Participant and Assembly data Deleted or anonymised within 90 days after the end of the other than Records subscription or closure of the account, whichever is earlier.
Records and Attestation material 5 years from the date the Assembly ended, then deleted or for a completed Assembly reduced to non-personal form.
Email dispatch and delivery 90 days, unless a longer period is necessary for security, records troubleshooting or legal claims.
Technical and authentication logs 90 days. Logs relating to an identified security incident may be retained for up to 12 months.
Backups Rolling maximum of 35 days, then overwritten.
Billing and accounting records For the period required by applicable accounting legislation.
Data deleted from active systems may remain in backups until the backup cycle expires. Such data is not restored to active use and is deleted on expiry of the cycle.
Retention periods may be varied by written agreement where an Organisation’s own retention obligations require it.
Where personal data is relevant to an actual or reasonably anticipated legal dispute, regulatory investigation or security incident, we may retain it beyond the periods set out in section 19. Where appropriate, such data is isolated from ordinary processing and retained only for as long as necessary for that purpose.
Where AI-assisted functionality is available and has been enabled by an Organisation, personal data contained in the relevant Records or documents may be processed in order to generate the output.
Output is generated automatically, may be incomplete or inaccurate, and is a draft requiring human review before use. It is never a determination that anything is lawful or valid.
We do not use personal data processed through the platform to train generally available artificial intelligence models. Any provider used for this purpose is identified in the sub-processor list referred to in section 15. The Organisation decides whether to enable the functionality.
Depending on the circumstances, you have the following rights under the GDPR.
You may request confirmation of whether we process personal data concerning you, access to that data, correction of inaccurate or incomplete data, and deletion in the circumstances specified in Article 17 GDPR.
The right to erasure is not absolute. Deletion may be limited where processing is necessary to comply with a legal obligation, to establish, exercise or defend legal claims, or to preserve the integrity of records as described in section 13.
You may request restriction of processing where Article 18 GDPR applies, and, where the conditions are met, receive personal data you have provided in a structured, commonly used and machine- readable format or have it transmitted to another controller where technically feasible.
You may object under Article 21 GDPR to processing based on legitimate interests. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary for legal claims. You may object to direct marketing at any time, without exception.
Assembley does not make decisions producing legal or similarly significant effects about individuals solely by automated means. The calculation of a voting result is arithmetic performed on Records in accordance with parameters supplied by the Organisation, and the outcome of an agenda item is declared by a person, not by the platform.
To exercise a right concerning processing for which Assembley is the controller, contact privacy@assembley.dk. Please provide enough information for us to understand the request and identify the relevant account or processing activity.
We may need to verify your identity before responding, where reasonably necessary to protect personal data against unauthorised disclosure.
We respond without undue delay and in any event within one month of receiving the request. Where a request is complex or where several requests have been made, that period may be extended by up to a further two months as permitted by Article 12 GDPR. We will tell you if an extension applies.
If you took part in an Assembly organised by a third party, that Organisation is the data controller for your participant and voting information. You should contact the Organisation first.
For example, where a company uses Assembley for its annual general meeting, the company decides who may participate, what participant information is used, who has voting rights and with what weight, whether a ballot is non-attributed, and how the resulting records are retained. Assembley processes that information on the company’s behalf.
If you contact us directly about such information, we will refer or forward your request to the relevant Organisation, and we will not respond to the substance of the request ourselves.
If you believe we process your personal data unlawfully, please contact us first so that we can investigate. You also have the right to lodge a complaint with the competent supervisory authority. In Denmark this is:
Datatilsynet Carl Jacobsens Vej 35, 2500 Valby, Denmark www.datatilsynet.dk
If you are located in another EU or EEA member state, you may in certain circumstances lodge a complaint with the supervisory authority in that state.
We use cookies and similar technologies that are necessary to maintain secure sessions, verify access credentials, remember service settings, maintain security, detect misuse and provide essential functionality.
Where we use non-essential cookies or similar technologies requiring consent, we request consent before placing or using them. The technologies used and their purposes are described in the applicable cookie notice and consent mechanism.
We do not use cookies or tracking technologies for behavioural advertising.
We send service-related communications necessary to provide the platform, including account and security notices, Assembly invitations, voting notifications, transactional emails and administrative messages.
Where permitted by law, we may also send limited marketing communications to business contacts. You can unsubscribe at any time. Unsubscribing from marketing does not stop essential service or security communications.
Assembley is intended for organisations and the people involved in their governance processes. The platform is not directed at children, and we do not knowingly collect personal data from children for purposes unrelated to the provision of the service.
Where an Organisation lawfully includes a minor as a Participant, the Organisation is responsible for ensuring that the processing complies with applicable law.
Our website may link to third-party websites or services. This Privacy Policy does not apply to their processing activities, and we recommend reviewing their privacy policies before providing them with personal data.
If Assembley is involved in a merger, acquisition, financing, restructuring, sale of assets or similar transaction, personal data may be transferred or disclosed as reasonably necessary in connection with that transaction, subject to applicable data protection law and appropriate confidentiality and security requirements.
We may update this Privacy Policy to reflect changes to the platform, our infrastructure, our processing activities or applicable law, or to improve its clarity and accuracy.
Where required by law, we provide appropriate notice of material changes. The “Last updated” date at the top of this Privacy Policy shows when it was most recently revised, and previous versions are available on request.
This Privacy Policy is published in English and may be made available in Danish translation. In the event of any discrepancy, the English version prevails, except where mandatory law requires otherwise.
This Privacy Policy describes the processing of personal data under the GDPR and applicable Danish data protection legislation, including the Danish Data Protection Act (databeskyttelsesloven).
Nothing in this Privacy Policy limits any mandatory right available to individuals under applicable data protection law.
Assembley ApS Address: Vesterbrogade 13, 4. th, 1620 København V, Denmark
CVR no.: XX
Privacy: privacy@assembley.dk Security: security@assembley.dk General enquiries: hello@assembley.dk
Privacy Policy · version 2 · in effect from 7 September 2026