1. Who we are
Coldvio is a LinkedIn content and outreach platform operated by Taktflow ApS, CVR no. 46667832, registered at Tinbergens Alle 123, 9260 Gistrup, Denmark. Coldvio ApS is a registered secondary name of Taktflow ApS.
We are the data controller for personal data you provide directly to us. Where you use our leads and enrichment features, you act as data controller for contact data you upload or enrich — and Coldvio acts as your data processor for that data.
2. Data we collect
- Account dataEmail address, name, and password (hashed) when you sign up.
- Voice profileText samples, interview answers, and writing preferences you provide to train your voice profile.
- LinkedIn usage dataPost drafts, scheduled content, campaign configurations, and engagement metrics from your connected LinkedIn account.
- Usage dataFeature usage, credit consumption, session logs, and error data used to operate and improve the service.
- Payment dataWhen billing is activated, payments are processed by Stripe. We store subscription and credit records, but Coldvio does not store full card numbers.
- Lead dataContact data you upload or enrich via the leads feature. You are the data controller for this data; Coldvio processes it on your behalf as a data processor.
3. How we use your data and our legal basis
We process your personal data only for specific purposes and under a lawful basis under Article 6 of the GDPR.
- Service deliveryTo provide, maintain and improve Coldvio — including authentication, billing, and feature access. Legal basis: performance of contract (Art. 6(1)(b)).
- AI content generationTo generate content, replies, and outreach in your voice using your voice profile. Legal basis: performance of contract (Art. 6(1)(b)).
- LinkedIn actionsTo execute actions you explicitly request — posting, scheduling, connection requests, or messages. Legal basis: performance of contract (Art. 6(1)(b)).
- PaymentsTo process subscriptions and credit top-ups. Legal basis: performance of contract and legal obligation (Art. 6(1)(b) and (c)).
- Transactional emailTo send receipts, password resets, and service updates. Legal basis: performance of contract (Art. 6(1)(b)).
- Service improvement and securityTo analyse usage patterns, diagnose errors, and prevent abuse. Legal basis: legitimate interests (Art. 6(1)(f)) — our interest in operating a reliable and secure service.
- Analytics cookies (optional)If you accept analytics cookies, to understand how the product is used and diagnose friction through privacy-masked session replays. Replay masks all page text and form inputs and excludes console logs and network bodies. Legal basis: consent (Art. 6(1)(a)). You may withdraw consent at any time via cookie settings.
- No sellingWe do not sell your data to third parties.
- No model trainingWe do not use your voice profile, drafts, or content to train public AI models.
4. International data transfers
Coldvio uses Supabase for account, voice, and usage data. The production project region and supporting contractual evidence must be verified and recorded before commercial launch; some processing also involves services based outside the EU.
If you consent to analytics, product usage events and privacy-masked session replays are processed in PostHog EU Cloud in Frankfurt, Germany, only after that consent is given; account-level DPA and region evidence must still be verified and recorded before commercial launch.
When you use content generation or AI features, relevant request content is sent through Coldvio's Railway-hosted LiteLLM proxy to an approved model provider. Anthropic is the release provider. Google Gemini integrations remain disabled in both application runtime and release proxy configuration until paid-service processor evidence is retained.
We also use providers headquartered outside the EU. Railway, Supabase, Upstash, Browserbase and Sentry production regions remain subject to recorded account evidence, while Vercel uses global infrastructure. Stripe and People Data Labs are US-based services.
Before a commercial feature transfers personal data outside the EU, Coldvio must verify and document a valid transfer mechanism for each provider. That may be an adequacy decision or executed Standard Contractual Clauses (SCCs) under Article 46(2)(c) GDPR with any required transfer assessment. A feature must remain disabled where that verification is pending.
A full list of sub-processors is provided in Section 5.
5. Service providers and other recipients
The following services may process personal data depending on the features you use. Provider-specific agreements and transfer safeguards must be verified before the corresponding commercial data processing is enabled.
- SupabaseDatabase and authentication. Account DPA evidence and production region verification pending. supabase.com
- RailwayBackend application and self-hosted LiteLLM proxy. A signed DPA and production region evidence are required before launch. railway.com
- VercelFrontend application and global edge infrastructure. DPA coverage depends on the production account being on a covered Pro or Enterprise plan. vercel.com
- UpstashRedis-backed rate limiting, caching and queues. The standard DPA is incorporated into Upstash's terms; production account and region evidence remain pending. upstash.com
- AnthropicLLM inference. Its commercial DPA and SCCs are incorporated into the commercial terms; account and transfer evidence remain pending. anthropic.com
- Google Gemini APIOptional LLM inference. Disabled in application runtime and release proxy configuration; commercial EEA use would require a paid Cloud-billing-backed service covered by Google's processor terms and retained account evidence. ai.google.dev
- ResendTransactional email. Its DPA is incorporated into the service agreement; production account evidence remains pending. resend.com
- SentryError and performance monitoring with application-level PII scrubbing. Dashboard DPA and production region evidence remain pending. sentry.io
- NangoOAuth credential storage and proxying for customer-selected CRM integrations. Its cloud DPA applies automatically; production account evidence remains pending. nango.dev
- ZernioLinkedIn publishing and analytics. Commercial processing remains disabled until DPA execution and jurisdiction evidence are retained. zernio.com
- BrowserbaseCloud-browser infrastructure for outreach and lead workflows. Commercial personal-data processing remains disabled until a DPA-covered plan and region are evidenced. browserbase.com
- People Data LabsOptional contact enrichment. Commercial processing remains disabled until the parties' processing roles, DPA and transfer safeguards are agreed in writing. peopledatalabs.com
- ApifyOptional public LinkedIn and trend ingestion. Commercial processing remains disabled until a written DPA and source-specific lawful-basis review are retained. apify.com
- RedditOptional trend source. Coldvio sends only an inferred subreddit selection, not raw voice-rule text; access remains disabled until the corporate developer account, current Developer/Data API terms, controller-role assessment and transfer safeguards are approved. reddit.com
- Hacker News search via AlgoliaOptional trend fallback. Search phrases may be derived from expertise or identity voice rules. Access remains disabled until data minimisation, Algolia contractual coverage, role allocation and transfer safeguards are approved. hn.algolia.com
- StripePayment processing, when billing is activated. Stripe's DPA forms part of its services agreement. stripe.com
- Google Tag ManagerOptional analytics and marketing tags. It loads only after a recorded cookie choice and only when configured. tagmanager.google.com
- PostHogEU Cloud (Frankfurt, Germany) product analytics and privacy-masked session replay, enabled only after analytics consent. Its DPA is incorporated into PostHog's terms; production account and region evidence remain pending. posthog.com
6. LinkedIn data
Coldvio accesses your LinkedIn account via the official LinkedIn Marketing API for content publishing and via a cloud browser session for outreach actions. You authorise this access explicitly.
We access only what is needed to perform the specific actions you request. We do not store your LinkedIn password — access uses OAuth tokens and session credentials you provide.
7. Chrome extension
The Coldvio Chrome extension reads LinkedIn page content to assist with drafting and CRM sync. It communicates with Coldvio servers using your account API token and does not share page content with any third party directly.
8. Data retention
Account data, voice profiles, and content history are retained for as long as your account is active. When you delete your account, personal data is deleted within 30 days.
Lead data can be deleted at any time from within the app — list by list or in full.
Payment records are retained for the period required by applicable accounting and tax law (7 years in Denmark).
PostHog privacy-masked session replays are retained for up to 30 days.
9. Your rights under GDPR
As a data subject under GDPR, you have the following rights:
- Access (Art. 15)Request a copy of the personal data we hold about you.
- Rectification (Art. 16)Correct inaccurate or incomplete personal data.
- Erasure (Art. 17)Request deletion of your personal data, subject to legal retention obligations.
- Restriction (Art. 18)Request that we limit the processing of your data in certain circumstances.
- Data portability (Art. 20)Receive your data in a structured, machine-readable format.
- Objection (Art. 21)Object to processing based on legitimate interests.
- Withdraw consentWhere processing is based on consent (e.g. analytics cookies), withdraw it at any time without affecting prior processing.
10. Right to lodge a complaint
If you believe we are processing your personal data in breach of GDPR, you have the right to lodge a complaint with the Danish Data Protection Authority:
Datatilsynet · Carl Jacobsens Vej 35 · 2500 Valby · Denmark · [email protected] · datatilsynet.dk
You may also contact the data protection authority in your country of residence.
11. Security
Data is encrypted in transit (TLS) and at rest where supported by our infrastructure providers. Access to production systems and databases is restricted to authorised personnel.
12. Changes to this policy
We may update this policy. Material changes will be communicated to account holders by email before taking effect.
13. Contact
Questions, requests, or to exercise your rights: [email protected]
Taktflow ApS (registered secondary name: Coldvio ApS)
CVR no. 46667832
Tinbergens Alle 123
9260 Gistrup, Denmark