Privacy policy
This privacy policy explains how Capison ApS processes personal data in connection with the operation of its debt collection business, including the collection of claims for, among others, parking companies.
Last updated:
This policy has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation, GDPR) and the Danish Data Protection Act.
Contact details
- Capison ApS
- Capison ApS
- Address:
- Trindsøvej 4, 8000 Aarhus
- CVR no.:
- DK-45504921
- Email:
- contact@capison.com
1. Data controller
Capison ApS is the data controller for the processing of your personal data. Our contact details are given above.
2. Scope
This privacy policy applies to all processing of personal data carried out by Capison in connection with debt collection activities.
Capison processes personal data both as a data controller and, in certain cases, as a data processor:
- As data controller, we process personal data in connection with debt collection, including the collection of claims on behalf of our clients.
- As data processor, in certain cases we process personal data on behalf of our clients and in accordance with their instructions, which is governed by a separate data processing agreement.
3. Purpose of the processing
We process personal data for the following purposes:
- Collection of claims on behalf of our clients
- Identification of debtors
- Communication with debtors and clients
- Administration of debt collection cases
- Establishment, exercise and defence of legal claims
- Compliance with legal obligations, including bookkeeping, anti-money laundering and debt collection legislation
4. Legal basis for the processing
Our processing of personal data is based on the following legal grounds:
- GDPR Article 6(1)(f) (legitimate interest), as we have a legitimate interest in identifying the correct debtor and collecting claims on behalf of our clients.
- GDPR Article 6(1)(c) (legal obligation), where the processing is necessary to comply with the Danish Debt Collection Act, the Danish Bookkeeping Act, the Danish Administration of Justice Act, or other relevant legislation.
- Section 11(2)(4) of the Danish Data Protection Act, cf. GDPR Article 9(2)(f), when processing Danish civil registration numbers (CPR numbers), where this is necessary for unambiguous identification or for the establishment, exercise or defence of legal claims.
- GDPR Article 10 and Section 8(3) of the Danish Data Protection Act, when processing information on criminal offences, where this is necessary in connection with the handling of debt collection cases.
5. Processing of personal data about debtors
We may process the following categories of personal data:
Ordinary personal data
- Name, address, email address and telephone number
- Date of birth and CPR number
- Marital status and household
- Financial circumstances
Information from vehicle and ownership registers
- Registration number
- Information about the vehicle's owner and user, for example from the Danish Motor Register (DMR)
Special categories of personal data
- Health information, where necessary for case processing
Information on criminal offences
- Information on judgments, legal proceedings and enforcement (bailiff's court) proceedings
Sources of information
- Our clients, including parking companies
- The data subject
- Public authorities and registers, including the Danish Motor Register (DMR), the Civil Registration System (CPR register), the Central Business Register (CVR register) and the courts
- Credit reference agencies
- Publicly available sources
6. Processing of personal data about clients
We process personal data about contact persons at our clients for the purpose of administering the collaboration. This typically includes name, position, work address, email and telephone number.
The legal basis is GDPR Article 6(1)(f), our legitimate interest in administering the client relationship.
7. Disclosure of personal data
We may disclose personal data to:
- Our clients
- Courts and enforcement courts (bailiff's courts)
- Lawyers and other advisers
- Public authorities
- Credit reference agencies
- Data processors who process data on our behalf
8. Transfers outside the EU and EEA
As a general rule, personal data is not transferred to countries outside the EU or the EEA.
9. Storage and deletion
We store personal data for as long as necessary for case processing and in accordance with applicable law. As a general rule, data is stored:
- For the duration of the active debt collection case
- For up to 5 years after the case is closed, pursuant to the Danish Bookkeeping Act
10. Your rights
Under the GDPR you have a number of rights, including:
- The right of access
- The right to rectification
- The right to erasure
- The right to restriction of processing
- The right to object
- The right to data portability, where applicable
11. Security
We have implemented appropriate technical and organisational security measures to protect personal data against accidental or unlawful destruction, loss, alteration or unauthorised access.
12. Complaints
If you are dissatisfied with our processing of your personal data, you can lodge a complaint with the Danish Data Protection Agency: