Data Protection Policy
RelevantEdge ApS — Summary for external reference | Last updated 6 August 2026
RelevantEdge ApS (“RelevantEdge”, “the Company”) is committed to protecting the rights and freedoms of data subjects and to processing personal data safely, securely, and in accordance with our legal obligations. This page summarizes our Data Protection Policy for customers, partners, and other external parties. It is based on the EU General Data Protection Regulation (GDPR, Regulation 2016/679).
How RelevantEdge Handles Customer Data
RelevantEdge does not provide a SaaS solution and does not store data on behalf of its customers. The RelevantEdge application is deployed on-premises, within the customer’s own network — whether a hosted tenant, cloud environment, or physical data center that the customer controls.
The application processes data from the customer’s Sitecore system (and optionally other customer-controlled sources) and loads it into a SQL database owned and controlled entirely by the customer. RelevantEdge does not retain a copy of this data, and access to it is governed by the customer’s own IT department.
Our Data Protection Principles
RelevantEdge is committed to processing personal data in line with the core GDPR principles:
- Processed lawfully, fairly, and transparently
- Collected for specified, explicit, and legitimate purposes only
- Limited to what is necessary (data minimization)
- Accurate and kept up to date
- Retained only as long as necessary
- Processed securely, with appropriate technical and organizational safeguards
- Transferred internationally only with appropriate safeguards in place, such as Standard Contractual Clauses
We maintain records of our data processing activities and will not process personal data without a recognized legal basis.
Security Measures
RelevantEdge maintains a broader Information Security Policy covering areas such as device and network security, patch management, data disposal, and physical security. In summary:
- Access to personal data is restricted to employees with a work-related need
- Staff with access to personal data are bound by confidentiality obligations
- Systems and devices are kept current with security patches, prioritized by severity
- Company devices are protected with antivirus, antimalware, and firewall protection, with continuous vulnerability scanning
- Electronic devices and media are securely disposed of or physically destroyed at end of life
- Security incidents are investigated and, where required, reported to the relevant supervisory authority and affected data subjects without undue delay
Use of Artificial Intelligence Tools
RelevantEdge staff may only use AI tools — including generative AI and large language models — that have been reviewed and approved for use with company or customer-related information. Unapproved (“shadow”) AI tools may not be used for company business without explicit approval.
Personal data, including any customer or employee data, may not be entered into an AI tool unless that tool has been specifically approved and appropriate safeguards, including a data processing agreement with the AI vendor where applicable, are in place. AI vendors that process personal data on RelevantEdge’s behalf are held to the same data protection obligations as our other data processors.
AI tools are not used to make decisions with legal or similarly significant effects on individuals without meaningful human review, consistent with Article 22 of the GDPR. Employees who use AI tools receive periodic training on their safe and compliant use.
Your Rights as a Data Subject
Under the GDPR, individuals have the right to be informed about how their personal data is used, to access their data, to have inaccurate data corrected, to request erasure or restriction of processing in certain circumstances, and to object to certain types of processing.
If you have questions about how your personal data is handled, or wish to exercise any of these rights, you can contact our Global Data Protection Officer using the details below.