heart (un)broken is operated by Heart (un)broken I/S with registered address at Gammel Kirkevej 14, 2770 Kastrup, Copenhagen, Denmark, VAT-no. DK46489179.
We are the data controller for the personal data we collect and process through our website and platform.
If you have any questions about this privacy policy or how we handle your personal data, please contact us at letter@heartunbroken.co.
We take your privacy seriously. We collect only what we need, store it securely, and never sell your personal data to third parties. This policy explains what data we collect, why we collect it, how we use it, and what rights you have.
2.1 When you visit our website
We automatically collect:
Purpose: Website functionality, security, fraud prevention, and analytics.
Legal basis: Legitimate interest (GDPR Article 6(1)(f)).
2.2 When you create an account
We collect:
Purpose: To provide you with access to your account and your letter archive.
Legal basis: Performance of a contract (GDPR Article 6(1)(b)).
2.3 When you write a letter
We collect and store the content of your letters, including any text, audio files, and video files you attach.
Audio and video files are stored on Amazon Web Services S3, configured exclusively in EU regions in accordance with GDPR. Text content, including letter content, recipient names, and delivery addresses, is encrypted using AES-256 encryption before being stored on our servers hosted by Simply.com at team.blue Denmark A/S in Skanderborg, Denmark.
Physical letters are stored digitally until they are printed. Printing is handled by us personally. We handle physical letters only for the purpose of printing, packing and posting. We have no interest in reading your letters and take all reasonable steps to protect their confidentiality during handling. We do not retain a digital copy of physical letters after printing unless you have saved it in your account archive.
Purpose: To deliver your letter on the date you have chosen.
Legal basis: Performance of a contract (GDPR Article 6(1)(b)).
2.4 When you make a purchase
We collect:
We never store your full card details. Payment data is handled entirely by Stripe.
Purpose: To process your payment and comply with accounting obligations under Danish bookkeeping law.
Legal basis: Performance of a contract and legal obligation (GDPR Article 6(1)(b) and 6(1)(c)).
2.5 When you sign up for our newsletter
We collect:
Purpose: To send you occasional updates, letters, and news from heart (un)broken.
Legal basis: Consent (GDPR Article 6(1)(a)).
You can withdraw your consent and unsubscribe at any time via the link in any email we send you.
2.6 When you contact us
We collect:
Purpose: To respond to your inquiry and provide support.
Legal basis: Legitimate interest (GDPR Article 6(1)(f)).
We retain your data only for as long as necessary for the purpose it was collected.
Account and letter data: Retained until you delete your account. Upon account deletion, all letters, attachments and personal data are permanently deleted and cannot be recovered.
Order data including payment amounts, dates, and delivery status: Retained for 5 years in accordance with Danish bookkeeping legislation (Bogføringsloven).
You can access all your written letters through your account as an order history. Letters remain in your archive until you manually delete them or delete your account. We believe your letters belong to you and we will never delete them without your instruction, except in the event of account deletion.
We use cookies to ensure our website functions correctly, to analyse usage, and to manage your cookie preferences.
We use Complianz as our GDPR-compliant cookie consent solution. When you visit our website for the first time, you will be presented with a cookie banner allowing you to accept or reject non-essential cookies.
The types of cookies we use include:
You can change your cookie preferences at any time via the cookie settings on our website.
We share your data with third parties only where necessary to provide our services. We never sell or rent your personal data.
Stripe Payment processing. Stripe processes payment data securely. We have a data processing agreement with Stripe. Privacy policy: stripe.com/privacy
Mailchimp Newsletter delivery. We share your email address and first name with Mailchimp for the purpose of sending our newsletter. Privacy policy: mailchimp.com/legal/privacy
Brevo (via WP Mail SMTP) Transactional email delivery including order confirmations and letter delivery notifications. We share your email address with Brevo for this purpose only. Privacy policy: brevo.com/legal/privacypolicy
Amazon Web Services S3 Storage of audio and video files attached to digital letters. Files are stored exclusively in EU regions. Privacy policy: aws.amazon.com/privacy
Google Analytics 4 Website analytics. Google may process anonymised usage data. We have configured Google Analytics to anonymise IP addresses. Privacy policy: policies.google.com/privacy
Jetpack Website performance and security monitoring. Privacy policy: automattic.com/privacy
Wordfence Website security and malware protection. Wordfence may process IP addresses for security purposes. Privacy policy: wordfence.com/privacy-policy
Simply.com / team.blue Denmark A/S Website hosting. All servers are located in Denmark. No data is transferred outside the EU in connection with our hosting. Privacy policy: simply.com/dk/privatlivspolitik
Our website and account data are hosted exclusively in Denmark and do not leave the EU.
Audio and video files are stored on AWS S3 in EU regions only, covered by Amazon’s standard contractual clauses in accordance with GDPR.
Mailchimp and Google Analytics may process data outside the EU. Both operate under appropriate safeguards including standard contractual clauses approved by the European Commission.
We do not transfer personal data to countries outside the EU or EEA without ensuring appropriate safeguards are in place.
Our platform is open to users of all ages. However, users under the age of 18 must have the consent of a parent or legal guardian before creating an account or submitting personal data, in accordance with GDPR Article 8 and Danish data protection law.
Users under the age of 13 may not use our platform independently under any circumstances.
When heart (un)broken works with institutions such as schools, youth organisations, hospices or social services, the institution acts as an independent data controller for their own users and is responsible for obtaining any necessary consent from minors and their guardians. heart (un)broken acts as a data processor in such contexts and enters into a data processing agreement with each institution.
As a resident of the EU or EEA, you have the following rights regarding your personal data:
To exercise any of these rights, please contact us at letter@heartunbroken.co. We will respond within 30 days in accordance with applicable law.
You also have the right to lodge a complaint with the Danish Data Protection Authority:
Datatilsynet Carl Jacobsens Vej 35 2500 Valby Denmark dt@datatilsynet.dk datatilsynet.dk
We implement appropriate technical and organisational measures to protect your personal data, including:
SSL encryption on all data transmitted through our website. Servers hosted exclusively in Denmark by team.blue Denmark A/S. Physical letters stored in a locked security box with a personal access code prior to posting. Audio and video files stored on AWS S3 with access controls and encryption at rest. Limited internal access to personal data on a need-to-know basis. Security monitoring via Wordfence and Jetpack. Letter content, recipient names, and delivery addresses are encrypted at rest using AES-256 encryption prior to storage.
In the event of a personal data breach, we will:
Investigate and contain the breach immediately. Notify Datatilsynet within 72 hours where required under GDPR Article 33. Inform affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on you.
We may update this privacy policy from time to time. We will notify you of any material changes by email or by displaying a notice on our website. The date at the top of this policy indicates when it was last updated.
Your continued use of our services after such notice constitutes your acceptance of the updated policy.
If you have any questions about this privacy policy or how we handle your personal data, please contact us at:
heart (un)broken letter@heartunbroken.co
We and selected third parties use functional, statistics, and marketing cookies.
Functional cookies ensure the website works properly. Statistics cookies help us improve your experience. Marketing cookies allow us to show relevant content and personalized offers.
By clicking accept, you consent to essential, analytics and marketing cookies.