Privacy & Security

Privacy Policy

Your privacy is fundamental to our values. Learn how we protect your data and respect your rights.

Last updated: May 2026

Privacy at a Glance

Data Protection

Enterprise-grade security and encryption for all your data

Your Rights

Full control over your personal data and privacy settings

Secure Processing

AI processing with privacy-preserving technologies

Data Minimization

We only collect what's necessary for our services

Introduction

Hamiltonian Lab ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, process, and safeguard your information when you use our services, visit our website, or interact with our AI agents.

By using our services, you agree to the collection and use of information in accordance with this policy. We will not use or share your information with anyone except as described in this Privacy Policy.

Data Controller

For the purposes of the EU General Data Protection Regulation (Regulation 2016/679, "GDPR") and the Danish Data Protection Act, the data controller responsible for your personal data is:

Hamiltonian Lab
Contact: via the contact form on our website

For client engagements where we process personal data on your behalf as part of our services, we act as a data processor under your instructions, and a separate Data Processing Agreement (DPA) will govern that processing.

Legal Basis for Processing

We process personal data on the following legal bases under Article 6 GDPR:

  • Performance of a contract (Art. 6(1)(b)): Delivering the services you or your organisation has engaged us for, responding to inquiries, and operating the chat widget you initiate
  • Legitimate interests (Art. 6(1)(f)): Securing our systems, preventing fraud and abuse, analysing aggregated website performance to improve our services, and informing existing clients about closely related services, balanced against your interests and rights
  • Consent (Art. 6(1)(a)): Non-essential cookies, marketing communications to new contacts, and any optional data collection; you may withdraw consent at any time without affecting prior lawful processing
  • Legal obligation (Art. 6(1)(c)): Retaining accounting and tax records, responding to lawful requests from authorities, and complying with regulatory requirements

Where we rely on legitimate interests, you may object to processing at any time using the contact form; we will stop unless we demonstrate compelling legitimate grounds that override your interests.

Information We Collect

Personal Information

  • Contact information (name, email address, phone number)
  • Company information (organization name, role, industry)
  • Professional details relevant to our services
  • Communication preferences and history

Technical Information

  • IP address (for security and analytics)
  • Browser type, version, and user agent
  • Device information and operating system
  • Page views and website usage (via Vercel Analytics)
  • Performance metrics and Core Web Vitals (via Vercel Speed Insights)
  • Chat session IDs and conversation context
  • Scroll positions and navigation patterns (stored locally)

Business Information

  • Business processes and operational data (when provided for analysis)
  • System integration requirements
  • Performance metrics and optimization goals
  • Feedback and service usage data

How We Use Your Information

We use the collected information for the following purposes:

  • Service Delivery: To provide, maintain, and improve our AI implementation services
  • Communication: To respond to inquiries, provide support, and send service-related notifications
  • Analysis: To understand your business needs and design appropriate AI solutions
  • Optimization: To enhance our AI agents and improve service quality
  • Legal Compliance: To comply with applicable laws and regulations
  • Security: To protect against fraud, abuse, and security threats

AI Processing and Data Handling

Chat Widget and AI Interactions

  • Chat messages are processed via secure external API endpoints
  • Session IDs are generated and stored in browser sessionStorage for conversation continuity
  • User messages, email addresses (if provided), and timestamps are collected
  • Chat data is transmitted to external AI processing systems for response generation
  • No chat data is stored permanently in browser cookies
  • Conversation context is maintained only for the duration of the session

Business Data Processing

  • Business data provided for analysis is processed only for service delivery
  • We implement privacy-preserving techniques when analyzing your data
  • Data is anonymized and aggregated whenever possible
  • Access to your business data is strictly limited to authorized personnel

Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share information in the following limited circumstances:

  • Sub-processors: See the dedicated section below for our current list
  • Legal Requirements: When required by law, court order, or regulatory authority; we will challenge overbroad requests where lawful and feasible
  • Business Transfer: In the event of a merger, acquisition, reorganisation, or sale of assets, subject to equivalent privacy protections
  • Consent: When you have given explicit consent for specific sharing
  • Protection: To protect our rights, property, or safety, or that of our users or the public

Sub-processors

We use the following service providers to operate the website and deliver services. Each is bound by a written agreement requiring confidentiality and protection of personal data, including, where applicable, EU Standard Contractual Clauses.

ProviderPurposeRegion
Vercel Inc.Hosting, analytics, performance monitoringUSA / EU edge
Supabase Inc.Database, content storageEU
n8n GmbHWorkflow orchestration for the chat widgetEU
OpenAI / Anthropic (and similar LLM providers)Generating chat responsesUSA

This list may change as we evolve the service. Material changes will be reflected here with a revised "Last updated" date.

Data Security

We implement comprehensive security measures to protect your information:

  • Encryption: All data is encrypted in transit and at rest using industry-standard protocols
  • Access Controls: Strict role-based access controls and multi-factor authentication
  • Infrastructure: Secure cloud infrastructure with regular security audits
  • Monitoring: Continuous monitoring for security threats and unauthorized access
  • Incident Response: Comprehensive incident response procedures and breach notification protocols

Your Rights and Choices

You have the following rights regarding your personal information:

GDPR Rights (EU Residents)

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate or incomplete data
  • Erasure: Request deletion of your personal data ("right to be forgotten")
  • Portability: Request transfer of your data in a structured format
  • Restriction: Request limitation of processing in certain circumstances
  • Objection: Object to processing based on legitimate interests

General Rights

  • Consent Withdrawal: Withdraw consent for processing at any time
  • Communication Preferences: Opt-out of marketing communications
  • Data Retention: Request information about how long we retain your data
  • Complaints: Lodge complaints with relevant data protection authorities

To exercise any of these rights, please use our contact form. We will respond within one month (extendable by a further two months for complex requests, as permitted by Art. 12 GDPR). You also have the right to lodge a complaint with the Danish Data Protection Authority (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark (datatilsynet.dk), or with the supervisory authority in your EU country of residence.

Automated Decision-Making and AI Processing

Our chat widget uses third-party large language models to generate responses. These responses are produced automatically and may be inaccurate. They are not used to make decisions that produce legal effects or similarly significant effects on you within the meaning of Article 22 GDPR.

Where a client engagement involves automated decision-making about individuals on the client's behalf, the client (as data controller) is responsible for the lawful basis, the safeguards required by Art. 22 GDPR, and providing meaningful human review.

Personal data submitted to our chat widget is transmitted to LLM providers (e.g., OpenAI, Anthropic) under contracts that prohibit using your data to train their general-purpose models, where such option is available.

Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience:

  • Local Storage: Cookie consent preferences (hamilton-cookie-consent)
  • Session Storage: Chat session IDs (hamilton-chat-session-id) and scroll positions
  • Vercel Analytics: Privacy-focused website usage analytics (no personal data)
  • Vercel Speed Insights: Performance monitoring and Core Web Vitals tracking
  • No Traditional Cookies: We do not set traditional HTTP cookies for tracking

You can control cookie settings through your browser preferences. However, disabling certain cookies may affect website functionality.

Data Retention

We retain your information for no longer than necessary for the purposes set out in this Policy:

  • Chat session ID: Cleared when the browser session ends
  • Chat message logs (server-side): Up to 90 days for quality, debugging, and abuse prevention, then deleted or anonymised
  • Contact information from inquiries: Up to 24 months after the last interaction, then deleted unless a contract is signed
  • Client business records: Duration of the engagement plus 5 years (Danish Bookkeeping Act / Bogføringslov)
  • Accounting and tax records: 5 years from the end of the financial year, as required by Danish law
  • Cookie consent records: 12 months, then re-asked
  • Vercel Analytics: Aggregated, anonymised data retained under Vercel's policy
  • Marketing contacts: Until you unsubscribe or object
  • Backups: Cycled out within 30 days of the primary deletion

Where retention is required by law or to establish, exercise, or defend legal claims, we may retain data longer to the minimum extent necessary.

International Data Transfers

Some of our sub-processors (notably Vercel and LLM providers) are based in the United States. Where personal data is transferred outside the EEA, we rely on one or more of the following safeguards under Chapter V of the GDPR:

  • EU Commission Standard Contractual Clauses (2021/914) with supplementary technical and organisational measures where required
  • An EU adequacy decision, where one applies (e.g., the EU-US Data Privacy Framework for certified recipients)
  • Your explicit, informed consent for the specific transfer, where appropriate

You may request a copy of the relevant safeguards by contacting us through the website's contact form.

Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Danish Data Protection Authority (Datatilsynet) without undue delay, and in any event within 72 hours of becoming aware, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to you, we will also notify affected individuals as required by Article 34 GDPR.

Children's Privacy

Our services are intended for business users and are not directed to individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe a child has provided personal data to us, please contact us through the website's contact form and we will delete it promptly.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For material changes, we will provide additional notice through email or prominent website notification.

Contact Us

If you have any questions about this Privacy Policy, would like to exercise your rights, or wish to raise a complaint, please contact us:

Hamiltonian Lab

Contact: via the contact form on our website

Supervisory Authority

Datatilsynet (Danish DPA)
Carl Jacobsens Vej 35, 2500 Valby
datatilsynet.dk