1. Who we are
2do IT Vest ApS ("we", "us") provides the Microsoft Teams application 2do Uniconta AI Agent (the "App"). For personal data processed through the App we act as data processor on behalf of the customer organisation whose Uniconta data the App reads; that organisation is the data controller. For the limited operational data described in section 4 we act as controller.
2do IT Vest ApS · CVR 34605076
John Tranums Vej 23, 2., 6705 Esbjerg Ø, Denmark
lv@2doit.nu
2. What this policy covers
This policy covers the App only — the Teams bot and the services behind it. Our website is covered separately by our Privacy & Cookie Policy. The App sets no cookies and runs no analytics or advertising trackers.
3. What the App processes
| Category | What it is |
|---|---|
| Message content | The questions you type in the chat, and the answers we return. |
| Teams identifiers | The conversation ID, and the tenant/user identifiers Microsoft Teams attaches to each message, used to keep conversations apart and to apply your language setting. |
| Uniconta business data | Records read from your organisation's synced Uniconta database — invoices, debtors, creditors, orders, inventory, GL transactions, projects, time registrations, employees and CRM records. These may contain personal data about your employees and business contacts. |
| Attachments | Files and images you send to the bot. |
| Access keys | The key you send with login@ to connect a conversation to a company. |
| Diagnostic logs | A technical record of each answered question — see section 6. |
The App reads from a hosted mirror of your Uniconta database over an authenticated HTTPS gateway. It is read-only: it never writes to, alters or deletes anything in Uniconta. A conversation stays locked and fetches no data at all until a valid access key is supplied, and the key alone determines which company's data that conversation can reach.
4. Why we process it
- To answer your questions — the purpose of the service, performed on the instructions of your organisation under our agreement with it.
- To keep the service working and secure — diagnostics, fault-finding and abuse prevention, on the basis of our legitimate interest in operating a reliable service (GDPR art. 6(1)(f)).
We do not sell your data, use it for advertising, or use your questions or your Uniconta data to train AI models.
5. Who else processes it
| Recipient | What reaches them | Where |
|---|---|---|
| Anthropic Claude, hosted by Microsoft Azure | Your question, the recent conversation turns, the database rows retrieved to answer it, and any image you attach. Used solely to compose the reply. | Azure Sweden Central (EU) |
| Tavily | Short search queries derived from your question, used to look up official Uniconta documentation before answering. Your Uniconta records are not sent. | United States |
| Microsoft (Teams & Azure Bot Service) | Message delivery between you and the bot, and hosting of the App. | Per your Microsoft 365 tenant |
| 2do IT Vest hosting | The Uniconta mirror database, and attachments you upload. | Denmark / EU |
Transfers outside the EU/EEA (Tavily) are made under the European Commission's Standard Contractual Clauses. We disclose data to public authorities only where legally required.
6. How long it is kept
- Conversation history — the last 10 turns, held in the running service's
memory. It is erased when you send
/clear, when you sendlogout, when a different access key is used, and whenever the service restarts. - Diagnostic logs — one record per answered question, including the question text and the data retrieved, kept for 14 days and then deleted automatically. Used only to investigate incorrect answers and faults.
- Attachments — stored on our file service for as long as needed to serve the conversation, and deleted on request.
- Uniconta mirror — kept in sync for the duration of your organisation's agreement with us and removed when that agreement ends.
- Access keys — never written to conversation history and never sent to the AI provider.
7. Security
All connections use TLS. Database access runs through an authenticated gateway that permits read-only queries and refuses anything else. Each conversation is scoped to a single company by its access key, so one customer's conversation cannot reach another customer's data. Access to production systems is restricted to authorised 2do IT Vest personnel.
8. Your rights
Under the GDPR you may request access to your personal data, correction, erasure, restriction of processing, portability, and you may object to processing. Because we act as processor for Uniconta data, please direct such requests to your own organisation, which will pass them to us; we will assist promptly. For data we hold as controller, contact us directly at lv@2doit.nu. You may also lodge a complaint with the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk).
9. Changes
We may update this policy. Material changes will be announced through the App or to your organisation's contact before they take effect. The effective date above always reflects the current version.
10. Contact
Questions about this policy or about how the App handles data: lv@2doit.nu. We aim to respond within one business day.
Dansk
1. Hvem vi er
2do IT Vest ApS ("vi", "os") leverer Microsoft Teams-applikationen 2do Uniconta AI Agent ("Appen"). For personoplysninger, der behandles gennem Appen, agerer vi databehandler på vegne af den kundevirksomhed, hvis Uniconta-data Appen læser; denne virksomhed er dataansvarlig. For de begrænsede driftsdata, der er beskrevet i afsnit 4, agerer vi dataansvarlig.
2do IT Vest ApS · CVR 34605076
John Tranums Vej 23, 2., 6705 Esbjerg Ø, Danmark
lv@2doit.nu
2. Hvad politikken dækker
Denne politik dækker kun Appen — Teams-botten og de bagvedliggende tjenester. Vores hjemmeside er dækket særskilt af vores Privatlivs- og cookiepolitik. Appen sætter ingen cookies og anvender hverken analyse- eller annoncesporing.
3. Hvad Appen behandler
| Kategori | Hvad det er |
|---|---|
| Beskedindhold | De spørgsmål, du skriver i chatten, og de svar, vi returnerer. |
| Teams-identifikatorer | Samtale-ID samt de tenant- og bruger-identifikatorer, Microsoft Teams vedhæfter hver besked. Bruges til at holde samtaler adskilt og til sprogvalg. |
| Uniconta-forretningsdata | Poster læst fra din virksomheds synkroniserede Uniconta-database — fakturaer, debitorer, kreditorer, ordrer, lager, finansposter, projekter, tidsregistreringer, medarbejdere og CRM. Disse kan indeholde personoplysninger om medarbejdere og forretningsforbindelser. |
| Vedhæftninger | Filer og billeder, du sender til botten. |
| Adgangsnøgler | Den nøgle, du sender med login@ for at forbinde en samtale til en virksomhed. |
| Diagnostiklogs | En teknisk registrering af hvert besvaret spørgsmål — se afsnit 6. |
Appen læser fra en hosted kopi af din Uniconta-database via en autentificeret HTTPS-gateway. Den er skrivebeskyttet: den skriver, ændrer eller sletter aldrig noget i Uniconta. En samtale forbliver låst og henter ingen data, før en gyldig adgangsnøgle er angivet, og nøglen alene afgør, hvilken virksomheds data samtalen kan nå.
4. Hvorfor vi behandler dem
- For at besvare dine spørgsmål — tjenestens formål, udført efter instruks fra din virksomhed i henhold til vores aftale med den.
- For at holde tjenesten kørende og sikker — diagnostik, fejlfinding og misbrugsforebyggelse på grundlag af vores legitime interesse i at drive en pålidelig tjeneste (databeskyttelsesforordningens art. 6, stk. 1, litra f).
Vi sælger ikke dine data, bruger dem ikke til annoncering og bruger hverken dine spørgsmål eller dine Uniconta-data til at træne AI-modeller.
5. Hvem der ellers behandler dem
| Modtager | Hvad de modtager | Hvor |
|---|---|---|
| Anthropic Claude, hostet af Microsoft Azure | Dit spørgsmål, de seneste samtaleturer, de databaserækker der hentes for at besvare det, samt eventuelle vedhæftede billeder. Bruges alene til at formulere svaret. | Azure Sweden Central (EU) |
| Tavily | Korte søgeforespørgsler udledt af dit spørgsmål, brugt til at slå officiel Uniconta-dokumentation op. Dine Uniconta-poster sendes ikke. | USA |
| Microsoft (Teams og Azure Bot Service) | Beskedlevering mellem dig og botten samt hosting af Appen. | Iht. din Microsoft 365-tenant |
| 2do IT Vest hosting | Uniconta-kopidatabasen og de vedhæftninger, du uploader. | Danmark / EU |
Overførsler uden for EU/EØS (Tavily) sker på grundlag af EU-Kommissionens standardkontraktsbestemmelser. Vi videregiver kun data til offentlige myndigheder, hvor det er lovpligtigt.
6. Hvor længe de opbevares
- Samtalehistorik — de seneste 10 turer, holdt i tjenestens hukommelse. Den
slettes, når du sender
/clear, når du senderlogout, når en anden adgangsnøgle bruges, og hver gang tjenesten genstarter. - Diagnostiklogs — én registrering pr. besvaret spørgsmål, inklusive spørgsmålsteksten og de hentede data, opbevares i 14 dage og slettes derefter automatisk. Bruges udelukkende til at undersøge forkerte svar og fejl.
- Vedhæftninger — gemmes på vores filtjeneste, så længe det er nødvendigt for samtalen, og slettes på anmodning.
- Uniconta-kopi — holdes synkroniseret i din virksomheds aftaleperiode og fjernes, når aftalen ophører.
- Adgangsnøgler — skrives aldrig til samtalehistorikken og sendes aldrig til AI-leverandøren.
7. Sikkerhed
Alle forbindelser bruger TLS. Databaseadgang går gennem en autentificeret gateway, der kun tillader læseforespørgsler og afviser alt andet. Hver samtale er bundet til én virksomhed via sin adgangsnøgle, så én kundes samtale ikke kan nå en anden kundes data. Adgang til produktionssystemer er begrænset til autoriseret personale hos 2do IT Vest.
8. Dine rettigheder
Efter databeskyttelsesforordningen kan du anmode om indsigt, berigtigelse, sletning, begrænsning af behandling og dataportabilitet samt gøre indsigelse mod behandling. Da vi er databehandler for Uniconta-data, bedes du rette sådanne anmodninger til din egen virksomhed, som videresender dem til os; vi bistår hurtigst muligt. For data, vi behandler som dataansvarlig, kontakt os direkte på lv@2doit.nu. Du kan også klage til Datatilsynet.
9. Ændringer
Vi kan opdatere denne politik. Væsentlige ændringer varsles gennem Appen eller til din virksomheds kontaktperson, før de træder i kraft. Ikrafttrædelsesdatoen øverst afspejler altid den gældende version.
10. Kontakt
Spørgsmål til denne politik eller til Appens behandling af data: lv@2doit.nu. Vi tilstræber at svare inden for én hverdag.