Privacy Policy

We, Trolle Advokatfirma Advokatpartnerselskab, are the data controller for the processing of your personal data, and we are therefore obliged to provide you with a number of pieces of information.

The purpose of the present document is therefore to inform you of the personal data we have received about you — that is, information received from our website, which we have received from you, when you visit our website, and information we may have received or obtained from third parties — and to inform you of the rights you have under the General Data Protection Regulation.

The information we must provide you with is as follows:

• How to contact us?
• The purposes and legal basis for the processing of your personal data.
• Categories of personal data.
• Any recipients or categories of recipients.
• The source of your personal data.
• Particular notes on our obligations under the Anti-Money Laundering Act.
• Website.
• Parties, counterparties, representatives, and other third parties.
• Particular notes regarding bankruptcy, debt relief, compulsory dissolution, reconstruction, and liquidation proceedings (“estate matters”).
• Period for storage of your personal data.
• The right to withdraw consent.
• Your rights.
• Whether providing personal data is required by law and the possible consequences of not providing such information.
• Security.
• Changes to the privacy policy.
• Complaints to the Danish Data Protection Authority (Datatilsynet).

How to contact us?
Our contact details are as follows:

Trolle Advokatfirma Advokatpartnerselskab
Vesterballevej 25, 2.
7000 Fredericia
CVR no.: 34 89 04 04
Phone: 70 15 15 32
Email: info@trolle-law.dk

The purposes and legal basis for the processing of your personal data.
We process your personal data in connection with our case handling and for use in our advisory services.

This may be in relation to you as a client or in relation to you as a data subject within the meaning of the GDPR. That is, even if you are not a client with us, we may have an obligation to provide you with a number of pieces of information about the processing of your personal data.

The legal basis for our processing of ordinary personal data follows from Article 6(1)(a)–(f) of the GDPR, the Danish Data Protection Act, the Bookkeeping Act, the VAT Act, the Archives Act, and the rules of professional conduct for Danish attorneys.

If our processing of your personal data requires the processing of sensitive personal data, the legal basis for our processing is Article 9(2)(a), (f), and (j) of the GDPR, and/or information about criminal offences pursuant to section 8(3) and (4) of the Danish Data Protection Act, if the circumstances of the case or cases we have undertaken make it necessary. This may be the case, for example, in insurance/compensation matters.

If we are required to make registrations in public authorities’ databases via portals such as virk.dk or tinglysningen.dk, it may be necessary to process your CPR number, cf. section 11(2) of the Danish Data Protection Act.

We do not use personal data for automated decision-making, including profiling.

Categories of personal data.
We process only the personal data necessary for us to handle your case or our client’s case.

In order for us to handle the case, we need your master data: name, address, phone number, email address, possibly CPR number, and possibly CVR number. In addition, we process information about financial circumstances, including payment information and tax information.

As a general rule, we do not process sensitive personal data unless it is necessary for our case handling.

Any recipients or categories of recipients.
We may disclose your personal data to the following recipients:
The counterparty, the counterparty’s representative, witnesses, expert valuers, the courts, insurance companies, appeal boards, industry organisations, public authorities, credit bureaus, Epona A/S, Zantio IT A/S, secure document destruction companies, and archiving bureaus.

The source of your personal data.
Your personal data comes from information you provide to us, or from information we collect/receive from third parties.

Particular notes on our obligations under the Anti-Money Laundering Act.
As a law firm, we are subject to obligations under the Danish Anti-Money Laundering Act (Hvidvaskloven) in connection with certain of our legal services, and we will therefore also process your personal data in this connection, including identification information such as name, CPR number, passport number, nationality, etc. If you or your business is a client with us, you may therefore be asked to provide documentation of who you are, or to assist in identifying the beneficial owners of your employer.

We process only information obtained under the Anti-Money Laundering Act — identification information and information about the business relationship — for the purpose of fulfilling our obligations under this Act. The information is not used for commercial purposes. The legal basis for this processing is the Anti-Money Laundering Act.

Website.
When you use our website, cookies may be used to collect information about, for example, user behaviour, browser type, device category, information about your preferred settings, and IP address.
Processing for marketing purposes is based on Article 6(1)(a) of the GDPR (consent).
Processing for other purposes, such as website visit statistics, optimisation of functionality, and similar, is based on Article 6(1)(f) of the GDPR (the balancing of interests rule), where the legitimate interest of Trolle Law is to develop and maintain a relevant website that functions optimally.
You can change your choices regarding cookie placement and withdraw any consents by clicking on the round icon in the lower left corner of your screen.

Parties, counterparties, representatives, and other third parties.
If you are a party, counterparty, representative, or other third-party actor in a case that Trolle Law handles, we generally process your information in order to be able to assist our client in the case concerned.
We may process your identification, contact, and professional information, including name, email address, phone number, your private address, your position, your relation to the case, and other ordinary personal data that forms part of the case, such as financial information.

The legal basis for our processing is our legitimate interest as attorneys in assisting our client with the handling of the case, cf. Article 6(1)(f) of the GDPR. In certain cases, the legal basis may also be compliance with a legal obligation, cf. Article 6(1)(c) of the GDPR.
Depending on the specific circumstances of the case or cases we are assisting with, we may also process sensitive personal data about you, cf. Article 6(1)(f) and Article 9(2)(f) of the GDPR, information about criminal offences, cf. section 8(3) and (4) of the Danish Data Protection Act, and/or information about your CPR number, cf. Article 6(1)(f) and Article 9(2)(f) of the GDPR, cf. section 11(2)(4) of the Danish Data Protection Act, cf. section 7(1).
We may also process your sensitive personal data if you have made it public yourself and it is relevant to the case we are handling, cf. Article 6(1)(f) and Article 9(2)(e) of the GDPR.

Particular notes regarding bankruptcy, debt relief, compulsory dissolution, reconstruction, and liquidation proceedings (“estate matters”)

In connection with our obligations in the above-mentioned cases, we are the data controller for the processing of personal data that we have received and collected in connection with the interests of the estate. We will process information about the bankruptcy estate’s owners, board members, management members, employees, customers, suppliers, etc. In some cases, we may be appointed by the Bankruptcy Court (Skifteretten) to handle debt relief cases, in which case we will process personal data for the purpose of assisting the Bankruptcy Court with the debt relief.

When we enter as trustee, we will process a number of ordinary personal data, including name, position, private and work-related contact information, email, address, and phone number. In connection with the handling, we may process information relating to employment, including but not limited to employment contracts, working hours, salary, tax, and financial information, CPR numbers of debtors, employees, and management members. In most cases, we will need to process a number of sensitive personal data, including trade union affiliations, health information, etc. There may be situations where we need to process information about criminal offences.

The sources of the information are primarily from yourself or your employer. The information may also originate from a public authority.

We process your personal data in order to comply with the legal obligations we assume when we assist the Bankruptcy Court and enter as trustee or reconstructor, cf. Article 6(1)(c) and (e) of the GDPR. Our processing may furthermore take place on the basis of the balancing of interests rule, Article 6(1)(f) of the GDPR. The legitimate interests we pursue are our exercise of the legal profession.

Our legal basis for processing CPR numbers is in accordance with the legislation applicable in the area, cf. section 11(2)(1) of the Danish Data Protection Act. When we disclose your CPR number, it takes place as a natural part of operations and is of crucial importance for the identification of the data subject, and it takes place where the interest outweighs the consideration for the data subject, cf. section 11(2)(3) of the Danish Data Protection Act.

We process your sensitive personal data in order to pursue, establish, or defend a legal claim, cf. Article 9(2)(f) of the GDPR. We process your personal data in order to comply with the legal obligations we assume when we assist the Bankruptcy Court and enter as trustee or reconstructor, cf. Article 9(2)(g) of the GDPR. Information about criminal offences is processed when it is necessary for the interests of the case and the interest outweighs the consideration for the data subject, cf. section 8(3) of the Danish Data Protection Act. In addition, information about criminal offences may be processed in order to pursue, establish, or defend a legal claim, cf. section 8(5) of the Danish Data Protection Act.

As a general rule, we do not disclose your personal data to third parties. If an authority — for example the Bankruptcy Court, the Debt Collection and Tax Administration, the Police, or similar — takes an interest in the case, we are obliged under the rules of the Bankruptcy Act and the Companies Act to disclose the information to the authorities concerned. In addition, the transfer may take place as part of the case handling, for example to external legal advisers who assist in the handling, co-trustees, and similar.

We retain your personal data for as long as is necessary for the purpose or purposes for which the data is processed. As a general rule, the data is retained for 10 years after the conclusion of the case, but in special cases there may be shorter or longer retention periods in order to comply with legal requirements for deletion or storage.

Period for storage of your personal data.
We cannot at present say how long we will retain your personal data. As a general rule, we retain personal data for 10 years after a case is finally concluded.

When we determine how long your information will be retained, we will take into account whether disagreement has arisen regarding the case handling, and how long we risk being met with claims in connection with the handling of the case.

The right to withdraw consent.
You have the right at any time to withdraw your consent, if the lawfulness of our processing is based on your consent. You can do this by contacting us at the contact details provided above.

If you withdraw your consent, we are no longer entitled to process your personal data, unless we can demonstrate lawful grounds for continued processing.

Your rights.
Under the GDPR, you have a number of rights in relation to our processing of information about you.

If you wish to exercise your rights, please contact us — preferably in writing so that we can avoid any ambiguities.

Your rights are as follows:

a. Right of access to information, cf. Article 15.
You are entitled at any time to request information from us about, among other things, what information we have registered about you, what purpose the registration serves, what categories of personal data and recipients of information there may be, as well as information about the source of the information.

b. Right to rectification (correction), cf. Article 16.
You have the right to have inaccurate personal data about yourself rectified.

c. Right to erasure, cf. Article 17.
In certain cases, you have the right to have all or some of your personal data deleted.

To the extent that the processing of your information is necessary for our handling, we are not obliged to delete your personal data.

d. Right to restriction of processing, cf. Article 18.
In certain cases, you have the right to have the processing of your personal data restricted to storage only, if you, for example, believe that the information we are processing about you is incorrect.

If you have the right to restriction of processing, we may in future only process the information — apart from storage — with your consent, or for the purpose of establishing, exercising, or defending legal claims, or for the protection of a person or important social interests.

e. Right to object, cf. Article 21.
In certain cases, you have the right to object to our otherwise lawful processing of your personal data.

If you object to the processing, we are no longer entitled to process your personal data, unless we can demonstrate lawful grounds for continued processing.

f. Right to transmit information (data portability), cf. Article 20.
In certain cases, you have the right to receive your personal data without hindrance in a structured, commonly used, and machine-readable format, and to have this personal data transferred to another data controller.

You can read more about your rights in the Danish Data Protection Authority’s guidance on the rights of data subjects, which you can find at www.datatilsynet.dk.

Whether providing personal data is required by law and the possible consequences of not providing such information.
In order to handle your case, we need you to answer our questions, including providing master data.

Otherwise, this may mean that we cannot take on the case.

Security.
We have implemented appropriate technical and organisational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, or impairment, as well as against unauthorised access or misuse.

It should be noted that all employees and partners are subject to a duty of confidentiality.

If you need to send us sensitive personal data, we recommend that you use encryption, for example secure email or a password-protected file (Word or PDF format).

Changes to the privacy policy
There may be a need to update this external privacy policy, and we continuously ensure that it is up to date, accurate, and in compliance with applicable legislation and the principles of lawful processing of personal data.

The right to complain.
You have the right at any time to lodge a complaint with the Danish Data Protection Authority, Carl Jacobsens Vej 35, 2500 Valby, email: dt@datatilsynet.dk, phone: 33 19 32 00, regarding our processing of your personal data.

Info

  • Trolle Fredericia Vesterballevej 25 DK-7000 Fredericia
  • Trolle Vejle Damhaven 1 DK-7100 Vejle
  • Trolle Middelfart The Platform Jernbanegade 57 DK-5500 Middelfart
  • Trolle Odense Asylgade 9 DK-5000 Odense
  • Trolle Haderslev Ole Rømers Vej 30 DK-6100 Haderslev
  • Contact info
    +45 70 15 15 32info@trolle-law.dk
    Middelfart Sparekasse
    0755 7550009121
    CVR nr.: 34 89 04 04