Effective date: 5 August 2026
Applies to yellow3.io, the DPP Supplier Register, the DPP Buyer Platform, advisory services and related communications.
This opening summary is provided for convenience. The complete notice below explains the processing in detail.
This Privacy Notice explains how yellow3 ApS collects, uses, discloses, stores and protects personal data when we act as data controller. It also explains the limited circumstances in which yellow3 acts as a processor for a customer using the DPP Buyer Platform.
This notice applies when you:
This notice should be read together with our Terms of Service, Cookie Policy and, where applicable, the Buyer Platform Terms and their Data Processing Addendum.
The data controller is:
yellow3 ApS
CVR no. 44954087
Hovedgaden 43
2970 Hørsholm
Denmark
Email: hello@yellow3.io
yellow3 has not appointed a data protection officer. Questions and requests concerning this notice may be sent to the address above.
yellow3 acts as controller when we determine why and how personal data is processed, including for:
When a customer places personal data inside its private DPP Buyer Platform programme, the customer normally determines the purpose of that processing. For that data, the customer is controller and yellow3 is processor.
That processing is governed by the Data Processing Addendum incorporated into the Buyer Platform Terms. The customer is responsible for its own privacy information, legal basis and instructions.
If your personal data appears in a customer programme, you should normally direct your request to that customer. Where we receive the request directly, we may forward it to the relevant customer and assist it in responding.
yellow3 may still act as controller for separate account, security, billing and legal records connected with the same Platform relationship.
Depending on your relationship with yellow3, we may process the following categories.
| Category | Examples |
|---|---|
| Identity and professional details | Name, job title, organisation, department, professional biography, role and business affiliation. |
| Contact details | Business email address, telephone number, postal address and professional social-media or repository profile. |
| Account and authentication data | User identifier, organisation, role, permissions, authentication events, login records and account-security settings. |
| Customer and transaction data | Company details, orders, contracts, invoices, subscription information, payment status and limited payment metadata. Complete card details are normally handled by the payment provider. |
| Communications | Messages, enquiries, support requests, correction submissions, evidence requests, Provider responses, meeting notes and records of consent or preferences. |
| Public research data | Public professional information, company affiliations, public statements, source URLs, publication dates, repository contributions, public filings and the provenance of a research finding. |
| Technical and usage data | IP address, device and browser information, timestamps, security events, pages or features used, diagnostic information and cookie identifiers where applicable. |
| Submitted content | Documents, logos, screenshots, evidence, questionnaires, correspondence and other material supplied to a yellow3 service. |
| Inferences and workflow records | Research classifications, proposed findings, uncertainty states, comparison criteria and records showing how an output was produced. |
We do not intentionally collect or publish special-category personal data, criminal-offence data, private residential addresses or other highly sensitive personal data through the Register. Customers must not submit such data to the Platform unless yellow3 has expressly agreed in writing and appropriate safeguards have been established.
We may obtain personal data:
Where personal data was not obtained directly from you, this section identifies the categories of sources used. Where applicable law requires individual notice, we provide it directly unless a lawful exception applies.
The table below summarises the principal purposes and legal bases. More than one basis may apply to the same record where it is used for different purposes.
| Processing activity | Purpose | Legal basis |
|---|---|---|
| Website and Platform delivery | Provide pages and features, authenticate Users, maintain sessions and respond to technical requests. | Contract, and legitimate interests in providing and operating secure services. |
| Security and misuse prevention | Protect accounts, systems, Customer Data and research datasets, investigate incidents and enforce our terms. | Legitimate interests, and legal obligations where applicable. |
| Enquiries and pre-contract communications | Respond to questions, proposals, service requests and other communications. | Steps requested before a contract, contract, or legitimate interests. |
| Customer administration and support | Create accounts, deliver purchased services, manage Users, provide support and maintain the business relationship. | Contract and legitimate interests. |
| Payments, accounting and tax | Process payments, maintain invoices and records, collect debts and meet bookkeeping and tax duties. | Contract, legal obligation and legitimate interests. |
| Public Register and independent research | Identify relevant organisations, document public evidence, publish dated findings, maintain provenance, support corrections and improve market transparency. | Legitimate interests in independent business research, transparent sourcing and maintaining an evidence-backed Register. |
| Provider profile claims and corrections | Verify authority, prevent impersonation, review evidence, publish authorised company-supplied material and retain an audit trail. | Contract or steps requested by the Provider, and legitimate interests. |
| Service improvement and analytics | Understand service performance, identify errors and improve usability, research methods and workflows. | Legitimate interests, or consent where non-essential cookies or similar technologies require it. |
| Communications and marketing | Send requested publications, event information or marketing messages and record preferences. | Consent, or another basis permitted by applicable direct-marketing law. |
| Legal and corporate matters | Comply with law, respond to authorities, conduct audits, obtain advice and establish, exercise or defend legal claims. | Legal obligation and legitimate interests. |
Where we rely on legitimate interests, we assess whether the processing is necessary and balance our interests against the rights and reasonable expectations of the individuals concerned.
Our relevant interests include:
Public Register processing is limited primarily to professional information connected with an organisation and its publicly presented capabilities. We avoid publishing unnecessary personal details and provide routes for correction and objection.
The Register concerns organisations and products. It may nevertheless contain limited professional personal data, such as the name and role of a founder, executive, author, repository contributor or authorised company representative.
Published records may include the individual’s professional affiliation, a public statement, the source in which the information appeared and the date on which yellow3 reviewed it.
Information published in the Register is available to internet users worldwide and may be indexed, quoted, archived or republished by third parties. yellow3 cannot control independent copies made lawfully by other persons, but we will correct or remove the yellow3-controlled version where required.
Where a person claims a Provider profile, we may process their name, business contact details, domain, verification records, account activity and submitted materials.
Profile verification establishes control of the relevant account, domain or organisational channel. It does not certify the individual, Provider or capability.
A Provider or individual may request correction of inaccurate personal data or object to processing based on legitimate interests. We will assess the request against the evidence, the public and commercial context, our legal obligations and any overriding legitimate grounds.
An objection does not automatically require removal of accurate public professional information. Where a current record is corrected, we may retain a restricted historical record where necessary to document provenance, prevent repeated error or establish, exercise or defend legal claims.
yellow3 acts as controller for Platform User accounts, access administration, subscription management, billing, support, service communications, security monitoring and enforcement of the Buyer Platform Terms.
Programme material entered or uploaded by a customer is buyer-private. For personal data in that material, yellow3 normally acts as processor on the customer’s documented instructions.
We do not disclose which buyers are assessing a Provider, or that a Provider is being assessed, unless the buyer chooses to send an evidence request, instructs disclosure or disclosure is required by law.
A Provider response supplied for a specific buyer engagement is kept within that engagement and is not automatically published as a general Register finding.
A public fact independently established from a public source may be retained as Independent Research, but the buyer’s identity, requirements, private context, negotiated commitments and confidential correspondence are not reused as general research.
The customer controls the principal retention and deletion instructions for Customer Personal Data. Default Platform retention is described in the Buyer Platform Terms and Data Processing Addendum.
yellow3 may retain separate controller records for billing, security, support and legal purposes under this notice.
yellow3 may use automated systems and artificial intelligence to assist with research, extraction, classification, drafting, comparison, workflow execution, inconsistency detection and preparation of proposed findings or outputs.
When personal data is processed through an artificial-intelligence service:
yellow3 does not use buyer-private programme data to train or fine-tune a general-purpose, shared or publicly available model unless the customer has expressly agreed in writing.
yellow3 does not make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning an individual. The Platform supports organisational procurement and programme decisions. The relevant customer remains responsible for the decision it makes.
We may disclose personal data to the following categories of recipient where necessary:
Current service providers may include Vercel for website and application hosting, Supabase for database, authentication and storage services, Stripe for payments and fraud prevention, Resend for outbound email delivery (including sign-in links, invitations, evidence requests to providers and enquiry notifications), and OpenAI business or API services for authorised artificial-intelligence processing.
The specific suppliers used may change. For Buyer Platform processing, an up-to-date subprocessor list is available on request or through the Platform where provided.
We do not sell or rent personal data and do not disclose it to third parties for their independent advertising purposes.
Some recipients or infrastructure providers may process personal data outside Denmark or the European Economic Area.
Where the GDPR requires transfer safeguards, we rely on one or more of:
You may contact us for information about the safeguards relevant to a particular transfer. Commercially sensitive and security-related information may be provided in a redacted or summarised form.
Because the Register is public, personal data intentionally published there can be accessed from any country. That public availability is different from yellow3 appointing a service provider to process data outside the European Economic Area.
We use cookies and similar technologies to provide essential Website and Platform functions, maintain security and, where enabled, understand service usage.
Strictly necessary technologies may be used without consent where permitted by law. Non-essential analytics, preference or marketing technologies are used only where the required consent has been obtained.
Further information is provided in our Cookie Policy. You may withdraw a cookie consent through the consent controls made available on the Website. Browser deletion alone may not record your withdrawal for future visits.
Service communications, security notices, invoices and messages necessary to administer an account or deliver a purchased service are not marketing communications.
We send newsletters, event announcements and other marketing messages where you have requested them, consented, or another lawful basis is available under applicable direct-marketing rules.
You may unsubscribe through the link in a marketing email or by contacting us. We may retain a minimal suppression record so that we continue to respect the opt-out.
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security, research-integrity and claims requirements.
| Record type | Typical retention |
|---|---|
| Website security and server logs | Normally up to 12 months, unless a longer period is needed to investigate an incident or establish a legal claim. |
| Contact forms and general enquiries | Normally 12 months after the matter is closed, or longer where the communication leads to a customer relationship, dispute or legal obligation. |
| Customer accounts and relationship records | For the active relationship and normally up to 24 months afterwards, subject to longer contractual, legal or claims records. |
| Contracts, invoices and bookkeeping material | At least five years from the end of the financial year to which the material relates, or longer where another legal duty applies. |
| Marketing records | Until consent is withdrawn or the communication is no longer relevant. A limited suppression record may be retained afterwards. |
| Provider claim and verification records | For the life of the claimed profile and normally up to 24 months afterwards. Material fraud, correction or dispute records may be kept for the applicable limitation period. |
| Public Register findings and source records | Current findings are retained while relevant to the Register. Superseded findings and provenance records are reviewed and may be retained for up to seven years where needed for research integrity, corrections or legal claims. |
| Buyer Platform Customer Personal Data | As instructed by the customer and described in the Buyer Platform Terms and Data Processing Addendum. Separate yellow3 controller records follow this notice. |
| Backups | Deleted data may remain in protected rolling backups for a limited period, normally no more than 90 days, before being overwritten. |
| Legal and security records | For as long as necessary to meet a legal duty or establish, exercise or defend a legal claim. |
A shorter or longer period may apply where required by law, requested by the relevant controller, necessary for an active investigation or justified by the nature of a historical research record.
At the end of the applicable period, personal data is deleted, anonymised or placed beyond ordinary use, subject to protected backups and lawful archival or claims requirements.
Subject to the conditions and exceptions in applicable law, you may have the right to:
These rights are not absolute. For example, we may retain data where processing is required by law, necessary for legal claims, protected by freedom-of-expression or information rules, or supported by compelling legitimate grounds.
Where you object to processing based on legitimate interests, we will stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is required for legal claims.
To protect you and other Users, we may request information necessary to verify your identity and authority. We normally respond within one month. The period may be extended by up to two additional months for a complex or numerous request, in which case we will inform you.
We do not normally charge for a request. A reasonable fee may be charged, or a request may be refused, where it is manifestly unfounded or excessive as permitted by law.
Please contact yellow3 first so that we have an opportunity to address your concern.
You may also complain to the Danish Data Protection Agency, Datatilsynet, or another competent supervisory authority. Datatilsynet’s complaint information is available online.
Datatilsynet’s contact details are:
Datatilsynet
Carl Jacobsens Vej 35
2500 Valby
Denmark
Telephone: +45 33 19 32 00
Email: dt@datatilsynet.dk
yellow3 implements technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access.
Measures may include:
No online service can guarantee absolute security. You are responsible for protecting your credentials, using appropriate account settings and notifying us promptly of suspected unauthorised access.
Customer-private programme material and non-public business communications are handled as confidential information under the applicable agreement.
Public Register sources, public statements and company-supplied material intended for publication are not confidential merely because they concern an organisation or professional representative.
Do not send trade secrets, private personal information or information you are not authorised to disclose through a public profile, public correction route or ordinary email.
yellow3’s services are designed for organisations and professional users. They are not directed to children, and we do not knowingly offer accounts or paid services to persons under 18.
If you believe a child has supplied personal data to us without appropriate authority, contact us so that we can investigate and take appropriate action.
Our websites and research may link to third-party websites, repositories, documents or services. Those third parties determine their own processing and are responsible for their privacy information.
A link or source citation does not mean that yellow3 controls or endorses the third party’s privacy practices.
We may update this Privacy Notice to reflect changes to our services, technology, suppliers, research methods or legal obligations.
The current version will be published at yellow3.io/privacy with its effective date. Where a change materially affects an active paid service or requires new consent, we will provide additional notice where appropriate.
For questions, rights requests or privacy concerns, contact:
yellow3 ApS
Hovedgaden 43
2970 Hørsholm
Denmark
CVR no. 44954087
Email: hello@yellow3.io
Website: www.yellow3.io
For a correction relating to a public Register profile, you may also use the correction route displayed on the relevant profile. For personal data controlled by a Buyer Platform customer, please contact that customer first.