Privacy Policy
Last updated 31 August 2026
1. Who we are
Open-Leaf is operated by Valuesoft ApS, a company registered in Denmark under CVR number DK26757762, with its registered address at Melanders Vænge 3, 2970 Hørsholm, Denmark.
For questions about this policy or about how we handle personal data, contact claus@valuesoft.dk.
We are not required to appoint a Data Protection Officer and have not appointed one. The contact address above reaches the person responsible for data protection.
2. Two different roles
This matters for understanding the rest of this policy, so we state it plainly rather than burying it.
We are the data controller for the account and usage data of the organisations and individuals who use Open-Leaf directly — the people who sign in to our portal. Sections 3 to 5 cover that data.
We are a data processor for the content our customers put through the service: the documents they ask us to collect, and the questions their own end users ask through the chat widget. For that content our customer is the controller and decides what happens to it; we act on their instructions. Section 6 covers that.
3. Personal data we process as controller
Account data
| What | Email address, display name, and the subject identifier issued to you by Microsoft Entra External ID. |
|---|---|
| Where from | Microsoft, when you sign in. We never receive your password. |
| Why | To identify you, associate you with your organisation's tenant, and control access. |
| Legal basis | Performance of a contract (GDPR Art. 6(1)(b)). |
Session data
| What | A session identifier, a CSRF token value, your tenant identifier and status, and your Microsoft account identifier — plus the Microsoft ID, access and refresh tokens issued for your sign-in, which carry your email and name. Held in Azure Managed Redis, not in the browser. |
|---|---|
| Why | To keep you signed in and to prevent cross-site request forgery. |
| Retention | Deleted after 30 minutes of inactivity, or immediately when you sign out. |
| Legal basis | Performance of a contract, and our legitimate interest in securing the service (Art. 6(1)(b) and (f)). |
Usage records
| What | Records of operations that consume resources — documents processed, questions answered, and the compute cost of each — attributed to your organisation's tenant. |
|---|---|
| Why | To enforce usage limits, to show you your own consumption, and for billing where applicable. |
| Legal basis | Performance of a contract (Art. 6(1)(b)). |
Technical logs
| What | Request timestamps, paths, response codes, error diagnostics, and IP addresses. |
|---|---|
| Why | To operate the service, investigate faults, and detect abuse. |
| Legal basis | Our legitimate interest in running a secure and reliable service (Art. 6(1)(f)). |
4. Cookies
We use no advertising cookies and no third-party analytics. We do not run Google Analytics or any comparable product, and no advertising or data-broker network receives anything from us.
Portal sign-in cookies
Signing in to our portal sets six cookies, all strictly necessary to
authenticate you and keep the session secure. All carry the
__Host- prefix and are marked Secure:
- a session identifier;
- a CSRF token, checked on every state-changing request;
- four short-lived values used only during sign-in (OAuth state, nonce, PKCE verifier, and the page you were heading to), discarded as soon as sign-in completes.
The chat widget's visitor cookie
When a customer embeds our chat widget on their website, opening a chat
sets one further cookie in the visitor's browser,
__Host-ol_widget_visitor. It holds a random identifier — no
name, no email, nothing derived from who you are — and exists so that
repeated abuse of a customer's widget can be rate-limited rather than
having to block everyone.
| What it holds | A random 32-character identifier, generated on first use and reused on later visits. |
|---|---|
| Lifetime | Up to 12 months. |
| Set by | Our API, on the visitor's browser, while they use a widget embedded on a customer's site. |
| Legal basis | Our and our customer's legitimate interest in preventing abuse of the service (Art. 6(1)(f)). |
It is not used for advertising, profiling, or measuring you across different websites, and it is not shared with anyone. It is nonetheless a persistent identifier, so we describe it here rather than leaving it out of a cookie disclosure.
The static pages of this public site — this one, the landing page and the terms — set no cookies at all.
5. Who else processes this data
Microsoft is our only sub-processor. We do not sell personal data, we do not share it for advertising, and we do not disclose it to anyone else except where the law requires it.
- Microsoft Azure — hosting, databases and storage.
- Microsoft Entra External ID — authentication.
- Azure OpenAI Service — the language models that read documents and generate answers.
Where data is processed
The platform and the language models both run in Microsoft's Sweden Central region — the databases, the session store, the API and the logs. The public website you are reading is served from Azure's global edge and holds no personal data. Where Microsoft processes data outside the EEA in the course of providing these services, it does so under the safeguards in its own data protection terms.
How the AI models are used
When a question is answered, the question and the relevant excerpts of the source document are sent to Azure OpenAI to generate the answer. Azure OpenAI is dedicated to our subscription: content sent to it is not used to train Microsoft's or OpenAI's models, and is not shared with other customers.
Microsoft additionally screens prompts and generated answers for abuse. As part of that, content may be retained by Microsoft for up to 30 days and, where automated screening flags a serious problem, reviewed by authorised Microsoft personnel. This happens inside Azure and is limited to detecting misuse — it is not used to train models or for any other purpose. We mention it because it is a genuine processing activity, not because it affects most users.
6. Customer content, where we act as processor
Our customers direct us to collect documents from sources they nominate, and their end users ask questions through the chat widget. That material can contain personal data — a manual may name its authors, and a person asking a question may type personal details into it.
We process that content only to provide the service:
- to collect, read and structure the documents a customer nominates;
- to answer questions from the resulting knowledge base;
- to keep the service running and secure.
We do not use customer content for our own purposes, and we do not use it to train models. Each customer's data is isolated from every other customer's.
If you are an end user who asked a question through a chat widget on someone else's website, that organisation — not us — decides how your question is handled. Please direct requests to them; we will support them in responding.
Business customers who need a written data processing agreement under GDPR Article 28 can request one at claus@valuesoft.dk.
7. How long we keep data
| Session data | 30 minutes of inactivity, or until you sign out. |
|---|---|
| Account data | For as long as the account is active, and deleted within 90 days of the account being closed. |
| Customer content | Documents and the knowledge base built from them: for as long as the customer keeps them in the service, and deleted within 90 days of the account being closed. |
| Chat questions | Not retained. A question is processed to produce its answer and is not stored by us afterwards; conversation history lives in the visitor's own browser for the duration of the conversation. |
| Usage records | Up to 24 months, so that consumption and billing can be reconciled. |
| Technical logs | Up to 90 days. |
We may keep data for longer where the law requires it — Danish bookkeeping rules, for example — or where it is needed to establish or defend a legal claim.
8. Your rights
Under the GDPR you have the right to:
- ask what personal data we hold about you, and get a copy;
- have inaccurate data corrected;
- have data erased;
- restrict or object to how we process it;
- receive data you gave us in a portable format;
- withdraw consent, where processing rests on consent.
Write to claus@valuesoft.dk. We respond within one month.
If you are unhappy with how we have handled your data you can complain to the Danish Data Protection Agency, Datatilsynet (datatilsynet.dk), Carl Jacobsens Vej 35, 2500 Valby, Denmark.
9. Security
Authentication is delegated to Microsoft Entra External ID, so no password is ever entered on or stored by our systems. Traffic is encrypted in transit, data is encrypted at rest, and each customer's data is separated from every other customer's. Access to production systems is limited to those who need it.
To report a security problem, see our security contact.
10. Children
Open-Leaf is a business service and is not directed at children. We do not knowingly collect personal data from children.
11. Changes to this policy
If we change this policy we will update the date at the top. If a change materially affects how we handle personal data, we will tell account holders directly.