← Open-Leaf

Privacy Policy

Last updated 31 August 2026

1. Who we are

Open-Leaf is operated by Valuesoft ApS, a company registered in Denmark under CVR number DK26757762, with its registered address at Melanders Vænge 3, 2970 Hørsholm, Denmark.

For questions about this policy or about how we handle personal data, contact claus@valuesoft.dk.

We are not required to appoint a Data Protection Officer and have not appointed one. The contact address above reaches the person responsible for data protection.

2. Two different roles

This matters for understanding the rest of this policy, so we state it plainly rather than burying it.

We are the data controller for the account and usage data of the organisations and individuals who use Open-Leaf directly — the people who sign in to our portal. Sections 3 to 5 cover that data.

We are a data processor for the content our customers put through the service: the documents they ask us to collect, and the questions their own end users ask through the chat widget. For that content our customer is the controller and decides what happens to it; we act on their instructions. Section 6 covers that.

3. Personal data we process as controller

Account data

WhatEmail address, display name, and the subject identifier issued to you by Microsoft Entra External ID.
Where fromMicrosoft, when you sign in. We never receive your password.
WhyTo identify you, associate you with your organisation's tenant, and control access.
Legal basisPerformance of a contract (GDPR Art. 6(1)(b)).

Session data

WhatA session identifier, a CSRF token value, your tenant identifier and status, and your Microsoft account identifier — plus the Microsoft ID, access and refresh tokens issued for your sign-in, which carry your email and name. Held in Azure Managed Redis, not in the browser.
WhyTo keep you signed in and to prevent cross-site request forgery.
RetentionDeleted after 30 minutes of inactivity, or immediately when you sign out.
Legal basisPerformance of a contract, and our legitimate interest in securing the service (Art. 6(1)(b) and (f)).

Usage records

WhatRecords of operations that consume resources — documents processed, questions answered, and the compute cost of each — attributed to your organisation's tenant.
WhyTo enforce usage limits, to show you your own consumption, and for billing where applicable.
Legal basisPerformance of a contract (Art. 6(1)(b)).

Technical logs

WhatRequest timestamps, paths, response codes, error diagnostics, and IP addresses.
WhyTo operate the service, investigate faults, and detect abuse.
Legal basisOur legitimate interest in running a secure and reliable service (Art. 6(1)(f)).

4. Cookies

We use no advertising cookies and no third-party analytics. We do not run Google Analytics or any comparable product, and no advertising or data-broker network receives anything from us.

Portal sign-in cookies

Signing in to our portal sets six cookies, all strictly necessary to authenticate you and keep the session secure. All carry the __Host- prefix and are marked Secure:

The chat widget's visitor cookie

When a customer embeds our chat widget on their website, opening a chat sets one further cookie in the visitor's browser, __Host-ol_widget_visitor. It holds a random identifier — no name, no email, nothing derived from who you are — and exists so that repeated abuse of a customer's widget can be rate-limited rather than having to block everyone.

What it holdsA random 32-character identifier, generated on first use and reused on later visits.
LifetimeUp to 12 months.
Set byOur API, on the visitor's browser, while they use a widget embedded on a customer's site.
Legal basisOur and our customer's legitimate interest in preventing abuse of the service (Art. 6(1)(f)).

It is not used for advertising, profiling, or measuring you across different websites, and it is not shared with anyone. It is nonetheless a persistent identifier, so we describe it here rather than leaving it out of a cookie disclosure.

The static pages of this public site — this one, the landing page and the terms — set no cookies at all.

5. Who else processes this data

Microsoft is our only sub-processor. We do not sell personal data, we do not share it for advertising, and we do not disclose it to anyone else except where the law requires it.

Where data is processed

The platform and the language models both run in Microsoft's Sweden Central region — the databases, the session store, the API and the logs. The public website you are reading is served from Azure's global edge and holds no personal data. Where Microsoft processes data outside the EEA in the course of providing these services, it does so under the safeguards in its own data protection terms.

How the AI models are used

When a question is answered, the question and the relevant excerpts of the source document are sent to Azure OpenAI to generate the answer. Azure OpenAI is dedicated to our subscription: content sent to it is not used to train Microsoft's or OpenAI's models, and is not shared with other customers.

Microsoft additionally screens prompts and generated answers for abuse. As part of that, content may be retained by Microsoft for up to 30 days and, where automated screening flags a serious problem, reviewed by authorised Microsoft personnel. This happens inside Azure and is limited to detecting misuse — it is not used to train models or for any other purpose. We mention it because it is a genuine processing activity, not because it affects most users.

6. Customer content, where we act as processor

Our customers direct us to collect documents from sources they nominate, and their end users ask questions through the chat widget. That material can contain personal data — a manual may name its authors, and a person asking a question may type personal details into it.

We process that content only to provide the service:

We do not use customer content for our own purposes, and we do not use it to train models. Each customer's data is isolated from every other customer's.

If you are an end user who asked a question through a chat widget on someone else's website, that organisation — not us — decides how your question is handled. Please direct requests to them; we will support them in responding.

Business customers who need a written data processing agreement under GDPR Article 28 can request one at claus@valuesoft.dk.

7. How long we keep data

Session data30 minutes of inactivity, or until you sign out.
Account dataFor as long as the account is active, and deleted within 90 days of the account being closed.
Customer contentDocuments and the knowledge base built from them: for as long as the customer keeps them in the service, and deleted within 90 days of the account being closed.
Chat questionsNot retained. A question is processed to produce its answer and is not stored by us afterwards; conversation history lives in the visitor's own browser for the duration of the conversation.
Usage recordsUp to 24 months, so that consumption and billing can be reconciled.
Technical logsUp to 90 days.

We may keep data for longer where the law requires it — Danish bookkeeping rules, for example — or where it is needed to establish or defend a legal claim.

8. Your rights

Under the GDPR you have the right to:

Write to claus@valuesoft.dk. We respond within one month.

If you are unhappy with how we have handled your data you can complain to the Danish Data Protection Agency, Datatilsynet (datatilsynet.dk), Carl Jacobsens Vej 35, 2500 Valby, Denmark.

9. Security

Authentication is delegated to Microsoft Entra External ID, so no password is ever entered on or stored by our systems. Traffic is encrypted in transit, data is encrypted at rest, and each customer's data is separated from every other customer's. Access to production systems is limited to those who need it.

To report a security problem, see our security contact.

10. Children

Open-Leaf is a business service and is not directed at children. We do not knowingly collect personal data from children.

11. Changes to this policy

If we change this policy we will update the date at the top. If a change materially affects how we handle personal data, we will tell account holders directly.