| Controller | Pinploy ApS, trading as Handyhand. CVR 40021892. Registered office: Tordenskjoldsgade 14, 4. th., 1055 København K, Denmark (the privacy notice and the company register entry are to be aligned; see action plan). |
|---|---|
| Privacy contact | [email protected]. No Data Protection Officer is designated at the date of this assessment; the Article 37 assessment and appointment are in the action plan. |
| Lead supervisory authority | Datatilsynet (Denmark). The Autoriteit Persoonsgegevens (Netherlands) is the authority concerned for the NL market. Where the ICO template says 'consult the ICO', read 'consult Datatilsynet' (GDPR Article 36 prior consultation). |
| Processing assessed | The whole Handyhand service: web platform (handyhand.dk / handyhand.nl), iOS and Android app, public SEO website, admin dashboard, back-office analytics, and the notification, payment, identity-verification and AI features behind them. |
| Type of assessment | Retrospective DPIA of live processing plus forward-looking review of recent and planned features (NL market, AI features, message screening). To be repeated when nature, scope, context or purposes change materially. |
| Version / date | Version 1.0, 10 September 2026. Prepared by Saxo Merrild (management) on the basis of a technical analysis of the production codebase, the production database, the live websites, the Tag Manager container GTM-5T5GZ93 and the published privacy notice. |
| Status | Final for approval. Measures and residual risks are submitted for sign-off in Step 7. Confirmations still to be obtained and the mitigation work are scheduled in Appendix B (action plan) with an owner and a target date each. |
How to read this document
This document follows the seven steps of the ICO sample template. Each grey box repeats the template prompt; the text beneath it is Handyhand's answer. Facts were taken from the production codebase (what the system does), the production database (how much data and how many people), the live websites and Tag Manager container (what actually runs in users' browsers), and the published privacy notice (what users are told). Where these sources disagree, the disagreement is recorded as a risk and addressed in Step 6.
Handyhand is established in Denmark and operates in Denmark and the Netherlands, so the EU GDPR applies rather than the UK GDPR. The ICO method is used because it is clear and widely accepted; the substantive requirements (Articles 35 and 36) are the same, and the Danish Datatilsynet endorses the same WP248 criteria. Datatilsynet's own DPIA template and list of processing that always requires a DPIA were also checked (datatilsynet.dk/regler-og-vejledning/behandlingssikkerhed/konsekvensanalyse).