Skip to content
Legal

Privacy Policy

Data controller

Accel Comply (CVR: DK37260312), operated by Behzad Motaghi, is the data controller for personal data collected through this website.

Accel Comply is a sole-trader practice. Throughout this privacy policy, "I," "me," and "my" refer to Behzad Motaghi personally. Where the policy uses "we" or "our," this refers to the same sole trader; there are no other data controllers or co-owners involved in this website.

Contact: bm@accelcomply.com

What we collect

When you use our website, contact form, or scoping questionnaire, we collect the information you provide. This may include:

  • Your name, work email, phone number, company, legal entity name, CVR number, and role
  • Message content, form responses, and deadline information
  • Customer or prospect names or anonymised descriptions, and customer industry
  • Contract value or ARR context, and exact or summarised customer wording
  • Document owners and roles, tooling status, and audit or assessment history
  • Infrastructure descriptions and other business information you choose to submit

Do not submit passwords, secrets, production credentials, special-category personal data, criminal-offence data, full customer contracts, regulator correspondence, or privileged legal advice unless we have expressly agreed a secure route and your company has confirmed that disclosure is permitted.

Scoping questionnaire and third-party business contacts

If you identify colleagues, document owners, customers, prospects, auditors, advisors, authorities, or other business contacts in a form response, we process that information as an independent controller for a limited set of purposes:

  • Understanding the enquiry and deciding whether a defined engagement may be relevant
  • Preparing a proposal or engagement letter
  • Conflict and admin checks
  • Protecting our legal interests

We obtain that information from the person submitting the form or from your company. We ask you to provide only business information and to anonymise or redact where required by law, NDA, customer contract, legal privilege, or internal policy.

Google Ads click identifier (gclid)

Campaign identifiers and advertising attribution are processed only after the relevant consent has been given. They are not attached to an enquiry before consent. Withdrawing or refusing marketing consent does not prevent Accel Comply from handling the enquiry itself.

Legal basis

B2B enquiry, contact-form, and scoping-questionnaire data is processed on the basis of our legitimate interests under GDPR Article 6(1)(f): responding to business enquiries, understanding the requested decision, preparing proposals, managing pre-contract communications, operating a secure website and CRM, and protecting our legal interests.

Where you personally ask us to take steps before entering into a contract with you as an individual or sole trader, GDPR Article 6(1)(b) may also apply.

Non-essential analytics, marketing cookies, pixels, remarketing, campaign attribution, and advertising conversion measurement are used only after the relevant consent has been obtained through the cookie banner.

Whether you must provide the data

Providing scoping-questionnaire data is not a statutory requirement. It is needed only to understand the current decision and determine whether a defined engagement can be proposed. If key information is missing, we may be unable to respond with a useful next step.

Cookies

This site uses three categories of cookies:

  • Necessary: Required for site security and remembering your cookie preferences.
  • Analytics: Google Analytics for site usage measurement. Requires consent.
  • Marketing: Google and LinkedIn tags for advertising and conversion tracking. Requires consent.

You can manage your cookie preferences at any time using the cookie settings link in the footer.

Data retention

Contact-form and scoping-questionnaire data for enquiries that do not become engagements is deleted or anonymised within 12 months after the last substantive contact, unless we need to retain it to establish, exercise, or defend legal claims, comply with law, or you have asked us to keep in touch.

For enquiries that become engagements, business-contact and contract-administration data is retained for the duration of the business relationship plus 2 years, unless a longer period is required by law or needed for legal claims.

Personal data processed on a client's behalf during a signed engagement is returned or deleted according to the applicable data processing agreement. Analytics data is retained for 14 months unless the cookie tool or analytics provider is configured differently.

Your rights

Depending on the circumstances, you may have rights to access, correct, delete or restrict processing of your personal data, object to processing, and receive data you provided in a portable format where Article 20 applies. You can also withdraw consent at any time. Contact bm@accelcomply.com to exercise these rights.

You have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet).

Direct marketing: phone and postal mail

This section applies if Accel Comply has contacted you by phone or postal letter without you having reached out first.

Data controller: Behzad Motaghi, trading as Accel Comply (CVR: DK37260312), Frydenlund 403, 7120 Vejle Øst, Denmark. Contact: bm@accelcomply.com.

Purpose and legal basis: the purpose is to contact relevant professionals at Danish companies about customer requirements and AI decisions, including the security, compliance and governance work those decisions may require. This processing relies on GDPR Article 6(1)(f), legitimate interest.

The concrete legitimate interest: Accel Comply has a legitimate business interest in being able to approach, directly, the people at a company whose work function makes such an advisory service relevant, without first needing to obtain consent for a single, limited, and proportionate contact.

Categories of data: name, job title, company name, work phone number, and business address. No sensitive data and no private contact details are used.

  • Where the data comes from: publicly available business sources, including the company's own website, public LinkedIn profiles, and, where the company is not registered as reklamebeskyttet (advertising-protected), the Danish Central Business Register (CVR).
  • Recipients and processors: the data is processed by Behzad Motaghi as data controller. Where relevant, processors handling this data on Accel Comply's behalf (CRM/HubSpot, hosting, print/distribution for postal mail) can be disclosed on request.
  • Retention period: the data is retained for up to 6 months from first contact, unless a client relationship is established or you object, in which case the data is deleted immediately except for the minimal record needed to honour your objection (see below).
  • Your rights: you have the right to access, correct, and delete your data, and the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk).

Your right to object (Article 21): you have an unconditional right, at any time, to object to your data being processed for direct marketing. If you object, this processing stops immediately, with no need to justify it. Email bm@accelcomply.com, say so directly during a phone call, or write to the return address shown on a letter from us.

Engagement data subjects

The work I provide to business clients can involve reviewing security, compliance or AI-related systems, documents and processes. These reviews may involve personal data belonging to the client's employees, IT staff, vendors and other individuals (collectively, "engagement data subjects").

If you are an engagement data subject, meaning your personal data has been reviewed as part of a security assessment carried out for your employer or another organisation, the following applies to you under GDPR Art. 14:

Who controls your data: The organisation that engaged Accel Comply (your employer or the commissioning organisation) is the data controller for your personal data in the engagement context. They determine what is reviewed and why. I process that data as a data processor on their behalf.

What data is involved: Typically your name, work email, job title, system access rights, usernames in log files, and similar professional information visible in the systems under review. No health, financial, or sensitive personal data is processed unless the engagement scope explicitly includes it.

Why it is processed: To assess the organisation's cybersecurity posture and compliance with applicable requirements. The legal basis is the controller's legitimate interest (Art. 6(1)(f)) or, for public-sector engagements, performance of a task in the public interest.

How to exercise your rights: Your rights of access, rectification, erasure, and objection are exercisable against the controller (the organisation that engaged me). Contact that organisation's data protection contact. I will assist the controller in responding to your request if you contact me directly: bm@accelcomply.com.

How long your data is retained: Engagement data is returned or deleted according to the signed engagement terms and any applicable data processing agreement, subject to legal retention duties.

Recipients, service providers, and international transfers

We use service providers to operate our website, forms, CRM, hosting, analytics, and marketing. Current recipients and service providers include HubSpot for CRM, forms, and the scoping questionnaire; Vercel for website hosting; Google Analytics and Google Ads where consented; and LinkedIn where consented.

HubSpot processes CRM and form data for us as a processor where it acts on our instructions. Depending on the features enabled, some HubSpot tracking or enrichment processing may be controller-to-controller processing under HubSpot's terms. Google and LinkedIn may also act as independent controllers for some analytics or marketing processing.

Personal data may be transferred outside the EU/EEA, including to the United States, through provider support, hosting, tracking, subprocessor access, or group-company access. We rely on relevant safeguards such as the EU-US Data Privacy Framework, Standard Contractual Clauses, and provider data processing terms where applicable.

Automated decision-making

We do not use automated decision-making under GDPR Article 22 to accept, reject, or price engagements.

Changes to this policy

We may update this privacy policy to reflect changes in our practices or legal requirements. The date at the bottom of the page indicates when it was last revised. Material changes will be communicated via the website.

Last updated: 31 August 2026