Point InsertionSoftware studio

Privacy Policy

Last updated 6 September 2026

Point Insertion ApS is a one-person software studio. This policy explains what happens to personal data on this website and in the software we operate — including the applications we use to reach our own Google accounts.

Who we are

Point Insertion ApS is the data controller for the processing described here.

Point Insertion ApS
Sjællandsgade 28, sal 1 · 8000 Aarhus C · Denmark
CVR 44984636
hello@point-insertion.com

This website

point-insertion.com is a static site. It sets no cookies, runs no analytics, embeds no tracking pixels, and has no accounts or forms. There is nothing here for you to log into and nothing that follows you afterwards.

Two things still involve third parties, and you should know about both:

  • Hosting. The site runs on Cloudflare, which processes request metadata — IP address, user agent, timestamp — in order to serve pages and to protect the site from abuse. Cloudflare acts as our data processor. Their handling is described in Cloudflare's privacy policy.
  • Fonts. Typefaces are loaded from Google Fonts, so your browser makes a request to Google's servers and Google receives your IP address as part of it. We would rather it didn't, and we may self-host the fonts in future. If you would prefer to avoid it now, block requests to fonts.googleapis.com and fonts.gstatic.com.

If you email us, we keep the correspondence for as long as we need it to deal with what you wrote about, and no longer.

The Google Workspace integration

Point Insertion operates an internal application, registered with Google, that connects to Google accounts we own and administer ourselves. It exists so that our own tooling can read and write our own mail, calendars, files, contacts, tasks and meetings.

This application is not offered to the public. It is used only by Point Insertion, only against Google accounts belonging to Point Insertion and its owner. We do not connect it to anyone else's account, and we do not process third parties' Google data through it.

How it works in practice:

  • Access is granted through Google's standard OAuth consent flow, by us, as the holder of the accounts involved.
  • The resulting access and refresh tokens are stored on the operator's own device. They are not held on a Point Insertion server, and there is no Point Insertion service sitting between the device and Google.
  • Data retrieved from Google is processed locally, on that device, to carry out whatever task was asked for. It is not copied to our servers, not used to train machine-learning models, not sold, and not shared with third parties.
  • Access can be withdrawn at any time from the Google account permissions page, which immediately invalidates the tokens.

Limited Use disclosure

Point Insertion's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Legal basis for processing

  • Website and hosting logs — our legitimate interest in running a website and keeping it available and secure (GDPR Art. 6(1)(f)).
  • Email correspondence — our legitimate interest in answering people who contact us, or the steps leading to a contract (Art. 6(1)(f) and 6(1)(b)).
  • The Workspace integration — this concerns our own accounts and our own data, accessed with our own consent as the account holder (Art. 6(1)(a) and 6(1)(f)).

How long we keep things

  • Hosting and security logs: retained by Cloudflare under their own schedule, typically days rather than months.
  • Email: kept while the matter is live, then archived or deleted.
  • OAuth tokens: kept on the operator's device until access is revoked or the local credential store is deleted.

Your rights

If we hold personal data about you, you have the right to ask for a copy of it, to have it corrected or erased, to restrict or object to how we use it, and to receive it in a portable form. Write to hello@point-insertion.com and we will answer within a month.

If you think we have handled your data badly, you are entitled to complain to the Danish Data Protection Agency, Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby.

Changes to this policy

If this policy changes, the date at the top changes with it. There is no mailing list to notify, so the date is the honest record.