Skip to content
AboutLogin
AboutLogin

Privacy Policy

Last updated: 21 September 2026

PILLAR is provided by:

  • PILLAR Relocation ApS
  • CVR 46773705
  • Lavetten 47, 4100 Ringsted, Denmark
  • Contact, including privacy and data requests: support@pillarrelocation.com

PILLAR is a software platform used by relocation management companies to run international employee relocations. It holds the cases, tasks, documents, appointments and communications that make up a relocation from start to finish, and it includes an AI assistant that helps the people working on a case.

This page explains what personal data passes through PILLAR, why it is there, who decides what happens to it, how long it is kept, and what rights people have. If anything is unclear, write to us and we will explain it.

Our role: who decides what happens to the data

Section titled “Our role: who decides what happens to the data”

PILLAR has two different roles, and it matters which one applies to you.

We are a data processor for everything inside a customer’s workspace. That means the relocation cases and the people in them. Our customer is the relocation management company that signed up for PILLAR. That company decides what data is collected and why, usually because an employer has engaged it to move an employee. We only handle the data to run the service on the customer’s instructions. The customer’s own privacy notice governs that data, not this one.

We are a data controller for our own business data. Here we decide, and this page applies directly. This covers:

  • Our customers’ account and contact details, billing records and support correspondence.
  • Feedback sent to us from inside the product. When a user sends feedback, we receive the message, the area of the product it is about, an optional screenshot, and whether the user agreed to be contacted. We use it to improve the product and to reply if the user asked us to.
  • Enquiries sent through the “Try PILLAR” form: your first name, last name, email address and message. On www.pillarrelocation.com the form sends these to our server, which emails them to us through SendGrid; the server also uses your IP address to limit how many requests one address can send in a short period, and records the address only when it blocks a request. On the documentation site at app.pillarrelocation.com/docs, the form opens an email in your own mail program instead, and we receive only what you choose to send.
  • Our websites.

If you are a relocating employee or a family member and want to know why your data is in PILLAR, the company handling your relocation holds the answer. Write to us and we will point you to them.

  • Relocating employees (transferees)
  • Their dependents, including family members and children
  • Emergency contacts named by a transferee
  • Case managers and other staff at the relocation company
  • Field agents who carry out tasks locally
  • HR and other contacts at the employer
  • People who write to a customer’s shared case mailbox, when the customer has switched inbound email capture on (see below)
  • Identity and contact details
  • Immigration documentation, including passports, visas and residence permits
  • Family and dependent details
  • Addresses and relocation destinations
  • Employment details such as job title, current employer and, where the customer records it, a salary range
  • Case tasks, notes and appointments
  • Documents uploaded or imported by users, and the details read out of them
  • Email correspondence filed to a case
  • Sign-in and activity records needed to keep the service secure

Immigration paperwork is detailed and personal by nature, so we treat everything in a case as confidential.

Some of what a relocation needs is data the GDPR treats as especially sensitive. PILLAR can hold:

  • Health information. A transferee record has fields for medical conditions and for special accommodation or accessibility needs. A document can be filed under the category “medical records”.
  • Criminal-record certificates. Police clearance certificates are a common immigration requirement and have their own document category.
  • Data that may reveal other sensitive matters indirectly — for example, a marriage certificate or a passport can reveal nationality, and dependent records can reveal family circumstances.

These fields are optional. The customer decides whether to record them, and needs a lawful reason under Article 9 or Article 10 of the GDPR to do so — usually the explicit consent of the person, or a legal requirement of the immigration process. The health fields are encrypted at field level in production (see “How we protect it”), on top of the protection every other field has.

Passport photos are not biometric data in our hands. PILLAR stores the scan a user uploads and reads the printed text off it. It does not process the photo to identify or verify a person, so it does not process biometric data in the GDPR sense.

  • Directly from users — a case manager, agent, employer contact or transferee types it in or uploads a document.
  • Read out of documents. When a document is processed, PILLAR reads details such as names, document numbers and dates out of it. Those details are shown as suggestions; nothing is written onto the person’s record until a person reviews and saves them.
  • From a customer’s connected services. If a customer connects its Microsoft 365 organisation, PILLAR can read the customer’s staff directory (names, email addresses and job titles) so that administrators can invite colleagues, and can show staff profile photos. See “Services the customer connects”.
  • From email. If a customer switches inbound email capture on, PILLAR reads the messages sent to that customer’s shared case mailbox. That is how we come to hold data about people who have never used PILLAR, such as a landlord, a school or a lawyer who wrote to the mailbox.
  • From other people. A transferee’s dependents and emergency contacts are usually entered by the transferee or the case manager, not by the person concerned. Employer contacts are entered by the relocation company.

If you have never used PILLAR and your data is in it, one of the last three routes is how it got there. The relocation company that runs the case is the controller for it.

Section titled “Why we process it, and on what legal basis”

As a processor, we process case data only on documented instructions from the customer. The legal basis for that processing belongs to the customer — typically the relocation or employment agreement, a legal obligation such as an immigration filing, or their legitimate interests. They are the ones who must be able to explain it.

As a controller, for our own data:

WhatWhyLegal basis
Account and contact details of customer staffTo provide and support the servicePerformance of a contract
Billing and accounting recordsTo invoice, and to keep the books for as long as Danish bookkeeping law requiresLegal obligation
Security, availability and fraud prevention, including sign-in and audit recordsTo keep the service working and safeLegitimate interests
In-product feedbackTo improve the product and reply if askedLegitimate interests
Website enquiriesTo answer youSteps taken at your request before a contract
Website analytics on www.pillarrelocation.comTo understand how the website is usedConsent

PILLAR runs on Microsoft Azure in the Sweden Central region, inside the EU. The application, the database, file storage, the cache and the sign-in service all sit there. Database backups are copied to Azure’s paired region, Sweden South, which is also inside the EU.

These are the companies that handle personal data on our behalf to deliver the service. This is the current list. We will tell customers before we add one.

ProviderWhat it doesWhere
Microsoft AzureCloud hosting, database, file storage, cache, and the sign-in service (Keycloak, open-source identity software that we run ourselves inside Azure)Sweden Central, EU
Microsoft Foundry (Azure OpenAI)The in-product AI assistant, and part of document readingEU Data Boundary — see “How the AI features use data”
Azure AI Document IntelligenceReading the text out of uploaded documentsSame region as our Azure resource, EU
SendGrid (Twilio)Delivering the emails PILLAR sends, such as invitations and notificationsSee “International data transfers”
BoldSign (Syncfusion)Electronic signatures on documents that need signingSee “International data transfers”

The certifications each of these providers holds are listed on our Security page.

The platform and its data are hosted in the EU. Our Microsoft services run under Microsoft’s Data Protection Addendum, and our AI processing stays within Microsoft’s EU Data Boundary (the EU plus EFTA countries such as Norway and Switzerland).

SendGrid and BoldSign are operated by companies based in the United States. When PILLAR sends an email or a signature request through them, the recipient’s name, email address and the content of that message or document may be processed outside the EU. Each of those transfers is covered by the transfer safeguards in that provider’s own data-processing terms, and we will send you those terms on request.

The storage services a customer connects themselves — Microsoft 365, OneDrive, SharePoint, Google Drive and Dropbox — are the customer’s own accounts, under the customer’s own agreement with that provider. Data the customer chooses to import from or export to those services is governed by that relationship, not by ours.

There are two different kinds of connection, and they give PILLAR very different access.

Per-user file pickers. A user can connect their own OneDrive, SharePoint, Google Drive or Dropbox account and pick a file to bring into a case. For these, PILLAR only accesses the files the user actually selects. We ask for the narrowest permission each provider offers: for Google Drive we use the “drive.file” permission together with Google’s file picker, which limits PILLAR to the files you open through it.

The Microsoft 365 organisation connection. A customer administrator can connect the customer’s whole Microsoft 365 organisation. This is a wider grant, given by the customer’s own administrator through Microsoft’s admin-consent screen, and it is not limited to files a user selects. With it, PILLAR can:

  • read the customer’s staff directory (names, email addresses, job titles and departments) so that administrators can find and invite colleagues;
  • show staff profile photos;
  • send email from the customer’s own domain on the customer’s behalf;
  • create, update and cancel calendar appointments in the calendars of the customer’s case managers and agents, and check when they are free;
  • work with the customer’s SharePoint document libraries.

PILLAR uses these permissions only for the features listed. Which of them a customer grants is the customer’s choice, and the customer can withdraw them at any time in its own Microsoft 365 administration.

Google API Services. PILLAR’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain words: data we receive from Google Drive is used only to bring the file you selected into your case; it is not sold, not used for advertising, not used to train AI models, and not read by our staff except with your permission, for security, or where the law requires it.

A customer administrator can optionally switch on inbound email capture, so that replies sent to a shared case mailbox (for example, cases@the-customer.com) are filed against the right case automatically. It is off unless a customer administrator turns it on.

Capture is limited to that one mailbox. The limit is set in the customer’s own Microsoft 365 environment, and PILLAR checks it before every capture run: if PILLAR finds it has been granted access to more than the one mailbox, capture stops, the customer’s administrator is told, and our team is alerted to fix it. How that check works is described on our Security page.

Mail that does not match a case goes into an “unfiled” tray where a case manager can file it by hand. Unfiled messages are deleted automatically after 90 days at the latest; a customer can shorten that period but cannot lengthen it, because the sender may have no connection to any case.

PILLAR is built around AI: an in-product assistant, and automatic reading of uploaded documents.

The assistant runs on OpenAI models hosted by Microsoft in Microsoft Foundry, inside our own Azure subscription. When a user asks it something, the question and the case context needed to answer it are sent to that service — including the content of a document, if the user asks about one. Microsoft states that for these models:

  • prompts and responses are processed within Microsoft’s EU Data Boundary (the EU plus EFTA countries such as Norway and Switzerland), and stored at rest in our region;
  • prompts and responses are not used to train, retrain or improve the underlying models, and are not available to OpenAI or to other customers;
  • Microsoft may hold a sample of prompts and responses for abuse monitoring, reviewed by authorised Microsoft staff located in the European Economic Area.

Source: Microsoft’s data, privacy and security page for these models.

Document reading works in three steps, all inside the EU:

  1. The document’s file name and the description the user typed are sent to the assistant’s model to work out what kind of document it is (a passport, a contract, an invoice).
  2. The document itself is sent to Azure AI Document Intelligence, Microsoft’s document-reading service. Microsoft states that the document and the results are processed in the same region as our Azure resource, held temporarily, and deleted automatically 24 hours after processing. Source: Microsoft’s data, privacy and security page for Document Intelligence.
  3. If Document Intelligence cannot read the document, it is sent instead to an EU-resident OpenAI model in Microsoft Foundry, under the same EU Data Boundary terms as the assistant.

PILLAR refuses to send a document to any model outside the EU Data Boundary; if no EU-resident model is available, the reading job fails and the user is told, rather than the document going elsewhere.

Content only goes to these services when a user uses the feature. Conversations with the assistant are deleted after 90 days. The details read out of a document are kept for 30 days by default; a customer can set this between 7 and 90 days.

PILLAR does not make decisions about people by automated means that have legal or similarly significant effects. The AI features suggest; a person decides:

  • When the assistant is asked to change something in a case, it must show the proposed change and wait for the user to approve it before anything is written.
  • Details read out of a document are shown as suggestions and are not written onto the person’s record until a person reviews and saves them.

We do not sell data, and it is not used to train AI

Section titled “We do not sell data, and it is not used to train AI”

We do not sell personal data, share it for advertising, or use it to train AI models. Microsoft states that the assistant’s prompts and responses are not used to train its models either, as described above.

Each customer organisation’s data is kept separate from every other customer’s. Data is encrypted in transit to and from PILLAR and at rest, and in production the most sensitive fields — contact details, passport and visa numbers, nationality, addresses, employment and salary details, health and accommodation notes, emergency contacts, invitation and connection tokens, captured emails, and conversations with the assistant — are encrypted a second time at field level, separately for each category. Users only see what their role and permissions allow. Administrative actions and access to personal data are recorded, and personal data is masked in our application logs.

The full description, with what each provider is certified for and what PILLAR itself is not yet certified for, is on our Security page.

Case data belongs to the customer, and the customer decides how long it is kept. PILLAR does not delete cases, people or documents on a timer. A finished relocation stays in the workspace until the customer deletes it, asks us to erase a person, or leaves PILLAR. If a relocation company needs a fixed retention period for closed cases, that is its policy to set and apply.

Some kinds of data are deleted automatically, because they are either short-lived by nature or concern people who may have no connection to a case:

DataKept forWho can change it
Cases, people, dependents, documents and case notesUntil the customer deletes them, erases the person, or leaves PILLARThe customer
Emails filed to a caseAs long as the case, by defaultThe customer can set a shorter window, from 30 days up to 10 years
Unfiled inbound emails90 daysThe customer can shorten it, not lengthen it
Details read out of a document by the AI30 days by defaultThe customer can set 7 to 90 days
Conversations with the assistant90 days—
In-app notifications and records of emails PILLAR sent90 days—
Sign-in records2 years—
Audit log of administrative actions and access to personal data7 years—
User accountsUntil the account is erased or the customer leavesThe customer’s administrator
Billing recordsAs long as Danish bookkeeping law requires (currently 5 years after the financial year)—

When a customer leaves PILLAR, the customer has 30 days from the end of the agreement to take a copy of its data. If the customer asks us to return the data instead, we provide it within that window. After the 30 days we delete the customer’s whole workspace — every case, person, document and file, plus the customer’s sign-in configuration. Deleting a workspace is a deliberate, restricted operation carried out by us; it does not run on a timer, and we do not carry it out before the 30 days have passed.

We keep automatic backups of the database so that we can recover from a failure. Backups are retained for 7 days and then expire on their own. When data is deleted from the live system, it remains in those backups until they expire; backups are used only to restore the service after a failure, never to bring deleted records back into normal use.

PILLAR is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 18. If we learn that an account belongs to a child, we will close it.

However, a customer may enter details about a relocating employee’s dependent family members, including children, because immigration filings and school placements require it. That data is provided by the customer or by the employee, is processed on the customer’s instructions, and is protected exactly like every other piece of case data.

Our websites set only the cookies they need to work — the cookie that remembers your choice in the cookie banner, and your display preferences — plus, on www.pillarrelocation.com only and only if you accept the “analytics” category, Microsoft Azure Application Insights, which counts visits and pages viewed using the ai_user and ai_session cookies, is hosted in the EU, and is never used for advertising. On the documentation site at app.pillarrelocation.com/docs no analytics runs today, so accepting that category sets nothing. We use no advertising cookies, and you can change your choice at any time using the “Cookie Settings” button in the site footer.

The PILLAR product itself uses only the cookies needed to keep you signed in and secure.

If we hold personal data about you, you have the right to:

  • Access it — ask for a copy and for an explanation of what we do with it.
  • Rectify it — have anything wrong corrected.
  • Erase it — ask for it to be deleted.
  • Restrict its use — ask us to stop using it while something is being sorted out.
  • Portability — receive it in a common format, or have it sent elsewhere.
  • Object — object to processing we carry out on the basis of legitimate interests.
  • Withdraw consent — where processing is based on your consent, withdraw it at any time. That does not affect what was done before you withdrew it. For website cookies, use the “Cookie Settings” button in the footer; for anything else, write to us.

Where we hold your data as a processor for one of our customers, we will pass your request to that customer within a few days, because they are the ones who decide, and we will tell you when we have done so. PILLAR gives the customer the tools to act on it: a case manager with the right permission can produce a person’s complete data file, or erase a person — their details, their dependents, the details read out of their documents, and the documents themselves — including people who never had a login.

Write to support@pillarrelocation.com. Questions about personal data are handled by the company’s management. We will acknowledge your request promptly and respond within one month, as the GDPR requires. If a request is complex we may take up to two further months, and we will tell you within the first month if so. We may need to check your identity before acting on a request.

If you are unhappy with how your personal data has been handled, you can complain to the Danish Data Protection Agency:

Datatilsynet — datatilsynet.dk

You can complain to Datatilsynet whether or not you have raised the matter with us first, though we would rather you gave us the chance to put it right.

We will update this page when what we do changes. The date at the top shows when it was last changed. If a change materially affects how we handle personal data, we will tell our customers directly rather than relying on this page alone.