Collectaz ApS
Denmark · owned by Independent (Denmark) · collectaz.dk · 12 vendors
Resilience scores
- Digital Sovereignty: 42
- Digital Resilience: 5
- Financial Resilience: 5
Technology vendors
- Google LLC — Technology — United States
- The Apache Software Foundation — Technology — United States
- Varnish Software AB — Technology — Sweden
- and 9 more
Services catalogue
2 services in catalogue across 2 categories; runs on 12 sub-vendors.
- CollectPay
- Fundraising
Insights
Last updated 2026-09-13 · revision 2
12 direct vendors, 176 subvendors
Direct vendors by controlling owner country (sample)
- India: 1
- Italy: 1
- United States: 4
Subvendors by controlling owner country (sample)
- Netherlands: 2
- Norway: 1
- China: 2
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Collectaz ApS exhibits medium migration readiness, primarily due to its existing 'web-based CRM (SaaS)' product architecture. This suggests the company is already operating in a cloud-like environment, which is a significant advantage over migrating from traditional on-premise infrastructure. The presence of a 'REST API' for custom integrations also indicates a degree of modularity and openness that can facilitate data and functionality migration. The company's established GDPR compliance is a positive, as maintaining regulatory adherence is a key consideration during any migration. However, several critical factors introduce uncertainty and potential challenges. The specific architecture of the core 'Collect' CRM (e.g., monolithic application, containerization, microservices adoption) is not detailed. If it is a legacy monolithic system, migration would be considerably more complex and costly. The company's website uses WordPress version 7.0.4, which might require modernization or careful migration planning. Crucially, there is no information regarding data residency requirements, which are paramount for cloud migration and could significantly limit potential cloud providers or architectures. Financial stability and the ability to fund a potentially extensive migration are also unknown. The 'Vendor Lock-in Risk' is unspecified, but the reliance on 15 external services implies numerous dependencies that would need careful assessment for compatibility, re-integration, and potential contractual complexities during a migration. The contradictory 'Total Vendors: 0' data point makes it difficult to fully assess the vendor landscape and associated lock-in. Without clarity on these critical unknowns, a high readiness score cannot be justified.
Compliance
8 in-scope frameworks identified; showing 3.
GDPR (source) — Partially Compliant
Collectaz ApS is headquartered in Denmark (EU) and operates as both a data processor for its customers and a data controller for its own operations. It processes significant volumes of personal data on behalf of Danish NGOs, associations, and fundraising organizations — including donor data, member data, event participant data, and payment data. The company has demonstrated meaningful GDPR compliance steps: a published privacy policy, a cookie consent mechanism, and a Data Processing Agreement (DPA) modeled on the Danish Datatilsynet template (last revised January 2026). However, the privacy policy was last updated in July 2022 (body text), and there is no publicly disclosed Data Protection Officer (DPO), no record of a formal GDPR audit, and no evidence of a Records of Processing Activities (RoPA) being maintained or published. The use of Google Analytics introduces a third-country data transfer risk (US), which requires a valid transfer mechanism (e.g., Standard Contractual Clauses). Risk is Medium rather than High because the company has taken visible compliance steps and operates in a relatively low-sensitivity data environment (no health or financial data beyond payment processing), but gaps remain in demonstrable full compliance.
Evidence: https://collectaz.dk/privatlivspolitik/, https://collectaz.dk/persondatabeskyttelse_og_gdpr/, https://collectaz.dk/wp-content/uploads/2026/01/DATABEHANDLERAFTALE-januar-2026.pdf, https://www.datatilsynet.dk/english, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
ePrivacy Directive — Partially Compliant
The Danish Cookie Order (Bekendtgørelse nr. 1148 af 9. december 2011, implementing the ePrivacy Directive) requires informed consent before placing non-essential cookies. Collectaz has implemented a cookie consent banner with granular controls (necessary, functional, preference, analytics, marketing categories). However, the cookie consent implementation uses the CookieLawInfo plugin, and the cookie policy references Google Analytics for web analytics — which involves data transfer to the US. Risk is Low because the company has a visible and functional consent mechanism, but there may be minor gaps in the implementation (e.g., whether analytics cookies are blocked prior to consent).
Evidence: https://collectaz.dk/, https://collectaz.dk/privatlivspolitik/, https://www.datatilsynet.dk/english/cookies, https://www.retsinformation.dk/eli/lta/2011/1148
NIS2 (source) — Assessment Required
Collectaz ApS operates as a SaaS/CRM provider for Danish non-profit organizations, fundraising bodies, and associations. It does not appear to operate in any of the NIS2 Essential Entity sectors (energy, transport, banking, health, water, digital infrastructure, public administration, space) or the explicitly listed Important Entity sectors (postal/courier, waste management, chemicals, food, manufacturing). However, it could potentially fall under the 'digital providers' category as a cloud/SaaS service provider, which is an Important Entity sector under NIS2. The size threshold (50+ employees or €10M+ annual turnover) is uncertain — based on the company's profile (small Danish SaaS company, single office in Randers), it is likely below the threshold, which would exempt it from NIS2. Risk is Low because the sector match is weak and the company likely falls below the size threshold, but a formal assessment is required to confirm both the sector classification and size metrics.
Evidence: https://collectaz.dk/, https://www.cfcs.dk/da/cybersikkerhed/nis2/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://erhvervsstyrelsen.dk/nis2
Financials
Three-year financials
- 2025: gross profit DKK 3.74M, EBIT DKK 343K, equity DKK 362K
- 2024: gross profit DKK 3.57M, EBIT DKK 455K, equity DKK 611K
- 2023: gross profit DKK 3.22M, EBIT DKK 595K, equity DKK 502K
Financial Resilience Score: 5/10
Collectaz ApS is a small Danish private limited company (ApS) operating as a vertical SaaS provider for the non-profit sector in Denmark. As a class B reporting entity, detailed financial disclosures are limited and no revenue, EBIT, or equity figures could be retrieved for this assessment. The qualitative profile suggests a moderately resilient business: vertical SaaS models typically benefit from recurring subscription revenue, sticky customer relationships, and high renewal rates. The company's 15+ years of experience in the fundraising software niche indicates an established customer base and brand recognition within the Danish NGO segment. However, the company faces several structural risks that constrain its resilience score. As a small ApS with a single office in Randers, Denmark, it likely has limited geographic diversification and potential customer concentration risk. The payments arm (CollectPay) operates in a regulated space with compliance obligations under PSD2, AML/KYC, and GDPR frameworks. Competition from larger CRM and fundraising platforms (Salesforce NPSP, BetterNow, Heyloyalty) may limit pricing power. Additionally, key-person risk is elevated in small founder-led ApS entities, and disclosure opacity limits external visibility into financial trends. Without access to actual financial statements from CVR (datacvr.virk.dk), a definitive resilience score cannot be established. The mid-range score of 5 reflects the balance between the strengths of an established niche SaaS operator and the inherent risks of a small, single-market, privately held company with limited public financial transparency.
Key strengths: Established niche SaaS operator with 15+ years of experience in Danish non-profit fundraising software, Recurring subscription revenue from Collect CRM product plus transactional revenue from CollectPay, Vertical SaaS moat with sticky customer relationships in a specific segment (NGOs, associations, foundations), Low capital intensity typical of SaaS businesses, Three product lines (Collect, CollectPay, CollectEvent) providing upsell and cross-sell opportunities
Risk factors: Small-company customer concentration risk; loss of a few key NGO clients could materially impact revenue, Geographic concentration ~100% in Denmark with no international diversification, Regulatory exposure via CollectPay under PSD2, AML/KYC, and GDPR compliance requirements, Competition from larger CRM/fundraising platforms including Salesforce NPSP, BetterNow, and Heyloyalty, Key-person risk typical of small founder-led ApS entities, Disclosure opacity as a class B ApS; revenue not required to be disclosed publicly
Revenue by geography
- Denmark: 100%
Revenue by product/service
- Collect (CRM subscription): 0%
- CollectEvent (event registration): 0%
- CollectPay (payment/donation processing): 0%
Workforce by country
- Denmark: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.