Version 1.0 — Effective 2026-07-08. Language: English (primary). Governing law: Danish law.
This Privacy Policy explains how DistributorFit (DK27383637) ("DistributorFit", "we", "us", "our") collects, uses, and protects personal data in connection with our web application and related services (the "Service").
We act as data controller for the personal data described in this policy. Where we process personal data on behalf of our customers (for example, data that customers enter about their distributors or colleagues), we act as data processor — this is governed by our Data Processing Agreement, which forms part of our Terms of Service.
This policy applies to:
The Service is intended exclusively for business customers. We do not knowingly collect personal data from private individuals acting outside a professional capacity.
Questions about this policy or your rights can be directed to: contact@distributorfit.com
We collect only the personal data necessary for the purposes described below. We do not collect special categories of personal data (sensitive data as defined in GDPR Article 9).
| Category of data subjects | Categories of personal data | Purpose of processing | Legal basis |
|---|---|---|---|
| Account holders / contact persons at customer organisations | Name, work email address, job title, company name, country. Account credentials (email address used for login). Subscription and billing information (plan tier, billing cycle — payment card details are handled exclusively by Stripe and never stored by us). | To create and manage your account. To provide the Service. To communicate with you about your subscription, invoices, and material changes to the Service or these terms. | Performance of contract, cf. GDPR Article 6(1)(b). Compliance with legal obligations (bookkeeping), cf. GDPR Article 6(1)(c). |
| Account holders / contact persons at customer organisations | Usage data: login timestamps, feature interactions, error logs. | To operate, maintain, and improve the Service. To detect and investigate security incidents. | Legitimate interests, cf. GDPR Article 6(1)(f): ensuring the security, stability, and continued development of the Service. |
| Team members added by a customer (V2 / multi-user feature) | Name and work email address. | To enable the customer to invite colleagues to their organisation account within the Service. | Performance of contract with the customer, cf. GDPR Article 6(1)(b). Legitimate interests of the customer and DistributorFit in providing the agreed multi-user functionality, cf. GDPR Article 6(1)(f). |
| Website visitors | IP address, browser type, device type, pages visited, time on site — collected via cookies and similar technologies. | To ensure the website functions correctly. To understand how visitors use the site (aggregated analytics). | Legitimate interests, cf. GDPR Article 6(1)(f), for functional cookies. Consent, cf. GDPR Article 6(1)(a), for non-essential analytics or marketing cookies — obtained via our cookie consent banner. |
| Individuals who contact us | Name, email address, company, and the content of the message. | To respond to enquiries, support requests, or feedback. | Legitimate interests, cf. GDPR Article 6(1)(f): handling communications in connection with our business. |
The Service allows customers to enter information about their distributors and, on the Professional tier, to invite distributor contacts to contribute to a shared cooperation timeline. Data that customers enter about their distributors is customer data — DistributorFit processes it solely to provide the Service and does not use it for our own purposes. If you are a distributor contact who has been invited via a token link by one of our customers, the customer is the data controller for that invitation and for any information they have shared about you. Our role is limited to providing the technical platform.
We collect personal data in the following ways:
We share personal data with third-party service providers who act as our data processors. They process data only on our instructions and are contractually bound to appropriate data protection obligations.
Our primary sub-processors are:
| Provider | Role | Location |
|---|---|---|
| Supabase (EU region) | Database and application hosting; transactional account email (sign-up confirmation, password reset) | EU |
| Stripe | Payment processing and subscription management | EU / USA (EU SCCs in place) |
We do not sell personal data. We do not share personal data with third parties for their own marketing purposes.
We may disclose personal data if required by law, court order, or a competent supervisory authority, to the extent permitted or required by applicable law.
Our Service is hosted on Supabase in the EU region. Personal data is primarily processed within the EU/EEA.
Where we use sub-processors located outside the EU/EEA (currently Stripe, which processes payment data in the USA), transfers are made on the basis of the European Commission's Standard Contractual Clauses (SCC) or another approved transfer mechanism under GDPR Chapter V.
We retain personal data for as long as necessary for the purposes described in this policy, or as required by applicable law.
| Situation | Retention |
|---|---|
| Active subscription | For the duration of the subscription. |
| After subscription ends | Account data is retained for 20 days from the end of the subscription or from suspension due to non-payment, during which access can be restored. After 20 days, account data and customer data entered into the Service are permanently deleted. |
| Invoices and financial records | As required by Danish bookkeeping law (currently 5 years from the end of the relevant financial year). |
| Website visitor data (cookies, logs) | As specified in our Cookie Policy. Generally 30–90 days for server logs; cookie retention periods are set out in our cookie consent banner. |
| Contact and correspondence | Until the purpose of the communication has been fulfilled, or until you request deletion, whichever is earlier. |
Under the GDPR, you have the following rights regarding your personal data:
To exercise any of these rights, please contact us at contact@distributorfit.com. We will respond within 30 days. We may ask you to verify your identity before processing the request.
You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet): www.datatilsynet.dk.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure. These measures include:
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify affected individuals without undue delay where required under GDPR Article 34.
We use cookies and similar technologies on our website. A cookie consent banner is displayed on first visit and allows you to accept or decline non-essential cookies.
Essential cookies (necessary for the Service to function) do not require consent. Non-essential cookies (analytics, preferences) require your consent before being set.
We may update this Privacy Policy from time to time. We will notify you of material changes by email to your registered account address at least 30 days before the changes take effect. Minor corrections or administrative updates that do not affect the substance of how we process your data may be made without prior notice.
The current version of this policy is always available at distributorfit.com/privacy.
If you have questions about this Privacy Policy or wish to exercise your rights:
DistributorFit, Hjallesevej 161, 5230 Odense, Denmark
DK27383637
contact@distributorfit.com