DistributorFit
How it works Pricing Blog About Sign in Start free

Privacy Policy

Version —
Effective date —

Version 1.0 — Effective 2026-07-08. Language: English (primary). Governing law: Danish law.

Introduction

This Privacy Policy explains how DistributorFit (CVR DK27383637) ("DistributorFit", "we", "us", "our") collects, uses, and protects personal data in connection with our web application and related services (the "Service").

We act as data controller for the personal data described in this policy. Where we process personal data on behalf of our customers (for example, data that customers enter about their distributors or colleagues), we act as data processor — this is governed by our Data Processing Agreement, which forms part of our Terms of Service.

This policy applies to:

  • contact persons at companies that register for or use the Service (customers and trial users)
  • visitors to our website at distributorfit.com
  • individuals who contact us directly

The Service is intended exclusively for business customers. We do not knowingly collect personal data from private individuals acting outside a professional capacity.

Questions about this policy or your rights can be directed to: contact@distributorfit.com

1. What personal data we collect and why

We collect only the personal data necessary for the purposes described below. We do not collect special categories of personal data (sensitive data as defined in GDPR Article 9).

Category of data subjectsCategories of personal dataPurpose of processingLegal basis
Account holders / contact persons at customer organisationsName, work email address, job title, company name, country. Account credentials (email address used for login). Subscription and billing information (plan tier, billing cycle — payment card details are handled exclusively by Stripe and never stored by us).To create and manage your account. To provide the Service. To communicate with you about your subscription, invoices, and material changes to the Service or these terms.Performance of contract, cf. GDPR Article 6(1)(b). Compliance with legal obligations (bookkeeping), cf. GDPR Article 6(1)(c).
Account holders / contact persons at customer organisationsUsage data: login timestamps, feature interactions, error logs.To operate, maintain, and improve the Service. To detect and investigate security incidents.Legitimate interests, cf. GDPR Article 6(1)(f): ensuring the security, stability, and continued development of the Service.
Team members added by a customer (V2 / multi-user feature)Name and work email address.To enable the customer to invite colleagues to their organisation account within the Service.Performance of contract with the customer, cf. GDPR Article 6(1)(b). Legitimate interests of the customer and DistributorFit in providing the agreed multi-user functionality, cf. GDPR Article 6(1)(f).
Website visitorsIP address, browser type, device type, pages visited, time on site — collected via cookies and similar technologies.To ensure the website functions correctly. To understand how visitors use the site (aggregated analytics).Legitimate interests, cf. GDPR Article 6(1)(f), for functional cookies. Consent, cf. GDPR Article 6(1)(a), for non-essential analytics or marketing cookies — obtained via our cookie consent banner.
Individuals who contact usName, email address, company, and the content of the message.To respond to enquiries, support requests, or feedback.Legitimate interests, cf. GDPR Article 6(1)(f): handling communications in connection with our business.

A note on distributor data

The Service allows customers to enter information about their distributors and, on the Professional tier, to invite distributor contacts to contribute to a shared cooperation timeline. Data that customers enter about their distributors is customer data — DistributorFit processes it solely to provide the Service and does not use it for our own purposes. If you are a distributor contact who has been invited via a token link by one of our customers, the customer is the data controller for that invitation and for any information they have shared about you. Our role is limited to providing the technical platform.

2. How we collect personal data

We collect personal data in the following ways:

  • Directly from you: when you register for an account, subscribe to a plan, fill out a contact form, or communicate with us.
  • Automatically: when you use the Service or visit our website, through server logs, cookies, and similar technologies.
  • From our customers: when a customer adds a colleague (team member) to their organisation account, or when a customer provides contact details for a distributor invite.

3. Data processors and third-party sharing

We share personal data with third-party service providers who act as our data processors. They process data only on our instructions and are contractually bound to appropriate data protection obligations.

Our primary sub-processors are:

ProviderRoleLocation
Supabase (EU region)Database and application hosting; transactional account email (sign-up confirmation, password reset)EU
StripePayment processing and subscription managementEU / USA (EU SCCs in place)

We do not sell personal data. We do not share personal data with third parties for their own marketing purposes.

We may disclose personal data if required by law, court order, or a competent supervisory authority, to the extent permitted or required by applicable law.

4. International data transfers

Our Service is hosted on Supabase in the EU region. Personal data is primarily processed within the EU/EEA.

Where we use sub-processors located outside the EU/EEA (currently Stripe, which processes payment data in the USA), transfers are made on the basis of the European Commission's Standard Contractual Clauses (SCC) or another approved transfer mechanism under GDPR Chapter V.

5. How long we keep your data

We retain personal data for as long as necessary for the purposes described in this policy, or as required by applicable law.

SituationRetention
Active subscriptionFor the duration of the subscription.
After subscription endsAccount data is retained for 20 days from the end of the subscription or from suspension due to non-payment, during which access can be restored. After 20 days, account data and customer data entered into the Service are permanently deleted.
Invoices and financial recordsAs required by Danish bookkeeping law (currently 5 years from the end of the relevant financial year).
Website visitor data (cookies, logs)As specified in our Cookie Policy. Generally 30–90 days for server logs; cookie retention periods are set out in our cookie consent banner.
Contact and correspondenceUntil the purpose of the communication has been fulfilled, or until you request deletion, whichever is earlier.

6. Your rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access: you may request a copy of the personal data we hold about you.
  • Right to rectification: you may ask us to correct inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten"): you may ask us to delete your personal data, subject to any legal retention obligations.
  • Right to restriction of processing: you may ask us to restrict how we process your data in certain circumstances.
  • Right to data portability: you may request a copy of your data in a structured, machine-readable format.
  • Right to object: you may object to processing based on legitimate interests. We will then assess whether our legitimate interests override your interests, rights, and freedoms.
  • Right to withdraw consent: where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before the withdrawal.

To exercise any of these rights, please contact us at contact@distributorfit.com. We will respond within 30 days. We may ask you to verify your identity before processing the request.

You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet): www.datatilsynet.dk.

7. Data security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure. These measures include:

  • Data hosted on Supabase in the EU with encryption at rest and in transit (TLS).
  • Access to production data restricted to authorised personnel only.
  • Stripe handles all payment card data; we never store card details ourselves.
  • Regular review of access controls and security practices.

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify affected individuals without undue delay where required under GDPR Article 34.

8. Cookies

We use cookies and similar technologies on our website. A cookie consent banner is displayed on first visit and allows you to accept or decline non-essential cookies.

Essential cookies (necessary for the Service to function) do not require consent. Non-essential cookies (analytics, preferences) require your consent before being set.

9. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email to your registered account address at least 30 days before the changes take effect. Minor corrections or administrative updates that do not affect the substance of how we process your data may be made without prior notice.

The current version of this policy is always available at distributorfit.com/privacy.

10. Contact

If you have questions about this Privacy Policy or wish to exercise your rights:

DistributorFit, Hjallesevej 161, 5230 Odense, Denmark
CVR DK27383637
contact@distributorfit.com

© DistributorFit About Terms of Service Privacy Policy Consultancy Terms Manage cookie preferences
DistributorFit · CVR DK27383637 · Hjallesevej 161, 5230 Odense · contact@distributorfit.com · +45 31 25 30 23