Privacy Policy

Last updated September 2026

Data controller

We are the data controller for the processing of the personal data we process about our customers and partners. You can find our contact details below.

Buffed

Company reg. no. (CVR):

It is not a requirement for our company to have an external DPO, but if you have questions about the processing of your personal data, you can contact us at kontakt@buffedapp.dk.

Processing activities

As data controller under the GDPR, we have the following processing activities, which we keep track of in our GDPR software.

Visiting the website

When you visit our website, we use cookies so the website can function, which you can read more about in our cookie policy.

Communication with potential customers

When you have questions about our site, or want to hear more about our services, you can contact us via:

- Contact form

- Email

Through this we process your personal data so we can engage in a dialogue with you, for example to answer questions about our services. We only process the information you give us in connection with our communication.

We will typically process the following general information: name, email, phone number.

Our legal basis for processing this personal data is Article 6(1)(f) of the Data Protection Regulation.

We delete our communication with you once it is clear whether you want our services or not.

Should a special case create a need to store your personal data for longer, this may be the case.

Communication with customers

We need to communicate with our customers to make sure the service is delivered correctly. Through this we may process information about name, address, services, special agreements, payment information and the like.

The legal basis for processing this personal data is Article 6(1)(b) of the Data Protection Regulation.

Once the service is delivered and any outstanding matters are settled, we will delete the personal data shortly thereafter.

Bookkeeping

We must keep all accounting records under the Danish Bookkeeping Act. This means we store invoices and similar records for accounting purposes. These may contain general personal data such as name, address and service description.

Our legal basis for processing personal data for bookkeeping is Article 6(1) of the Data Protection Regulation.

We store this information for at least 5 years after the end of the current financial year.

Data processors

Few can do everything themselves, and the same goes for us. We therefore have partners and use suppliers, some of which may be data processors.

External suppliers may, for example, provide systems to organize our work, services, advice, IT hosting or marketing.

- Supabase for storing data and login

- Vercel for hosting the app and website

- Resend for sending emails (password reset and contact form)

- Upstash (QStash) for scheduling push notifications

- Vercel Analytics for anonymous usage statistics

It is our responsibility to ensure your personal data is handled properly. We therefore set high requirements for our partners, and our partners must guarantee that your personal data is protected.

We therefore enter into agreements with companies (data processors) that handle personal data on our behalf, in order to increase the security of your personal data.

Disclosure of personal data

We do not disclose your personal data to third parties.

Profiling and automated decisions

We do not carry out profiling or automated decisions.

Third-country transfers

As a rule, we use data processors in the EU/EEA, or who store data in the EU/EEA.

In some cases this is not possible, and here data processors outside the EU/EEA may be used, if they can give your personal data an adequate level of protection.

Processing security

We keep the processing of personal data secure by having implemented appropriate technical and organizational measures.

We have carried out a risk assessment of our processing of personal data and, on that basis, implemented appropriate measures such as encryption of sensitive data (like weight and height), restricted access and secure hosting.

We stay up to date on the GDPR on an ongoing basis and periodically review our procedures for processing personal data.

Rights of the data subject

Under the Data Protection Regulation, you have a number of rights in relation to our processing of information about you.

If you want to exercise your rights, please contact us so we can help you with this.

Right of access

You have the right to gain insight into the information we process about you, as well as a range of additional information.

Right to rectification (correction)

You have the right to have inaccurate information about yourself corrected.

Right to erasure

In special cases you have the right to have information about you deleted before the time of our general routine deletion.

Right to restriction of processing

In certain cases you have the right to have the processing of your personal data restricted. If you have the right to restricted processing, we may in future only process the data – apart from storage – with your consent, or for the establishment, exercise or defence of legal claims, or to protect a person or important public interests.

Right to object

In certain cases you have the right to object to our otherwise lawful processing of your personal data. You can also object to the processing of your data for direct marketing.

Right to data portability

In certain cases you have the right to receive your personal data in a structured, commonly used and machine-readable format, and to have this personal data transferred from one data controller to another without hindrance.

You can read more about your rights in the Danish Data Protection Agency's guidance on the rights of data subjects, which you can find at www.datatilsynet.dk.

Withdrawal of consent

When our processing of your personal data is based on your consent, you have the right to withdraw your consent.

Complaint to the Danish Data Protection Agency

You have the right to lodge a complaint with the Danish Data Protection Agency if you are dissatisfied with the way we process your personal data. You can find the Danish Data Protection Agency's contact details at www.datatilsynet.dk.

We generally encourage you to read more about the GDPR so you stay up to date on the rules.