Privacy Policy

fermt ApS · Version 2.0 · Effective 20 September 2026

1. Who we are

The fermt platform is operated by fermt ApS, Åløkkevej 1, 2720 Vanløse, Denmark ("fermt", "we", "us"). You can reach us at info@fermt.com.

We have not appointed a data protection officer. We are not required to do so, as our processing does not meet the criteria in Article 37 GDPR.

2. Two different roles — read this first

We handle personal data in two distinct capacities, and different rules apply to each. Keeping them apart matters, because it determines who decides what happens to the data and who answers for it.

DataOur roleWhat governs it
Account, billing, support and website data — the data we need in order to have you as a customer.Controller. We decide the purposes and means.This Privacy Policy.
Customer Data — everything you enter into the fermt platform: products, recipes, batches, orders, traceability records, and any personal data contained in them, including data about your own employees, suppliers and customers.Processor. You decide the purposes and means. We act on your documented instructions.The Data Processing Agreement between you and fermt ApS, concluded under Article 28 GDPR.

Sections 3 to 9 describe the data we process as controller. Section 10 describes, in summary, the data we process as processor; the binding terms for that processing are in the Data Processing Agreement, not in this policy.

3. Personal data we process as controller

CategoryDataPurposeLegal basis
Account dataName, email address, company name, job title, organisation details. We do not store passwords: authentication is handled by Microsoft Entra External ID, and the application only validates a signed token issued by that service.Creating and administering your account; authenticationArt. 6(1)(b) — performance of a contract
Billing dataCompany name, billing address, VAT number, subscription and invoice history, payment status. Card details are handled by Stripe and are not stored by us.Invoicing, payment collection, accountingArt. 6(1)(b) and Art. 6(1)(c) — legal obligation under the Danish Bookkeeping Act
Support dataCorrespondence with us, including any information you choose to includeAnswering enquiries, troubleshootingArt. 6(1)(f) — our legitimate interest in supporting customers
Technical and log dataIP address, browser and device information, timestamps, pages and actions within the application, error traces, and a pseudonymous reference to the signed-in user. Free-text content is removed before it reaches our telemetry.Operating and securing the Service, detecting abuse, diagnosing faultsArt. 6(1)(f) — our legitimate interest in a secure and functioning service
Website analytics dataPages visited, referrer, approximate location, device type — on www.fermt.com only, and only if you accept analytics in the consent banner.Understanding how the website is usedArt. 6(1)(a) — consent, withdrawable at any time
Marketing dataEmail address and communication preferences, where you have signed upSending product updates and newslettersArt. 6(1)(a) — consent, withdrawable at any time

We do not use the data above for automated decision-making or profiling with legal or similarly significant effects.

4. Where the data is stored

4.1The fermt platform and its databases are hosted on Microsoft Azure in the West Europe (Netherlands) region, within the EU/EEA. Some operational telemetry is stored in the North Europe (Ireland) region, also within the EU/EEA.

4.2Payment processing is carried out by Stripe. Stripe may transfer personal data outside the EU/EEA; such transfers rely on the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

4.3Transactional email is delivered by Proton AG in Switzerland, a country covered by a European Commission adequacy decision.

4.4If you accept analytics on www.fermt.com, Google Analytics may transfer data outside the EU/EEA under the Standard Contractual Clauses and the EU–US Data Privacy Framework. This applies to the marketing website only. The fermt application and the public product-label pages contain no analytics at all.

4.5Apart from the above, we do not transfer personal data outside the EU/EEA.

5. Recipients and processors

We share personal data only with the following recipients, and only to the extent necessary.

RecipientRolePurposeLocation
Microsoft Ireland Operations Ltd. (Microsoft Azure)Our processorHosting, storage, backup, platform infrastructureEU/EEA — West Europe (Netherlands)
Microsoft Ireland Operations Ltd. (Microsoft Entra External ID)Our processorAuthentication and credential managementEU/EEA
Microsoft Ireland Operations Ltd. (Azure OpenAI Service)Our processorOptional assistance features, where you use them. Prompts are not used to train models.EU/EEA — West Europe (Netherlands)
Microsoft Ireland Operations Ltd. (Azure Application Insights)Our processorError tracking and usage telemetryEU/EEA — West Europe and North Europe
Proton AGOur processorTransactional and support emailSwitzerland — adequacy decision
Stripe Payments Europe, Ltd.Independent controller for payment data; our processor for subscription administrationCard payment processing, fraud prevention, subscription billingIreland, with onward transfers under SCCs
Google Ireland Ltd. (Google Analytics)Our processorWebsite analytics on www.fermt.com — only if you accept analytics in the consent bannerIreland, with onward transfers under SCCs and the EU–US Data Privacy Framework
Public authorities, our accountant or legal advisersRecipientsWhere required by law or to establish or defend legal claimsDenmark

6. How long we keep the data

DataRetention period
Account dataFor the duration of the subscription, then 30 days after termination
Billing and accounting recordsFive years from the end of the financial year to which they relate, as required by the Danish Bookkeeping Act
Support correspondenceThree years from the last message, or longer where needed to defend a legal claim
Application telemetry (errors, timings, usage)90 days
Infrastructure logs30 days
Database backups7 days, on a rolling point-in-time window
Website analytics dataIn accordance with the provider’s configured retention, or until you withdraw consent
Marketing dataUntil consent is withdrawn

7. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.2 or higher) and at rest, individual user accounts with role-based permissions, administrative access restricted to a single named person and protected by the identity provider, an IP firewall in front of the production database, an audit trail of actions within the Service, automated alerting on errors, continuous database backup, and development carried out against generated data rather than production data.

A fuller description is given in Annex C to the Data Processing Agreement, which states the measures actually in place rather than measures intended.

8. Your rights

Where we act as controller, you have the right to request access to your personal data, rectification, erasure, restriction of processing, and data portability, and to object to processing based on our legitimate interests. Where processing is based on consent, you may withdraw it at any time; this does not affect the lawfulness of processing carried out before withdrawal.

Requests are made to info@fermt.com. We respond within one month. There is no charge unless the request is manifestly unfounded or excessive.

You may lodge a complaint with the Danish Data Protection Agency: Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark, dt@datatilsynet.dk, www.datatilsynet.dk.

9. Cookies

The fermt web application (erp.fermt.com) uses only cookies and equivalent storage that are strictly necessary for authentication and security. These do not require consent, and the application contains no analytics.

The public product-label pages reached by QR code contain no cookies and no analytics of any kind. This is deliberate: an electronic wine label may not track the person reading it.

The marketing website (www.fermt.com) uses analytics cookies, but nothing is loaded and no cookie is set until you accept in the consent banner. If you accept, Google Analytics and Microsoft Application Insights are loaded. Your choice is remembered in your browser and you can change it at any time.

10. Data you enter into the platform — our role as processor

10.1Customer Data that you enter into the fermt platform is processed by us on your behalf. You determine the purposes and means; we act only on your documented instructions.

10.2The terms of that processing — instructions, security, sub-processors, assistance with data subject rights, breach notification, audit, and deletion or return on termination — are set out in the Data Processing Agreement concluded between you and fermt ApS under Article 28 GDPR. That agreement, not this policy, is the binding instrument for Customer Data.

10.3If a data subject contacts us directly about Customer Data, we will not respond substantively. We will refer them to you and inform you without undue delay.

10.4On termination, Customer Data is available for export for 30 days and is then deleted, as set out in the Data Processing Agreement.

11. Changes to this policy

We may update this policy. Material changes affecting customers are notified by email at least 30 days in advance. The version and effective date are stated at the top of the document.