Privacy Policy
fermt ApS · Version 2.0 · Effective 20 September 2026
1. Who we are
The fermt platform is operated by fermt ApS, Åløkkevej 1, 2720 Vanløse, Denmark ("fermt", "we", "us"). You can reach us at info@fermt.com.
We have not appointed a data protection officer. We are not required to do so, as our processing does not meet the criteria in Article 37 GDPR.
2. Two different roles — read this first
We handle personal data in two distinct capacities, and different rules apply to each. Keeping them apart matters, because it determines who decides what happens to the data and who answers for it.
| Data | Our role | What governs it |
|---|---|---|
| Account, billing, support and website data — the data we need in order to have you as a customer. | Controller. We decide the purposes and means. | This Privacy Policy. |
| Customer Data — everything you enter into the fermt platform: products, recipes, batches, orders, traceability records, and any personal data contained in them, including data about your own employees, suppliers and customers. | Processor. You decide the purposes and means. We act on your documented instructions. | The Data Processing Agreement between you and fermt ApS, concluded under Article 28 GDPR. |
Sections 3 to 9 describe the data we process as controller. Section 10 describes, in summary, the data we process as processor; the binding terms for that processing are in the Data Processing Agreement, not in this policy.
3. Personal data we process as controller
| Category | Data | Purpose | Legal basis |
|---|---|---|---|
| Account data | Name, email address, company name, job title, organisation details. We do not store passwords: authentication is handled by Microsoft Entra External ID, and the application only validates a signed token issued by that service. | Creating and administering your account; authentication | Art. 6(1)(b) — performance of a contract |
| Billing data | Company name, billing address, VAT number, subscription and invoice history, payment status. Card details are handled by Stripe and are not stored by us. | Invoicing, payment collection, accounting | Art. 6(1)(b) and Art. 6(1)(c) — legal obligation under the Danish Bookkeeping Act |
| Support data | Correspondence with us, including any information you choose to include | Answering enquiries, troubleshooting | Art. 6(1)(f) — our legitimate interest in supporting customers |
| Technical and log data | IP address, browser and device information, timestamps, pages and actions within the application, error traces, and a pseudonymous reference to the signed-in user. Free-text content is removed before it reaches our telemetry. | Operating and securing the Service, detecting abuse, diagnosing faults | Art. 6(1)(f) — our legitimate interest in a secure and functioning service |
| Website analytics data | Pages visited, referrer, approximate location, device type — on www.fermt.com only, and only if you accept analytics in the consent banner. | Understanding how the website is used | Art. 6(1)(a) — consent, withdrawable at any time |
| Marketing data | Email address and communication preferences, where you have signed up | Sending product updates and newsletters | Art. 6(1)(a) — consent, withdrawable at any time |
We do not use the data above for automated decision-making or profiling with legal or similarly significant effects.
4. Where the data is stored
4.1The fermt platform and its databases are hosted on Microsoft Azure in the West Europe (Netherlands) region, within the EU/EEA. Some operational telemetry is stored in the North Europe (Ireland) region, also within the EU/EEA.
4.2Payment processing is carried out by Stripe. Stripe may transfer personal data outside the EU/EEA; such transfers rely on the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
4.3Transactional email is delivered by Proton AG in Switzerland, a country covered by a European Commission adequacy decision.
4.4If you accept analytics on www.fermt.com, Google Analytics may transfer data outside the EU/EEA under the Standard Contractual Clauses and the EU–US Data Privacy Framework. This applies to the marketing website only. The fermt application and the public product-label pages contain no analytics at all.
4.5Apart from the above, we do not transfer personal data outside the EU/EEA.
5. Recipients and processors
We share personal data only with the following recipients, and only to the extent necessary.
| Recipient | Role | Purpose | Location |
|---|---|---|---|
| Microsoft Ireland Operations Ltd. (Microsoft Azure) | Our processor | Hosting, storage, backup, platform infrastructure | EU/EEA — West Europe (Netherlands) |
| Microsoft Ireland Operations Ltd. (Microsoft Entra External ID) | Our processor | Authentication and credential management | EU/EEA |
| Microsoft Ireland Operations Ltd. (Azure OpenAI Service) | Our processor | Optional assistance features, where you use them. Prompts are not used to train models. | EU/EEA — West Europe (Netherlands) |
| Microsoft Ireland Operations Ltd. (Azure Application Insights) | Our processor | Error tracking and usage telemetry | EU/EEA — West Europe and North Europe |
| Proton AG | Our processor | Transactional and support email | Switzerland — adequacy decision |
| Stripe Payments Europe, Ltd. | Independent controller for payment data; our processor for subscription administration | Card payment processing, fraud prevention, subscription billing | Ireland, with onward transfers under SCCs |
| Google Ireland Ltd. (Google Analytics) | Our processor | Website analytics on www.fermt.com — only if you accept analytics in the consent banner | Ireland, with onward transfers under SCCs and the EU–US Data Privacy Framework |
| Public authorities, our accountant or legal advisers | Recipients | Where required by law or to establish or defend legal claims | Denmark |
6. How long we keep the data
| Data | Retention period |
|---|---|
| Account data | For the duration of the subscription, then 30 days after termination |
| Billing and accounting records | Five years from the end of the financial year to which they relate, as required by the Danish Bookkeeping Act |
| Support correspondence | Three years from the last message, or longer where needed to defend a legal claim |
| Application telemetry (errors, timings, usage) | 90 days |
| Infrastructure logs | 30 days |
| Database backups | 7 days, on a rolling point-in-time window |
| Website analytics data | In accordance with the provider’s configured retention, or until you withdraw consent |
| Marketing data | Until consent is withdrawn |
7. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.2 or higher) and at rest, individual user accounts with role-based permissions, administrative access restricted to a single named person and protected by the identity provider, an IP firewall in front of the production database, an audit trail of actions within the Service, automated alerting on errors, continuous database backup, and development carried out against generated data rather than production data.
A fuller description is given in Annex C to the Data Processing Agreement, which states the measures actually in place rather than measures intended.
8. Your rights
Where we act as controller, you have the right to request access to your personal data, rectification, erasure, restriction of processing, and data portability, and to object to processing based on our legitimate interests. Where processing is based on consent, you may withdraw it at any time; this does not affect the lawfulness of processing carried out before withdrawal.
Requests are made to info@fermt.com. We respond within one month. There is no charge unless the request is manifestly unfounded or excessive.
You may lodge a complaint with the Danish Data Protection Agency: Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark, dt@datatilsynet.dk, www.datatilsynet.dk.
9. Cookies
The fermt web application (erp.fermt.com) uses only cookies and equivalent storage that are strictly necessary for authentication and security. These do not require consent, and the application contains no analytics.
The public product-label pages reached by QR code contain no cookies and no analytics of any kind. This is deliberate: an electronic wine label may not track the person reading it.
The marketing website (www.fermt.com) uses analytics cookies, but nothing is loaded and no cookie is set until you accept in the consent banner. If you accept, Google Analytics and Microsoft Application Insights are loaded. Your choice is remembered in your browser and you can change it at any time.
10. Data you enter into the platform — our role as processor
10.1Customer Data that you enter into the fermt platform is processed by us on your behalf. You determine the purposes and means; we act only on your documented instructions.
10.2The terms of that processing — instructions, security, sub-processors, assistance with data subject rights, breach notification, audit, and deletion or return on termination — are set out in the Data Processing Agreement concluded between you and fermt ApS under Article 28 GDPR. That agreement, not this policy, is the binding instrument for Customer Data.
10.3If a data subject contacts us directly about Customer Data, we will not respond substantively. We will refer them to you and inform you without undue delay.
10.4On termination, Customer Data is available for export for 30 days and is then deleted, as set out in the Data Processing Agreement.
11. Changes to this policy
We may update this policy. Material changes affecting customers are notified by email at least 30 days in advance. The version and effective date are stated at the top of the document.
