Privacy Policy
Last updated: 4 May 2026
1. Who we are
FIT-Outcomes ApS ("FIT-Outcomes", "we", "us") is the controller for the personal data described in this Privacy Policy, except where we act as processor on behalf of an Agency (see section 3).
FIT-Outcomes ApS
Breeltehøj 4
DK-2970 Hørsholm
Denmark
VAT: DK-33954263
Contact for privacy matters: info@fit-outcomes.com
2. Scope of this policy
This Privacy Policy describes how we process personal data when:
- you visit our website at https://www.fit-outcomes.com;
- you create an Agency, register as a User, or otherwise use the FIT-Outcomes platform (the "Service");
- you contact us by email, web form, or other channel.
What this policy does and does not cover. When an Agency uses the Service to process personal data about its Clients, Raters, and other data subjects, we act as the Agency's processor. The Agency's own privacy notice and the Data Processing Agreement ("DPA") between the Agency and FIT-Outcomes govern that processing. This Privacy Policy describes our own processing as controller (e.g. of Users, account holders, website visitors, support contacts) and provides general transparency about how the Service works.
If something in this policy conflicts with the DPA on the processing of Clinical Data, the DPA prevails.
3. Our roles: controller vs. processor
- We are the controller for: website visitors; people who contact us; individuals registering an Agency or User account; billing contacts; the operational metadata we keep about Users and Agencies (login times, audit logs, support history).
- We are the processor for: Clients, Raters, Episodes, Sessions, feedback responses (ORS, SRS, and similar), and any other personal data an Agency or its Users put into the Service in the course of clinical work. The Agency is the controller for that data, and our processing of it is governed by the DPA.
The rest of this policy concerns our role as controller, except where stated otherwise.
4. What we collect, why, and lawful basis
4.1 Website visitors
| Data | Purpose | Lawful basis (GDPR) |
|---|---|---|
| IP address, request metadata, user agent, referer, timestamps (server logs) | Operating and securing the website; abuse prevention | Art. 6(1)(f) legitimate interest |
| Strictly necessary cookies and similar storage | Making the site work (e.g. session, theme, language) | Art. 6(1)(f) legitimate interest / Cookie Order §3(2) (storage strictly necessary for the requested service) |
We do not use advertising, profiling, or third-party analytics cookies on the website.
4.2 Account holders and Users
When you create an Agency or are invited as a User, we process:
| Data | Purpose | Lawful basis |
|---|---|---|
| Name, email address, role, language preference, time zone, agency membership | Providing the Service, authenticating you, displaying the right UI | Art. 6(1)(b) performance of contract (with the Agency or with you) |
| Password hash or SSO identifier (Microsoft or Google) | Authentication | Art. 6(1)(b) performance of contract |
| Login events, session timestamps, device/browser metadata | Security, fraud prevention, audit | Art. 6(1)(f) legitimate interest |
| Operational logs of actions in the Service (audit trail) | Security, compliance, troubleshooting | Art. 6(1)(f) legitimate interest; Art. 6(1)(c) where required by law |
| Billing details (Agency invoicing contact, VAT number) | Invoicing, accounting | Art. 6(1)(b) contract; Art. 6(1)(c) bookkeeping obligations |
4.3 People who contact us
If you email us, fill in a contact form, or otherwise reach out, we process the contact details and message content you provide, in order to respond and to keep a record of the exchange. Lawful basis: Art. 6(1)(f) legitimate interest in handling enquiries, or Art. 6(1)(b) where the exchange relates to a contract.
4.4 Clinical Data (processed as processor)
Clinical Data — including data about Clients, Raters, Episodes, Sessions, feedback links, and feedback responses — is processed on behalf of the Agency under the DPA. The Agency decides what is collected, why, and how long it is kept. We do not use Clinical Data for our own purposes.
5. Single sign-on (Microsoft and Google)
If you sign in with a Microsoft or Google account, that provider authenticates you and sends us a limited set of profile data (typically your name, email address, and a stable user identifier) so we can match you to your User record. We do not receive your Microsoft or Google password. The provider acts as an independent controller for the authentication itself; its handling of your account is governed by that provider's own privacy statement.
6. Cookies, local storage, and similar technologies
The Service uses only first-party storage that is strictly necessary for the Service to work. We do not set advertising or cross-site tracking cookies and we do not use third-party analytics.
Specifically:
- A first-party session cookie is used to keep you signed in. It is
HttpOnlyandSecure. Without it, the Service cannot authenticate you. - Browser local storage is used for UI preferences only: your selected language, theme, and current agency (
agency-id). These never leave your browser.
Because all of this is strictly necessary to provide a service you have actively requested, no separate consent banner is required under the Danish Cookie Order (Cookiebekendtgørelsen) §3(2).
7. Server logs and security telemetry
Our servers keep technical logs (IP address, request path, status code, response time, user agent, timestamp). IP addresses are personal data under the GDPR; we treat them as such. Logs are used for operating and securing the Service, investigating incidents, and meeting our security obligations. They are kept for up to ninety (90) days unless a longer period is needed to investigate a specific incident.
8. Sub-processors and third-party services
We use a small number of providers to operate the Service. The current list of sub-processors that may process personal data on our behalf:
| Provider | Role | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud hosting (servers, databases, backups) | Germany (EU) |
9. International transfers
We aim to keep all processing within the EU/EEA. The sub-processors we currently use store and process data in the EU/EEA only. We do not currently transfer personal data to countries outside the EU/EEA. If that changes in the future, we will update this policy and rely on a valid transfer mechanism under the GDPR (Standard Contractual Clauses, an adequacy decision, or another lawful safeguard).
10. Retention
We keep personal data only as long as we need it for the purposes described in section 4, or as required by law.
- Website visitor logs: up to 90 days (see section 7).
- Active accounts and Agencies: for as long as the account or Agency is active.
- After a trial ends without conversion: we keep account and operational data for 7 days, then delete or anonymise it.
- Billing and accounting records: kept for the period required by Danish bookkeeping law (currently five years from the end of the relevant financial year).
- Support correspondence: kept for up to 24 months after the last interaction, unless we need it longer for a specific dispute or claim.
- Backups: retained for the period and deleted as described in the DPA. Personal data in backups is overwritten on the normal backup rotation; we do not surgically remove individual records from existing backups.
When the retention period ends, we delete the data or irreversibly anonymise it.
11. Security
We use technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS), encryption at rest for databases and backups, role-based access control inside the Service, hashed passwords, audit logs of administrative actions, principle-of-least-privilege access for our staff, and regular updates of dependencies. No system is perfectly secure; if you become aware of a security issue, please report it to info@fit-outcomes.com.
12. Your rights under the GDPR
You have the following rights in relation to your personal data:
- Access — to obtain confirmation of whether we process personal data about you, and a copy of that data.
- Rectification — to have inaccurate or incomplete data corrected.
- Erasure ("right to be forgotten") — to have your data deleted in certain circumstances.
- Restriction — to have processing restricted in certain circumstances.
- Objection — to object to processing based on legitimate interest.
- Portability — to receive your data in a structured, commonly used, machine-readable format, where the processing is based on consent or contract and is carried out by automated means.
- Withdraw consent — where we rely on consent, to withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
These are your rights as a data subject. Where we act as processor for an Agency (Clinical Data), please direct rights requests to the Agency, which is the controller; we will support them as required by the DPA.
13. How to exercise your rights and complain
To exercise your rights, contact us at info@fit-outcomes.com. We will respond within one month of receiving your request. Where the request is complex or we receive a large number of requests, we may extend that period by up to two further months and will tell you within the first month. Exercising your rights is free of charge, except where requests are manifestly unfounded or excessive (in which case we may charge a reasonable fee or refuse to act, as permitted by Art. 12(5) GDPR).
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement. The Danish supervisory authority is Datatilsynet (https://www.datatilsynet.dk).
14. Children
The Service is intended for professional use by Agencies and their Users, all of whom must be at least 18 years old. The Service may, however, be used by Agencies to record information about Clients who are children (for example in family or youth therapy). In that case the Agency is the controller and is responsible for having a lawful basis (including parental consent where required), for providing appropriate information to the data subjects, and for handling rights requests. Our role is processor under the DPA.
We do not knowingly collect personal data directly from children for our own purposes. If you believe we have, please contact us so we can investigate and, if appropriate, delete the data.
15. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the latest version. For changes that materially affect how we process your personal data, we will give reasonable advance notice (e.g. by email or in-app notification). The current version is always available on the Service.
16. Contact
For any question about this Privacy Policy or how we handle personal data, contact us at:
FIT-Outcomes ApS
Breeltehøj 4
DK-2970 Hørsholm
Denmark
info@fit-outcomes.com