FIT-Outcomes

Privacy Policy

Last updated: 4 May 2026

1. Who we are

FIT-Outcomes ApS ("FIT-Outcomes", "we", "us") is the controller for the personal data described in this Privacy Policy, except where we act as processor on behalf of an Agency (see section 3).

FIT-Outcomes ApS
Breeltehøj 4
DK-2970 Hørsholm
Denmark
VAT: DK-33954263
Contact for privacy matters: info@fit-outcomes.com

2. Scope of this policy

This Privacy Policy describes how we process personal data when:

What this policy does and does not cover. When an Agency uses the Service to process personal data about its Clients, Raters, and other data subjects, we act as the Agency's processor. The Agency's own privacy notice and the Data Processing Agreement ("DPA") between the Agency and FIT-Outcomes govern that processing. This Privacy Policy describes our own processing as controller (e.g. of Users, account holders, website visitors, support contacts) and provides general transparency about how the Service works.

If something in this policy conflicts with the DPA on the processing of Clinical Data, the DPA prevails.

3. Our roles: controller vs. processor

The rest of this policy concerns our role as controller, except where stated otherwise.

4. What we collect, why, and lawful basis

4.1 Website visitors

DataPurposeLawful basis (GDPR)
IP address, request metadata, user agent, referer, timestamps (server logs)Operating and securing the website; abuse preventionArt. 6(1)(f) legitimate interest
Strictly necessary cookies and similar storageMaking the site work (e.g. session, theme, language)Art. 6(1)(f) legitimate interest / Cookie Order §3(2) (storage strictly necessary for the requested service)

We do not use advertising, profiling, or third-party analytics cookies on the website.

4.2 Account holders and Users

When you create an Agency or are invited as a User, we process:

DataPurposeLawful basis
Name, email address, role, language preference, time zone, agency membershipProviding the Service, authenticating you, displaying the right UIArt. 6(1)(b) performance of contract (with the Agency or with you)
Password hash or SSO identifier (Microsoft or Google)AuthenticationArt. 6(1)(b) performance of contract
Login events, session timestamps, device/browser metadataSecurity, fraud prevention, auditArt. 6(1)(f) legitimate interest
Operational logs of actions in the Service (audit trail)Security, compliance, troubleshootingArt. 6(1)(f) legitimate interest; Art. 6(1)(c) where required by law
Billing details (Agency invoicing contact, VAT number)Invoicing, accountingArt. 6(1)(b) contract; Art. 6(1)(c) bookkeeping obligations

4.3 People who contact us

If you email us, fill in a contact form, or otherwise reach out, we process the contact details and message content you provide, in order to respond and to keep a record of the exchange. Lawful basis: Art. 6(1)(f) legitimate interest in handling enquiries, or Art. 6(1)(b) where the exchange relates to a contract.

4.4 Clinical Data (processed as processor)

Clinical Data — including data about Clients, Raters, Episodes, Sessions, feedback links, and feedback responses — is processed on behalf of the Agency under the DPA. The Agency decides what is collected, why, and how long it is kept. We do not use Clinical Data for our own purposes.

5. Single sign-on (Microsoft and Google)

If you sign in with a Microsoft or Google account, that provider authenticates you and sends us a limited set of profile data (typically your name, email address, and a stable user identifier) so we can match you to your User record. We do not receive your Microsoft or Google password. The provider acts as an independent controller for the authentication itself; its handling of your account is governed by that provider's own privacy statement.

6. Cookies, local storage, and similar technologies

The Service uses only first-party storage that is strictly necessary for the Service to work. We do not set advertising or cross-site tracking cookies and we do not use third-party analytics.

Specifically:

Because all of this is strictly necessary to provide a service you have actively requested, no separate consent banner is required under the Danish Cookie Order (Cookiebekendtgørelsen) §3(2).

7. Server logs and security telemetry

Our servers keep technical logs (IP address, request path, status code, response time, user agent, timestamp). IP addresses are personal data under the GDPR; we treat them as such. Logs are used for operating and securing the Service, investigating incidents, and meeting our security obligations. They are kept for up to ninety (90) days unless a longer period is needed to investigate a specific incident.

8. Sub-processors and third-party services

We use a small number of providers to operate the Service. The current list of sub-processors that may process personal data on our behalf:

ProviderRoleLocation
Hetzner Online GmbHCloud hosting (servers, databases, backups)Germany (EU)

9. International transfers

We aim to keep all processing within the EU/EEA. The sub-processors we currently use store and process data in the EU/EEA only. We do not currently transfer personal data to countries outside the EU/EEA. If that changes in the future, we will update this policy and rely on a valid transfer mechanism under the GDPR (Standard Contractual Clauses, an adequacy decision, or another lawful safeguard).

10. Retention

We keep personal data only as long as we need it for the purposes described in section 4, or as required by law.

When the retention period ends, we delete the data or irreversibly anonymise it.

11. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS), encryption at rest for databases and backups, role-based access control inside the Service, hashed passwords, audit logs of administrative actions, principle-of-least-privilege access for our staff, and regular updates of dependencies. No system is perfectly secure; if you become aware of a security issue, please report it to info@fit-outcomes.com.

12. Your rights under the GDPR

You have the following rights in relation to your personal data:

These are your rights as a data subject. Where we act as processor for an Agency (Clinical Data), please direct rights requests to the Agency, which is the controller; we will support them as required by the DPA.

13. How to exercise your rights and complain

To exercise your rights, contact us at info@fit-outcomes.com. We will respond within one month of receiving your request. Where the request is complex or we receive a large number of requests, we may extend that period by up to two further months and will tell you within the first month. Exercising your rights is free of charge, except where requests are manifestly unfounded or excessive (in which case we may charge a reasonable fee or refuse to act, as permitted by Art. 12(5) GDPR).

You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement. The Danish supervisory authority is Datatilsynet (https://www.datatilsynet.dk).

14. Children

The Service is intended for professional use by Agencies and their Users, all of whom must be at least 18 years old. The Service may, however, be used by Agencies to record information about Clients who are children (for example in family or youth therapy). In that case the Agency is the controller and is responsible for having a lawful basis (including parental consent where required), for providing appropriate information to the data subjects, and for handling rights requests. Our role is processor under the DPA.

We do not knowingly collect personal data directly from children for our own purposes. If you believe we have, please contact us so we can investigate and, if appropriate, delete the data.

15. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the latest version. For changes that materially affect how we process your personal data, we will give reasonable advance notice (e.g. by email or in-app notification). The current version is always available on the Service.

16. Contact

For any question about this Privacy Policy or how we handle personal data, contact us at:

FIT-Outcomes ApS
Breeltehøj 4
DK-2970 Hørsholm
Denmark
info@fit-outcomes.com