GDPR in Balermo

Last updated 25 July 2026.

When you use Balermo, you handle information about your customers, names, phone numbers and what they have asked you to do. That puts you within the scope of the General Data Protection Regulation. This page explains who is responsible for what, what the system actually stores, and what you need to do yourself. It is written so you can read it without a lawyer beside you.

Two layers, two responsibilities

The key thing to understand is that Balermo has two separate layers:

You are the controller

Your customers' data

Customer register, bookings, enquiries, communication, follow-ups and time entries. This is your data about your customers. You decide what is stored and for how long, and you are the one your customer should contact.

We are the controller

Your own account

Your name, email, phone number, company registration number and your sign-ins. We process that in order to deliver the service to you. It is described in the privacy policy.

For your customers' data we are the processor. We store and display it for you, but we do not use it for anything ourselves: no resale, no marketing, no profiling, no training of AI models. The framework is the data processing agreement, which applies automatically from the moment you start using Balermo.

Record of processing activities

Article 30 requires you to be able to produce a record of what you process if the data protection authority asks. The record below is derived from what Balermo actually stores in the database, so it matches reality. You can copy it into your own paperwork and add whatever you process outside Balermo, invoices or photos on your phone, for instance.

ProcessingPurposeDataLegal basisErasure
Customer register Being able to contact the customer and remember what was agreed Name, email, phone, notes, where the customer came from Art. 6(1)(b), contract When you delete the customer
Bookings Agreeing and carrying out a visit Name, email, date, time, duration, service, remarks Art. 6(1)(b), contract When you delete the person entirely, but 5 years if it is a record behind an invoice
Enquiries (quiz) Being able to assess and answer an enquiry Name, phone, email, job type, scope, urgency, free-text description Art. 6(1)(b), steps prior to contract When you delete the person entirely
Communication log Being able to document what was agreed Channel, direction, subject, content, time Art. 6(1)(f), legitimate interest When you delete the customer
Follow-ups Remembering to get back to the customer Subject, due date, whether it is done Art. 6(1)(f), legitimate interest When you delete the customer
Time tracking Being able to account for time spent on a job Date, minutes, note, link to a booking or task Art. 6(1)(b), contract The note is cleared on full erasure of the person. The hours remain, and must be kept for 5 years if they are an accounting record under Danish bookkeeping law

When a customer asks to be deleted

If you delete a customer in the register, the customer card, the notes, the communication log and the follow-ups disappear immediately.

But bookings and enquiries hold their own copy. A booking and a quiz enquiry each store the name, email and phone number themselves, so they remain even after you delete the customer card. To remove the person completely, use the Delete the person entirely button at the bottom of the customer card in the dashboard. It first shows you what will be hit, then removes the customer card, bookings, enquiries, notes, communication and follow-ups in one go. Time entries are not deleted, they are anonymised: the hours and date remain as an accounting record while the note and the link are cleared.

Already deleted the customer card? Use the Delete a person with no customer card card at the bottom of the Customers tab. It finds the rest by email or phone number. Note that bookings can only be found by email, not by phone.

If the job has been invoiced, you may refuse. The right to erasure yields to bookkeeping law and to your need to defend a legal claim, art. 17(3)(b) and (e). Answer the customer in writing with the reason, and keep the record.

Bear in mind that the right to erasure is not absolute. If you need the information as documentation for work carried out or as an accounting record, you may keep it for as long as that is necessary, but only for that purpose.

What you need to do yourself

Security in the system

If there is a data breach

If we discover a personal data breach, we notify you without undue delay so you can meet your own deadline. If you are the controller for the affected information, it is you who must notify the data protection authority within 72 hours, and in serious cases the affected customers as well. We give you what you need: what happened, when, which data was affected, and what we have done about it.

Questions

If anything here is unclear, write to kontakt@balermo.com. We are not lawyers and cannot give you legal advice, but we can always answer precisely what the system stores and where it sits.

This page exists in Danish and English. In case of discrepancy between the language versions, the Danish version prevails.