Privacy policy

Last updated 25 July 2026.

This policy covers the information JURIDISK_NAVN_OG_CVR processes as data controller: visitors to balermo.com, tradespeople who create an account, and people who contact us for support.

Two layers, and this is only one of them. Information about a tradesperson's customers is the tradesperson's own responsibility as data controller. There we are the processor, and we act only on their instructions.

If you are a customer of a tradesperson and have booked a time or sent an enquiry, contact the tradesperson, not us. The framework is set out in the data processing agreement, and the whole model is explained on the GDPR page.

Data controller

JURIDISK_NAVN_OG_CVR
kontakt@balermo.com

What we process, and why

Visitors to balermo.com

The web server logs the IP address, the time and which page was requested. This is done to operate and secure the service, and the legal basis is our legitimate interest in secure operation, art. 6(1)(f). The logs sit with our hosting provider and are kept only briefly.

Your tradesperson account

When you create an account, we process what you enter yourself: name, email, phone number, area, company registration number, company name and optionally a link to your Google business profile. The registration number is used to look up your company name and area so you do not have to type them. The purpose is to give you access and deliver the service, and the legal basis is performance of our contract with you, art. 6(1)(b).

If you use Google sign-in, we receive your Google ID, name, email and profile picture from Google. We request only the basic scopes (openid, email and profile), we get no access to your Gmail, your Drive or your calendar.

Sign-in links by email

If you request a sign-in link, we store your email address and a one-time link. The link itself is stored only as a one-way hash, so a compromised database does not give access to your account. It expires after 15 minutes and can be used only once. The legal basis is performance of our contract with you, art. 6(1)(b).

Your public page

Whatever you put on your own trade page, company name, services, area, phone number, is publicly available. That is the entire point of the page, but it is worth being aware of: if you publish your private mobile number, anyone can see it.

Support enquiries

If you write to us, we process what you tell us, typically your name, email and a description of your problem. The legal basis is our legitimate interest in being able to help you, art. 6(1)(f). Enquiries are deleted once the matter has been closed for a reasonable period.

Cookies

We set one cookie, and it is strictly necessary. It is called sid, keeps you signed in, and contains nothing but a random session id, no information about you. It cannot be read by JavaScript, is sent only over HTTPS, and expires on its own.

We use no cookies for statistics, advertising or profiling, and there are no tracking scripts, pixels or third-party embeds on these pages. That is also why you never meet a consent banner: necessary cookies do not require consent, and there is nothing else to consent to. Should we ever add statistics or marketing, we will ask for consent first, with categories you can choose individually, and where "reject all" sits just as visibly and takes just as few clicks as "accept all".

Who receives the information

We do not sell information and do not use it for profiling or automated decisions. We use these processors:

Data is stored within the EU/EEA. If you use Google sign-in, that processing happens at Google under Google's own terms, and Google may transfer data to the United States on the basis of the European Commission's adequacy decision.

How long we keep it

Your rights

You have the right of access, rectification, erasure, restriction, data portability and to object. Some of these you can exercise directly in the app; the rest we handle for you:

You can complain to the Danish Data Protection Agency, Carl Jacobsens Vej 35, 2500 Valby, datatilsynet.dk.

Security and data breaches

The connection is encrypted with HTTPS, sign-in links are stored as one-way hashes, sessions are kept in a directory blocked from web access, and access to data requires being signed in to the exact account the data belongs to. If we discover a personal data breach, we notify the Danish Data Protection Agency within 72 hours for the data we are the controller for. For information about a tradesperson's customers the tradesperson is the controller, and there we notify them without undue delay so they can meet their own deadline. Who does what is set out on the GDPR page.

Changes

If we change this policy materially, we update the date at the top and give notice in the app or by email before the change takes effect.

This policy exists in Danish and English. In case of discrepancy between the language versions, the Danish version prevails.