Privacy Policy
Last updated: 20 July 2026
This Privacy Policy explains how Meritur (“Meritur”, “we”, “us”) collects, uses, and protects personal data when you use our platform: a business-to-business marketplace for Danish IT & digital consulting projects, where clients post projects, providers bid, bids are ranked on quality, and the resulting engagements are managed. Meritur is a facilitator, not a party to the contracts agreed between clients and providers.
Who we are (data controller)
The data controller for the processing described here is Meritur, operated by [Company legal name], CVR [CVR number], [registered address], Denmark. For any privacy question or to exercise your rights, contact us at laust.kreibergfricke@gmail.com.
Who this policy applies to
Merituris a business-to-business service intended for companies and their representatives. We do not knowingly offer the service to consumers or to children. “Personal data” here means information about identifiable individuals acting for a business (for example a company’s named contact), which is still protected under the EU General Data Protection Regulation (GDPR) and Danish data protection law.
Data we process
- Account data: your name, work email, role (client / provider / admin), and authentication credentials. Sign-in is handled by our authentication provider; your password is stored by that provider in hashed form and is never visible to us.
- Company data: company name, CVR number, sector, description, and verification status (confirmed by an administrator).
- Project & bid content: projects you post, budgets, timelines, categories, uploaded attachments, bids, proposal text and files, price ranges, counter-proposals, and notes, which may contain personal data if you choose to include it.
- Confidential-project (NDA) contacts: for confidential projects, the name, email, and phone number of each person a provider places under a signed non-disclosure agreement, so the client knows who is legally bound and can reach them.
- Messages: in-platform messages, which become available only after an engagement exists between the parties.
- Operational data: fee and invoice records (incl. 25% Danish VAT) and an audit log of key actions taken on the platform. Meritur never holds client funds. Payment flows directly between client and provider.
- Technical data: basic log data generated when you use the platform, used to operate and secure the service.
Why we process it (legal bases)
- Performance of a contract (Art. 6(1)(b) GDPR): to provide the marketplace, match clients and providers, enable messaging and engagements, and record fees.
- Legitimate interests (Art. 6(1)(f)): security, fraud and abuse prevention, preventing circumvention of the platform, and keeping the audit log.
- Consent (Art. 6(1)(a)): for non-essential cookies (see below). You can withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): bookkeeping, tax, and VAT records.
AI features & automated decision-making
We use AI features (for example the brief helper and scoring assistance) provided by a third-party model provider. We minimise the personal data sent to the model and process it within the EU. AI-suggested bid scores are not final automated decisions: a human administrator reviews and confirms scoring before it takes effect, so there is always a human in the loop (Art. 22 GDPR). The parameters used to rank bids can be disclosed to providers on request.
How we protect your contact details
To keep interactions on-platform, we do notdisplay other users’ email addresses or phone numbers in the interface; only company names are shown. The one exception is confidential projects, where the client sees the name, email, and phone of each person covered by a provider’s signed NDA, so the client knows who is bound and can contact them.
Sub-processors we share data with
We do not sell your personal data. We rely on the following sub-processors to run the platform. Each processes personal data only on our instructions, under a data-processing agreement, and only as needed for the purpose shown:
- Supabase — database, authentication, and file storage. Purpose: storing and serving all account, company, project, bid, and file data. Location: EU.
- Vercel — application hosting and content delivery. Purpose: running the website and its server functions. Location: EU (function region), global edge network for static delivery.
- Resend — transactional email delivery. Purpose: sending notification and account emails. Data shared: recipient email address and the message content.
- Anthropic — AI model provider for the brief helper and the confidential-project redaction helper. Purpose: generating those suggestions. Data shared: the project text you submit to those features (for redaction, this is your draft project details); we minimise the personal data sent and process within the EU.
This list may change as the platform evolves; we will keep it current. We may also disclose data where required by law, or to establish, exercise, or defend legal claims.
Where your data is stored
We host data and run our AI processing within the EU. If any transfer outside the EU/EEA becomes necessary, we will rely on an approved safeguard such as the European Commission’s Standard Contractual Clauses.
Retention & security
We keep personal data only as long as your account is active and as needed for the purposes above, then only as required by law (e.g. accounting records), to resolve disputes, and to enforce our agreements; when no longer needed, we delete or anonymise it.
Audit logs. We keep an audit log of key actions (such as awards, access grants, and scoring) for security, abuse-prevention, and accountability. These records are retained for a limited period and then deleted; they are accessible only to administrators.
We protect data with appropriate technical and organisational measures, including access controls, EU-hosted infrastructure, private storage for uploaded files, database-level access restrictions, and encryption in transit.
Cookies
We use essential cookies and local storage only by default. These keep you signed in and remember your language and cookie choices, and do not require consent. Any non-essential cookies (for example analytics) are declined by default and are only set if you explicitly accept them. You can change your choice at any time via .
Your rights
Under the GDPR you can request access, rectification, erasure, restriction, and portability of your personal data, object to certain processing, and withdraw consent at any time (without affecting processing already carried out). To exercise these rights, contact us at laust.kreibergfricke@gmail.com. You may also lodge a complaint with the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk).
Changes & contact
We may update this policy from time to time; when we make material changes we will update the “Last updated” date above. Questions? Contact Meritur at laust.kreibergfricke@gmail.com. You can also review our Terms of Service.
This page is a practical draft for the prototype, not legal advice. The bracketed details must be completed and the wording reviewed by a Danish lawyer before launch.