Privacy Policy

Version 2026-09-23

1. Who we are

Recortex is provided by KDI ApS, Danish company registration number (CVR) 46525892, Thors Allé 1, 4673 Rødvig Stevns, Denmark ("we"). Contact for anything about your personal data: hello@klamer-dueholm.com. We have not appointed a data protection officer; write to the same address.

2. Two different roles

For your account and our website, we decide why and how your personal data is processed — we are the controller. Sections 3 and 4 describe that processing.

For the business data your company connects — its shop, ad account or bookkeeping — we process it on your company's behalf, as its processor, under the Data Processing Agreement. Your company decides the legal basis for that data. Section 5 describes what it is, so you know what you are connecting.

3. Personal data we process about you

WhatWhy, and on what basisHow long
Your email address and sign-in activityTo let you sign in (there are no passwords: you sign in with a single-use link sent by email). Performing our agreement with you (GDPR art. 6(1)(b)); if your employer is our customer, our legitimate interest in providing the service they bought (art. 6(1)(f)).While you are a member of a workspace. Without a workspace: removed in the first monthly run after 30 days without a sign-in — at the latest 65 days after the last sign-in (our own staff's accounts excepted).
Your acceptance of our Terms and Data Processing Agreement: the versions, the time, your email address and the workspaceTo document the agreement. Legitimate interest (art. 6(1)(f)). We do not record your IP address.An exception, kept longer than the rest of your data: at most 3 years after the customer relationship ends — the period within which claims under the agreement can be made.
Your workspace: the company name and that you are its ownerTo set up your company's account. Performing our agreement (art. 6(1)(b)).Until the customer relationship ends; deleted within 30 days after that.
Invitations: your email address, who invited you, and when the invitation was sent, used and expiresTo let a customer add colleagues. Legitimate interest (art. 6(1)(f)).Removed in the first monthly run after 30 days from when it is used or expires — at the latest 65 days after.
Waitlist sign-ups: your email address, the page you signed up on, the referring page if your browser shares it, the consent text and time, and a hashed (not readable) form of your IP addressTo tell you when Recortex opens, if you asked us to — your consent (art. 6(1)(a)), which you can withdraw at any time by unsubscribing. The hashed IP address limits repeated sign-ups: legitimate interest (art. 6(1)(f)). Your address is not mailed until you confirm it.Unconfirmed: at the latest 65 days after sign-up. Confirmed: until you unsubscribe, and at the latest 24 months plus 35 days after you confirmed. After you unsubscribe: at the latest 65 days. The hashed IP address: at the latest 42 days.
Emails you send usTo answer you. Legitimate interest (art. 6(1)(f)), or our agreement with you.Removed in the first monthly run after 2 years from our last correspondence — at the latest 2 years plus 35 days.
Technical logs kept by our hosting providers: IP address, time, and the full address requestedTo keep the service running and secure. Legitimate interest (art. 6(1)(f)).Vercel: up to 30 days. Supabase: 7 days.

A "monthly run" is a deletion we carry out on the first working day of each month; the times given are the latest it happens. Data of these kinds that existed when this version was published — including the IP addresses recorded with acceptances before 23 September 2026 — is deleted by 31 October 2026 at the latest.

Our database provider keeps daily backups for 7 days, so data we delete can remain in a backup for up to 7 days before it is gone.

4. Cookies and browser storage

We use one cookie while you are signed in: the session cookie that keeps you signed in. It is strictly necessary for a service you asked for.

We also store your light/dark theme preference in your browser's local storage. It never leaves your device.

We use no analytics, advertising or tracking cookies, and no third-party trackers.

5. Business data your company connects

Recortex only reads from the systems you connect. It never creates, changes or deletes anything in them.

SourceStatusWhat we read, and what we keep
ShopifyNot yet available (awaiting Shopify's approval of our app).When available: For each order: the amounts (item prices, quantities, discounts, refunds), tax rates, currency and dates. We do not request customer names, email addresses, phone numbers, addresses or product details. We keep only totals per day; individual orders are not stored.
Meta (Facebook/Instagram ads)Not yet available.When available: ad spend and the purchase value Meta attributes to its own ads, for the whole ad account, per day. No ad-level data and no data about individual people.
e-conomicNot yet available (awaiting e-conomic's approval of our app).When available: only the accounts you choose, summed per month into booked marketing cost and booked revenue, plus the company name, agreement number and currency so you can see which books are connected. e-conomic's answers also contain information we do not ask for and do not keep — the signed-in user's name and email address, and the text of individual bookings, which can name people. We read it while handling a request and do not store it. You connect e-conomic by pasting the access token e-conomic shows you, so the token is never part of a web address.
Your Playbook answersIn use.What you tell us about your business in your own words. Please do not enter personal data about other people there.

When connections become available, the access you grant will be stored encrypted and never be visible to anyone signed in to Recortex.

6. AI

Every number, comparison and proposed action in Recortex is computed by Recortex's own rules. We use one AI service, and only to put some of those results into plain language.

Anthropic (Claude)

Once Shopify can be connected, Anthropic will receive, for recommendations built on your Shopify figures: your Playbook answers, the daily totals the recommendation concerns, and the action Recortex has already computed. Recortex does not yet read any data from Meta or e-conomic (section 5), so none can reach Anthropic. When those connections become available, their data will not be sent to Anthropic either: recommendations that rest on them will be worded by Recortex's own fixed templates. Before anything is sent, Recortex checks the text for patterns such as email addresses and identification numbers and refuses to send it if it finds one.

Anthropic processes this as our sub-processor under its commercial terms and data processing addendum. It stores the data in the United States and may process it in the United States, Europe, Asia and Australia; the transfer outside the EU/EEA is covered by the EU Standard Contractual Clauses in that addendum. Anthropic does not train its models on it and deletes it within 30 days — unless its automated safety systems flag it, in which case it can be kept for up to two years.

We use no other AI service on your data. Before we add one, we update this policy and tell customers as described in section 12.

7. Where your data is stored, and who processes it

ProviderWhat forLocation
SupabaseDatabase, encrypted store for access credentials, sign-in and sign-in emailsDatabase: Frankfurt, Germany (EU)
SupabaseBackground processing (reading connected systems, preparing recommendations)Supabase Edge Functions, which read and write the database in Frankfurt; Supabase may run them in the region nearest to where they are started
VercelWebsite and applicationApplication functions: Frankfurt, Germany (EU); requests pass through Vercel's global network
AnthropicPlain-language wording of recommendations (section 6)Stored in the United States; may be processed in the United States, Europe, Asia and Australia

Anthropic stores what it receives in the United States under the EU Standard Contractual Clauses. Supabase and Vercel keep the data in Frankfurt; both are US companies, and their data processing agreements, which include the EU Standard Contractual Clauses, cover any access from outside the EU/EEA. The systems you connect (Shopify, Meta, e-conomic) are your company's own providers, not ours.

8. How long we keep business data

  • While your company is a customer, the daily and monthly figures Recortex computes from connected systems are kept for 24 months, for history, tracking and analysis, and deleted once they are older.
  • When the customer relationship ends, everything attributable to the customer is deleted within 30 days — carried out by us when the relationship ends, not in a monthly run. The one exception is the record that the customer accepted our Terms and Data Processing Agreement (section 3).

Shopify, Meta and e-conomic cannot be connected yet. From the day each becomes available, the following applies to it:

  • A connection error or expired access does not end anything: the figures already collected are kept, and your company can reconnect.
  • When your company disconnects a system, Recortex deletes its access at once and stops reading. The figures already collected stay under the 24-month rule unless your company asks us to delete them sooner, or the platform's terms require earlier deletion — in which case we follow those terms.
  • When Recortex is uninstalled in Shopify, its access to the store is deleted at once, and the store's data is deleted when Shopify asks us to (48 hours after the uninstall) and in any case within 30 days, as Shopify's terms require.

9. Your rights, and how to have data deleted

Under the GDPR you have the right to access your personal data; to have it corrected or erased; to restrict or object to its processing; to receive it in a portable format; and, where processing is based on your consent, to withdraw that consent at any time. Email us (hello@klamer-dueholm.com) to use any of these rights. Where we process data on a customer's behalf, we pass your request to that customer and help them answer it.

Deleting data from a connected system (for example Meta or Shopify), once connections are available: disconnect it on the Connections page — Recortex deletes its access at once and stops reading — and email us asking for the data already collected from it to be deleted. We confirm when it is done. Removing Recortex's access in the other system (for example in Meta's business settings, or uninstalling Recortex in Shopify) also stops all reading.

You can complain to the Danish Data Protection Agency (Datatilsynet), datatilsynet.dk.

10. Security

  • All connections to Recortex are encrypted (HTTPS/TLS).
  • When connections become available, their access credentials will be stored encrypted in a separate store that only the service itself can read, and never shown to anyone signed in.
  • Each workspace can see only its own data. The database itself enforces this, not only the application.
  • Recortex has read-only access to the systems you connect.

11. What Recortex does not do

We do not sell personal data or share it for advertising, do not build profiles of individual people, make no automated decisions about individual people, and do not use your data to train AI models.

12. Changes to this policy

When this policy changes, the version above changes with it. We tell each workspace owner by email about material changes — a new purpose, a new kind of data, a new provider that processes your data, or a longer retention period — at least 30 days before they take effect.