LEGAL · DATA PROTECTION
Privacy Policy
This Privacy Policy explains how Testora ApS processes personal data relating to website visitors and business contacts, applicants, customers, recipients and suppliers.
Last updated: 21 August 2026 · Version 1.0 draft
On this page
- 1. Data controller
- 2. Who this policy covers
- 3. Data we collect
- 4. How data is collected
- 5. Purposes and legal bases
- 6. Cookies, analytics and marketing
- 7. Recipients and service providers
- 8. International transfers
- 9. Retention
- 10. Security
- 11. Your rights
- 12. Complaints
- 13. Business contact data provided by customers
- 14. Changes
Key point
Testora.eu is a B2B website. Most information concerns companies, but names, business contact details, account data, device data and correspondence can identify individual people and are therefore personal data.
1. Data controller
The data controller is Testora ApS, CVR 46447077, Ryparken 74, 1.th, 2100 Copenhagen Ø, Denmark. Privacy enquiries may be sent to support@testora.eu.
2. Who this policy covers
This policy covers visitors to Testora.eu; representatives, employees and recipients connected with customers and prospective customers; users who create or apply for a business account; people who contact support or submit forms; newsletter recipients; supplier and professional contacts; and persons connected with product complaints or safety incidents.
3. Data we collect
Depending on the interaction, we may process name, job title, employer, company registration and VAT information, professional role, email, phone number, billing and delivery address, account credentials, order and invoice information, correspondence, marketing preferences, IP address, device and browser data, cookie identifiers, website activity, fraud-prevention signals and information submitted in a product complaint or incident report. Do not include patient names, civil registration numbers or other directly identifying health information in an incident report. If special-category data is genuinely required, Testora must identify an applicable legal condition and provide any additional information required before processing it.
4. How data is collected
We receive data directly from you or your organisation, through account and checkout forms, correspondence, support and incident reports. We also receive technical data through the website, and fulfilment, delivery, payment, VAT-validation and transaction status from service providers involved in an order.
5. Purposes and legal bases
We process data to respond to enquiries; assess and administer business accounts; prepare quotations; take steps to enter into and perform contracts; process payment, fulfilment, delivery, returns and complaints; comply with accounting, tax, sanctions, product-safety and other legal obligations; protect the website and prevent misuse; establish, exercise or defend legal claims; improve our services; and send marketing where permitted. The legal bases are performance of a contract or pre-contractual steps, compliance with legal obligations, our legitimate interests in operating and protecting a B2B business, and consent where consent is required. Where we rely on legitimate interests, we consider the impact on the individual and do not use that basis where the individual’s interests or fundamental rights override ours.
6. Cookies, analytics and marketing
Necessary technologies support security, account sessions, baskets and checkout. Optional analytics, preference and marketing technologies are used only in accordance with the choices presented in our consent tool and applicable law. Further details and the current settings are available in the Cookie Policy and through the cookie settings control on the website. You may withdraw consent at any time without affecting processing carried out before withdrawal.
7. Recipients and service providers
We disclose data only where relevant to operate the business or meet legal obligations. Recipients may include hosting and website providers, e-commerce and account tools, payment and banking providers, email and form providers, analytics and consent providers, transport companies, warehouse and fulfilment providers, VAT-validation and fraud-prevention services, professional advisers, insurers, auditors and public authorities. Service providers may process data only under the applicable contractual and legal safeguards.
8. International transfers
Some service providers may process data outside the European Economic Area. Where this occurs, we use a lawful transfer mechanism, such as an adequacy decision or the European Commission’s standard contractual clauses, together with supplementary safeguards where required. Information about relevant safeguards may be requested using the contact details above.
9. Retention
We retain data only for as long as necessary for the relevant purpose. Account and customer-contact data is retained while the relationship is active and for a reasonable period afterwards. Transaction, invoice, tax and accounting records are retained for the periods required by applicable law. Support, complaint, traceability and product-safety records may be retained for the period necessary to meet legal, regulatory, warranty, limitation and recall obligations. Consent records and suppression lists are retained as needed to demonstrate and respect the individual’s choices. Data is then deleted or anonymised unless continued retention is legally required.
10. Security
We use organisational and technical safeguards appropriate to the nature of the data and risk, including access controls, encrypted connections, backups, monitoring and limits on provider access. No internet service can guarantee absolute security. Please contact us promptly if you suspect unauthorised access to an account or correspondence.
11. Your rights
Subject to the conditions and exceptions in applicable data-protection law, individuals may request access, rectification, erasure, restriction, portability and objection, and may withdraw consent at any time. An individual also has the right not to be subject to a solely automated decision producing legal or similarly significant effects where the relevant conditions apply. We may request information needed to verify identity and authority before responding.
12. Complaints
Please contact us first so that we can try to resolve the matter. You may also lodge a complaint with the Danish Data Protection Agency (Datatilsynet) or the competent supervisory authority in your country of work or residence. Datatilsynet can be found at datatilsynet.dk.
13. Business contact data provided by customers
A business customer that provides details about employees, recipients or other contacts is responsible for having a lawful basis and giving any required information to those individuals. Testora acts as an independent controller for ordinary account, order, compliance and customer-service administration unless a separate written agreement states otherwise.
14. Changes
We may update this policy to reflect changes in services, providers or legal requirements. The current version and update date will be posted on this page. Material changes will be communicated where required.