Privacy Policy

Last updated: 21/07/2026

1. About This Privacy Policy

This Privacy Policy explains how UpcycleIT collects, uses, stores, and shares personal data.

It applies when you:

• Visit our website;

• Submit an enquiry through our contact form;

• Contact us by email or another communication channel;

• Request information or a quotation;

• Represent a customer, potential customer, reseller, supplier, or other business partner; or

• Otherwise interact with UpcycleIT in a business context.

Separate privacy information may apply to employees, job applicants, and other processing activities not covered by this policy.

2. Data Controller

The data controller responsible for the processing described in this Privacy Policy is:

UpcycleIT, a part of Fourcom ApS.

CVR number: 30717260

Registered address: Edwin Rahrs Vej 66

Postal code and city: 8220 Brabrand

Country: Denmark

Email concerning privacy matters: info@upcycleit.dk

Website: www.upcycleit.com

References to “UpcycleIT”, “we”, “us”, or “our” in this Privacy Policy mean the legal entity identified above.


3. Personal Data We Collect

The personal data we collect depends on how you interact with us.

3.1 Contact-Form Information

When you submit our website contact form, we may collect:

• Your full name;

• Your email address;

• The name of the company you represent;

• A CVR, VAT, EORI, or other business registration number;

• Your country;

• The information included in the additional-information field; and

• Any other information you choose to provide.

The CVR/VAT/EORI and country fields are optional.

Please do not include sensitive personal data, passwords, payment-card information, identification documents, or other unnecessary confidential information in the additional-information field.

3.2 Business Correspondence

When you communicate with us, we may process:

• Your name;

• Your work contact details;

• Your employer or the company you represent;

• Your job title or business role;

• The date and contents of communications;

• Information concerning your enquiry; and

• Related correspondence and documentation.

3.3 Customer and Commercial Information

If an enquiry leads to a quotation, order, contract, or other business relationship, we may also process:

• Quotation and pricing information;

• Order and transaction details;

• Delivery and billing information;

• Invoice and payment-status information;

• Product or service requirements;

• Returns, complaints, warranty matters, and support requests; and

• Other information necessary to manage the business relationship.

We do not collect complete payment-card information through the website contact form.

3.4 Technical Website Information

When you visit our website, Framer may process technical information necessary to deliver, operate, maintain, and protect the website.

This may include:

• Your IP address;

• Browser and device information;

• Operating system;

• Pages or website resources requested;

• Date and time of access;

• Referring website information; and

• Technical, operational, and security logs.

3.5 Framer Analytics

We use Framer’s built-in analytics to understand the general use and performance of our website.

Framer Analytics does not use cookies or persistent identifiers. It provides us with aggregated or anonymised statistics that may include:

• Page views;

• Entry and exit pages;

• Referring websites;

• Campaign parameters;

• Approximate country;

• Device type;

• Browser type; and

• Operating system.

We do not use Framer Analytics to identify individual visitors, follow visitors across unrelated websites, or create individual advertising profiles.

4. Where Personal Data Comes From

We normally receive personal data directly from you when you:

• Complete the contact form;

• Send us an email;

• Request a quotation;

• Place an order;

• Communicate with our employees; or

• Otherwise provide information during a business relationship.

We may also receive business contact information from the company you represent or from publicly available business sources where necessary to manage or verify a business relationship.

5. Why We Process Personal Data

We only process personal data where we have a defined purpose and a lawful basis.

5.1 Responding to Enquiries

We process contact-form information and correspondence to:

• Respond to your enquiry;

• Understand your requirements;

• Determine whether we can provide the requested products or services;

• Identify the company you represent;

• Assess relevant delivery, tax, customs, or trade considerations;

• Prepare a quotation or other commercial information; and

• Contact you about the matter you submitted.

For business-to-business enquiries, the legal basis is normally Article 6(1)(f) of the GDPR. We have a legitimate interest in responding to enquiries, preparing quotations, and establishing and managing business relationships.

Where you are personally entering into a contract with us, including as a sole trader, the legal basis may also be Article 6(1)(b) of the GDPR because the processing is necessary to take steps at your request before entering into a contract.

5.2 Managing Quotations, Orders, and Contracts

We process personal data to:

• Prepare and administer quotations;

• Confirm and fulfil orders;

• Arrange delivery;

• Issue invoices;

• Receive and record payments;

• Provide customer service;

• Handle returns, repairs, complaints, and warranty matters; and

• Maintain the business relationship.

The legal basis is normally:

• Article 6(1)(b) of the GDPR, where the individual is a party to the contract;

• Article 6(1)(f) of the GDPR, where the individual represents a company or another legal entity; or

• Article 6(1)(c) of the GDPR, where processing is required to comply with a legal obligation.

5.3 Website Operation and Security

We process technical website information to:

• Display and deliver the website;

• Provide requested website functionality;

• Maintain the stability and performance of the website;

• Protect the website and related systems;

• Prevent misuse, fraud, and security incidents;

• Diagnose technical problems; and

• Maintain relevant operational and security records.

The legal basis is Article 6(1)(f) of the GDPR. We have a legitimate interest in operating a functional, reliable, and secure website.

5.4 Website Improvement

We use aggregated and anonymised information from Framer Analytics to:

• Understand how the website is generally used;

• Identify popular or underused pages;

• Diagnose usability issues; and

• Improve the website’s structure, content, and performance.

Framer Analytics does not provide us with information that identifies individual website visitors.

5.5 Legal Obligations and Claims

We may process personal data to:

• Meet bookkeeping, tax, and documentation requirements;

• Respond to lawful requests from authorities;

• Establish, exercise, or defend legal claims;

• Resolve complaints and disputes; and

• Document our compliance with applicable law.

The legal basis is Article 6(1)(c) of the GDPR where processing is required by law, and Article 6(1)(f) where processing is necessary to protect our legal interests.

6. Required and Optional Information

The form identifies which fields are required and which are optional.

Your name, email address, and company name are generally needed for us to identify and respond to your enquiry.

The CVR/VAT/EORI and country fields are optional. Providing this information may help us assess your enquiry, verify the relevant company, and identify delivery, tax, customs, or trade requirements.

You are not required to provide optional information.

If you do not provide the information necessary to understand or respond to your request, we may be unable to process the enquiry or prepare a quotation.

7. How We Share Personal Data

We do not sell personal data.

Personal data may be shared with the following recipients where necessary.

7.1 Authorised UpcycleIT Employees

Contact-form submissions are initially delivered to an authorised UpcycleIT company mailbox.

The mailbox owner may share relevant information with UpcycleIT employees, including sales personnel, where they need the information to:

• Respond to the enquiry;

• Assess the request;

• Prepare a quotation;

• Communicate with the potential customer; or

• Manage an existing business relationship.

Access is limited to personnel who require the information for their work. Contact-form submissions are not intended to be generally available to all employees.

7.2 Framer

Framer provides our:

• Website hosting;

• Website infrastructure;

• Contact-form infrastructure;

• Website security and technical operation; and

• Built-in website analytics.

Framer processes relevant personal data on our behalf as a data processor.

7.3 Microsoft

Microsoft provides our company email service through Microsoft Outlook or Microsoft 365.

Microsoft may process and store contact-form submissions and related correspondence on our behalf in order to provide the email service.

7.4 Other Recipients

Where necessary, we may also share relevant information with:

• IT support and security providers;

• Accountants, auditors, lawyers, insurers, and other professional advisers;

• Delivery, logistics, or commercial partners involved in a requested transaction;

• Public authorities, courts, regulators, or law-enforcement bodies where disclosure is required or permitted by law; and

• A purchaser or adviser involved in a sale, merger, restructuring, or transfer of all or part of our business.

We only share information that is reasonably necessary for the relevant purpose.

8. International Transfers

Framer, Microsoft, or their approved subprocessors may process personal data outside Denmark or the European Economic Area.

Where personal data is transferred outside the European Economic Area, the transfer must be protected through an approved transfer mechanism.

Depending on the recipient and destination, this may include:

• A European Commission adequacy decision;

• The EU-US Data Privacy Framework, where applicable;

• The European Commission’s standard contractual clauses; or

• Another lawful safeguard under Chapter V of the GDPR.

You may contact us for further information about the safeguards used for relevant transfers.

9. Retention of Personal Data

We retain personal data only for as long as necessary for the purposes described in this Privacy Policy.

9.1 Enquiries That Do Not Lead to a Business Relationship

Where an enquiry does not result in a quotation, order, contract, or continuing business relationship, the enquiry and related correspondence will normally be deleted no later than twelve months after the last relevant communication.

9.2 Quotations and Continuing Discussions

Where a quotation has been issued or commercial discussions remain active, relevant information may be retained for as long as reasonably necessary to:

• Continue the discussion;

• Document the quotation;

• Follow up on the request;

• Resolve a disagreement; or

• Establish, exercise, or defend a legal claim.

9.3 Customer and Accounting Records

Where an enquiry results in an order, contract, or customer relationship, relevant information may be retained for the duration of the relationship and afterwards for the periods required by:

• Bookkeeping and tax legislation;

• Warranty and complaint periods;

• Applicable limitation periods;

• Compliance obligations; and

• The need to establish, exercise, or defend legal claims.

Accounting records are normally retained for five years from the end of the financial year to which the records relate, as required by applicable Danish bookkeeping rules.

9.4 Technical Information

Technical, operational, and security information is retained only for as long as reasonably necessary to operate, maintain, and protect the website and related systems.

Actual retention may also depend on the retention settings and contractual arrangements applying to our service providers.

9.5 Longer Retention

Information may be retained for longer where necessary to:

• Handle a complaint or dispute;

• Prevent fraud, misuse, or repeated unwanted enquiries;

• Comply with a legal obligation;

• Respond to a public authority; or

• Establish, exercise, or defend a legal claim.

When personal data is no longer required, it will be deleted or anonymised.

10. Security

We use appropriate technical and organisational measures designed to protect personal data against:

• Unauthorised access;

• Accidental or unlawful loss;

• Destruction;

• Alteration;

• Unauthorised disclosure; and

• Other unlawful processing.


Depending on the circumstances, these measures may include:

• Restricted user access;

• Company-managed accounts;

• Authentication controls;

• System and software updates;

• Secure hosting and email services;

• Confidentiality obligations;

• Staff instructions;

• Backups; and

• Procedures for handling security incidents.

No online service or transmission method can be guaranteed to be completely secure.

11. Cookies and Similar Technologies

We currently do not use:

• Google Analytics;

• Advertising pixels;

• Remarketing tools;

• Behavioural advertising systems; or

• Other non-essential tracking technologies.


Framer’s built-in analytics does not use cookies or persistent identifiers.

The website may use technologies that are technically necessary to:

• Deliver and display the website;

• Maintain security;

• Prevent misuse;

• Provide functionality requested by the visitor; or

• Remember privacy-related choices.

Technically necessary technologies may be used without consent where permitted by law.

If we introduce non-essential analytics, advertising, personalisation, embedded media, or other tracking technologies, we will review this Privacy Policy and implement an appropriate consent mechanism before activating them.

12. External Links

Our website may contain ordinary links to websites and services operated by third parties, including LinkedIn or other social-media platforms.

When you select an external link, you leave our website. The third party may then process information about your visit under its own privacy policy and terms.

UpcycleIT does not control the privacy practices of independently operated third-party websites.

An ordinary external link does not mean that the relevant third party processes contact-form submissions or other information held by UpcycleIT.

13. Embedded Videos and External Content

We do not currently embed YouTube or Vimeo video players on the website.

If embedded video or other third-party content is added in the future, the visitor’s browser may communicate directly with the relevant provider.

Before introducing such content, we will assess whether:

• The content uses cookies or similar technologies;

• Personal data is transferred to the provider;

• Consent is required before the content loads;

• International transfers are involved; and

• This Privacy Policy and our cookie information need to be updated.

14. Marketing

Submitting the contact form does not automatically subscribe you to a newsletter or general marketing list.

We may contact you to respond to your enquiry and follow up on the products or services you asked about.

We will only send separate electronic direct marketing where we have a lawful basis under applicable data-protection and marketing rules.

Where marketing is based on consent, you may withdraw that consent at any time.

15. Automated Decision-Making

We do not use the personal data described in this Privacy Policy to make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning you.

We do not use contact-form information to create automated credit, eligibility, or customer profiles.

16. Your Rights

Subject to the conditions and limitations of applicable law, you may have the following rights.

16.1 Right to Information

You have the right to receive clear information about how we process your personal data.

16.2 Right of Access

You may request confirmation of whether we process personal data about you and obtain a copy of that information.

16.3 Right to Rectification

You may request that inaccurate personal data be corrected and incomplete information be completed.

16.4 Right to Erasure

In certain circumstances, you may request that we delete your personal data.

This right does not apply where continued processing is necessary, for example, to comply with a legal obligation or establish, exercise, or defend a legal claim.

16.5 Right to Restriction

In certain circumstances, you may request that we restrict the processing of your personal data.

16.6 Right to Object

You may object to processing based on our legitimate interests.

We will stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the information is required for legal claims.

You have an unconditional right to object to processing for direct-marketing purposes.

16.7 Right to Data Portability

Where processing is based on consent or a contract and is carried out by automated means, you may have the right to receive personal data you provided in a structured, commonly used, and machine-readable format.

Where technically feasible, you may also have the right to request that the information be transferred to another controller.

16.8 Right to Withdraw Consent

Where processing is based on consent, you may withdraw your consent at any time.

Withdrawal does not affect processing that took place lawfully before the consent was withdrawn.

16.9 Exercising Your Rights

To exercise your rights, contact us using the details in Section 2.

We may request reasonable information to confirm your identity and prevent personal data from being disclosed to an unauthorised person.

Your rights are not absolute, and the result of a request will depend on the circumstances and the applicable legal requirements.

17. Complaints

You may contact us if you have questions or concerns about how we process personal data.

You also have the right to lodge a complaint with the Danish Data Protection Agency:

Datatilsynet

You can find current contact information and instructions for submitting a complaint on Datatilsynet’s official website.

You may also be entitled to complain to another competent supervisory authority, particularly in the country where you live or work.

18. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

• Changes to our website;

• New service providers or integrations;

• Changes to our forms or business processes;

• New analytics, video, or marketing technologies;

• Changes to legal requirements; or

• Changes to how we process personal data.

The current version will be published on our website together with its effective date.

Where required, we will provide additional notice of material changes.

19. Contact

Questions, requests, and complaints concerning personal data may be sent to:

UpcycleIT, a part of Fourcom ApS.

Edwin Rahrs Vej 66

8220 Brabrand

Denmark

Email: info@upcycleit.dk

Telephone: +45 96 32 21 00

Professional refurbished IT, prepared in Denmark and supplied across Europe. Quality, support and long-term partnerships built into every shipment.

Contact

Edwin Rahrs Vej 66

8220 Brabrand, Denmark

info@upcycleit.dk

CVR: 30717260

© 2026 UpcycleIT. All rights reserved.

·

Refurbished in Denmark.