Privacy Policy
Last updated: March 2026
1. Who We Are
Qufit B.V. (“Qufit”, “we”, “us”) is the data controller responsible for processing your personal data. We are registered in the Netherlands.
KvK: 97312967 · VAT: NL867997941B01
Keizersgracht 520 H, 1017 EK Amsterdam, The Netherlands
Data protection enquiries: info@qufit.com
2. What Data We Collect
We may collect and process the following categories of personal data:
- Identity data: name, email address, shipping address, phone number (when you place an order or contact us)
- Transaction data: order details, payment method (we do not store full card numbers — payments are processed by our third-party payment provider)
- Technical data: IP address, browser type, device type, operating system, pages visited, referring URL
- Communication data: messages you send us via email or contact forms
- Marketing data: your preferences for receiving marketing communications (only with your explicit consent)
3. Why We Process Your Data (Legal Bases)
Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:
| Purpose | Legal Basis |
|---|---|
| Fulfilling your order | Contract performance |
| Processing payments | Contract performance |
| Sending order updates & shipping notifications | Contract performance |
| Responding to your enquiries | Legitimate interest |
| Sending marketing emails & newsletters | Consent (opt-in only) |
| Website analytics & performance improvement | Legitimate interest / Consent |
| Fraud prevention | Legitimate interest |
| Legal compliance (tax, accounting) | Legal obligation |
4. Cookies & Tracking
Our website uses cookies and similar technologies. We categorise cookies as follows:
- Strictly necessary cookies: Required for the website to function (e.g. shopping cart, authentication). No consent needed.
- Analytics cookies: Help us understand how visitors use our site. Only activated with your consent.
- Marketing cookies: Used to deliver relevant advertisements. Only activated with your consent.
You can manage your cookie preferences at any time through our cookie banner or by adjusting your browser settings. Declining non-essential cookies will not affect your ability to use our website or make purchases.
5. Who We Share Your Data With
We do not sell your personal data. We may share your data with the following categories of third parties, only to the extent necessary:
- Payment processors — to securely process your transactions
- Shipping carriers — to deliver your orders
- Shopify — our e-commerce platform provider
- Analytics providers — to help us improve our website (with consent)
- Email service providers — to send transactional and marketing emails
- Legal authorities — when required by law
All third-party processors are bound by data processing agreements and must handle your data in accordance with the GDPR.
6. International Data Transfers
Some of our service providers may process data outside the European Economic Area (EEA). When this occurs, we ensure adequate safeguards are in place, including:
- EU-approved Standard Contractual Clauses (SCCs)
- EU adequacy decisions for the recipient country
- Other approved transfer mechanisms under the GDPR
7. How Long We Keep Your Data
- Order data: 7 years (Dutch tax and accounting obligations)
- Marketing data: Until you withdraw consent or unsubscribe
- Communication data: 2 years after last contact
- Analytics data: Anonymised after 26 months
- Account data: Until you request deletion
8. Your Rights Under GDPR
As an EU/EEA resident, you have the following rights regarding your personal data:
- Right of access — request a copy of your personal data
- Right to rectification — correct inaccurate or incomplete data
- Right to erasure — request deletion of your data (“right to be forgotten”)
- Right to restrict processing — limit how we use your data
- Right to data portability — receive your data in a machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — at any time, without affecting prior processing
To exercise any of these rights, contact us at hello@qufit.com. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your national data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (AP).
9. Children’s Privacy
Our products and services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
10. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. All data transmitted between your browser and our servers is encrypted using TLS/SSL. However, no method of transmission or storage is 100% secure.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised “Last updated” date. For material changes, we will notify you by email or through a prominent notice on our website.
12. Contact
For any privacy-related questions or to exercise your rights:
- Email: info@qufit.com
- Website: qufit.com/contact