Phenora HealthGet in touch

Privacy Policy

Phenora Health ApS · Last updated 9 June 2026

Contents

Introduction

This Privacy Policy explains how Phenora Health ApS (“we”, “us”, “our”) processes personal data and applies only to the use of this website, job applications submitted to us, and general enquiries and communication.

Contact: Phenora Health ApS, Fruebjergvej 3, 2100 Copenhagen, Denmark, contact@phenorahealth.com

We have appointed a Data Protection Officer (DPO) due to the nature of our activities, which involve regular processing of personal data, including special categories of personal data (health data). The DPO’s contact details — for questions about Phenora’s data protection — are dpo@phenorahealth.com.

Categories of personal data we process

Depending on your interaction with us, we may process the following:

  • Contact information (name, email address, phone number).
  • Job application information (CV, cover letter, references, interview notes).
  • Technical website data (IP address, device information, browser type; collected only via strictly necessary cookies).

For information on the processing of personal data for research purposes, please refer to Phenora’s Research Privacy Policy.

Purposes and legal bases

a) Website operation — to ensure security, stability and correct functioning of our website. Legal basis: GDPR Art. 6(1)(f) (legitimate interest in operating a secure site).

b) Enquiries and communication — to respond to contact requests, provide information or handle business interactions. Legal basis: Art. 6(1)(f).

c) Recruitment — to assess applicants, evaluate qualifications and manage hiring processes. Legal basis: Art. 6(1)(b) and 6(1)(f).

Recipients and transfer of personal data

Personal data may be shared only where necessary and under appropriate safeguards with IT and hosting providers acting as data processors; recruitment service providers actively involved in a hiring process; external auditors or supervisory authorities where the law requires it; and collaborating partners, solely where permitted and under a valid legal basis. All processors operate under a binding data processing agreement.

We process personal data within the EU/EEA. If transfers outside the EU/EEA occur, we rely on the European Commission’s Standard Contractual Clauses and implement supplementary measures where required.

Retention of personal data

  • Enquiries: up to 12 months after the last interaction.
  • Job applications: 6 months unless extended with consent.
  • Technical / log data: retained per IT security standards.

Security

We have implemented appropriate technical and organisational safeguards, including role-based access control and strict authorisation procedures, encryption and secure storage environments, and logging and monitoring of system access, ensuring a level of protection appropriate to the risks of our activities.

Rights of data subjects

You have the right to request access to your personal data; request correction or deletion; request restriction of processing; object to our processing; and request data portability where legal requirements are met. Requests may be sent to dpo@phenorahealth.com.

Right to lodge a complaint

You have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) if you are dissatisfied with the way we process your personal data. We encourage you to contact us first so we can address your concerns.

Updates to this policy

We may update this Policy from time to time. The “last updated” date reflects the latest revision.

Back to home