+45 28 88 88 37

Privacy Policy

Emporra ApS · Last updated 4 August 2026

Privacy Policy — Emporra

Emporra ApS · Last updated: 4 August 2026

1. Introduction

Emporra ApS ("Emporra", "we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store and share personal data when you visit emporra.com, submit a sourcing request, or otherwise interact with us.

This Privacy Policy applies to personal data we process as a data controller under Regulation (EU) 2016/679 (the "GDPR") and the Danish Data Protection Act.

2. Data Controller

The data controller is:
Emporra ApS
CVR no. 46360397
Horsensgade 7, 4. tv, 2100 Copenhagen, Denmark
Phone: +45 28 88 88 37
Email: info@emporra.com

For privacy enquiries, contact us at info@emporra.com.

3. Personal Data We Collect

We collect the following categories of personal data:

3.1 Information you provide

  • Contact details (name, email, phone, company name).
  • Sourcing requests, including part numbers, quantities, target dates and compliance requirements.
  • Bills of materials (BOMs) and related sourcing files you upload.
  • Communications you send to us (email correspondence, contact form submissions).
  • Payment and invoicing details, when you place an order.

3.2 Information collected automatically

  • Technical data such as IP address, browser type, device information and operating system.
  • Usage data, including pages visited, time spent and referring URL.
  • Cookies and similar technologies, where used (see clause 10).

4. Purposes and Legal Basis

We process personal data for the following purposes and on the following legal bases under Article 6 GDPR:

  • To respond to enquiries and provide sourcing quotes (Article 6(1)(b) – steps prior to entering a contract).
  • To perform contracts with you, including processing sourcing requests, coordinating with Sourcing Partners, invoicing and delivery (Article 6(1)(b)).
  • To comply with legal obligations, such as accounting, tax and export-control requirements (Article 6(1)(c)).
  • To operate, maintain and improve our website and services, including security and fraud prevention (Article 6(1)(f) – legitimate interest).
  • To send transactional and service-related communications (Article 6(1)(b) and (f)).
  • To send marketing communications where you have consented or where permitted by law (Article 6(1)(a) or (f)).

5. How We Share Personal Data

We share personal data only as necessary to operate our services and as described below.

5.1 Sourcing Partners

To fulfil sourcing requests and orders, we share relevant part numbers, quantities, specifications and BOM data with selected brokers, distributors and OEM excess holders in our vetted Sourcing Partner network ("Sourcing Partners"). We share only what is necessary for them to assess availability or fulfil an order. We do not share your company identity with a Sourcing Partner beyond what is necessary for that purpose, and Sourcing Partners are subject to confidentiality and non-circumvention obligations.

5.2 Data processors

We use the following third-party processors to operate our services:

  • Lovable AB (Sweden, EU) – development and hosting platform, including edge compute infrastructure.
  • Cloudflare, Inc. (USA) – DNS, CDN, edge runtime and security services.
  • Resend (USA) – transactional email delivery.
  • UploadThing (USA) – file upload infrastructure for BOMs and sourcing files.
  • Google Ireland Limited / Google LLC (Ireland / USA) – Google Workspace for our business email accounts, and Google Analytics / Tag Manager where enabled on our website.

Each processor handles personal data on our behalf under a data processing agreement that meets the requirements of Article 28 GDPR.

5.3 Authorities and legal requirements

We may disclose personal data when required by law, regulation, court order, export-control or sanctions compliance obligations, or to protect our rights, property or safety, or that of others.

6. International Data Transfers

Some of our processors are located outside the European Economic Area (EEA), in particular in the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards as required by Chapter V GDPR, including the European Commission's Standard Contractual Clauses or, where applicable, the EU–US Data Privacy Framework. You may request a copy of the safeguards in place by contacting us at info@emporra.com.

7. Data Retention

We retain personal data only for as long as necessary for the purposes set out in this Privacy Policy, including:

  • Sourcing requests that do not result in an order: up to 24 months from the last interaction.
  • Order data and related communications: as required by Danish accounting law (currently 5 years from the end of the relevant financial year).
  • BOMs and sourcing files: deleted or anonymised within 24 months of the last related order, unless retention is required by law or by an ongoing dispute.
  • Marketing data: until you withdraw consent or object to processing.

8. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration or disclosure. These include encryption in transit (TLS), access controls, secure infrastructure and contractual safeguards with our processors. No method of transmission or storage is completely secure. While we take reasonable measures, we cannot guarantee absolute security.

9. Your Rights

Subject to applicable law, you have the following rights regarding your personal data:

  • Right of access – to obtain confirmation of, and a copy of, the personal data we hold about you.
  • Right to rectification – to have inaccurate personal data corrected.
  • Right to erasure – to have your personal data deleted in certain circumstances.
  • Right to restriction – to restrict processing in certain circumstances.
  • Right to data portability – to receive your data in a structured, commonly used and machine-readable format.
  • Right to object – to object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.

To exercise your rights, contact us at info@emporra.com. We will respond within one month, although this may be extended for complex requests. You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet, www.datatilsynet.dk) or your local supervisory authority.

10. Cookies

Our website may use cookies and similar technologies for essential site functionality, analytics and, where applicable, marketing purposes. Where analytics or marketing cookies are used, we will request your consent in accordance with Danish and EU law before they are activated, and provide a mechanism to withdraw that consent at any time.

For full details of the cookies we use and how to manage your preferences, see our Cookie Policy.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements or other reasons. The "Last updated" date at the top of this page indicates when the policy was most recently revised.

12. Contact

If you have any questions about this Privacy Policy or our handling of your personal data, please contact us:
Emporra ApS
CVR no. 46360397
Horsensgade 7, 4. tv, 2100 Copenhagen, Denmark
Phone: +45 28 88 88 37
Email: info@emporra.com

Back to top ↑