Private by
default.
This notice explains how PHENOMENAL uses personal data for evidence-backed Market Drafts and invite-only BUYIF markets.
Notice status
Effective 4 August 2026
Version: 2026-08-04-v1. This notice applies to personal data—information relating to an identifiable person. Purely company-level information may fall outside data-protection law.
1. Controller
X PROJECTS ApS
CVR 41736720
c/o Christensen Kjærulff, AIH, Østbanegade 123, 2100 København Ø
Denmark
Privacy questions and rights requests: privacy@phenomenal.fit. Routing and the processor register are approved for this dedicated channel. Do not send passwords, invitation tokens, authenticator codes, payment-card data, or special-category information by email. This mailbox is not used for sales or market activation.
2. Scope
This notice covers visitors who request a Market Draft, supplier and buyer contacts, invited private-market participants, and authorised operators. PHENOMENAL is a business service and is not directed to children. Please do not submit health information, biometric data, political or religious beliefs, trade-union membership, sexual-orientation data, government identifiers, payment-card data, or other special-category or highly sensitive personal data.
3. Personal data categories
Contact and organisation data. Work email, contact name where supplied, organisation, role, and communication or privacy-request history.
Market Draft intake. Supplier website, product or capability, a submitter's description, and—only behind the approved storage gate—private economic thresholds or viable-volume information.
Private BUYIF market data. Invitation and participation status, quantity range, commitment strength, conditions, private notes, privacy acknowledgements, confirmation instructions, expiry, and append-only supersession history. A Buy-If is non-binding and is not a payment or purchase order.
Public research and evidence. Public supplier pages, public product context, external public sources, titles, excerpts, timestamps, URLs, and content hashes. Public pages can contain names or business contact details even though PHENOMENAL does not perform contact enrichment.
Account, audit and security data. Operator account identifiers, access role, authentication assurance level, timestamps, event provenance, idempotency and rate-limit records, essential-cookie data, network/request metadata, and security logs. TOTP is required for operators; PHENOMENAL does not expose authenticator secrets in the operator console.
4. Purposes and legal bases
Responding to a request and taking requested pre-contract steps — GDPR Article 6(1)(b). Where the person is the prospective contracting party, PHENOMENAL uses the necessary contact and request data to provide the requested preview, manage an invitation, or take steps the person asks for before a contract.
Operating a responsible B2B market service — GDPR Article 6(1)(f). PHENOMENAL has legitimate interests in researching public supplier information, reviewing evidence, responding to company representatives, forming private cohorts, aggregating compatible demand, maintaining an audit trail, improving reliability, and protecting confidential commercial conditions. PHENOMENAL limits fields, separates public evidence from private economics, restricts access, and considers the person's interests and rights before relying on this basis.
Security, abuse prevention and legal claims — GDPR Article 6(1)(f). Technical and audit data is used to authenticate operators, enforce invitation and rate limits, prevent fraud, diagnose incidents, and establish, exercise or defend legal claims.
Legal obligations — GDPR Article 6(1)(c). Information may be processed where necessary to comply with applicable data-protection, accounting, law-enforcement, court, or regulatory duties.
A privacy-notice acknowledgement records that the notice was presented; it is not consent and is not used to turn unnecessary processing into necessary processing. If PHENOMENAL later relies on consent for a distinct optional purpose, it will request that consent separately and explain how to withdraw it. Current V0 does not perform outbound marketing or automated outreach.
5. Is providing data required?
A supplier website is needed to compile a Market Draft; optional product context helps focus the result. A work email and explicit storage request are required only when asking PHENOMENAL to store and follow up on an intake. Invitation credentials and the marked required Buy-If fields are necessary to enter or update a private market record. Optional notes can be omitted. Without required data, PHENOMENAL can still provide an unstored public-evidence preview where available, but cannot store the request, authenticate the participant, or operate the requested private workflow.
6. Public research preview and AI
The bounded research pipeline inspects up to four same-domain public pages directly. Firecrawl is used only as a fallback for inaccessible or JavaScript-dependent supplier sites; Exa may return up to five relevant external public sources; OpenAI may produce one structured, citation-bound synthesis. Crawled content is treated as untrusted evidence, never as instructions.
Only the public website, public product context, and public evidence excerpts go through that research pipeline. Work email, contact details, private economics, private notes, and individual Buy-If terms are not sent to OpenAI, Exa, or Firecrawl. No contact enrichment, candidate creation, activation, outreach, or market-state change occurs during public compilation.
7. Recipients and processors
Access is limited by role and purpose. Authorised PHENOMENAL operators may review stored submissions, evidence, private market records, and rights requests. Other participants do not receive a buyer's identity or individual private conditions. Suppliers may receive approved aggregate market information and common-offer requirements, not private participant records, unless a separate lawful and disclosed process requires it.
When enabled and contractually approved, service-provider categories may include Vercel for hosting and delivery; Supabase for database, authentication and related infrastructure; OpenAI for structured synthesis; Exa for external public-source retrieval; Firecrawl for public-site fallback extraction; AgentMail for the dedicated privacy mailbox—not sales activation or automated outreach; and professional legal, security or accounting advisers. Personal data may also be disclosed where required to courts, regulators, law enforcement, or another recipient under applicable law. PHENOMENAL does not sell personal data.
Current approved processor summary: Approved processors: Supabase for database and authentication; Vercel for hosting; OpenAI for structured synthesis of public evidence; Exa for external public-source search; Firecrawl for bounded fallback extraction; AgentMail for verified privacy and commercial email routing. Contact details and private economics are not sent to research providers.
8. International transfers
Some approved providers may process data outside Denmark or the European Economic Area. Before such a transfer is enabled, PHENOMENAL must use a lawful transfer mechanism appropriate to the destination and recipient—such as an adequacy decision or the European Commission's Standard Contractual Clauses—and assess supplementary safeguards where required. You may request information about the applicable mechanism through the privacy contact. Read the European Commission's international-transfer overview.
9. Sources
PHENOMENAL receives data directly from the person who uses a form or private invitation; from the organisation or authorised operator arranging an invitation; from public supplier websites and other public sources returned by the bounded research tools; and from service-generated authentication, security and audit events. PHENOMENAL does not use Apify, HarvestAPI, BetterContact, or contact-enrichment services in the public compiler.
10. Retention and deletion
Approved retention summary: Stored supplier intake, participant contact details, private economics, research excerpts and review notes are erased or irreversibly de-identified after 30 days unless a documented legal hold applies. Identity-free integrity and authority records may be retained for accountability.
PHENOMENAL keeps personal data only for the documented purpose and approved period, then deletes or irreversibly anonymises it unless a legal obligation or the establishment, exercise or defence of legal claims requires longer retention. A private invitation session cookie expires no later than the invitation or market close. A real Buy-If expires exactly when its market closes; reconfirmation appends a new record that supersedes rather than silently rewriting the earlier audit record. Expiry of commercial authority does not itself erase an audit record, so the approved retention schedule still applies.
11. Essential cookies
PHENOMENAL uses strictly necessary cookies for invite-only operator authentication and private invitation sessions. The invitation URL fragment is removed immediately and exchanged for an encrypted, HttpOnly, Secure, SameSite=Strict cookie. PHENOMENAL does not currently use advertising cookies or cross-site behavioural tracking. If optional analytics or other non-essential cookies are introduced, this notice and the consent controls will be updated before they are enabled.
12. Security
PHENOMENAL applies proportionate technical and organisational measures, including transport encryption, server-only provider credentials, hashed invitation tokens in the database, encrypted invitation-session cookies, least-privilege and row-level database controls, mandatory AAL2/TOTP for operators, restrictive caching and indexing headers, rate limits, append-only audit events, and collection gates. No system is completely secure; suspected incidents are investigated and affected people and authorities are notified where the law requires it.
13. Automated decision-making
PHENOMENAL does not make decisions producing legal or similarly significant effects about a person solely by automated means. AI can retrieve public evidence and propose a cited market thesis, but it cannot approve evidence, create or publish a market, change market state, invite a participant, confirm a Buy-If, place an order, or process a payment. Those actions require authorised human or participant action under explicit controls. See the AI disclosure.
14. Your rights
Subject to the conditions and exceptions in applicable law, you may request access to your personal data; correction of inaccurate or incomplete data; erasure; restriction; and a portable copy of data you provided where processing is automated and based on consent or contract. You may object, on grounds relating to your situation, to processing based on legitimate interests. You may also withdraw consent at any time where a distinct activity actually relies on consent, without affecting earlier lawful processing.
PHENOMENAL may need to verify identity before disclosing or changing private records and will normally respond within the period required by law. A request may be limited where another person's rights, confidential information, a legal duty, or legal claims require it. Read the European Commission's GDPR rights overview.
15. Complaints
Please contact PHENOMENAL first so the issue can be investigated. You also have the right to complain to the Danish supervisory authority, Datatilsynet, or another competent supervisory authority. Datatilsynet explains the current process and complaint form at Sådan klager du.
16. Changes to this notice
PHENOMENAL may update this notice when the product, providers, purposes, legal requirements, or safeguards change. The public version and effective date above identify the current approved notice. Material changes will be communicated through an appropriate channel before they take effect where required. Earlier acknowledgements remain linked to the version presented at the time.
17. Privacy contact
To ask a privacy question or exercise a right, email privacy@phenomenal.fit. PHENOMENAL may move the conversation to a more secure reviewed channel before verifying identity or disclosing private records. Do not send passwords, invitation tokens, authenticator codes, payment-card data, identifiers, records, evidence, or special-category information by email.