Privacy Policy

Last updated: 29 June 2026

This Privacy Policy explains how personal data is processed in connection with Ofero, a B2B digital signage and marketing content platform. Ofero is operated by Advermint (CVR 43665499, VAT DK43665499), Asser Rigs Vej 8, st. tv., 5000 Odense C, Denmark (“Ofero”, “we”, “us”).

Ofero is intended for businesses, organizations, and professionals. It is not directed to consumers or children, and users must be at least 18 years old and act on behalf of a business or professional activity.

1. Who is responsible for your data

Advermint is the data controller for the personal data described in the “Data we process as controller” section below. You can reach our privacy contact at privacy@ofero.co.

  • Legal entity: Advermint
  • Company registration: CVR 43665499
  • VAT: DK43665499
  • Registered address: Asser Rigs Vej 8, st. tv., 5000 Odense C, Denmark
  • Privacy contact: privacy@ofero.co

2. Controller vs. processor

Ofero plays two different roles depending on the data involved, and this affects who you should contact about it.

We are the controller for:

  • Account and identity data, authentication and security telemetry, billing and account administration, product analytics, and our own operational records — i.e. the data needed to provide, secure, and run the Ofero service itself.

We are a processor for:

  • Any personal data a customer chooses to put inside their own content (for example, a name or photo included in a menu, promotion, message, or public menu page). The customer is the controller of that data; we process it on their behalf under our Data Processing Agreement. If you are an individual whose personal data appears inside a customer’s content, please direct your request to that customer (the controller); we will support them in responding.

3. Data we process as controller

  • Account & identity: your name, email address, business/organization name, password (stored only as a salted hash — never in plain text), and any two-factor authentication (2FA) configuration.
  • Authentication & security telemetry: sign-in, sign-up, password-reset and verification events, IP address, and user-agent — used to operate, secure, and audit access.
  • Business content & settings: the menus, promotions, messages, collections, templates, brand settings, and public menu pages you create, plus their configuration.
  • Uploaded images and media you add to your content and brand assets.
  • Screens & devices: the screens and display devices you pair, including labels you assign and pairing/activity status.
  • Team data: members you invite to your account, their roles, and invitation status.
  • Product analytics: limited usage and screen-playback signals used to understand and improve how the product is used.
  • Communications: messages you send to our support, privacy, security, or abuse contacts, and our replies.
  • Legal & compliance records: consent and acceptance records (e.g. which terms/privacy version you accepted) and records of data-subject requests.

4. Why we process it, and our legal bases

We process the data above under the following legal bases of the GDPR:

  • Performance of a contract (Art. 6(1)(b)): to create and manage your account, provide the platform and its features, pair and run your screens, enable team collaboration, and provide support.
  • Legitimate interests (Art. 6(1)(f)): to keep the service secure, prevent abuse and fraud, maintain audit logs, understand product usage through limited analytics, and improve the service — balanced against your rights and interests.
  • Legal obligation (Art. 6(1)(c)): to comply with accounting, tax, and other statutory requirements, and to respond to lawful requests.
  • Consent (Art. 6(1)(a)): for optional marketing communications and for non-essential cookies — which you can withdraw at any time without affecting use of the core service.

5. How long we keep data (retention)

  • Account and content data is kept for the life of your account.
  • When an account is deleted, we apply a 30-day grace period and then delete or anonymize the associated personal data, subject to the exceptions below.
  • Authentication and security logs are retained for approximately 12 months.
  • Product analytics and screen-playback signals are retained for approximately 90 days.
  • Encrypted backups follow a rolling rotation of roughly 30–35 days, after which deleted data ages out of backups.
  • Billing, invoicing, and tax records are retained for approximately 5 years where required by applicable law.

6. Your rights and how to exercise them

Where we act as controller, you have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing, in accordance with the GDPR.

  • You can export your data and request deletion of your account directly in the product at Settings → Privacy.
  • You can also exercise any of your rights by emailing privacy@ofero.co. We aim to respond within 30 days.
  • If your personal data appears inside a customer’s content, that customer is the controller — please contact them directly, and we will assist them as their processor.

7. International transfers

Ofero is hosted in the European Economic Area (EEA). Where a subprocessor processes personal data outside the EEA (for example, a US-based provider), we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs), together with the protections in our Data Processing Agreement.

8. Subprocessors

We use a limited set of vetted third-party providers (subprocessors) to operate the service — for example for hosting, email delivery, and payments. The current list is published at our subprocessors page.

9. Cookies

We use strictly necessary cookies to run the service (for example, to keep you signed in), and — only with your consent — limited non-essential cookies. You can review and manage your choices in our Cookie Policy.

10. How we protect data (security)

We take reasonable technical and organizational measures to protect personal data. In particular:

  • Data is encrypted in transit using TLS.
  • Passwords are never stored in plain text — they are stored as salted hashes using scrypt.
  • Tenant data is isolated using PostgreSQL row-level security (RLS) combined with explicit account scoping on every query.
  • The application connects to the database using a least-privilege role.
  • Screen and session cookies are signed and set with secure attributes; the platform sends security response headers including a Content-Security-Policy.
  • Hosting is in the EEA (Hetzner, Helsinki, Finland).

No service can guarantee absolute security, but we work to keep these protections current.

11. Data breaches

If you become aware of a security issue, please contact security@ofero.co. In the event of a personal-data breach, where required we will notify Datatilsynet (the Danish Data Protection Agency) within 72 hours of becoming aware of it, and we will inform affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

12. Complaints and contact

If you have a concern, contact us first at privacy@ofero.co — we would like the chance to help. You also have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is Datatilsynet (the Danish Data Protection Agency).

For general questions about this policy, email privacy@ofero.co.