Skip to main content

GDPR Compliance Statement of OfferSwap

Offerswap avatar
Written by Offerswap
Updated over 3 months ago

Effective Date: 27.12.2024

Last Updated: 27.12.2024

OfferSwap (“we,” “us,” “our”) is committed to protecting the personal data of our users, partners, and employees. As part of our dedication to transparency and accountability, we adhere to the General Data Protection Regulation (GDPR) and ensure that all personal data is processed in compliance with its principles. This statement outlines the measures we have implemented to ensure GDPR compliance and safeguard individual rights.


1. Our Commitment to GDPR Compliance

Compliance with GDPR is an integral part of OfferSwap’s broader commitment to data protection and privacy. To meet GDPR requirements, we have implemented policies, procedures, and practices that ensure:

  • Transparency: Clear communication about how we collect, use, and share personal data.

  • Accountability: Responsible management of our data protection measures.

  • Security: Safeguarding personal data with appropriate technical and organizational measures.

  • Adherence to Principles: Full compliance with the data protection principles of GDPR.


2. Personal Data We Process

We process personal data as part of our operations, including:

  • Account Data: Name, email address, phone number, and passwords.

  • Transaction Data: Payment details, purchase history, and billing information.

  • Usage Data: IP addresses, device information, and activity logs on our platform.

  • Business Data: Information about businesses, such as company name, industry, and other relevant details.

  • Content Data: User-generated content, including messages and interactions on our platform.

We process personal data only for specified, explicit, and lawful purposes.


3. Rights of Data Subjects

We respect and facilitate the rights of data subjects under GDPR, including:

  • Right of Access: The right to request confirmation of data processing and access to personal data.

  • Right to Rectification: The right to correct inaccurate or incomplete personal data.

  • Right to Erasure: The right to request the deletion of personal data under certain conditions, such as when data is no longer necessary.

  • Right to Restrict Processing: The right to request restricted processing of personal data in specific circumstances.

  • Right to Data Portability: The right to receive personal data in a structured, commonly used, and machine-readable format and to transfer it to another controller.

  • Right to Object: The right to object to personal data processing, particularly for direct marketing purposes.

  • Right Not to Be Subject to Automated Decision-Making: The right to opt out of significant automated decisions unless necessary for contract performance or legally authorized.

Data subjects can exercise their rights by contacting us at contact@offer-swap.com.


4. Legal Bases for Processing

We process personal data based on the following legal grounds:

  • Consent: When data subjects provide explicit consent for specific purposes (e.g., marketing communications).

  • Contractual Necessity: To fulfill contractual obligations, such as processing payments or providing requested services.

  • Legal Obligation: To comply with applicable laws or regulatory requirements.

  • Legitimate Interests: To improve our services, ensure security, and support our business operations, provided these interests do not override individual rights.


5. Data Protection Measures

We have implemented comprehensive measures to protect personal data, including:

  • Access Control: Restricting access to personal data to authorized personnel only.

  • Data Minimization: Ensuring that we collect and process only the data necessary.

  • Encryption: Encrypting personal data during transfer and storage.

  • Regular Audits: Conducting regular internal reviews of data processing activities.

  • Incident Response: Establishing clear procedures for identifying and managing data breaches.

  • Training: Providing mandatory data protection training for employees and contractors.


6. Third Parties and Data Sharing

We work with third-party service providers for various functions, such as payment processing, analytics, and cloud storage. All third parties:

  • Enter into data processing agreements with OfferSwap that include GDPR-compliant terms.

  • Process personal data only for the purposes specified in the agreements.

  • Implement robust security measures to protect personal data.

We share personal data only when necessary and ensure that our partners comply with GDPR.


7. International Data Transfers

When personal data is transferred outside the European Economic Area (EEA), we ensure the following safeguards:

  • Standard Contractual Clauses (SCCs): Contractual commitments to protect personal data.

  • Adequacy Decisions: Ensuring that the recipient country offers an adequate level of data protection, as assessed by the European Commission.

  • Additional Measures: Implementing supplementary safeguards where necessary to protect data during transfers.


8. Automated Decision-Making and Profiling

OfferSwap uses automated decision-making processes for specific purposes, such as:

  • Ad Targeting: Recommending relevant advertisements based on user activity and preferences.

  • Service Matching: Suggesting suitable service providers based on user needs and profiles.

Data subjects have the right to opt out of automated decision-making that produces significant effects. For more information, contact us at contact@offer-swap.com.


9. Data Retention

We retain personal data only as long as necessary to fulfill the purposes for which it was collected or to comply with legal requirements. Retention periods are regularly reviewed, and unnecessary data is securely deleted.


10. Data Breach Management

In the event of a data breach, OfferSwap will:

  • Notify the relevant supervisory authority within 72 hours, if required by GDPR.

  • Inform affected data subjects if the breach poses a high risk to their rights and freedoms.

  • Take immediate action to minimize the impact of the breach and prevent recurrence.


11. Regular Reviews and Updates

To ensure ongoing GDPR compliance, we:

  • Conduct regular reviews of our data protection practices.

  • Update this GDPR Compliance Statement and related policies as necessary.

  • Notify users and stakeholders of significant changes.


12. Contact Information

For GDPR-related inquiries or to exercise your data rights, please contact us at:

OfferSwap Oy

Address: Palokunnankatu 28 Lh5, 13100 Hämeenlinna, Suomi

Company ID: 3466554-5

VAT ID: FI34665545

Did this answer your question?