Data Processing Agreement
This Data Processing Agreement (“DPA”) describes how Advermint (CVR 43665499, VAT DK43665499; Asser Rigs Vej 8, st. tv., 5000 Odense C, Denmark), operating the Ofero service, processes personal data on behalf of its customers. It forms part of the agreement between Ofero and the customer and reflects the requirements of Article 28 of the EU General Data Protection Regulation (GDPR). It is governed by the laws of Denmark, and the competent supervisory authority is the Danish Data Protection Agency (Datatilsynet).
Roles: controller and processor
For personal data contained in the content and account information a customer puts into the service, the customer is the controller and Ofero is the processor. Ofero processes that personal data only on the customer’s documented instructions, which include the customer’s use of the service and this DPA. The customer warrants that it has a valid legal basis and the necessary rights to provide the personal data to Ofero and to instruct the processing described here.
Subject matter and duration
The subject matter of the processing is the provision of the Ofero digital-signage platform. Processing continues for the duration of the customer’s subscription and ends on termination, subject to the deletion and return provisions below.
Nature and purpose of processing
Ofero processes personal data to host, operate, secure, and support the service — including storing and displaying the content customers create, managing accounts and team access, sending transactional emails, and maintaining backups. Processing is limited to what is necessary to provide the service.
Types of personal data and categories of data subjects
The personal data processed may include account and contact details (such as names and email addresses), authentication data, and any personal data the customer chooses to include in the content it uploads. Categories of data subjects include the customer’s team members and account users, and any individuals referenced in customer content. Customers should avoid placing special categories of personal data in content where it is not needed.
Sub-processing
Ofero engages third-party subprocessors to help provide the service and remains responsible for their compliance with this DPA. The current list is published on our Subprocessors page. Ofero will update that page and notify customers of material subprocessor changes where required by this DPA or applicable law, so that customers have the opportunity to review them.
Security measures
Ofero maintains appropriate technical and organizational measures to protect personal data, taking into account the state of the art and the nature of the processing. These include, at a high level, encryption of data in transit, access controls and least-privilege access to systems, logical isolation of each customer’s data (tenant isolation), and EEA-first hosting of the production database and infrastructure. Personnel with access to personal data are bound by confidentiality obligations.
International transfers
The production database and core infrastructure are hosted within the EEA. Where a subprocessor is located outside the EEA, transfers are made under appropriate safeguards such as the European Commission’s Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework. Details are set out on the Subprocessors page.
Assistance to the customer
Taking into account the nature of the processing, Ofero will provide reasonable assistance to help the customer respond to requests from individuals exercising their rights under applicable data-protection law (such as access, correction, deletion, and portability), and to help the customer meet its obligations regarding security, data-protection impact assessments, and prior consultation.
Personal-data breaches
Ofero will notify the affected customer without undue delay after becoming aware of a personal-data breach affecting that customer’s personal data, and will provide the information reasonably available to help the customer meet its own notification obligations.
Deletion and return of data
On termination of the service, and at the customer’s choice, Ofero will delete or return the customer’s personal data in accordance with our retention practices, and delete existing copies unless storage is required by applicable law. Backups are cycled out on a defined schedule as described in our retention policy.
Requesting or signing the DPA
A signable version of this Data Processing Agreement is available to customers on request. To request or sign the DPA, or for any data-processing questions, email privacy@ofero.co.
Last updated: 29 June 2026