Privacy policy

If you are or plan to become a user of SuperDeals Portal, this information is for you.

1. Who is accountable for processing your Personal Data?

Name: Epassi Finland Oy

Business ID: 3220764-7

Osoite: Porkkalankatu 22 A, 00180 Helsinki

Contact the DPO or the Data Controller: dataprivacy@epassi.com

2. How do we collect your personal data?

In SuperDeals Portal (“SuperDeals Portal”), we collect user’s data in the following cases:

  • From your employer: Since your registration is subject to a company or entity (your employer) being a customer of Epassi or related entities, we may receive certain personal data from your employer, and once registered, your employer may ask us to unsubscribe you from the service.
  • At the time of registration: we ask you to provide us information about yourself to configure your profile.
  • Directly in your user profile: you will be able to add or modify your profile data at any time.
  • When you use our services, or interact with products: We will collect data concerning your use of SuperDeals Portal, our services and products. Furthermore, we may deliver personal data to third parties in case you instruct us to deliver your data to the third parties. We may also receive information from third parties concerning your use of their services or products you have expressed interest in through our Portal.
  • Information collected from cookies: we may receive information from cookies about the user’s use of our Portal, we recommend you to read the cookies policy for more information.

3. For what purpose do we process your Personal Data?

Eligibility for accessing the SuperDeals Portal: We process your Personal Data to enable your access to, create and configure your profile at the SuperDeals Portal and that you meet the requirements for accessing the SuperDeals Portal.

Managing your user profile: We will use the data you provide us to manage your profile. You can modify your profile data directly on your profile page. Please keep your data updated at all times.

Discounts, offers and promotions and related communication: In the SuperDeals Portal, we aim to inform users of the discounts, offers and promotions provided by different merchants and from which they can benefit, as this is one of the main purposes of the SuperDeals Portal. In order to do this, at the time of registration, you will be asked if you want to receive commercial communications in your email with content about the promotions. We remind you that in your personal profile you can configure and change your preferences regarding communications at any time, you should also bear in mind that in each of our communications, you will find a link that will allow you to unsubscribe and stop receiving this type of email.

Usage reporting data: Whenever you make a purchase or hire a service from our partners which related to SuperDeals Portal, we may need to process the data for the internal reporting and financial purposes.

Development of Services: The personal data concerning your usage of then services is processed for the distribution, use, maintenance, and development of our services offered to you.We also inform you that we will be able to share your data anonymously for statistical use for our partners and your employer.

4. How long do we keep your personal data?

We will process your personal data as long as your user account is active, and maximum three (3) years after the termination of your user account. Any optional personal data in your profile is kept only until you decide to delete such data. Retention time is provided without prejudice to the possibility that the data will be need to be retained for longer period of time in order to comply with our legal obligations or to respond to possible complaints.

5. What is the legal basis for the processing of your personal data?

The legal basis for processing your personal data is mainly based on a contract between you and us. You accept our SuperDeals Terms of Use when you register in the SuperDeals Portal, and due to the contractual requirements, we need to process your personal data for example, to manage your profile.

We may also process your data based on your consent, for example when you express interest towards third party promotions or content and we in this purpose deliver your Personal Data to our partners, if you consent to such delivery of data. Electronic direct marketing is based on the consent you give us e.g. when you register. In some cases, if an applicable legal exception concerning direct marketing is available, we may send electronic direct marketing to you in which case you may always opt-out from direct marketing at any time.

The processing of your personal data may also be necessary to fulfill legal obligations that may derive from your activity (such as, transaction history or any financial records).

Finally, we may process your data based on our legitimate interest, such as to improve our services and SuperDeals Portal, produce data analytics or to resolve issues.

6. Who else receives your data?

Transfer to independent controllers: If you are interested in an offer or promotion on the SuperDeals Portal which requires communication of your personal data to the third party, we may communicate your data to such third parties based on your separate consent. Further, SuperDeals Portal may communicate your personal data directly to a third party when you are redirected to the website of such third party. In this case, we recommend that you to read carefully such third party’s privacy policy.

Entities processing data for SuperDeals Portal: SuperDeas Portal uses certain trusted partners for processing your personal data. Epassi remains always liable for the processing activities it has entrusted with third parties, and will ensure the processing activities completed by these processors will comply with the this Privacy Policy.

List of processors

Name

Address

Processing activity

Data Location

Zendesk

Zendesk Inc 181 Fremont ST. 17th floor, 94105 San Francisco, UNITED STATES

Managing support tickets

Ireland

Digital Ocean

DIGITAL OCEAN LLC 105 EDGEVIEW DR., SUITE 425, BROOMFIELD, Colorado 80021, UNITED STATES

Cloud servers for the Portal

Germany

VIP District S. L.

Address: AVDA.BURGOS Nº16-D,PL.11-IZQDA. Madrid 28036

Managing the Portal

Spain

Communication to your employer: To enable the correct provision of the services for the eligible users, your employer may have access to your data to manage subscriptions and unsubscriptions, since the user’s link to the company is necessary to enjoy our services in SuperDeals Portal. Your employer may also receive statistical information about your use of SuperDeals Portal.

7. What are your rights when you give us your data?

  • Right to Access your Personal Data: (you can ask us if we are processing your data).
  • Right to rectification of inaccurate personal data and to have incomplete personal data completed.
  • Right to erasure of personal data.
  • Right to restriction of processing: in this case, data will be processed only for the establishment, exercise or defense of legal claims.
  • Right to object to the processing of data: data will not be processed, except for the establishment, exercise or defense of legal claims.
  • Right to data portability: the subject has the right to receive the personal data concerning him/her and transmit them to another data controller.
  • Right not to be subject to a decision based solely on automated personal data processing.
  • Right to withdraw your consent: you may withdraw your consent at any time, but that will not affect the lawfulness of the processing of your personal data prior to such withdrawal.

To exercise your rights you can contact the Data Controller by sending an email to us at dataprivacy@epassi.com

You can file a complaint to the relevant Data Protection Authority on the Finnish Data Protection Ombudsmans website tietosuoja.fi

8. Security measures

Securing the confidentiality, integrity, and availability of personal data is important for SuperDeals Portal. Our Security Management System is based on the requirements from laws, regulations, contracts and certain standards (such as ISO 27001). Security Management System consists of appropriate technical, administrative, and organizational security measures to protect personal data against unauthorized access, disclosure, destruction, or other unauthorized processing.

Administrative and organizational measures:

  • Dedicated servers in two different geographical locations in the EU. Facilities are certified against internationally recognized Information Security Standard.
  • Role based access rights management

Technical measures:

  • Firewalls
  • Backups
  • Access controls
  • Monitoring of processing
  • Safe encryption technologies
  • Encrypted network connections (HTTPS)

Nevertheless, considering the cyber threats in modern day online environment, we cannot give full guarantee that our security measures will prevent illegally and maliciously operating third parties from obtaining access to personal data or absolute security of the personal data during its transmission or storage on our systems.

All parties processing personal data have a duty of confidentiality in matters related to the processing of personal data. Access to personal data is restricted to those employees and parties who need it to perform their duties. We also require our service providers to have appropriate methods in place to protect personal data.

9. Changes

We will update this Privacy Policy from time to time. In case the changes have a major effect on the data processing concerning you, we will notify you in a suitable manner on reasonable time beforehand.

Updated on November 2025