Privacy Policy
Last updated: July 14, 2026
1. Who we are
This privacy policy covers the Profferio platform (web app and native Android app) as used by employees of Profferio's clients (e.g. Othisi) in the context of their employment. The data controller for each deployment is the respective employer/client; Profferio acts as data processor (software provider).
For questions about your data, contact your employer's HR/IT department first, or reach us at info@profferio.com.
2. What data we collect
Account/profile — at sign-in (via Microsoft 365 SSO or email/password): full name, work email, role, team/project.
Location (GPS) — only for users with a Door-to-Door (D2D) field sales role, and only while clocked in ("WORKING" status, from clock-in to clock-out). Used so the team leader can see the field team's location in real time, for coordination and employee safety. On Android this runs as a native background (foreground) service with a persistent, visible notification whenever active — it is never recorded covertly.
Platform usage data — work hours/shifts, support tickets, internal chat messages, contact center calls (if applicable), depending on which modules your employer has enabled.
3. Why we process it
- Managing work schedules/shifts and human resources.
- Coordination and safety of field teams (live location of D2D sales reps during their shift).
- Operating the platform modules your employer uses (tickets, chat, calls).
Legal basis: performance of the employment contract and the employer's legitimate interest in organizing and securing work (GDPR Art. 6(1)(b) and 6(1)(f)).
4. How long we keep it
- Location: automatically deleted as soon as the shift ends (clock-out) — no route history is stored beyond the current shift.
- Other platform data: for the duration of the employment relationship, and afterwards for whatever period your employer or applicable law requires.
5. Who we share data with
We do not sell or share data with third parties for advertising purposes. We use the following processors to operate the service:
- Microsoft 365 — login authentication (SSO), if enabled by your employer.
- Google Maps Platform — map display and reverse geocoding of coordinates.
- MongoDB Atlas — database hosting (encrypted connection).
6. Security
Connections use HTTPS. Sensitive files (e.g. ticket attachments) are stored encrypted (AES-256-GCM) on the server. Access to location data is limited to team leaders/admins with explicit permission.
7. Your rights
You have the right to access, correct, delete, restrict, or object to the processing of your data, as well as the right to lodge a complaint with the Hellenic Data Protection Authority (dpa.gr) or your local data protection authority. To exercise any right, contact your employer or info@profferio.com.
8. Android app permissions
The Android app requests location permission only for D2D sales reps, active only during their work shift, with a visible notification whenever active. You can revoke it at any time from your device settings — this will stop sharing your location with your team leader.
9. Changes to this policy
We may update this page from time to time. The "Last updated" date above shows when it last changed.