Privacy Policy

Privacy Policy

The Spenn Platform

1. About this privacy policy

This Privacy Policy applies to the processing of personal data by Spenn Group AS (hereafter referred to as "Spenn Group", "we", or "us") when you are in contact with us and in connection with your use of Spenn and the Spenn Platform. The Privacy Policy applies to both our website, www.spenn.no, and the Spenn Platform.

Personal data means any information relating to an identified or identifiable natural person. This policy includes information on your data protection rights and how we process your personal data.

In the privacy policy, we use terms from the GDPR, for example "processing", "controller" and "data processor".

You can find more information about the terms on the Norwegian Data Protection Authority's website (www.datatilsynet.no).

2. Who is responsible for processing your personal data?

Spenn Group is the controller of the personal data we process. This means that we are responsible for ensuring that the processing is compliant with the data protection legislation.

We would like to hear from you if you have questions or objections to how we process your personal data, or if you wish to exercise your rights.

You can contact our data protection officer by: privacy@spenngroup.com

Our contact information is:

  • Business name and registration no.: Spenn Group AS, 932 435 888

  • Address: Inkognitogata 33, 0256 OSLO, Norway

  • E-mail: privacy@spenngroup.com

Please note that the providers of the loyalty programs that issue Spenn, are solely responsible for their own processing of your personal data unless otherwise specified.

For information on your rights and how to exercise them, see section 8 below.

3. The Spenn Platform

By becoming a Spenn User, you will receive personalised content and offers based on your interests and preferences, and can earn and use the loyalty currency known as Spenn across different eligible partners and loyalty programs. The Spenn Platform aims to unify and make available the advantages of various loyalty programs through a single app with the same loyalty points, offering Spenn Users enhanced value beyond what each individual partner and loyalty program provides. The Spenn Platform does not replace the partners' loyalty programs.

See www.spenngroup.com/terms-conditions (“Terms”) for further details about the Spenn Platform and the Spenn loyalty currency.

4. What personal data do we process and for which purposes?

When we process your data, we must have a legal basis. We are only allowed to processed personal data for specific purposes. We will process personal data as necessary for (i) the performance of Terms, (ii) any consents granted from Spenn Users, (iii) Spenn Group’s legitimate interests; and (iv) Compliance with Spenn Group’s legal obligations.

The table below is an overview of the the categories of personal data we process, our purposes and legal bases. The subsequent sections provide further explanations.

We do not take any decisions with legal or similar material effect based on fully automated processing of your personal data.


4.1 We process personal data to personalise the Spenn Platform

One of the main purposes of the Spenn Platform is to provide you with personalised content and offers, benefits, rebates, rewards or discounts on Partner products which can be acquired by using Spenn.

In order to offer you a personalised service, we will collect information about your interests and preferences. This may include your actions within the Spenn Platform and how you use the Spenn App, geographical data to provide location specific offers and services, demographic data and answers to questionnaires or contests.

We will also collect data from our partners on your purchases of products or services from them.

Certain personalisation based on your data is necessary to deliver the Spenn Platform. This processing is necessary for the performance of our agreement with you (the Terms). If you wish to receive an even more personalised service, you can consent to further processing data.


4.1.1 Personalisation that is necessary to deliver the Spenn Platform

A degree of personalisation based on your data is necessary to fulfil the purpose of the Terms. We create personalised content, such as your home screen on the mobile app, based on your Usage Data. Some recommendations are based on the preferences of other Spenn Users with similar behaviour patterns or popular content elements in your country.

The types of personal data that is processed includes: User Data, Usage Data, Payment Data, Purchase Data, Technical data


4.1.2 Additional personalisation

You may consent to the processing of additional data. This will enable the Spenn Group to provide you with even more personalised content, services and offers.

The types of personal data that may be processed for additional personalisation includes: Location Data


4.1.3 Training of personalisation algorithms

The purpose of the Spenn Platform is to provide you with suitable content, offers and relevant recommendations. For this purpose, we need to train and continuously improve our personalisation algorithms.

The types of personal data that will be used for this purpose includes: User Data, Account Data, Usage Data, Technical Data, Marketing Data, Data processed in context of customer support.

The legal basis for this processing is that it is necessary for the performance of the contract. The Spenn Group will not be able to perform the service of offering personalized offers if the algorithms lack data, or if the algorithms are not continuously improved and updated.


4.2 We process personal data to offer the Spenn Platform

When you register a user account on the Spenn Platform, we need to process personal data about you to register and manage your Spenn User. This information is collected when you sign up for the Spenn Platform or may be received from a partner where you are a member.

The data collected and utilized varies depending on the type of partner program you may be associated with. The data is collected when you sign up for the Spenn Platform, or when you update your account. We receive this data from you directly through sign-up forms, from a partner where you are a member, and through third party service providers such as ad partners and analytics service providers.



4.2.1 Set up and manage your Spenn Account

We need to collect some of your personal data to verify that you are old enough to have a Spenn User account, and to create your Spenn user account. We will assign you internal, system-generated identifiers (e.g., Spenn User ID and Parent ID if you are a Spenn Together plan account holder) that will be associated with your Spenn account in our systems.

We need to know which year you are born, to ensure that you are old enough to use Spenn. The age limit for creating a Spenn User Account is 16. Furthermore, we need to know in which country you reside in order to provide you Spenn based on the correct currency.

The processing described in this section is necessary for the performance of our agreement with you (the Terms).


4.2.2 Earning and use of Spenn

We will process data received from our partners to issue Spenn to you, and information about your use of Spenn, to ensure that the correct amount of Spenn is deducted from your account when you use Spenn.

The types of personal data that is processed includes: User Data, Payment Data, Consent Data.

The processing described in this section is necessary for the performance of our agreement with you (the Terms).


4.2.3 Verify whether our services are available in your country

We determine your country of residence when you subscribe to our services and associate this country with your Spenn account. This allows us to deliver services that meet the legal, language, and content requirements of your region.

The types of personal data that is processed includes: Account Data.

The processing described in this section is necessary for the performance of our agreement with you (the Terms).


4.2.4 Spenn Together

When a Spenn Together account owner invites you to join their plan, we receive some of your data from the account owner and send you an email invitation. If you accept, your Spenn account will be associated with the Spenn Together plan in our systems.

The types of personal data that is processed in order to invite you to a Spenn Together account includes: User Data, Account Data.

The types of personal data that is processed when you accept an invitation includes: User Data, Usage Data.

The legal basis for this processing is our legitimate interest in extending the benefit of the Spenn Together plan account owner to you. This processing activity does not constitute a disproportionate interference in the Spenn User’s rights and freedoms, as it is assumed that the invitations are extended from someone known to the user, and it is assumed that the invitation is typically extended at the User’s wish or request.


4.2.5 Record your choices regarding Terms and privacy settings

We need to keep your profile and the details of our Contract with you updated, and you need to be able to access the latest version of our Terms, in order for you to have an overview of your contractual relationship with us.

The types of personal data that is processed includes: User Data, Account Data, Consent Data.

The processing described in this section is necessary for the performance of our agreement with you (the Terms).


4.3 We process personal data to communicate with you


4.3.1 When you contact our Customer Service

When you contact us, through our platform or social media, we will process personal data about you. The personal data we typically collect will includes: User Data and any other information you provide to us, which is necessary for us in order to respond to you.

Our legal ground for this processing is our legitimate interest. The legitimate interest is our need to be able to respond to you.


4.3.2 Send you important messages concerning our services

We have an obligation to keep you updated on changes and updates to our services, which includes Terms and Conditions, Privacy Policy, and other technical and security-related messages.

This information can be given through different channels, such as email, sms, in-app messages or notifications. These communications are essential, so you cannot opt out of receiving them.

The types of personal data that is processed includes: User Data, Account Data, Consent Data, Technical Data.

The processing described in this section is necessary for the performance of our agreement with you (the Terms).


4.4 We process personal data to improve and develop the Spenn Platform

We will use information on the usage of the Spenn Platform, in pseudonymous or anonymised form, to improve and develop the Spenn Platform as speficied below.

The fact that information is pseudonymised means that, for example, telephone numbers are removed and replaced with a unique indicator (e.g. a number code), before the information is processed as described above. Technically, however, the indicator can be “traced” back to the individual. Personal data is anonymised when it is no longer possible to re-identify the individual.


4.4.1 Evaluate the effectiveness and performance of our existing services and features

We analyze usage metrics to understand how our services and features are used, their frequency, and how they can be improved.

For this purpose, the following types of personal data will be processed: Usage Data, Payment Data, Purchase Data.

The legal basis for our processing is our legitimate interest in improving and developing the Spenn Platform for the benefit of our users.


4.4.2 Develop and test new services and features

We use feedback from users to develop, test, and evaluate new services and features, including their design and adoption metrics.

For this purpose, the following types of personal data will be processed: User Data, Usage Data, Payment Data, Purchase Data, Technical Data.

The legal basis for our processing is our legitimate interest in improving and developing the Spenn Platform for the benefit of our users.


4.4.3 For our analytics, forecasting, and reporting purposes

We measure and analyse how our services perform, preparing internal reports that inform business decisions, marketing campaigns, and product development. We use de-identified and/or aggregated information for this purpose.

The types of personal data that will be processed for this purpose includes: User Data, Usage Data, Payment Data, Purchase Data, Technical Data

The legal basis for our processing is our legitimate interest in improving and developing Spenn services and user experience.


4.5 We process data to diagnose, troubleshoot and fix technology and security problems


4.5.1 Diagnose, troubleshoot and fix technology and security issues

We collect information about errors, crashes, bugs, or other technical issues and security incidents from your device. This data is processed in our internal log systems to help resolve issues and prevent future occurrences.

The types of data that will be processed for this purpose includes: User Data, Payment Data, Technical Data.

The processing described in this section is necessary for the performance of our agreement with you (the Terms).


4.5.2 Test whether our services perform as they should

We conduct testing on de-identified or pseudonymized data to ensure our services and features operate correctly.

The types of data that will be processed for this purpose includes: User Data, Technical Data.

The processing described in this section is necessary for the performance of our agreement with you (the Terms).


4.6 We process personal data for marketing purposes

You can consent to receive news and relevant offers from us in various channels (e.g. email, SMS and through social media). The purpose of this processing is to send you news or other information you have requested or registered to receive. If you consent to receiving marketing communications, we may use your data to send you personalized content. In addition, we will collect data to measure the success of our marketing campaigns.


4.6.1 Deliver marketing emails, sms, in-app messages and notifications

The purpose of this processing is to send you news or other information you have requested or registered to receive. We may send you emails, sms, in-app messages or notifications and ads in social media about our services or events, and promotional offers from third-party partners or advertisers. You can manage your preferences and opt-out from receiving such notifications in the Spenn account settings.

The types of data that will be processed for this purpose includes: User Data, Usage Data, Payment Data, Purchase Data, Consent Data.

The legal basis for this processing is the consent you provide when you sign up to receive personalised marketing communications in the specific channels.

You can withdraw your consent at any time by following the procedure described at the bottom of all emails, or through the settings in the Spenn App. When you withdraw your consent, we will remove you from the recipient list.


4.6.2 Personalize our marketing campaigns

If you have consented to receive marketing communications, we may use your usage data and marketing data to send you more personalized content, such as offers or recommendations based on your behavior.

The types of data that will be processed for this purpose includes: User Data, Usage Data, Payment Data, Purchase Data, Technical Data, Consent Data.

Our legal basis for this processing activity is our legitimate interest in delivering relevant marketing campaigns when you have consented to receiving marketing communications. This processing activity does not constitute a disproportionate interference in the User’s rights and freedoms.


4.7 We process data to comply with legal obligations

We are required by law to process personal data in certain cases, for instance to document compliance with obligations within tax, accounting or legal processes. In this connection, it may be necessary to process personal data about you. This could, for example, be necessary if your name is listed on an invoice or contract subject to retention obligations.

The legal basis for such processing is the legal obligation to which we are subject.

The information will be deleted when the purpose of the processing is fulfilled, such as for example where the reporting obligation is fulfilled, or we are no longer required to retain the information.


5. What is the source for the personal data we process?

The personal data we process is collected directly from you, for example, when you provide information to us during the registration of the Spenn User Account or through your use of the Spenn Ap. Furthermore, we receive information from our partners, who offer you the various loyalty programs using Spenn, ad partners and analytics service providers.


6. Who do we share your personal data with?

6.1 Data processors

Your personal data will be accessible to those of our suppliers who process personal data on our behalf. We have entered into data processing agreements which, among other things, mean that your personal data cannot be used for other purposes.

Some of our suppliers are located in countries outside the EU/EEA. This means that personal data can be transferred or is accessible from a country with a regulatory framework that does not provide the same level of protection of personal data compared to the rules in Norway. To ensure your privacy, such transfer will only take place if we through other measures can ensure that your data enjoys the same level of protection as in the EU/EEA.


6.2 Our partners

Spenn Group’s partners will receive personal data of Spenn Users to the extent it is necessary to facilitate earning and use of Spenn, or other features of the Spenn Platform that require us to disclose personal data to partners.

Data sharing between us and our partners will only happen to the extent this is legally permissible and required to implement, promote and operate the Spenn Platform and create and offer value-adding analysis and insights that each individual partner could not have created outside of the Spenn Platform.

The categories of personal data shared from Spenn Group to partners includes: [….]. To learn more about the data our partners share and collect about you, we recommend reading the privacy policies of the partners' loyalty programs that you are a member of.

In some cases, Spenn Group and our partners will act as joint-controllers, and ensure your personal data is processed in accordance with the GDPR together. When this is the case, you will receive information on how we have allocated between us the responsibilities to safeguard your personal data.


7. When do we delete your personal data?

We will keep personal data received from you or our partners only for the duration necessary to fulfil the purposes for which it was collected. Upon request from you, we will promptly delete all personal data on you, as long as the data is not subject to any legal obligation requiring us to keep the data. Where our basis for processing is your consent, we will delete the information if you withdraw your consent. You can withdraw your consent at any time through the settings in the Spenn App, by following the procedure described in marketing emails or SMS received from us, or by submitting a request as outlined in section 8.


8. Your rights

You are entitled to the data protection rights listed below. Certain conditions must be met for them to be enforced and exceptions to the rights may also apply. You can read more on the Norwegian Data Protection Authority's website www.datatilsynet.no, in the GDPR chapter III and in chapter 4 of the Norwegian Personal Data Act.

  • Access: you have the right to request information about how we process your personal data and to obtain a copy of that personal data.

  • Rectification: you have the right to request the rectification of inaccurate personal data about you and for any incomplete personal data about you to be completed.

  • Objection: you have the right to object to the processing of your personal data, which is based on our legitimate interests.

  • Erasure: you have the right to request the erasure of your personal data (subject to certain conditions).

  • Automated decision-making: you have the right not to have a decision made about you that is based solely on automated processing if that decision produces legal effects about you or significantly affects you. We do not use automated individual decision-making for such purposes.

  • Restriction: you have the right to ask us to restrict our processing of your personal data, so that we no longer process that information until the restriction is lifted.

  • Portability: you have the right to receive your personal data, which you have provided to us, in a structured, commonly used and machine-readable format and to have that information transmitted to another organisation in certain circumstances.

  • Withdraw consent: you have the right to withdraw your consent at any time for processing requiring consent.

To exercise any of these rights, please contact privacy@spenngroup.com.

You can contact our Data Protection Officer for assistance with any questions or issues related to exercising your rights. The contact details for the Data Protection Officer is found in section 2.

  • Complaint: you have the right to lodge a complaint with the Data Protection Authority in Norway (Datatilsynet) if you have reason to believe that processing of your personal data does not comply with data protection legislation. Visit their website (www.datatilsynet.no) for information on how to lodge a complaint.


9. Changes to this policy

We update this privacy policy if there are changes in how we process personal data. You will always find the most recently updated privacy policy on www.spenngroup.com/privacy-policy. We will inform you directly via our website and the Spenn App prior to any material changes to this policy.

Date of last update: 17 October 2024