Datenschutzerklärung

1. Einleitung

Oper Credits BV und ihre derzeitigen und künftigen Tochtergesellschaften, einschließlich der Oper Credits AG (zusammenfassend „Oper“, „wir“, „uns“), nehmen den Schutz Ihrer Daten ernst. Diese Datenschutzerklärung erläutert, wie wir personenbezogene Daten für folgende Gruppen verarbeiten:

  • Website-Besucher: Personen, die unsere Website besuchen oder mit unseren Online-Inhalten interagieren, einschließlich Marketing-Seiten, Kontaktformularen, Newslettern oder Veranstaltungsanmeldungen.

  • Kunden: Mitarbeiter oder Vertreter von Finanzinstituten, die die Plattform von Oper nutzen.

  • Endnutzer: Kreditnehmer, die unsere Plattform über ein Finanzinstitut nutzen. (Endnutzer sind keine Mitarbeiter von Oper.)

Unsere Rollen gemäß der DSGVO:

  • Verantwortlicher: Oper ist der Verantwortliche für personenbezogene Daten von Website-Besuchern sowie für administrative oder betriebliche Daten von Kunden und Endnutzern (z. B. Kontoverwaltung, Authentifizierung, Sicherheitsprotokolle, Support-Tickets und Kommunikation).

  • Auftragsverarbeiter: Oper ist Auftragsverarbeiter bei der Verarbeitung von Baufinanzierungsdaten von Endnutzern sowie anderer auf der Plattform gehosteter personenbezogener Daten, die im Auftrag eines Kunden und streng nach dessen Anweisungen verarbeitet werden.

Wie Oper als Verantwortlicher bzw. Auftragsverarbeiter auftritt

Category Controller Role Processor Role
Site Visitors All personal data relating to website operation, analytics (with consent), marketing, security and enquiries. Not applicable.
Customers (employees/ representatives) Account creation, authentication, permissions, audit logs, support, security monitoring, product analytics, marketing (with consent). Only where the Customer instructs Oper to perform processing on Customer-provided datasets within the platform (rare; usually none).
End Users (borrowers) Limited administrative communication and optional product-research activities (consent-based). All mortgage-application data and related workflow processing performed strictly on Customer instructions.

 

Bei Fragen wenden Sie sich bitte an: privacy@opercredits.com.

 

2. Welche personenbezogenen Daten wir verarbeiten und warum

Wir verarbeiten personenbezogene Daten nur, wenn wir gemäß der DSGVO über eine rechtmäßige Grundlage verfügen. Für jede Datenkategorie geben wir an, in welcher Rolle Oper tätig ist:

  • Verantwortlicher: Oper bestimmt die Zwecke und Mittel der Verarbeitung.

  • Auftragsverarbeiter: Oper verarbeitet personenbezogene Daten ausschließlich im Auftrag und auf Anweisung eines Kunden (in der Regel ein Finanzinstitut).

2.1. Besucher der Website

A. Website-Betrieb, Sicherheit und Leistung


  • Daten: IP-Adresse, Browser-/Gerätedetails, Sicherheitsprotokolle, Ereigniszeitstempel.


  • Rechtsgrundlage: Berechtigte Interessen (Gewährleistung eines zuverlässigen und sicheren Betriebs der Website), gesetzliche Verpflichtungen.

B. Analyse und Produktverbesserung (nur mit Einwilligung)


  • Daten: Cookie-Identifikatoren, Nutzungsmetriken, Daten zur Seitenleistung.


  • Rechtsgrundlage: Einwilligung.

C. Beantwortung von Anfragen


  • Daten: Name, E-Mail-Adresse, Telefonnummer und alle von Ihnen übermittelten Informationen.


  • Rechtsgrundlage: Berechtigte Interessen (Beantwortung von Anfragen), Schritte vor Vertragsabschluss.

D. Marketing und Werbung (berechtigtes Interesse; Einwilligung, sofern nach lokalem Recht erforderlich)


  • Daten: E-Mail-Adresse, Cookie-Identifikatoren, IP-Adresse und Hash-Identifikatoren, die zur Erstellung professioneller Werbezielgruppen verwendet werden (z. B. LinkedIn Custom Audiences).

  • Rechtsgrundlage: Berechtigte Interessen (Werbung für unsere B2B-Dienstleistungen bei relevanten professionellen Zielgruppen); Einwilligung für Cookie-basiertes Tracking, sofern erforderlich.


  • Einzelpersonen können sich jederzeit über unsere Tools zur Verwaltung von Präferenzen oder durch Kontaktaufnahme mit privacy@opercredits.com von Marketingmitteilungen oder Marketingzielgruppen abmelden.

2.2. Kunden

A. Bereitstellung und Verwaltung des Zugriffs auf die Plattform (Oper als Verantwortlicher)


  • Daten: Name, berufliche Kontaktdaten, Organisation, Rolle/Berechtigungen, Anmeldedaten.


  • Rechtsgrundlage: Erfüllung eines Vertrags.

B. Authentifizierung, Zugriffskontrolle und Audit-Protokollierung (Oper als Verantwortlicher)


  • Daten: Anmeldezeitstempel, IP-Adresse, Geräte-/Browserinformationen, Audit-Protokolle.


  • Rechtsgrundlage: Berechtigte Interessen (Sicherheit und Überprüfbarkeit), gesetzliche Verpflichtungen.

C. Plattformleistung, Überwachung und Sicherheit (Oper als Verantwortlicher)


  • Daten: Fehlerprotokolle, Diagnosedaten, Systemereignisse.


  • Rechtsgrundlage: Berechtigte Interessen (Gewährleistung von Stabilität und Sicherheit).

D. Produktanalyse (Oper als Verantwortlicher für Kunden-Nutzer-Analysen)


  • Daten: Nutzungsmuster von Funktionen, Interaktionsdaten, pseudonymisierte oder anonymisierte Metriken.


  • Rechtsgrundlage: Berechtigte Interessen für wesentliche Analysen; Einwilligung für zusätzliche Analysen.
(Analysen in Bezug auf Baufinanzierung der Endnutzer werden nur auf Anweisung des Kunden durchgeführt und gemäß Abschnitt 2.3 behandelt.)

E. Kundensupport und Serviceverbesserung (Oper als Verantwortlicher)


  • Daten: Support-Tickets, Kommunikationsverlauf, Konfigurationsdetails.


  • Rechtsgrundlage: Berechtigte Interessen (Bereitstellung von Support), Erfüllung eines Vertrags.

F. Marketing und Produktforschung (Oper als Verantwortlicher, auf Einwilligung basierend)


  • Daten: Kontaktdaten, Interaktionsdaten, Umfrageantworten.


  • Rechtsgrundlage: Einwilligung.

2.3. End Users

A. Mortgage application processing (Oper as Processor)

  • Data:

    • Identification: name, contact details, address history, ID documents.

    • Financial: income, payslips, tax records, debts, savings, property documents.

    • Derived: affordability calculations and workflow-supporting outputs.

  • Legal basis: Performance of a contract between the End User and the financial institution. Processing follows Customer instructions.

B. Fraud prevention, KYC support and document handling (Oper predominantly as Processor; Controller only for system-level security metadata)

  • Data: Metadata from uploads, verification checks, IP address, device data.

  • Legal basis: Legitimate interests (security and integrity), legal obligations of financial institutions.

C. Administrative notices (Oper as Controller)

  • Data: Contact information required to provide operational updates related to the use of our platform.

  • Legal basis: Legitimate interests (ensuring correct platform operation), performance of a contract.‍

D. Product research (Oper as Controller, consent-based)

  • Data: Survey responses, interview participation, usage insights (minimised where possible).

  • Legal basis: Consent.

 

3. Cookies and Similar Technologies

We use essential cookies necessary for the website to function securely and reliably.

We use analytics or advertising cookies only if you consent. Details are provided in our Cookie Policy.

 

4. How We Share Personal Data

We share personal data only when needed and with appropriate safeguards.

4.1. Service Providers

We rely on specialised service providers to help us deliver a secure and reliable platform. These providers support areas such as:

  • Hosting and cloud infrastructure (including compute, storage, database services)

  • Security and monitoring (intrusion detection, anomaly detection, log management)

  • Customer support and communication tools (ticketing systems, email services, in-app messaging)

  • Operational tooling (deployment systems, CI/CD tooling, workflow automation)

  • Analytics and performance monitoring (site performance, uptime, product telemetry — only activated with consent where required)

Before engaging any service provider, we conduct due diligence to assess security, privacy controls, financial stability, and GDPR compliance. All service providers:

  • operate under a Data Processing Agreement (DPA);

  • access personal data only as needed to provide their service;

  • must implement appropriate technical and organisational measures, including encryption, access controls and audit logging;

  • are subject to ongoing monitoring and periodic reviews.

We maintain a structured subprocessor management process. Our current list of subprocessors is available on our website.

Oper applies a formal vendor management framework covering risk assessment, security review, contractual controls, and ongoing monitoring. Each subprocessor is assessed for technical and organisational measures, incident response capability, and compliance with GDPR and relevant financial sector expectations.

4.2. Marketing and advertising tools (consent-based)

If you give consent, we may use tools that support our CRM, communications, analytics or advertising activities. These tools may process limited identifiers to help us understand engagement or reach relevant audiences. Examples include:

  • CRM and email platforms (e.g., for newsletters, opt-in product updates)

  • Analytics tools (activated only with consent)

  • Advertising platforms used to create or measure audiences (e.g., hashed contact identifiers or cookie IDs)

  • HubSpot (CRM, email automation, subscription management)

  • LinkedIn Marketing Solutions (custom audiences, LinkedIn Ads)

Key points about these tools:

  • They operate only if you provide consent through our cookie banner or communication preferences.

  • Identifiers used for advertising purposes may be hashed or pseudonymised before being shared.

  • We do not share full customer or End User data with advertising platforms.

  • Opt-out: You may opt out of receiving marketing communications or being included in marketing audiences (including LinkedIn custom audiences) at any time by using the unsubscribe or preference-management links in our emails, or by contacting privacy@opercredits.com.

4.3. Marketing and advertising tools (consent-based)

If you consent, we may use CRM, analytics, or advertising tools that process limited identifiers, such as hashed email addresses or cookie IDs.

4.4. Security, fraud prevention, and compliance

We may disclose data where required by law, or to prevent, detect, or investigate fraud or security issues.

4.5. Business transactions

In the event of a merger, acquisition, or restructuring, personal data may be transferred under appropriate safeguards.

 

5. International Data Transfers

We do not transfer personal data outside the European Economic Area (EEA) in the normal course of our activities. All core infrastructure and services are located within the EEA.

In exceptional cases, where a transfer outside the EEA is unavoidable, we rely on:

  • an adequacy decision, or

  • Standard Contractual Clauses, supported by additional measures such as encryption and strict access controls.

We maintain internal controls to prevent unauthorised transfers.

 

6. Data Retention

We keep personal data only for as long as necessary for the purposes described in this Notice or to meet legal or regulatory requirements.

  • As controller, we follow documented retention schedules for operational, security, and audit needs.

  • As a processor, we handle end-user mortgage application data strictly in line with Customer instructions.

Regular reviews ensure data is not stored longer than needed.

 

7. Security

We apply a range of organisational and technical measures aligned with recognised standards such as ISO 27001, including:

  • Encryption in transit and at rest

  • Role-based access controls

  • Secure development practices

  • Monitoring and anomaly detection

  • Regular security testing

  • Subprocessor due diligence

While no online system is entirely risk-free, we take appropriate steps to safeguard the data entrusted to us.

 

8. Children

We do not knowingly collect or process data from individuals under 18. If you believe this has occurred, please contact us so we can take appropriate action.

 

9. Your Rights

You have rights under the GDPR, including:

  • Access to your data

  • Correction of inaccuracies

  • Erasure (where applicable)

  • Restriction of processing

  • Data portability

  • Objection to processing (including marketing)

  • Withdrawal of consent at any time

To exercise your rights, contact privacy@opercredits.com. We will respond within one month.

You may also contact your local Data Protection Authority. However, we encourage you to reach out to us first so we can address your concerns.


10. Automated Decision-Making

We do not carry out automated decision-making that produces legal or similarly significant effects under Article 22 GDPR. Financial institutions make all lending decisions.

 

11. Updates to This Notice

We may update this Notice occasionally. The revision date will indicate the latest version. Significant changes may also be communicated directly.

 

12. Contact

Oper Credits BV

Lange Gasthuisstraat 29-31

Antwerp, 2000, Belgium

Email: privacy@opercredits.com