Detailed information on the processing of personal data
Last uptade: 30 june 2021
When we process your personal data
See below for detailed information on the categories of personal data we process, the legal basis for this processing, and how long we store the data for each purpose.
To process orders of goods and services
Personal data:
- Identity data
- Communication
- Contact information
- Order information
- Organisational information
Legal basis:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in managing orders of goods and services.
Fulfilment of agreements. If the order is carried out by an individual company, we process the data to fulfil our agreement with you.
Retention period:
Personal data is retained for this purpose for as long as is necessary in order to process your order and for a period of 10 years thereafter in order to manage and meet legal requirements. Personal data in accounting material is stored for 7 years from the end of the calendar year in which the relevant financial year ended in order for us to fulfil our legal obligations (bookkeeping and accounting requirements in the Swedish Accounting Act (1999:1078)).
To manage relationships with customers, suppliers, and partners
Personal data:
- Identity data
- Communication
- Contact information
- Order information
- Organisational information
Legal basis:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in managing our customer or supplier relationships.
Fulfilment of agreements. If the agreement has been concluded with an individual company, we process the data to fulfil our agreement with you.
Retention period:
Personal data is retained for this purpose for as long as there is an active relationship and for a period of 10 years thereafter in order for us to fulfil our legitimate interest in managing and adhering to legal requirements. The relationship is active if you have had contact with us during the previous 12-month period.
To follow up on and evaluate relationships with customers, suppliers, and partners
Personal data:
- Identity data
- Order information
- Organisational information
Legal basis:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in following up on and evaluating our customer or supplier relationships or collaborations.
Retention period:
Personal data is retained for this purpose for a period of 27 months from the time of collection. General reports which do not contain personal data or statistics are retained indefinitely or until they are deleted.
To communicate about us and our business
Personal data:
- Identity data
- Audio and video materials
- Contact information
- Organisational information
Legal basis:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in communicating about us and our business.
Retention period:
Personal data is retained for this purpose for as long as there is an active relationship and for a period of 12 months thereafter for the same purpose. Published personal data in digital channels, such as in our social media feeds, is essentially retained indefinitely.
To enable communication between employees and external parties
Personal data:
- Identity data
- Audio and video materials
- Communication
- Contact information
- Order information
- Organisational information
Legal basis:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in facilitating business communication between employees and external parties.
Retention period:
In order for us to fulfil our legitimate interest in handling and meeting any legal requirements, personal data is retained for this purpose for a period of 1 year from the most recent communication in each conversation and for a period of 10 years thereafter.
To communicate offers via various channels
Personal data:
- User-generated data
- Audio and video materials
- Identity data
- Contact information
- Order information
- Technical data
Legal basis:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in communicating offers, via various channels, regarding our products and services.
Consent. If you have given your consent to our use of cookies and similar technologies for this purpose, your personal data is processed with the support of your consent.
Retention period:
Personal data is retained for this purpose for as long as there is an active relationship and for a period of 12 months thereafter for the same purpose. If there is no relationship, the data is retained for this purpose for a period of 3 months after the data is collected.
To manage our newsletters
Personal data:
- Identity data
- Contact information
Legal basis:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in managing our newsletters.
Retention period:
Personal data is retained for this purpose until further notice and until you unsubscribe from the newsletter.
To follow up on and evaluate the business
Personal data:
- Identity data
- Order information
- Organisational information
Legal basis:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in monitoring and evaluating the business.
Retention period:
Personal data is retained for this purpose for a period of 27 months from the time of collection. General reports which do not contain personal data or statistics are retained indefinitely or until they are deleted.
To develop and improve the business
Personal data:
- Identity data
- Order information
- Organisational information
Legal basis:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in developing and improving the business.
Retention period:
Personal data is retained for this purpose for a period of 27 months from the time of collection. General reports which do not contain personal data or statistics are retained indefinitely or until they are deleted.
To document the business
Personal data:
- Audio and video materials
- Identity data
- Contact information
- Communication
- Organisational information
Legal basis:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in documenting business activities.
Retention period:
Personal data is retained for this purpose indefinitely.
To carry out training, events, and other activities
Personal data:
- Audio and video materials
- Health data
- Identity data
- Communication
- Contact information
- Organisational information
- Training information
Legal basis:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in carrying out training, events, and other activities.
Explicit consent. Any special categories of personal data relating to health are processed only on the basis of your explicit consent, which is obtained when you register for training, an event, or an activity carried out by us.
Retention period:
Personal data is retained for this purpose for the time that the activity is conducted and for a period of up to 13 months thereafter, calculated from the time the activity is conducted, in order to fulfil our legitimate interest in following up on participation and evaluating the activity, as well as to plan any future activities. Personal data in accounting material is stored for 7 years from the end of the calendar year in which the relevant financial year ended in order for us to fulfil our legal obligations (bookkeeping and accounting requirements in the Swedish Accounting Act (1999:1078)). Any health information collected for this purpose is retained only for the period necessary in order to carry out the activity and is subsequently deleted. Audio and video material that is collected is retained until further notice and until the material is deleted if this is necessary for us to fulfil our legitimate interest in documenting the activity.
To answer questions and provide customer service
Personal data:
- Identity data
- Communication
- Contact information
- Order information
- Organisational information
Legal basis:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in responding to your question.
Retention period:
Personal data is retained for this purpose for a period of 2 years after the case is closed. Published personal data in digital channels, such as in our social media feeds, is essentially retained indefinitely.
To conduct surveys
Personal data:
- Identity data
- Contact information
- Communication
- Organisational information
Legal basis:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in carrying out surveys for the purpose of collecting your views on our business, products, and services.
Retention period:
Personal data is retained for this purpose during the period that the survey is carried out and for a period of 3 months thereafter in order for us to compile the responses in a report. Statistics which do not contain personal data are stored indefinitely or until the statistics are deleted.
To provide our apps and services
Personal data:
- Identity data
- Communication
- Contact information
- Organisational information
- Profile data
- Technical data
Legal basis:
Fulfilment of agreements. Processing is necessary in order to fulfil the applicable terms for the app or service.
Retention period:
Personal data is retained for this purpose for as long as your user account is active, after which the data is deleted.
To communicate about our apps and services
Personal data:
- Identity data
- Contact information
- Profile data
- Technical data
Legal basis:
Fulfilment of agreements. Processing is necessary in order to fulfil the applicable terms for the app or service.
Retention period:
Personal data is retained for this purpose for as long as your user account is active, after which the data is deleted.
To enable functionality on our websites
Personal data:
- Technical data
Legal basis:
Legitimate interest. Processing is necessary in order to fulfil our legitimate interest in enabling the functionality of our websites for the purpose of providing a better user experience.
Consent. If you have given your consent to our use of cookies and similar technologies for this purpose, your personal data is processed with the support of your consent.
Retention period:
Personal data is retained for this purpose throughout your visit and for a period of 12 months thereafter in order for us to fulfil our legitimate interest in providing a better user experience.
To follow up on and evaluate the use of our websites, digital channels, apps, and services
Personal data:
- User-generated data
- Technical data
Legal basis:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in following up on and evaluating the use of our websites, digital channels, apps, and services.
Consent. If you have given your consent to our use of cookies and similar technologies for this purpose, your personal data is processed with the support of your consent.
Retention period:
Personal data is retained for this purpose for a period of 3 months. Statistics which do not contain personal data are stored indefinitely or until the statistics are deleted.
To record phone calls and video meetings for training and quality purposes
Personal data:
- Audio and video materials
- Identity data
- Communication
- Contact information
- Organisational information
Legal basis:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in ensuring the necessary technical functionality of our websites, apps, and services.
Retention period:
Personal data is retained for this purpose for a period of 1 month from the time of the conversation.
To maintain a share register
Personal data:
- Identity data
- Contact information
- Information on shareholding
Legal basis:
Fulfilling a legal obligation. Processing is necessary in order for us to fulfil our legal obligations under the Swedish Companies Act (2005:551).
Retention period:
Personal data is retained for as long as the company exists and for at least 10 years after the company’s dissolution in order for us to fulfil our legal obligations.
To conduct annual general meetings
Personal data:
- Identity data
- Contact information
- Information on shareholding
Legal basis:
Fulfilling a legal obligation. Processing is necessary in order for us to fulfil our legal obligations under the Swedish Companies Act (2005:551).
Retention period:
Personal data is retained for as long as the company exists and for as long thereafter as is necessary for us to fulfil our legal obligations.
To ensure necessary technical functionality and security
Personal data:
- All relevant categories of personal data.
Legal basis:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in ensuring the necessary technical functionality and security of our websites, apps, services, and IT systems.
Retention period:
Personal data is retained for this purpose for as long as your user account is active. Personal data in logs is retained in order to fulfil our legitimate interest in troubleshooting and incident management for a period of 12 months from the log entry time.
To communicate in the event of an accident, illness, or similar event
Personal data:
- Identity data
- Communication
- Contact information
- Relationship information
Legal basis:
Legitimate interest. Processing is necessary in order for us to satisfy our legitimate interest in registering your data in our relatives register and in order to communicate with you in the event of an accident, illness, or similar incident concerning an employee or other staff hired by us.
Retention period:
Personal data is retained until the employee concerned or other staff hired by us reports otherwise, and no later than when the employment or assignment of the person concerned ends.
To manage and adhere to legal requirements
Personal data:
- All categories of personal data that are necessary for handling and meeting a legal requirement in an individual case.
Legal basis:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in handling and meeting legal requirements.
Retention period:
Personal data is retained for the period required in order for us to handle and meet the legal requirement.
To fulfil legal obligations
Personal data:
- All categories of personal data as are necessary for fulfilling the legal obligation.
Legal basis:
Fulfilling a legal obligation. Processing is necessary in order for us to fulfil our legal obligations.
Retention period:
Personal data is retained for the period required in order for us to fulfil each of our legal obligations. By way of example, personal data in accounting material is retained for 7 years from the end of the calendar year in which the relevant financial year ended in accordance with the Swedish Accounting Act (1999:1078).
When we share your personal data with different recipients.
See below for detailed information on the categories of personal data we share with different categories of recipients for various purposes and on which legal basis we do this.
Group companies
To process orders of goods and services
Personal data:
- Identity data
- Communication
- Contact information
- Order information
- Organisational information
Legal basis for the transfer:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in managing orders of goods and services.
To communicate and provide offers via various channels
Personal data:
- Identity data
- Contact information
Legal basis for the transfer:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in communicating and distributing offers, via various channels, regarding our products and services.
Business communication between employees and external parties
Personal data:
- Identity data
- Contact information
- Communication
- Organisational information
Legal basis for the transfer:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in enabling employees and external parties to communicate in relation to their work.
Partners
To carry out training, events, and other activities
Personal data:
- Audio and video materials
- Identity data
- Communication
- Contact information
- Organisational information
Legal basis for the transfer:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in carrying out training, events, and other activities.
Business communication between employees and external parties
Personal data:
- Identity data
- Contact information
- Communication
- Organisational information
Legal basis for the transfer:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in enabling employees and external parties to communicate in relation to their work.
Social networking platforms
To communicate and provide offers via various channels
Personal data:
- User-generated data
- Identity data
- Contact information
- Technical data
Legal basis for the transfer:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in communicating and distributing offers, via various channels, regarding our products and services.
Consent. If you have given your consent to our use of cookies and similar technologies for this purpose, your personal data is processed with the support of your consent.
To communicate about our apps and services
Personal data:
- Identity data
- Contact information
- Technical data
Legal basis for the transfer:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in communicating about our apps and services.
The public
To fulfil legal obligations
Personal data:
- Identity data
- Contact information
- Information on shareholding
Legal basis for the transfer:
Fulfilling a legal obligation. Processing is necessary in order for us to fulfil our legal obligations under the Swedish Companies Act (2005:551).
Other shareholders and proxies
To fulfil legal obligations
Personal data:
- Identity data
- Contact information
- Information on shareholding
Legal basis for the transfer:
Fulfilling a legal obligation. Processing is necessary in order for us to fulfil our legal obligations under the Swedish Companies Act (2005:551).
Euroclear Sweden
To fulfil legal obligations
Personal data:
- Identity data
- Contact information
- Information on shareholding
Legal basis for the transfer:
Fulfilling a legal obligation. Processing is necessary in order for us to fulfil our legal obligations under the Swedish Companies Act (2005:551).
External parties
To enable communication between employees and external parties
Personal data:
- Identity data
- Audio and video material
- Communication
- Contact information
- Order information
- Organisational information
Legal basis for the transfer:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in facilitating business communication between employees and external parties.
Other recipients
To manage a merger or sale of the business
Purpose:
Only the personal data that is necessary for this purpose is shared with the recipient.
Legal basis for the transfer:
Legitimate interest. Processing is necessary in order for us to fulfil our and the buyer’s legitimate interest in completing the sale or merger.
To manage and adhere to legal requirements
Purpose:
Only the personal data that is necessary for this purpose is shared with the recipient.
Legal basis for the transfer:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in handling and meeting legal requirements.
To fulfil legal obligations
Purpose:
Only the personal data that is necessary for this purpose is shared with the recipient.
Legal basis for the transfer:
Fulfilling a legal obligation. Processing is necessary in order for us to fulfil our legal obligations.
To respond to a legal request
Purpose:
Only the personal data that is necessary for this purpose is shared with the recipient.
Legal basis for the transfer:
Legitimate interest or to fulfil a legal obligation. To the extent that we are obliged to respond to a legal request, personal data is processed in order to fulfil this legal obligation. Otherwise, processing is based on a balance of interests when it is necessary to fulfil our and the requester’s legitimate interest in our responding to the enquiry.
To protect and guarantee the safety of our staff
Purpose:
Only the categories of personal data that are necessary for this purpose, such as to report an incident to a law enforcement authority.
Legal basis for the transfer:
Legitimate interest. Processing is necessary in order for us to fulfil our legitimate interest in protecting and guaranteeing the safety of our staff.
Recipients with whom we are jointly responsible for the use of your personal data
In the table below, you will find further information about the recipients with whom we are jointly responsible for the use of your personal data. In the table, you will also find further information on the recipients’ processing of personal data.
Recipient:
Facebook Ireland Limited
Grand Canal Square, Grand Canal Harbour, Dublin 2, D02C525, Ireland
Information:
Information about Facebook Ireland’s use of your personal data, including its legal basis for processing the data and how you can exercise your rights in respect of Facebook Ireland, can be found in its data policy, which is available here: https://www.facebook.com/about/privacy.
We have entered into a supplementary agreement on joint responsibility in order to determine our respective responsibilities and roles in relation to the use of your personal data that we and Facebook Ireland are jointly responsible for. Please see https://www.facebook.com/legal/controller_addendum.
Recipient:
LinkedIn Ireland Unlimited Company
70 Sir John Rogerson’s Quay, Dublin 2, D02R296, Ireland
Information:
Information about LinkedIn Ireland’s use of your personal data, including its legal basis for processing the data and how you can exercise your rights in respect of LinkedIn Ireland, can be found in its privacy policy, which is available here: https://www.linkedin.com/legal/privacy-policy.
We have entered into a supplementary agreement on joint responsibility for personal data with LinkedIn Ireland in order to determine our respective responsibilities in relation to the use of your personal data that we and LinkedIn Ireland are jointly responsible for. Please see https://legal.linkedin.com/pages-joint-controller-addendum.
Categories of personal data
In the table below you will find further information on the categories of personal data we process.
User-generated data
Category of data:
Data that you provide when using our websites, digital channels, apps, and services
Example of data:
Data on clicks, visits, and your behaviour on our websites, digital channels, apps, and services.
Audio and video materials
Category of data:
Data such as your image when photographed or your voice when recorded.
Example of data:
Photography, film, audio file.
Health data
Category of data:
Data on your health.
Example of data:
Allergies or other intolerances.
Identity data
Category of data:
Data that makes it possible to identify you.
Example of data:
Name, personal identity number, username, IP address.
Communication
Category of data:
Data included in communications with us.
Example of data:
E-mail content.
Contact information
Category of data:
Data that enables us to contact you.
Example of data:
Address, phone number, e-mail address.
Order information
Category of data:
Data on an ordered product or service.
Example of data:
E-mail content.a
Product, service, delivery time, price.
Organisational information
Category of data:
Data related to your organisation.
Example of data:
Title, name of company or organisation, address of the person or organisation.
Profile data
Category of data:
Data about your user profile when using our apps and services.
Example of data:
Profile settings.
Technical data
Category of data:
Technical data related to the device you use when using our websites, apps, and services.
Example of data:
App version, device information, operating system, browser, screen size, internet connection.
Training information
Category of data:
Data related to training you have taken part in.
Example of data:
Data about completed training.
Relationship information
Category of data:
Information about your relationship to an employee of ours or other staff hired by us.
Example of data:
Marital status, relationship information, e.g. cohabitant, relative, etc.
Information on shareholding
Category of data:
Data related to your shareholding.
Example of data:
The number of shares and the listing that, by law, is linked to each shareholding, such as share class.