Privacy Policy
CONTACT INFORMATION
Doconomy AB, with reg. no. 559163-0602, is the controller of personal data covered in this privacy policy. If you have any questions regarding the processing of your personal data or this privacy policy, please contact us at:
Doconomy AB
Östermalmsgatan 26A
114 26 Stockholm Stockholm
Mail: privacy@doconomy.com
1. Identity of data controller
Doconomy AB (company registration number 559163-0602) (“Doconomy”, “we”, “us” “our”) is the controller of personal data processing as described in this Privacy Policy.
If you have any questions regarding our processing of your personal data, or if you want to exercise your rights as set out in section 5 below, you can contact us on privacy@doconomy.com or at the address indicated below.
Doconomy AB
Östermalmsgatan 26A
114 26 Stockholm
2. Information regarding our processing of personal data
We process your personal data when you visit and use our website as further described below. We will also process your personal data if you represent one of our customers, suppliers or partners. Doconomy is as a main rule deemed as a data processor for the processing of personal data in relation to the services we provide. Such processing activities therefore fall outside of the scope of this Privacy Policy.
It is important that you feel comfortable with the processing of your personal data, and we therefore ask you to read this Privacy Policy.
We only process your personal data to the extent permitted in accordance with applicable data protection legislation. This means inter alia that we must have support for the purposes of the processing in the form of a so-called legal basis. The legal basis for each processing activity is set out in the tables below. We take measures to ensure that your personal data is handled in a safe way. We maintain appropriate safeguards and security standards to protect your personal data against unauthorized access, disclosure or misuse and access to systems containing personal data is restricted to our employees and service providers who need it to perform their job duties. We ensure that employees and service providers are informed of the importance of maintaining security and confidentiality in relation to the personal data being processed.
To maintain and improve our website
Purpose: Collect statistical data and analyse the web traffic on our website as well as other technical information generated when visiting our website, in order to maintain and improve its functionality, the user experience, and in order to discover and handle errors, breaches and incidents.
Categories of personal data:
IP address
Other technical information generated through visits on our website, such as the type of technical device that you have used, web browser, visited pages as well as the time of the visits (browser information, time zone at the place from which you visited our website, other web traffic information).
Legal basis: Legitimate interest, where our legitimate interest is to collect information to maintain and improve the functionality, content, and security of our website. Collection of information by use of cookies is carried out based on your consent, unless they are strictly necessary in order for you to be able to use our website in an appropriate manner. For more information on how we use cookies, please see our cookie policy here.
Retention period: We process information about how visitors engage with our website for no longer than six (6) months. In most cases, the collected personal data is however converted to aggregated data (anonymized data) before the said time period, in connection with us producing statistical data.
Sharing of personal data: We will share your personal data with our suppliers of IT services and group companies.
To create, maintain and develop potential business relationships
Purpose: Contact and communicate with you in your capacity as a representative of a potential customer, partner, supplier or other business contact for the purposes of creating, maintaining and developing our business relationship with you or the company you represent. This includes, among other things, communication via email regarding our business, services and other activities, such as marketing activities as stated below in this Privacy Policy.
Categories of personal data:
First and last name
Contact details such as email address, telephone number, location and business address
Professional title and information regarding the company you represent
Information that you provide us in our communications with you.
Legal basis: Legitimate interests, where our legitimate interest is to create,maintain and develop a business relationship with you or the company you represent.
Retention period: We process your personal data for a period of two (2) years after the data was collected. If a business relationship is established between us and you or the company you represent during this time, we will however continue to process your personal data in accordance with below.
Sharing of personal data: We will share your personal data with our suppliers and group companies.
To maintain and develop existing business relationships
Purpose: Contact and communicate with you in your capacity as a representative of one of our existing customers, partners, suppliers or other business contacts, maintain and develop our business relationship with you or the company you represent, and enter into a contract.
This includes, among other things, regular administration and communication regarding our customer, partner and supplier contracts and communication via email about our business, services and our current activities (see information about marketing measures below).
Categories of personal data:
First and last name
Contact details such as email address, telephone number, location and business address
Professional title and information regarding the company you represent
Information that you provide to us in our communication with you or matters regarding the contract.
Legal basis: Legitimate interest, where our legitimate interest is to maintain and develop our business relationship with you or the company you represent.
For administration and conclusion of contracts, the processing is necessary to conclude and perform a contract with you or the company that you represent.
Retention period: We process your personal data for as long as we have a business relationship with you or the company you represent, but no longer than two (2) years after the last time we were in contact in our business relationship.
We may however need to store your personal data for a longer time for other purposes, e.g. if we need to take measures in order to establish, exercise or defend legal claims. We may also need to store your personal data for a longer time in order to fulfil our legal obligations, e.g. relating to book keeping according to the Swedish Accounting Act.
Sharing of personal data: We will share your personal data with our suppliers, group companies and advisors.
Marketing measures, e.g. sending newsletters and other marketing messages
Purpose: To administer and send newsletters and marketing messages via email for the purposes of providing information about our business, services and current activities.
Categories of personal data:
First and last name
Contact details such as email address, telephone number and location
Professional title and information regarding the company that you represent
Legal basis: Legitimate interest, where our legitimate interest is to market ourselves and our services. We only send newsletters and marketing messages via email to you if the content is relevant in relation to you and the company you represent.
Retention period: We process your personal data to send newsletters and marketing messages via email to you as long as you have not opted out from receiving further messages. Such opt-out can be done at any time by using the link for opt-out provided in our messages.
Sharing of personal data: We will share your personal data with our suppliers of marketing services and group companies.
3. Sharing personal data
Your personal data may be shared with the following recipients:
Group companies: We will share your personal data with other companies within our group for administrative purposes. If we share your personal data with group companies, we will ensure that the personal data continues to be processed in line with this Privacy Policy.
Our suppliers: We use third party service providers to manage parts of our business operations. We will share personal data with such third parties in order for them to supply us with services, e.g. IT services or other administrative functions or provide services as subcontractors in connection with our own services. When we use such service providers, we enter into data processing agreements and take other suitable measures to ensure that your personal data is processed in line with this Privacy Policy.
Our partners: We will from time to time cooperate with external parties in order to improve our services and business such as marketing partners and advisors. Such parties either process your personal data as data controllers according to their own terms and policies for handling personal data, or as our data processors according to our instructions. In the latter case, we enter into data processing agreements and take other suitable measures to ensure that your personal data is processed in line with this Privacy Policy.
Sale or transfer: We will also disclose your personal data to a buyer/investor or potential buyer/investor in connection with a sale or other transfer of all or a part of our shares or assets, or our business. In the event of such a disclosure, we will take steps to ensure that the receiving party processes your data in a manner that complies with this Privacy Notice. The purpose of such processing is to allow a (potential) buyer/investor to carry out a due diligence of our business and, if applicable, to take measures and preparations for a possible purchase or investment. In that case, the transfer of personal data takes place with reference to the legitimate interest in such an opportunity for audit, measures, and preparations.
Authorities: We will share your personal data with public authorities such as the Swedish Police or the Swedish Tax Agency when we are required to do so by e.g. applicable law or other legal statutes or orders or decisions by courts or authorities in order to fulfil the legal obligation specified therein.
4. Where we process your personal dataWe aim to only process your personal data within the EU/EEA. However, as some of our suppliers are international, your personal data may be transferred to countries outside the EU/EEA in accordance with our agreements with suppliers. In such cases, we will ensure that the transfer takes place in accordance with applicable data protection legislation, e.g. by ensuring that the country to which the data is transferred meets the requirements for an adequate level of protection in accordance with the European Commission's decision, or by ensuring that the transfer is covered by appropriate protection measures in the form of e.g. standard contractual clauses decided by the European Commission.
5. Your rightsYou have rights in relation to us and our processing of your personal data. Information about your rights and how to exercise them is set out below. We ask you to note that your rights apply to the extent that follows applicable data protection legislation (unless exceptions apply).
Right to Access
You have the right to receive confirmation of whether we process personal data concerning you. If this is the case, you also have the right to access this personal data through a so-called register extract as well as additional information about the processing in question, such as for which purpose or purposes the processing takes place, the categories of personal data concerned and the recipients to whom the personal data have been disclosed.
Right to Rectification
You have the right to have incorrect information about you corrected without delay. You may also have the right to complete incomplete information.
Right to Erasure
You can request that we delete your personal data without delay if:
The personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
Our personal data processing takes place with the support of your consent, and you revoke your consent to the processing in question;
You object to processing that we carry out on the basis of legitimate interests and your objection outweighs our or someone else's legitimate interest in the processing;
Personal data has been processed illegally; or
Personal data must be deleted in order to fulfill a legal obligation.
Right to Restriction of Processing
You have the right to request that we restrict the processing of your personal data if:
You dispute the accuracy of the personal data, during the period which gives us the opportunity to check whether the data is correct or not;
The processing is illegal, and you object to us deleting your personal data and instead request that we restrict their use;
We no longer need to process the data for the purposes for which it was collected, at the same time as you need the data to be able to establish, assert, or defend legal claims; or
You have objected to the processing we carry out on the basis of a balance of interests and are awaiting control of whether your objection outweighs our or someone else's legitimate interest in continuing with the processing activity.
Right to Object
You have the right to object to such processing of your personal data that takes place based on our or someone else's legitimate interest. If this happens, in order to continue the processing, we must be able to show compelling justified reasons that outweigh your interests, rights, and freedoms.
Right to Data Portability
If we process your personal data with the support of an agreement with you (or on the basis of your consent), you have the right to obtain the personal data that you have provided to us and that concerns you in an electronic format. You have the right to have the data in question transferred from us directly to another personal data controller, where this is technically possible.
We ask you to note that this right to so-called data portability does not include such data that is processed manually by us.
Right to Revocation
If our processing of your personal data is based on your consent, you always have the right to revoke your consent at any time. A revocation of your consent does not affect the legality of the treatment that took place based on the consent before it was revoked.
Complaints to the Supervisory Authority
In Sweden, the Authority for Privacy Protection (Sw. Integritetsskyddsmyndigheten) is the authority responsible for monitoring the application of current data protection legislation. If you believe that we are processing your personal data incorrectly, we encourage you to contact us in the first instance so that we have the opportunity to review your views. However, you can always submit your complaint to the Authority for Privacy Protection (IMY).
6. Updates to this Privacy Policy
This policy will be updated from time to time. You can always find the latest version here, and we will inform you if important changes are being made to the Privacy Notice.