Privacy Policy
INFORMATION ON HOW WE PROCESS YOUR PERSONAL DATA
INTRODUCTION
This Privacy Policy (the “Policy”) describes how Lernberger Stafsing AB, reg. no. 556816-2704 (“Lernberger Stafsing”, “we”, “us” or “our”), at the address Karl Gustavsgatan 1A, 411 25 Gothenburg, processes your personal data when you visit and use our website or come into contact with us because of our business and services – usually because you represent a supplier or a partner of ours.
We are responsible for the processing of your personal data as described in the Policy in the capacity of data controller. If you would like to know more about our processing of your personal data, you are welcome to contact us, e.g. via the address above or via our email address: contact@lernbergerstafsing.com.
It is important to us that you feel comfortable with how we process your personal data, and we therefore ask you to read through this Policy, which we may update from time to time. If we make changes to the Policy, the new version will apply from the time it is published on our website. At the top of the page, you can see when the Policy was last changed.
HOW WE COLLECT YOUR PERSONAL DATA
The personal data we process relating to you is mainly collected from you when you visit and use our website or when we come into contact with you – e.g. via email, telephone or personal meetings, conventions or similar occasions. We may also collect your personal data from a third party, usually from the company or organization you represent.
HOW WE PROCESS YOUR PERSONAL DATA
INTRODUCTION
We only process your personal data to the extent permitted in accordance with applicable data protection legislation. This means inter alia that we need to have a legal basis for the purposes for our processing of your personal data, which in our context generally means one of the following legal bases.
Performance of a contract – the processing is necessary in order for us to provide you with our services or otherwise perform a contract between us (this applies if you conduct your business in a sole proprietorship), or to take steps at your request prior to entering into a contract.
If you are acting on behalf of someone else, e.g. in the capacity of representative of a company (which usually is the case), our processing is carried out with reference to our legitimate interest balanced against your interests or fundamental rights or freedoms, where our legitimate interest is to conclude and perform the contract with the company you represent.
Performance of legal obligations – the processing is necessary in order to fulfill our legal obligations according to law or other statutes that we are subject to, or if we are subject to orders or decisions by courts or authorities, which require us to process your personal data.
Legitimate interests – the processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, provided that they are not overridden by your interests or fundamental rights or freedoms (in which case the processing would not be allowed).
Consent – the processing is carried out with your prior consent, where we inter alia are responsible for clearly informing you of what processing you consent to and your right to withdraw your consent in relation to our continued processing.
Below, we explain more about the categories of personal data we process, for what purposes we process them and what legal bases we rely on when processing your personal data, including for how long we store your personal data and who we share your personal data with.
TO MAINTAIN AND IMPROVE OUR WEBSITE
PURPOSES OF THE PROCESSING
Collect statistical data and analyse the web traffic on our website as well as other technical information generated when visiting our website, in order to maintain and improve its functionality, the user experience, and in order to discover and handle errors, breaches and incidents.
To do this we use third party analytics services. The statistics we produce and the analysis we carry out by using these services are based on aggregated data and other de-identified or anonymized data.
CATEGORIES OF PERSONAL DATA
THE PERSONAL DATA WE PROCESS CONSIST OF:
·IP-address
·Other technical information generated through visits on our website, such as the type of technical device that you have used, web browser, visited pages as well as the time of the visits (browser information, time zone at the place from which you visited our website, other web traffic information).
Legal basis: Legitimate interest, where our legitimate interest is to collect information to maintain and improve the functionality, content, and security of our website. Collection of information by use of cookies and similar technologies is carried out based on your consent, unless they are strictly necessary in order for you to be able to use our website in an appropriate manner. For more information on how we use cookies and similar technologies, please see our cookie policy.
Storage period: We collect and store information on how visitors interact with our website for no longer than six (6) months. In most cases, the collected personal data is converted to aggregated data (anonymized data) before the expiration of that time period, in connection with us producing statistical data.
Sharing of personal data: We will share your personal data with our suppliers of IT services.
TO HANDLE PURCHASES
PURPOSES OF THE PROCESSING
To be able to handle your purchases (including sending order confirmations, notifying deliveries, delivering your purchased goods and handling contacts in connection with delayed deliveries).
To be able to handle your complaints, complaints and warranty matters regarding purchased goods.
To be able to carry out invoicing.
CATEGORIES OF PERSONAL DATA
THE PERSONAL DATA WE PROCESS CONSIST OF:
·Name
·Personal identification number
·Contact details (such as address, delivery address, e-mail address, telephone number and other information needed to deliver the order)
·Order number
·Order information, e.g. information about ordered goods
·Type of customer (individual/company).
·Pay, purchase and order history
Legal basis: The processing is necessary for the fulfillment of agreements on the purchase of goods from us.
Storage period: We store your personal data for as long as it is needed for us to fulfill our agreement with you, but no longer than three (3) years from your last purchase.
Sharing of personal data: We will share your personal data with our suppliers.
TO HANDLE CUSTOMER SERVICE ISSUES
PURPOSES OF THE PROCESSING
To be able to communicate with you and answer the questions you ask us via email.
To be able to handle your complaints and warranty matters regarding purchased goods.
CATEGORIES OF PERSONAL DATA
THE PERSONAL DATA WE PROCESS CONSIST OF:
·Name
·Personal identification number
·Contact details (such as address, e-mail address and telephone number)
·Order number
·Payment and delivery information
·Order history, e.g. information about ordered goods
·Photographs that you sent to customer service
·Your correspondence with us.
Legal basis: The processing is based on our legitimate interest in helping you if you have questions or complaints about purchased goods or problems with the use of our services.
Storage period: We store your personal data only as long as they are needed to handle your customer service case, but no longer than one (1) year from the end of your case.
Sharing of personal data: We will share your personal data with our suppliers and third party marketing platform.
TO CREATE POTENTIAL BUSINESS RELATIONSHIPS
PURPOSES OF THE PROCESSING
Contact and communication with you for the purposes of creating a business relationship with you or the company or organization you represent.
This includes, among other things, communication via email regarding our business, services and current activities (see also Section 3.6 below).
CATEGORIES OF PERSONAL DATA
THE PERSONAL DATA WE PROCESS CONSIST OF:
·First and last name
·Contact details such as email address, telephone number, location and business address
·Professional title and information regarding the company or organization you represent
·Information that you otherwise provide us in our communications with you.
Legal basis: Legitimate interests, where our legitimate interest is to create a business relationship with you or the company or organization you represent.
Storage period: We store your personal data for a period of six (6) months after the data was collected. If a business relationship is established between us and you or the company or organization you represent during this time, we will however continue to process your personal data in accordance with Section 3.6-3.8 below.
Sharing of personal data: We will share your personal data with our suppliers, including our PR agency.
TO MAINTAIN AND DEVELOP EXISITING BUSINESS RELATIONSHIPS
PURPOSES OF THE PROCESSING
Contact and communication with you in your capacity as, or representative for, one of our existing customers, partners, suppliers or other business contacts, in order to maintain and develop our business relationship with you or the company or organization you represent.
This includes, among other things, regular administration and communication regarding our customer, partner and supplier agreements and communication via email about our business, services and our current activities (see also Sections 3.7 and 3.8 below).
CATEGORIES OF PERSONAL DATA
THE PERSONAL DATA WE PROCESS CONSIST OF:
·First and last name
·Contact details such as email address, telephone number, location and business address
·Professional title and information regarding the company or organization you represent
·Information that you otherwise provide to us in our communication with you.
Legal basis: Legitimate interest, where our legitimate interest is to maintain and develop our business relationship with you or the company or organization you represent.
Storage period: We process and store your personal data for as long as we have a business relationship with you or the company or organization you represent, but no longer than two (2) years after the last time we were in contact in our business relationship.
We may however need to store your personal data for a longer time for other purposes, e.g. if we need to take measures in order to establish, exercise or defend legal claims. We may also need to store your personal data for a longer time in order to fulfil our legal obligations, e.g. relating to book keeping according to the Swedish Accounting Act (see further Section 3.9 below).
Sharing of personal data: We will share your personal data with our suppliers.
TO ADMINISTER THE CONCLUSION AND PERFORMANCE OF CONTRACTS
PURPOSES OF THE PROCESSING
Administration and communication in order to conclude or perform a contract between us and you or the company or organization you represent.
This includes, among other things, invoicing and customary contract management, as well as following up and documentation of contract related matters.
CATEGORIES OF PERSONAL DATA
THE PERSONAL DATA WE PROCESS CONSIST OF:
·First and last name
·Contact details such as email address, telephone number, location and business address
·Professional title and information regarding the company or organization you represent
·Information that you provide to us in contract related matters with you or the company you represent, e.g. questions and feedback on contracted services.
Legal basis: The processing is necessary to conclude and perform a contract with you or the company or organization that you represent. If you are acting on behalf of someone else, e.g. in the capacity of representative of a customer, partner or supplier to us, our processing is carried out based on our legitimate interests, where our legitimate interest is to conclude as well as perform the agreement with the company or organization you represent.
Storage period: We process and store your personal data for as long as we have a business relationship with you or the company or organization you represent, but no longer than two (2) years after the last time we were in contact in our business relationship.
We may however need to store your personal data for a longer time for other purposes, e.g. if we need to take measures in order to establish, exercise or defend legal claims. We may also need to store your personal data for a longer time in order to fulfil our legal obligations, e.g. relating to book keeping according to the Swedish Accounting Act (see further Section 3.9 below).
Sharing of personal data: We will share your personal data with our suppliers and advisors.
NEWSLETTER AND OTHER MARKETING MESSAGES
PURPOSES OF THE PROCESSING
To administer and send marketing messages via email for the purposes of providing information about our business, services and current activities.
CATEGORIES OF PERSONAL DATA
THE PERSONAL DATA WE PROCESS CONSIST OF:
·Email address
·First and last name
·Purchase history
Legal basis: We only send marketing messages via email to you if you have registered for them and thereby consented to receiving them.
Storage period: We process and store your personal data to send marketing messages via email to you as long as you have not opted out from receiving further messages. Such opt-out can be done at any time by using the link for opt-out provided in our messages.
Sharing of personal data: We will share your personal data with our suppliers of marketing services.
OUR USAGE OF SOCIAL MEDIA PLATFORMS; META (FACEBOOK, INSTAGRAM), PINTEREST, TIKTOK AND YOUTUBE
PURPOSES OF THE PROCESSING
To provide information about our products and services, create engagement around the Lernberger Stafsing brand, offer you a medium for communication, and respond to your questions or comments
CATEGORIES OF PERSONAL DATA
THE PERSONAL DATA WE PROCESS CONSIST OF:
·User name
·Name
·Your correspondence with us
Legal basis: The legal basis for the processing is our legitimate interest, which consists of promoting our products and services, creating engagement around our brand, and assisting you with service.
Storage period: If you have commented on our posts on a social media platform, such comments will be stored for as long as the post is up on our page. However, we may choose to remove, for example, offensive or offensive comments as well as comments that contain information about another individual in accordance with our legal obligations. We may also delete comments in languages other than Swedish and English. A user always has the right to delete their comments on our page. Direct messages will be stored as long as there is an ongoing correspondence between us.
Sharing of personal data: The social media platforms will have access to your data. If you want to read more about how the social media platform processes your personal data, please consult their respective privacy policy.
TO FULFILL LEGAL OBLIGATIONS OR TO ESTABLISH, EXCERCISE OR DEFEND LEGAL CLAIMS
We may process your personal data in order to fulfill our legal obligations according to law or other statutes that we are subject to, or if we are subject to orders or decisions by courts or authorities, which require us to process your personal data.
We may also process your personal data so that you, or the company or organization you represent, we or any relevant third party can establish, exercise or defend its legal claims, e.g. in connection with an ongoing dispute.
SECURITY MEASURES
We have taken measures to ensure that your personal data is handled in a safe way. For example, access to systems where personal data is stored is limited to our employees and service providers who require it in the course of their duties. Such parties are informed of the importance of maintaining security and confidentiality in relation to the personal data we process. We maintain appropriate safeguards and security standards to protect your personal data against unauthorized access, disclosure or misuse. We also monitor our systems to discover vulnerabilities. In addition, data processing agreements have been entered into with our suppliers of systems and services (see further Sections 5 and 6 below).
HOW WE SHARE YOUR PERSONAL DATA
Access to your personal data is limited to recipients who require such access for the purposes described in Section 3 above or as otherwise stated below. Your personal data will therefore be shared with the following categories of third party recipients:
a) Service providers: We use third party service providers to manage parts of our business operations. We will share personal data with such third parties in order for them to supply us with services, e.g. IT services or other administrative functions or provide services as sub-contractors in connection with our own services. When we use such service providers, we enter into data processing agreements and take other suitable measures to ensure that your personal data is processed in line with this Policy.
b) Our partners: We will from time to time cooperate with external parties in order to improve our services and business. Such parties either process your personal data as data controllers according to their own terms and policies for handling personal data, or as our data processors according to our instructions. In the latter case, we enter into data processing agreements and take other suitable measures to ensure that your personal data is processed in line with this Policy.
c) Sale or transfer of business or assets: We will share your personal data with a buyer/investor or prospective buyer/investor in the event of a sale, assignment or other transfer of all or parts of our shares, assets or operations. When such transfer occurs, we will take actions in order to ensure that the receiving party processes your personal data in accordance with this Policy. The purpose of such sharing or processing of your personal data is to allow a (potential) buyer/investor to carry out an assessment of us as a company and, where necessary, take actions and make preparations in the event a sale, assignment or other transfer should occur, where such sharing or processing of your personal data is carried out with reference to the legitimate interests of allowing such assessment, actions and preparations by the (potential) buyer/investor.
d) Public authorities: We will share your personal data with public authorities such as the Swedish Police or the Swedish Tax Agencywhen we are required to do so by e.g. applicable law or other legal statutes or orders or decisions by courts or authorities in order to fulfil the legal obligation specified therein.
WHERE WE PROCESS YOUR PERSONAL DATA
We strive to always process your personal data within the EU or EEA. However, we will transfer your personal data to service providers who, either themselves or by their sub-contractors, are located or have business activities in a country outside the EU or EEA. In such cases, we are responsible for ensuring that the transfer is made in accordance with applicable data protection legislation before it occurs, e.g. by ensuring that the country in which the recipient is located ensures an adequate level of data protection according to the European Commission, or by ensuring appropriate safeguards based on the use of standard contractual clauses that the European Commission has adopted and other appropriate measures to safeguard your rights and freedoms.
You may access a list of the countries that the European Commission has decided provide an adequate level of data protection at http://ec.europa.eu/justice/data-protection/international-transfers/adequacy/index_en.htm.
You may access the European Commission’s standard contractual clauses at http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32010D0087.
[The countries outside the EU/EEA to which our suppliers currently transfer personal data are: Canada, USA.
YOUR RIGHTS
You have rights in relation to us and our processing of your personal data. Below, you will find information about your rights and how you can exercise them.
Please note that your rights apply to the extent that follows from applicable data protection legislation and that there may be exceptions to the rights where applicable. We also ask you to note that we may need more information from you in order to e.g. confirm your identity before proceeding with your request to exercise your rights.
To exercise your rights or request information about them we ask that you contact us, which is most easily done via email: contact@lernbergerstafsing.com.
RIGHT OF ACESS
You have the right to obtain a confirmation as to whether or not we process your personal data. If that is the case, you also have the right to receive copies of the personal data concerning you that we process as well as additional information about the processing, such as for what purposes the processing occurs, relevant categories of personal data and the recipients of such personal data.
RIGHT TO RECTIFICATION
You have the right to, without undue delay, have incorrect personal data about you rectified. You may also have the right to have incomplete personal data completed.
RIGHT TO ERASURE
You have the right to obtain that we erase your personal data without undue delay in the following circumstances:
The personal data is no longer necessary in relation to the purposes for which they were collected or otherwise processed;
Our processing is based on your consent and you withdraw your consent to the relevant processing;
You object to processing that we carry out based on a legitimate interest, and your objection overrides our or another party’s legitimate interest of the processing;
The processed personal data is unlawfully processed;
The processed personal data has to be erased for our compliance with one or more legal obligations.
RIGHT TO RESTRICTION
You have the right to request that we restrict the processing of your personal data in the following circumstances:
You contest the accuracy of the personal data during a period enabling us to verify the accuracy of such data;
The processing is unlawful and you oppose erasure of the personal data and request restriction instead;
The personal data is no longer needed for the purposes of the processing, but is necessary for you for the establishment, exercise or defense of legal claims;
You have objected to the processing of the personal data which we carry out based on a legitimate interest, pending the verification whether your objection overrides our or another party’s legitimate interest to continue with the processing.
RIGHT TO OBJECT
You have a right to object to our processing of your personal data when it is based on our or another party’s legitimate interest. If you object, we must demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms in order to be allowed to continue with our processing.
RIGHT TO DATA PORTABILITY
If our processing of your personal data is based on the performance of a contract with you or your consent, you have the right to receive the personal data you have provided us relating to you in an electronic format. You also have the right to have the personal data transferred from us directly to another data controller, where technically feasible.
We ask you to observe that this right to so called data portability does not cover personal data which we process manually.
RIGHT TO WITHDRAW CONSENT
If our processing of your personal data is based on your consent, you always have the right to withdraw your consent at any time. A withdrawal of your consent does not affect the lawfulness of the processing that took place based on theconsent before your withdrawal.
COMPLAINTS WITH THE SUPERVISORY AUTHORITY
In Sweden, the Swedish Authority for Privacy Protection (Sw. Integritetsskyddsmyndigheten) is the authority responsible for supervising the application of current data protection legislation. If you believe that we process your personal data in a wrongful manner, we encourage you to contact us so that we can review your concerns. However, you may file a complaint with the Swedish Authority for Privacy Protection at any time.