Privacy Policy

 

ITAB Group (“ITAB” “we”, “our” and “us”) care about and value your privacy. In this privacy policy we therefore wish to provide you with information on how we process your personal data as well as what rights you have in relation to our processing of your personal data when you interact with us in different situations. Please be aware that a separate Privacy Policy applies to recruitment. The Privacy Policy applicable to recruitment is available on https://career.itab.com/data_privacy.   

This privacy policy applies to you who:

  • represent a company that is a customer or potential customer (prospect) to us;
  • represent a company that is a supplier or partner to us;
  • is a shareholder or represents a shareholder;
  • visits ITAB´s website; or
  • contacts us, communicates with us or subscribes to information from us.

In summary, we process your personal data in order to:

  • communicate with you;
  • administer, negotiate and execute agreements with the company you represent;
  • help you with customer service and support matters;
  • send newsletters, marketing and information to you;
  • arrange events;
  • handle any claims and fulfill legal obligations such as complying with the accounting act; and
  • comply with our legal obligations.

Below you can read more about how and why we process your personal data.

Who is responsible for the processing of your personal data?

ITAB Shop Concept AB (publ.) with company registration number 556292–1089 is responsible for the processing of your personal data as described in this privacy policy (controller). If you are in contact with any other company within the ITAB group of companies, the company that you are in contact with will be the controller of the processing of your personal data. For information about all companies within the ITAB group and their contact details, please visit https://itab.com/en/contact-us/.

If you have any questions regarding our processing of your personal data, or if you want to exercise any of your rights, please contact us at gdpr@itab.com. Our postal address is Instrumentvägen 2, 553 02 Jönköping, Sweden.

 

Who can gain access to your personal data and why?

Your personal data is primarily processed by us at ITAB and within the ITAB group. We will share your personal data with our IT-suppliers who will process the personal data on our behalf as processors.

We may transfer your personal data outside of EU/EEA to companies within the ITAB group and to our IT suppliers that are processing the personal data on behalf of us as processors. When we transfer your data outside of the EU/EEA, this will only be done if we have support for the transfer under applicable data protection legislation. This means that the transfer is based on either an adequacy decision by the Commission or standard contractual clauses.

If you have any questions about how we share your personal data, e.g. about what legal basis we have, which suppliers we share your personal data with or if you would like a copy of the appropriate safeguards we have taken, you are welcome to contact us at the contact details we have provided above.

 

Detailed information about how we process your personal data

We collect your personal data directly from you, for example when you contact us. We may also collect your personal data directly from the company you represent, if they state you as their representative. If you use our website, we will also use Google services to collect information on your browsing of our website to analyse your use of our website.

In the tables below you can read more about why we process your personal data, which categories of personal data we process and our legal basis for the processing. You can also read about how long we process your personal data for each purpose.

 

If you represent a prospect, customer or other partner

Purpose: To communicate with you as representative of a prospect, customer or other partner before, during and after an agreement is entered into with us

Processing performed

Personal data we process

Legal basis

·  Communicate with you

 

·  Name, organisational belonging and position in your organisation

·  Contact information such as email address and telephone number

·  Information you provide to us

Legitimate interest

The processing is justified by our legitimate interest in being able to communicate with the company that you represent

Retention time: We will store your personal data as long as we have a business relationship with your company. However, we will stop storing your personal data if we become aware that you no longer represent the company or if we conclude that we will not enter into an agreement with the company you represent.

 

Purpose: To administer and facilitate your company’s agreement with us

Processing performed

Personal data we process

Legal basis

·  Enter into, negotiate and administer agreements with the company you represent

 

·  Name, organisational belonging and position in your organisation

·  Contact information such as email address and telephone number

Legitimate interest

The processing is justified by our legitimate interest in being able to negotiate, enter into and fulfil agreements with the company you represent.

Retention time: We will store your personal data until the agreement with the company you represent has expired and the obligations under the agreement are otherwise fulfilled. However, we will stop storing your personal data if we become aware that you no longer represent the company, or if we conclude that we will not enter into an agreement with the company you represent. Some of your personal data will be stored for a longer period of time in order for us to comply with bookkeeping and accounting law. See retention times for that purpose below.

 

Purpose: Provide customer service and manage support matters

Processing performed

Personal data we process

Legal basis

·  Provide you with relevant information and communicate with you as a representative of your company

·  Answer and manage customer service matters, e.g. handle complaints

·  Name

·  Contact information such as email address and telephone number

·  Information you provide to us

Legitimate interest

The processing is justified by our legitimate interest in being able to maintain our customer service towards our customers.

Retention time: The data is stored for six months from the point that the matter concerning your company is finally handled. However, we will stop storing your personal data if we become aware that you no longer represent the company.

 

Purpose: To send newsletters, offers, invitations and other information about ITAB

Processing performed

Personal data we process

Legal basis

·  To send newsletters, offers and invitations to you who represent one of our customers or potential customers

·  Name

·  Email address

 

Legitimate interest

The processing is justified by our legitimate interest in being able to send relevant information to you as a representative of your company or if you have chosen to subscribe to information from us.

Retention time: We will store your personal data for one year. If you have subscribed to information from us, you will receive information, newsletters, offers and invitations from us as long as you represent your company or until you unsubscribe to our newsletters, offers and invitations.

 

Purpose: To arrange events

Processing performed

Personal data we process

Legal basis

·  Arrange events and meetings

·  Communicate with you as a representative of one of our customers or potential customers before and during the event

·  Name

·  Contact information such as email address and telephone number

·  Dietary preference

 

Legitimate interest

The processing is justified by our legitimate interest in being able to arrange events for you as a representative of a customer or potential customer

Consent

If we process special categories of data, we will obtain your explicit consent

·  Send requests to participate in evaluations after the event

·  Manage the answers you provide in the evaluation

·  Compile statistics of the results of our evaluations

·  Name

·  Email address

·  Information you provide in the evaluation

Legitimate interest

The processing is justified by our legitimate interest in being able to contact you for evaluation of the event

Retention time: We store your personal data until the event is completed. However, a participant list that you are a part of is saved for one year after the event in order for us to be able to follow up your participation in the event and invite you to similar events.

In cases where we have sent an evaluation to you after an event to which you responded, we will store the result of the evaluation for six months after you have answered the same. We stop sending evaluations if you object to getting them.

 

Purpose: To handle possible claims

Processing performed

Personal data we process

Legal basis

·  Handle possible complaints and claims

·  Name

·  Contact information such as email address and phone number

·  Information from our communication with you regarding your complaint or claim

 

Legitimate interest

The processing is justified by our legitimate interest in being able to communicate with your company and resolve an emergent situation as well as possible and, if necessary, to act in any dispute with the company you represent, including being able to defend us against any legal claim

Retention time: The personal data is processed from the time you submit your complaint or claim and is processed as long as the process of the complaint or claim is in progress. However, we will stop storing your personal data if we become aware that you no longer represent the company to which the claim relates.

 

Purpose: To comply with bookkeeping and accounting law

Processing performed

Personal data we process

Legal basis

·  Comply with bookkeeping and accounting law

 

·  Name

·  History regarding payments and other information that constitutes accounting records.

Legal obligation                          

The processing is necessary in order to comply with a legal obligation to which we are subject, i.e. the bookkeeping and accounting act

Retention time:  We will store your personal data until and including the seventh year after the end of the calendar year for the fiscal year to which the personal data relates or as long as relevant bookkeeping and accounting law requires.

 

If you represent a supplier or other partner

Purpose: To communicate with you as representative of a supplier or other partner before, during and after an agreement is entered into with us

Processing performed

Personal data we process

Legal basis

·  Communicate with you

 

·  Name, organisational belonging and position in your organisation

·  Contact information such as email address and telephone number

·  Information you provide to us

Legitimate interest

The processing is justified by our legitimate interest in being able to communicate with the company that you represent

Retention time: We will store your personal data as long as we have a business relationship with your company. However, we will stop storing your personal data if we become aware that you no longer represent the company.

 

Purpose: To administer and facilitate your company’s agreement with us

Processing performed

Personal data we process

Legal basis

·  Enter into, negotiate and administer agreements with the company you represent

·  Carry out payment

 

·  Name, organisational belonging and position in your organisation

·  Contact information such as email address and telephone number

Legitimate interest

The processing is justified by our legitimate interest in being able to negotiate, enter into and fulfil agreements with the company you represent.

Retention time: We will store your personal data until the agreement with the company you represent has expired and the obligations under the agreement are otherwise fulfilled. However, we will stop storing your personal data if we become aware that you no longer represent the company, or if we conclude that we will not enter into an agreement with you. Some of your personal data will be stored for a longer period of time in order for us to comply with bookkeeping and accounting law. See retention times for that purpose below.

 

Purpose: To handle possible claims

Processing performed

Personal data we process

Legal basis

·  Handle possible complaints and claims

·  Name

·  Contact information such as email address and phone number

·  Information from our communication with you regarding your complaint or claim

 

Legitimate interest

The processing is justified by our legitimate interest in being able to communicate with your company and resolve an emergent situation as well as possible and, if necessary, to act in any dispute with the company you represent, including being able to defend us against any legal claim

Retention time: The personal data is processed from the time you submit your complaint or claim and is processed as long as the process of the complaint or claim is in progress. However, we will stop storing your personal data if we become aware that you no longer represent the company to which the claim relates.

 

Purpose: To comply with bookkeeping and accounting law

Processing performed

Personal data we process

Legal basis

·  Comply with bookkeeping and accounting law

 

·  Name

·  History regarding payments and other information that constitutes accounting records.

 

Legal obligation                          

The processing is necessary in order to comply with a legal obligation to which we are subject, i.e. the bookkeeping and accounting act

Retention time:  We will store your personal data until and including the seventh year after the end of the calendar year for the fiscal year to which the personal data relates or as long as relevant bookkeeping and accounting law requires.

 

If you are a shareholder or shareholder representative

Purpose: To comply with our responsibilities towards you as a shareholder

Processing performed

Personal data we process

Legal basis

·  To follow and comply with the articles of association and the relevant company law

·  Share personal data with Euroclear Sweden AB

·  Name

·  Contact information such as email address and telephone number

·  Social security number

·  Information about your shareholding

Contractual
and legal obligation

The processing is necessary in order to comply with contractual and legal obligations to which we are subject, i.e. the relevant company law

·  Prepare and invite you to the shareholders meeting

·  Arrange and administer your participation in the shareholders meeting

·  Name

·  Contact information such as email address and telephone number

·  Social security number

·  Information about your shareholding

 

Contractual
and legal obligation

The processing is necessary in order to comply with contractual and legal obligations to which we are subject, i.e. the relevant company law and in being able to contact you to administer the shareholders meeting

Retention time: We store your personal data as long as you are a shareholder within the company or as long as it’s needed for fulfil the contractual and legal requirements.

 

If you visit our website

Purpose: To analyse and improve the use of our website

Processing performed

Personal data we process

Legal basis

·  Information which we collect through cookies, i.e IP-address, personal data related to your devise/browser and your activities on our website.

·  IP-address

Legitimate interest

The processing is justified by our legitimate interest in being able to provide and improve our website.

Retention time: We will store your personal data for a period of twelve months.

 

If you interact with us on our social media accounts 

Purpose: To communicate with you on our social media accounts (Instagram, LinkedIn, Twitter, Facebook and Pinterest), e.g. if you comment on a post and to keep records of such communication for reference.

Processing performed

Personal data we process

Legal basis

·  Communicate with you

·  Name

·  Social media username

·  Profile picture

Legitimate interest

The processing is justified by our legitimate interest in being able to communicate with you on our social media platforms.

Retention time: Your personal data will be removed if you ask us to remove it or if you delete the content yourself. 

 

Balancing of interests assessments when processing personal data based on the legal basis “legitimate interests”

As we have stated above, for some purposes we process your personal data relying on our legitimate interest as legal basis for the processing. When assessing the legal basis, we rely on a balance of interests test, through which we have determined that our legitimate interest for the processing outweighs your interest and your fundamental right not to have your personal data processed. We have stated what our legitimate interest are in the tables above.

You are welcome to contact us if you want to read more about how we have done this test. Our contact details are as stated in the beginning of this privacy policy.

 

What rights do you have in relation to our processing of your personal data?

According to the applicable data protection legislation, you are entitled to a variety of rights to affect our processing of your personal data.

If you would like to know more about your rights or if you wish to exercise any of your rights, please contact us at the contact details provided at the beginning of this privacy policy.

 

Right to object to processing

You have the right to object to our processing of your personal data. You have always right to object to marketing from us, such as newsletters.

The right to object is applicable when the processing is based on the legal basis “legitimate interest”. Read more about what this means in the tables above. In some cases, however, the right to object does not exist (e.g. when we must store your personal data). If we can show compelling legitimate reasons for the processing that outweigh your interests and fundamental rights or if it is for the purpose of determining, practicing or defending legal claims you do not have a right to object to the processing.

 

Right to access

You have the right to obtain confirmation as to whether or not we are processing personal data concerning you. If we process your personal data you have the right to obtain a copy of the personal data processed by us and information on how we process them.

 

Right to rectification

You have a right to obtain rectification of any inaccurate personal data concerning you and to ask us to have incomplete personal data completed.

 

Right to erasure (“right to be forgotten”) and restriction of processing

You have the right to have your personal data erased in certain instances. This is the case e.g. when the personal data is no longer necessary for the purposes for which it was collected or otherwise processed and where we process your personal data on the basis of our legitimate interest and we find that we do not have an overriding interest in continuing to process it.

You also have a right to request that we restrict our processing of your personal data. For example, when you question the accuracy of the personal data, when you have objected to our processing of your personal data based upon our legitimate interest, or where the processing is unlawful, and you oppose to the erasure of your personal data and instead want us to restrict our processing.

 

Right to lodge a complaint to a supervisory authority

You always have the right to lodge a complaint with a supervisory authority.

You may do this in the EU/EEA member state where you live, work or of where an alleged infringement of the applicable data protection laws has occurred. The supervisory authority in Sweden is The Swedish Data Protection Authority. This right is without prejudice to any other administrative or judicial remedy.

 

This privacy policy was updated by ITAB in February 2020.