Privacy policy.

ABOUT THIS POLICY

This privacy policy describes how tion digital AB collects and uses personal data, why we do so and what rights you have. The policy applies when you visit our website www.tiondigital.se, contact us, subscribe to our newsletter, register for our webinars or events, or are a contact person at a client, prospective client, supplier or partner. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and supplementary Swedish legislation.

In some assignments we process personal data on behalf of a client, for example in campaigns, analyses or systems that we manage for the client. In those cases, the client is the controller and we are the processor. We then process the data in accordance with the client's instructions and our data processing agreement with the client, and the client's privacy policy applies. Please direct any questions about such processing to the client in the first instance.

CONTROLLER AND CONTACT DETAILS

The controller for the processing described in this policy is tion digital AB, reg. no. 559385-4853, Masthamnsgatan 5, 413 27 Göteborg. You can reach us by email at hello@tiondigital.se. Please contact us if you have questions about this policy or wish to exercise your rights.

WHAT PERSONAL DATA WE PROCESS

The personal data we process depends on how you interact with us. It may include contact details such as name, email address and phone number, and professional details such as employer and job title[ and LinkedIn profile]. We also process the content of messages, enquiries and support cases, including case numbers, as well as information about agreements, orders, invoices and payments.

If you subscribe to our newsletter, we process your subscription status, the consents you have given and any unsubscribes, and whether you open our emails or click on links in them. If you register for a webinar or event, we process information about your registration and attendance.

When you visit our website, technical and usage data such as IP address, device and browser information and information about how you use the website is collected through cookies and similar technologies. We only collect data that is not necessary for the website to function if you have consented to it.

WHERE THE DATA COMES FROM

In most cases we receive the data directly from you, for example when you fill in a form, email us or enter into an agreement with us. We may also receive data from your employer when it designates you as a contact person, from public sources such as your company's website and LinkedIn, from advertising platforms when you submit a lead form via, for example, LinkedIn or Meta and through cookies and similar technologies on our website.

PURPOSES, LEGAL BASES AND RETENTION PERIODS

Below we describe why we process personal data, what data is involved, which legal basis we rely on and how long we keep the data.

Where we rely on legitimate interests, we have carried out a balancing test and concluded that our interest outweighs your interest in the data not being processed. Please contact us if you would like more information about this assessment. Where processing is based on a contract, we need the data to enter into or perform the agreement, and if you do not provide it we cannot deliver the service. In all other cases, providing personal data to us is voluntary.

ENQUIRIES AND COMMUNICATION

When you contact us, we process your contact details, professional details and the content of your message in order to respond to and follow up on your enquiry. The legal basis is our legitimate interest in being able to respond to and follow up on enquiries about our services. We keep the data for 24 months after the most recent contact.

CLIENTS AND SUPPLIERS

We process contact details, professional details, communications and contract details in order to enter into and perform agreements, for example to deliver our services and manage the client relationship, and in order to handle support cases and complaints. If you are a party to the agreement yourself, the legal basis is performance of a contract. If you are a contact person at a client or supplier, the legal basis is our legitimate interest in being able to perform the agreement with your employer and to handle and document cases. We keep data about the relationship for the term of the agreement and [24 months] thereafter, and data about support cases for 12 months after the case is closed.

INVOICING AND ACCOUNTING

We process contact details and contract and billing details in order to issue invoices and keep accounts. The legal basis is our legal obligation under the Swedish Bookkeeping Act (bokföringslagen). Accounting records are kept until the end of the seventh year after the end of the calendar year in which the financial year ended.

NEWSLETTERS AND EMAIL MARKETING

We process contact details, professional details and newsletter and email data in order to send newsletters and other marketing by email. The legal basis is your consent. For existing clients and contact persons at companies, the legal basis is our legitimate interest in marketing our services to people who have a business relationship with us or work within our target audience. We process the data until you unsubscribe, withdraw your consent or object. After that, we keep your email address on a suppression list so that you do not receive further emails.

WEBINARS AND EVENTS

We process contact details, professional details and information about your registration and attendance in order to run and follow up on webinars and events. The legal basis is our legitimate interest in being able to run and follow up on the event. If we send you marketing after the event, the section on newsletters and email marketing applies. We keep the data for 12 months after the event.

CLIENT SURVEYS AND SERVICE DEVELOPMENT

We process contact details and survey responses in order to conduct client surveys and improve our services. The legal basis is our legitimate interest in improving our services. We keep the data for 12 months, after which the responses are anonymised.

WEBSITE ANALYTICS AND ADVERTISING

If you consent via the cookie settings, we process technical and usage data in order to analyse how the website is used and to show targeted advertising and retargeting on LinkedIn, Google and Meta. If we upload contact lists to these platforms, we also use email addresses in hashed form. The legal basis is your consent. The data is kept as set out in our cookie policy, or until you withdraw your consent.

LEGAL CLAIMS AND LEGAL OBLIGATIONS

Where necessary, we process the data relevant to a claim in order to establish, exercise or defend legal claims. The legal basis is our legitimate interest in being able to protect our rights, and we keep the data for as long as the claim can be pursued, but no longer than until it becomes time-barred. We also process personal data where necessary to comply with other legal obligations, such as decisions by public authorities. The legal basis is then legal obligation, and we keep the data for as long as the obligation requires.

PROFILING AND AUTOMATED DECISION-MAKING

If you have consented to marketing cookies, we and the advertising platforms may use information about your visit to show you advertising that is relevant to you. This may involve profiling. We may also assess which contacts are most interested in our services based on how they interact with our emails and our website.

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.

WHO WE SHARE PERSONAL DATA WITH

We never sell your personal data. We only share it in the cases described below.

We use suppliers that process personal data on our behalf as processors. These include providers of web hosting, CRM systems, email and newsletter tools, office software and cloud storage, web analytics, and accounting systems and services. These suppliers may only process the data in accordance with our instructions and under data processing agreements with us.

If you consent to marketing cookies, information about your visit is transferred to LinkedIn, Google and Meta. We and the relevant platform may then be joint controllers for the collection and transmission of that data. Each platform is independently responsible for its own further processing, which is described in the platform's privacy policy. 

We disclose personal data to public authorities when required to do so by law or by a decision of an authority. We may also share data with advisers such as auditors and lawyers where necessary to meet our obligations or handle legal claims. These recipients are independent controllers.

TRANSFERS OUTSIDE THE EU/EEA

We aim to process personal data within the EU/EEA. However, some of our suppliers and advertising platforms, such as Google, Meta, LinkedIn and Microsoft, may process data in countries outside the EU/EEA, including the United States.

Where this happens, we ensure that the transfer is lawful under the GDPR. Either the recipient country or the recipient is covered by an adequacy decision from the European Commission, which for the United States applies to recipients certified under the EU–US Data Privacy Framework, or we have entered into the European Commission's standard contractual clauses with the recipient, supplemented by additional safeguards where necessary. Please contact us if you would like to know which safeguard applies to a particular transfer or would like a copy of it.

HOW LONG WE KEEP PERSONAL DATA

We do not keep personal data for longer than necessary for the purposes for which it is processed. The retention period for each purpose is described under Purposes, legal bases and retention periods. When the data is no longer needed, we delete or anonymise it. If we are required to keep data for longer because of legal requirements or to handle a legal claim, we restrict the processing to that purpose.

YOUR RIGHTS

You have the right to know whether we process personal data about you. If we do, you have the right to receive a copy of the data and information about, among other things, the purposes, the categories of data concerned, the recipients, how long the data is kept, where it comes from and what rights you have.

RIGHT TO RECTIFICATION

You have the right to have inaccurate data about you corrected and incomplete data completed.

RIGHT TO ERASURE

You have the right to have your data erased, for example if it is no longer needed for the purpose for which it was collected, if you withdraw consent on which the processing is based, or if you object to the processing and there are no overriding grounds to continue. However, we may keep data that we are required to keep by law, such as under the Swedish Bookkeeping Act, or that is needed to establish, exercise or defend legal claims.

RIGHT TO RESTRICTION OF PROCESSING

You have the right to ask us to restrict the processing of your data, for example while we verify whether the data is accurate, or while we assess whether our grounds outweigh yours after you have objected to the processing. While processing is restricted, we may in principle only store the data.

RIGHT TO OBJECT

You have the right to object at any time, on grounds relating to your particular situation, to processing based on legitimate interests. We may then only continue if we can demonstrate compelling legitimate grounds that override your interests, or if the processing is necessary to handle legal claims. You always have the right to object to processing for direct marketing, and we will then stop that processing. You can unsubscribe from our emails at any time via the link in each email.

RIGHT TO WITHDRAW CONSENT

Where processing is based on your consent, you can withdraw it at any time, as easily as you gave it. You can do so, for example, via the cookie settings on the website or the unsubscribe link in our emails. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

RIGHT TO DATA PORTABILITY

Where processing is based on consent or a contract and is carried out by automated means, you have the right to receive the data you have provided to us in a structured, commonly used and machine-readable format. You also have the right to have the data transferred directly to another controller where technically feasible.

RIGHT TO LODGE A COMPLAINT

If you are unhappy with how we process your personal data, we would appreciate it if you contact us first so that we can try to resolve the matter. You always have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), www.imy.se, or with the supervisory authority in the EU or EEA country where you live or work.

HOW TO EXERCISE YOUR RIGHTS

Contact us by email or post using the details under Controller and contact details. You do not need to use any particular form. If we have reasonable doubts about your identity, we may ask you to confirm it before we disclose or change any data.

Exercising your rights is free of charge. We respond without undue delay and within one month at the latest. If your request is complex or we have received a large number of requests, we may extend this period by a further two months. If so, we will inform you within one month of receiving your request. If a request is manifestly unfounded or excessive, for example because it is repetitive, we may charge a reasonable fee or refuse the request, and we will explain our reasons if we do so.

If we rectify or erase data, or restrict its processing, we will inform the recipients to whom the data has been disclosed, unless this proves impossible or would involve disproportionate effort. On request, we will tell you who those recipients are.

COOKIES

We use cookies and similar technologies on the website. We only use cookies that are not necessary for the website to function, such as analytics and marketing cookies, if you have consented to them. You can change or withdraw your consent at any time via cookie settings. More information is available in our cookie policy.

SPECIAL CATEGORIES OF PERSONAL DATA

We do not intentionally collect special categories of personal data. These are data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data used to identify a person, and data concerning health, sex life or sexual orientation. Please do not include such data in forms or messages you send to us.

SECURITY

We take appropriate technical and organisational security measures to protect personal data against loss, destruction, alteration and unauthorised access. These include [access controls, two-factor authentication, encryption and agreements with our suppliers]. Only employees who need the data for their work have access to it.

CHANGES TO THIS POLICY

We may update this policy, for example when we change how we process personal data or when legislation changes. The date of the most recent update is shown at the top of the policy. In the event of material changes, we will provide notice on the website and, if we have an ongoing relationship with you, by email. If we wish to process your data for a new purpose that requires consent, we will ask for your consent before the processing begins.

Kontakt

hello@tiondigital.se
+46 708 53 62 21

Adress

Masthamnsgatan 5
413 27 Göteborg
Sverige

Följ oss

Tion_logo_symbol_white
Untitled design (6)

Tion digital, MASTHAMNSGATAN 5, Våning 5,413 29 Göteborg,Sverige

Back to top Arrow
View