Privacy Policy

This Privacy Policy explains how Agerus (“we”, “us” or “our”) processes personal data relating to visitors to our website.

Personal data we process

We may process the following personal data relating to you as a visitor:

  • name
  • address
  • email address
  • telephone number
  • order information
  • IP address
  • other information that you provide through contact forms or comment fields.

If you are given the opportunity to try our digital platform, we may also process the following personal data:

  • organisation and organisational unit
  • image
  • description of purpose
  • development activities and key performance indicators
  • survey responses

Purposes of processing

We process your personal data to manage our customer relationships, deliver goods and market our goods and services. We retain your personal data for as long as necessary to fulfil the purposes of the processing. We process your data to perform a contract with you (Article 6(1)(b) GDPR, for example when delivering goods or services), to comply with legal obligations (Article 6(1)(c) GDPR, for example accounting requirements), for purposes relating to our legitimate interest in marketing our services to existing customers (Article 6(1)(f) GDPR), or on the basis of your consent where required, for example when sending newsletters to people who are not customers (Article 6(1)(a) GDPR).

If you subscribe to our newsletters, we retain your personal data so that we can provide you with relevant, high-quality content. To receive our newsletters, you must actively subscribe to our mailing lists. In certain cases where you have an existing customer relationship with us, we may carry out a legitimate interests assessment and invite you to subscribe to our newsletter. You can unsubscribe from the newsletter at any time. If you are given access to our digital platform, we may process additional personal data to provide an authentic customer experience and enable you to use the platform's functionality.

Transfers to third countries (where applicable)

Some of our service providers (for example Google and Facebook) are based outside the EU. If personal data is transferred to a country outside the EU/EEA, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses adopted by the European Commission. You may contact us for further information about these safeguards.

Recipients

We may disclose your personal data to our data processors, such as companies that provide invoice administration, IT services or cloud services. In such cases, we enter into data processing agreements to ensure that your personal data is processed only in accordance with this Privacy Policy. We do not sell, trade or otherwise transfer your personal information to external parties.

Cookies

This website uses cookies to tailor your user experience and improve the website. Cookies are small text files stored on visitors' devices that can be used to track what a visitor does on our website. There are two types of cookies: (i) persistent cookies, which remain on the visitor's device for a set period, and (ii) session cookies, which are stored only during a visit to the website. Session cookies disappear when you close your browser. We use cookies on the basis of your consent. If you do not accept the use of cookies, you can disable them in your browser's security settings. You can also configure your browser to ask for permission each time a website attempts to place a cookie on your device. Previously stored cookies can also be deleted through your browser. Please refer to your browser's help pages for more information. You may also manually delete cookies from your device at any time.

These cookies are used only with your consent. You can withdraw your consent at any time by changing the settings in the cookie banner or your browser. Please note that choosing not to accept cookies may limit the functionality of certain web pages.

We use the following cookies:

  • Google Analytics, Google Tag Manager, Albacross, Lead Forensics and cookies associated with Facebook and LinkedIn are used to measure visitor numbers and navigation, identify organisations' IP addresses and compile statistics about visitor behaviour.
  • Wordfence and Gstatic are used to increase security, prevent attempted intrusions on the website and stop bots from using contact forms.
  • WordPress is used to optimise the website and visitor experience, including the user's language selection and the loading of images and fonts to improve page-loading times.

Your rights

You have the right to obtain confirmation as to whether we process personal data relating to you and, if so, to access that personal data and information about how we process it. You have the right to have inaccurate personal data rectified without undue delay.

In certain circumstances, you have the right to have your personal data erased, for example if the data is no longer necessary for the purposes for which it was collected or if it has been processed unlawfully.

Under certain conditions, you have the right to receive and transfer the personal data that you have provided to us in a structured, commonly used and machine-readable format (the right to data portability under Article 20 GDPR).

In certain cases, you have the right to require us to restrict the processing of your personal data. For example, if you contest the accuracy of the data, you may require us to restrict its processing while we verify whether it is accurate.

You have the right to object to the processing of your personal data where the processing is based on our legitimate interests. If you object, we must demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms in order to continue processing your data.

You have the right to object to the processing of your personal data for direct marketing purposes. If you object, we will no longer process your personal data for that purpose.

To exercise your rights, or if you have any comments about how we process your personal data, please contact us or our Data Protection Officer (see below).

Information security

We take a range of security measures to protect your personal data. For example, we use encryption to protect sensitive data transmitted over the internet. Personal data is accessible only to employees who need it to perform their duties. The IT systems used to store personal data are protected by technical and organisational measures.

Data Protection Officer

Agerus's Data Protection Officer, registered with the Swedish Authority for Privacy Protection: Evelina Hjälm, IT-säkerhetsbolaget.
Email: evelina.hjalm@itsakerhetsbolaget.se

Right to lodge a complaint

You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), Sweden's supervisory authority for data protection.