General
Who is responsible for your personal data
Aunetic Holding AB, registration number 559360-5560, Tegnérgatan 35, 111 61 Stockholm, Sweden (“Aunetic”, “we”, “our”, “us”) is the controller for the processing of personal data described in this policy.
Aunetic Holding AB is the parent company of the Aunetic group. The processing described here is carried out for the group as a whole, and the following companies may be involved in it when we deliver our services and run our business:
• Aunetic International AB, Sweden
• Aunetic Sweden AB, Sweden
• Qnister AB, Sweden
• Aunetic Germany GmbH, Germany
• Aunetic Switzerland AG, Switzerland
Whichever company you have been in contact with, you can exercise your rights towards Aunetic Holding AB using the contact details below, and we will handle your request for the group.
How to contact us
If you have questions about this policy, want more information, or want to exercise any of your rights, please contact our Data Protection Officer at privacy@aunetic.com . You can also find our contact details on the contact page of our website.
If you want to complain
If you are not satisfied with how we process your personal data, or with the answer we have given you, you have the right to lodge a complaint with a data protection supervisory authority.
Because Aunetic Holding AB is established in Sweden, our lead supervisory authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY). You can always also complain to the authority in the EU or EEA country where you live, where you work, or where you believe the problem occurred.
Integritetsskyddsmyndigheten, Box 8114, 104 20 Stockholm, Sweden. Telephone +46 8 657 61 00, e-mail imy@imy.se , www.imy.se/en.
If you are in Germany, the authority for Aunetic Germany GmbH is Bayerisches Landesamt für Datenschutzaufsicht, Promenade 27, 91522 Ansbach, Germany, www.lda.bayern.de .
If you are in Switzerland, you can contact the Federal Data Protection and Information Commissioner, Feldeggweg 1, CH-3003 Bern, Switzerland. Telephone +41 58 462 43 95, e-mail info@edoeb.admin.ch , www.edoeb.admin.ch/en.
How we process personal data
Purposes and legal bases
Appendix 1 sets out, for each processing activity, what we do, which personal data we process, on what legal basis, which legitimate interest we pursue where that is the basis, who receives the data and how long we keep it.
In short, we process personal data when you contact us through the website or by e-mail, when you subscribe to our newsletter, when you attend our events, when you use one of our digital services, when you apply for a job with us, when you are our contact at a customer, partner or supplier, and when we approach you as a potential customer.
Our website and cookies
Our website uses cookies. Which cookies we use, what they do and how you can control them is described in our Cookie policy, which you find on the website.
Newsletter and marketing
Our newsletter contains news and marketing about Aunetic. You only receive it if you have signed up for it yourself. Signing up is separate from everything else: registering as a user of one of our digital services, contacting us, or attending an event does not sign you up for the newsletter, and you do not have to accept it in order to use anything else we offer.
You can unsubscribe at any time, either through the link in every newsletter or by writing to privacy@aunetic.com . Withdrawing your consent does not affect the lawfulness of the mailings we sent before you withdrew it.
Advertising and profiling
If you consent to marketing cookies on our website, information about your visit may be used to show you advertising for Aunetic when you are on LinkedIn or other social media and advertising platforms, and to avoid showing you the same advertisement repeatedly. This involves building a limited profile based on your behaviour on our website.
This only happens if you have given your consent, and you can withdraw it at any time through the cookie settings on our website. The advertising platforms we use process the data for their own purposes as well, which means they act as independent or joint controllers alongside us. Their own privacy policies apply to that processing.
We do not make decisions about you that are based solely on automated processing and that produce legal effects or similarly significant effects for you.
Who receives your personal data
We share personal data with others only where it is necessary. The categories of recipients are:
• Other companies in the Aunetic group, listed in section 1.1.
• Providers of hosting, infrastructure and IT operations for our website and our digital services with your consent.
• Providers of newsletter delivery, marketing automation and CRM with your consent.
• Advertising and social media platforms, where you have consented to marketing cookies.
• Providers of support and ticketing, recruitment tools, and accounting and ERP systems with your consent.
• Professional advisers, and public authorities where we are legally required to disclose data.
Appendix 1 states which of these categories applies to which processing activity. Where a recipient processes personal data on our behalf, we have a data processing agreement in place with them. If you want to know which providers we currently use, please contact us.
Transfers outside the EU/EEA
We aim to keep the processing of personal data within the EU and the EEA, and this is where our services are operated from. We cannot, however, rule out that personal data becomes accessible from outside the EU/EEA, for instance because some of the providers we use are owned by companies established in the United States or use support functions located there.
Where personal data is transferred to a country outside the EU/EEA, we make sure that appropriate safeguards are in place. These include:
• that the European Commission has decided that the country in question offers an adequate level of protection, corresponding to the level of protection under the GDPR; or
• that we conclude the European Commission’s standard contractual clauses with the recipient.
Where a transfer relies on the standard contractual clauses, we assess whether the laws of the recipient country affect the protection of your personal data, and we take technical and organisational measures where these are needed so that the protection travels with the data. You should be aware that, because of United States security legislation in particular, a residual risk remains that American authorities may access personal data transferred there in order to fight crime or protect national security, despite the measures we take.
Please contact us if you want more information about transfers to third countries or a copy of the safeguards we have in place.
How long we keep your personal data
How long we keep your personal data depends on why we collected it. The retention period for each processing activity is stated in Appendix 1. As a general rule we do not keep personal data for longer than we need it for the purpose it was collected for, and we delete it when we no longer have a valid consent, a contract or a legal obligation that requires us to keep it.
In some cases we have to keep data for longer than the periods stated, for example where accounting legislation requires it, or where the data is needed to establish, exercise or defend a legal claim.
Your rights
These rights apply to all the processing described in this policy, including your use of our digital services. To exercise any of them, contact us at privacy@aunetic.com .
• Withdraw your consent, where the processing is based on consent. Withdrawing consent does not affect the lawfulness of the processing that took place before you withdrew it.
• Object to processing based on our legitimate interest. Where we process your personal data for direct marketing, you can object at any time and we will then stop.
• Ask us to confirm whether we process personal data about you, to give you access to it, and to tell you more about how it is processed.
• Ask us to correct personal data that is inaccurate or incomplete.
• Ask us to erase your personal data. We can do this unless we have a right or a legal obligation to keep it.
• Ask us to restrict the processing in certain situations, for example while we are looking into a request from you to correct or erase data.
• Receive the personal data you have provided to us in a machine-readable format and have it transferred to another controller, where the processing is based on your consent or on a contract and is carried out by automated means.
• Lodge a complaint with a supervisory authority, as described in section 1.3.
Changes to this policy
We may update this policy, for instance when we start using a new service provider or change how we work. The date of the current version is stated at the top of this page. If we make a change that materially affects you, we will inform you before it takes effect.