To the extent that we rely on our legitimate interest as a legal basis for processing, we have carried out a balancing assessment between our interests and need to process the data and your interest in the protection of your personal data. Please contact us by email at dataskydd@northtracker.com if you would like more information about these balancing assessments.
Data Retention
We retain personal data that we collect when it is necessary for the purposes of the processing. When it is no longer necessary, we will either delete or anonymise the personal data.
Contact Data and User Data are retained to maintain documentation of the agreement we have or have had and for accounting and tax purposes for seven full financial years after the end of the year in which the transaction took place. If you are a customer and it is deemed necessary for our legitimate interest in administering our customer relationship, the data may be retained for up to ten full financial years after the end of the year in which you terminated your customer relationship with us. Information about partners and suppliers is stored during the contract term and for five years thereafter.
Marketing & Communication Data will be retained as long as necessary for the purposes of the processing. If you have consented to receive marketing, we will retain proof of your consent for five years after the most recent date on which we had evidence of your consent to send marketing. We will stop sending electronic marketing when you withdraw your consent.
Technical Data will primarily be retained as long as necessary or as long as your consent remains valid.
Recruitment Data will be retained for 12 months after the recruitment process has ended in order to consider you for future positions.
Data may be stored for a longer period if we are legally required to do so, or if retention is necessary to establish, exercise or defend legal claims.
Who May Receive Your Personal Data?
In order to provide our goods and services to you, we may transfer or share your information with selected third parties:
-
Banks in connection with payment administration
-
Debt collection and credit reference agencies where loans/credits/claims have fallen due and in connection with credit checks when entering into agreements
-
The Swedish Tax Agency, the Police and other authorities in connection with statutory reporting or other legal obligations
-
External service providers within accounting, support and IT
-
External service providers within customer service, marketing and CRM systems
-
Professional advisors and other data processors under data processing agreements
-
Insurance companies
-
Third parties where necessary due to a legal obligation. If we are required to disclose your personal data due to a court order or similar, we will inform you to the extent we are not legally prevented from doing so.
NorthTracker strives to process your personal data within the EU/EEA. If personal data is transferred to a data processor outside the EU/EEA, we use Standard Contractual Clauses approved by the European Commission, which provide the personal data with essentially equivalent protection as if it were processed within the EU/EEA.
Security Measures and Information Security
NorthTracker strives to protect your personal data and maintains appropriate technical and organisational security measures to prevent improper or accidental disclosure, use, unauthorised access, loss, alteration or damage to your personal data.
We follow the information security management standard ISO 27001:2017.
We apply network segmentation in all our production environments to reduce risks.
Our infrastructure is continuously updated with the latest security patches provided by our service providers.
We apply a recognised access control method known as the Principle of Least Privilege (PoLP) to ensure that only necessary access is granted in order to maintain infrastructure security.
For more detailed information about our security measures, please visit our website:
www.northtracker.com/dk
Your Rights and How to Exercise Them
Under applicable data protection legislation, you have several rights in relation to our processing of your personal data. More information about each of your rights and any limitations can also be found on the website of the Swedish Authority for Privacy Protection (IMY):
https://www.imy.se/verksamhet/dataskydd/det-har-galler-enligt-gdpr/de-registrerades-rattigheter/
You have the right to:
-
Be informed about our processing of your personal data, including when we process your data, why and for how long we store it.
-
Access your personal data (data extract), enabling you to receive a copy of the personal data we hold about you.
-
Request rectification of personal data we hold about you, allowing you to have incomplete or inaccurate information corrected.
-
Request erasure of your personal data (“the right to be forgotten”). This primarily applies where (a) the data is no longer necessary for the purposes for which it was collected, (b) you withdraw consent where processing is based solely on consent, or (c) processing is carried out for marketing purposes and you object to it. In certain cases, we may not be able to delete some or all of your personal data, for example where we are legally required to retain it.
-
Object to our processing where it is based on a legitimate interest assessment. You always have the right to object to processing for direct marketing purposes.
-
Request restriction of processing, for example if you believe that the data we hold is inaccurate and have requested correction.
-
Request data portability, meaning you may receive your personal data in a transferable format under certain conditions.
-
Withdraw your consent at any time where processing is based solely on your consent. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
-
Lodge a complaint with the supervisory authority. If you are not satisfied with how we process your personal data, you have the right to submit a complaint to the Swedish Authority for Privacy Protection (IMY). Contact details are available at imy.se.
If you wish to exercise any of your rights, please send your request by email to dataskydd@northtracker.com, and we will handle your request in accordance with applicable data protection legislation.
When we process data on behalf of our customers in connection with providing our services, any request for extended access, correction or deletion must be submitted to us by our customer. If you use our services through employment or other affiliation with our customer, you must contact the relevant person within that organisation, who can make the necessary decisions, including submitting a request to us.
Data Protection Officer
If you have any questions regarding this privacy policy, concerns about how we handle your personal data, or wish to submit a complaint, please contact us at:
Changes to this Privacy Policy
This privacy policy may be updated from time to time. The latest version is available on our website:
www.northtracker.com/uk
