Terms
Terms of use
Updated
The purpose of this Privacy Policy is to ensure that Wndy’s processing of personal data is carried out on lawful grounds and in accordance with the principles of the GDPR, and that we handle the personal data of our customers, employees and suppliers in a secure and transparent way.
1. Introduction
In the same way as society as a whole, Wndy AB (“Wndy”), our customers, employees and suppliers have been affected by digitalisation and globalisation, which has led to a significant increase in the use and dissemination of personal data. Digitalisation means increased opportunities, but also a greater need to protect registered personal data and privacy. This policy describes the overarching principles that apply to the processing of personal data within Wndy.
1.1. Purpose
The purpose of this policy is to define Wndy’s responsibilities and to assign roles and responsibilities for complying with the General Data Protection Regulation (GDPR).
1.2. Objective
The objective is that Wndy’s processing of personal data takes place on a lawful basis and in accordance with the principles of the GDPR, in order to assure our customers, employees and suppliers that we handle their personal data in a secure and transparent way.
1.3. Definitions
The following definitions are used in this policy:
Data controller:
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Data subject:
The living person to whom the personal data relates. A data subject is defined in this policy as a person with whom Wndy has some form of relationship, for example a customer, employee, consultant or other.
Data processor:
A natural or legal person, public authority, institution or other body which processes personal data on behalf of the data controller.
Personal data:
Any kind of information that directly or indirectly can be attributed to a living natural person counts as personal data. Images (photographs) and audio recordings of individuals processed on a computer may also be personal data even if no names are mentioned. Encrypted data and various kinds of electronic identities, such as IP numbers, count as personal data if they can be linked to natural persons.
Processing of personal data:
All forms of operations performed on personal data constitute processing of personal data, for example collection, registration, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
1.4. Scope
The scope of this policy is limited to the processing of personal data required under the General Data Protection Regulation (GDPR). This covers Wndy, external consultants who perform tasks on Wndy’s behalf, and data processors who carry out data processing on Wndy’s behalf.
In addition to the general guidelines in this policy, detailed requirements in local data protection laws must, where applicable, be followed by employees when processing personal data. In cases where Wndy is a data processor for an external organisation, the data processing shall be carried out in accordance with this policy, unless otherwise stated in a data processing agreement between Wndy and the data controller.
1.5. Target groups
The privacy policy applies to all personnel who perform tasks on Wndy’s behalf concerning the processing of personal data. It is also intended to form the basis for information to data subjects regarding the processing of personal data. It also applies to data processors who process personal data on Wndy’s behalf.
2. Roles and responsibilities
2.1. CEO
The CEO shall ensure that Wndy is properly organised, with delegated responsibility and sufficient resources for the processing of personal data within the company. The CEO is responsible for identifying information security risks, proposing appropriate information controls and following up on the information security controls. The CEO can be reached at kontakt@wndy.se
2.2. Data controller
The data controller is always responsible for the processing of personal data. The data controller is always the legal person that controls and decides on the handling of personal data.
2.3. Privacy Officer (PO)
The purpose of the role is to ensure compliance with the GDPR within the organisation. The PO can be reached at kontakt@wndy.se
2.4. Data processor
External suppliers of IT operations, cloud services and similar, where personal data is processed on Wndy’s behalf, are referred to as data processors. A data processor shall perform the tasks specified in a data processing agreement.
2.5. Employees
All employees are personally responsible for lawful and correct processing of personal data in their daily work. By following Wndy’s governing documents concerning the processing of personal data, employees contribute to compliance with correct processing of personal data.
3. Data protection requirements
3.1. Legal basis for processing
Personal data may only be processed if certain conditions are met, for example (A) if the person to whom the personal data relates has given consent to the processing; (B) the processing is necessary for the performance of a contract to which the person is a party; (C) the processing is necessary for Wndy to comply with a legal obligation; or (D) Wndy’s legitimate interest in processing personal data outweighs the individual’s interest in not having their personal data processed.
3.2. Principles for the processing of personal data
- Lawfulness, fairness and transparency — when processing personal data within Wndy we shall ensure that the processing is lawful and that we are transparent towards data subjects.
- Data minimisation — within Wndy we never collect and handle more personal data than is required to fulfil the purpose of the data. This means we must ask ourselves, for every collection of personal data, whether it is necessary. If the purpose of the data processing has expired, we must delete personal data that is no longer needed.
- Purpose limitation — when collecting personal data we must have a clear and legitimate purpose for the collection and the processing. If the purpose is no longer valid, we must delete the personal data processed under that purpose. If we wish to process personal data for a new purpose, it must not be incompatible with the original purpose, for example outside what the data subject concerned would reasonably expect. We must also make sure to inform the data subject of this, and of the legal basis on which we process the personal data.
- Accuracy — personal data must be accurate and up to date. Personal data that is inaccurate or incomplete should be erased or corrected.
- Storage limitation — personal data shall only be stored for as long as necessary for the purposes for which the data is processed, or as required by applicable law. When that period has expired, the personal data shall be permanently erased in a secure manner. If we wish to retain personal data for a longer period than is required for the purpose, we must ensure that the data can no longer be linked to a person, directly or indirectly (anonymisation). For personal data received from a person with whom we have a customer relationship, we retain the data for the period that constitutes practice as determined by the national data protection authority.
- Integrity and confidentiality — personal data shall be protected against, among other things, unauthorised or unlawful processing and against accidental loss, destruction or damage. Wndy shall therefore take appropriate technical and organisational measures to protect personal data.
- Accountability — Wndy is responsible for ensuring that the principles for the processing of personal data are complied with when personal data is processed, and shall be able to demonstrate how they are complied with.
3.3. The rights of the data subject
Wndy shall respond to the data subject’s requests in the manner required by applicable law, or otherwise considered reasonably practical and appropriate in consultation with our PO.
- Transparency and information — persons whose personal data is processed should be informed in a clear manner. Such a notice should be concise, easily accessible, written in clear and plain language, and must contain certain specific information.
- Right to information — an individual may request information about Wndy’s processing of personal data.
- Right to rectification and erasure — an individual may request that their personal data be corrected or erased.
- Right to object — an individual has, in certain cases, the right to object to the data controller’s processing of his or her personal data.
- The right to object — applies where personal data is processed to perform a task in the public interest, as part of the exercise of official authority, or following a balancing of interests.
- An individual has the right to complain about Wndy’s processing of their personal data.
- An individual has the right to compensation for damage.
3.4. Obligations of the data controller and the data processor
Where the processing is to be carried out by a data processor on behalf of the data controller, the data controller shall only use data processors that can provide sufficient guarantees of having implemented adequate technical and organisational protection, in order to meet the requirements of the GDPR and thereby protect the data subject.
There shall be a legally binding agreement between the data controller and the data processor that meets the requirements of data protection law and sets out the allocation of responsibility between the parties regarding the processing of personal data:
- Data protection through “privacy by design” — every new service or business process introduced by Wndy that involves the processing of personal data should be designed to take the protection of such data into account, for example by ensuring that necessary security measures are built into its design (“privacy by design”). Every such new service or business process shall also be designed to ensure that, by default, only personal data necessary for the specific purpose of the processing is processed (“privacy by default”).
- Data protection impact assessment — where there are high risks in the processing of personal data, in particular where new technologies, cloud services and other IT systems are concerned, Wndy should carry out an impact assessment before such processing. Wndy shall then follow the data protection authority’s guidelines on impact assessments.
- Reporting of personal data breaches — employees who suspect that this policy or relevant data protection laws have been breached shall contact Wndy’s PO immediately, so that Wndy can comply with statutory notification requirements.
- Provision of the data subject’s rights — as set out in chapter 3.1 of this policy.
- Security measures — an employee who has access to personal data may only process the data in accordance with the purpose of the processing, and may not share, distribute or otherwise disclose the personal data to a third party unless instructed to do so by Wndy. Appropriate technical and organisational measures should be implemented to protect personal data against accidental or unlawful destruction, accidental data loss or alteration, unauthorised disclosure or access, and other unlawful forms of processing. Appropriate safeguards in relation to the risk shall be taken.
- Transfer of personal data outside the EU and the EEA is only permitted where the importing entity has provided sufficient guarantees that personal data will be adequately protected. This can be achieved by using one of the EU’s standard data transfer agreements. Contact the PO for further information.
- Training and awareness — Wndy provides adequate training for all employees, based on the employee’s role and responsibilities.
4. Handling of personal data at Wndy
4.1. Personal data where Wndy is the data controller
4.1.1. Data on our corporate customers
In order to fulfil the agreement with the customer, contact details such as invoicing and delivery address are registered. This data is registered in our business system and processed for invoicing and accounting purposes.
4.1.2. Suppliers and subcontractors
Since we purchase some services that we may need, personal data is also processed about you as a supplier or subcontractor. This is so that we can make payments or contact you in one way or another, so that you can effectively perform your assignment or offer your product or service.
This applies to the following categories of data subjects:
- Employees at a supplier company
- Freelancers
- Consultants
- Persons paid by fee
4.1.3. Potential employees
We also process data as a result of job applications being sent to us.
4.2. What we use your personal data for
When we process your personal data we do so with your consent and/or on the basis of need, in order to run our business, fulfil our contractual and legal obligations, protect our systems or fulfil other legitimate interests, primarily related to sales and marketing activities.
4.2.1. Fulfilling obligations as a principal
In order for Wndy to fulfil its obligations as a principal, and to ensure secure and efficient administration, it is necessary for Wndy to collect, process and store personal data on freelancers, consultants and other subcontractors. Only personal data connected with the assignment is processed.
4.2.2. Customer support
We use data to provide support and assistance services to you so that you can make use of our Services.
4.3. Types of personal data we process, and for which purposes
We do not use data for any purpose other than what is described in this policy. The data we process may include the following:
4.3.1. Name and contact details
We collect first and last name, e-mail address, postal address, telephone number, delivery details and other similar contact details. This data is processed so that we can fulfil agreements with our customers, so that we can administer and keep records of freelancers, and so that we can contact you for recruitment purposes.
4.3.2. Personal identity number and payment information
In order to fulfil our agreements with suppliers, subcontractors, customers and persons paid by fee, we need to obtain payment information. Note that personal identity numbers are only registered for persons paid by fee, so that we can register and pay out agreed fees.
4.3.3. Device and usage data
This may also include information about operating system, IP address, device id, locale and language settings.
4.3.4. Film and photography
Applies only to customer assignments where we provide services that include film and photography.
4.3.5. Support and feedback data
We also collect information you provide to us and the content of messages you send to us, such as feedback or questions, and information you provide for customer support.
4.3.6. Sensitive personal data
As a rule we do not process any sensitive information, with the exception of a small number of interview situations where the content itself may be of a sensitive nature. In such situations, those of you who take part must actively give your consent to participating and to the content being published openly. However, it is the corporate customer in question that acts as data controller in these situations. It is therefore that customer that is responsible for obtaining and storing the consent.
4.4. Who your personal data may be shared with, and why we share it
Where we share information about you with others, we have made sure that those companies comply with our data protection requirements, and they are not permitted to use the personal data they receive for any purpose other than what has been agreed.
4.5. System and cloud providers
It may sometimes be necessary for us to share your information with external companies in order to facilitate our operations, deliver our services and fulfil our obligations. This may for example concern system and cloud providers we use to carry our work forward. They may not, however, look into our data without explicit permission.
4.6. E-mail and other unstructured data
Wndy has a specific internal policy for the processing of personal data in e-mail and other unstructured data. Firstly, we must have a legal basis for handling e-mail. Like other companies and private organisations, Wndy can therefore as a rule process personal data in incoming e-mail on the basis of a balancing of interests. The policy also states that Wndy shall not use e-mail for the systematic handling of personal data, and that data shall be weeded out.
4.7. Other
Finally, we may need to disclose or retain your data where we consider it necessary in order to:
- Comply with the law or legal process and provide information to the police and other competent authorities.
- Protect our customers, for example to prevent spam or attempted fraud, or to help prevent death or serious injury.
- Manage and maintain the security of our services, including preventing or stopping an attack on our systems or networks.
- Protect rights or property belonging to Wndy, including enforcing the terms governing use of the services. However, if we receive information that someone is using our services to deal in stolen intellectual or physical property belonging to Wndy, we will not ourselves investigate a customer’s private content; we may instead refer the matter to a police authority.
5. Contact us
If you have a question about what applies to your personal data, a request for a register extract, a complaint or a question for our PO, contact us by e-mailing kontakt@wndy.se. We answer questions within 30 days.
6. Internal audit
Wndy will carry out objective internal audits of this policy, including data protection, on a periodic basis. Wndy’s CEO is responsible for the overall monitoring and implementation of this policy. The PO is responsible for Wndy’s day-to-day compliance with this policy and with data protection laws.