Your personal data
We respect the integrity of our customers and site visitors. This policy shall clearly and transparently describe how we safely collect, use, display, transmit and store personal data. We carry out all processing of personal data in accordance with EU’s applicable privacy law, GDPR.
Johan Hagström HAB, VAT-number SE556038-4405, Ekensbergsvägen 117, Box 1285, 171 25 Solna, Sweden (”JH”, ”we”, ”us”) is the data controller for the processing of personal data on this and other websites operated by JH.
You can contact us at email@example.com or via a handwritten letter sent to Johan Hagström, Ekensbergsvägen 117, Box 1285, 171 25 Solna, Sweden.
Collection of personal data
What personal data is
Personal data is all kinds of information, individually or in combination with other information that can be linked to an identifiable person. Typical personal data is personal identification number, name, address, e-mail address and telephone number. Images and sound recordings of individuals processed by a computer may be personal data even if no names are mentioned. Encrypted data and various types of electronic identities, such as IP numbers and cookies, are considered as personal data if they can be linked to identifiable persons.
The purpose of collecting personal data and the data we collect
Visits to Website & Apps
Customer service and consumer contact
We collect personal data from you when you contact us, for example via consumer contact, by email, phone or other means. Firstly, we collect the personal data needed to answer your question or handle your case. It is data as name, e-mail address or phone number. When you contact us personally, we also collect other personal data you choose to provide. For example, data regarding allergies, health status or other data about you that is relevant to your case.
When you subscribe to JH’s newsletter, we will collect your name and e-mail address to send you the newsletter. We may also request additional information such as place of residence and occupation, to able to send relevant information related to city or occupation.
When we organize a competition, we collect personal data to identify participants, communicate with the participants, to ensure the age of the participants, and to select the winner and deliver prizes.
Trade fairs & events
At trade fairs and events, we may collect personal data with the purpose to inform about our products and services. We also collect personal data to communicate about the fair or event as such, both prior to, during and after it has taken place. This may include booking confirmations, answers to questions and evaluations. Categories of processed personal data is name, occupation, company name, mailing address, e-mail address and any request for special diets.
We use social networks in our marketing activities. Suppliers of these networks collect and process personal data from you as users of the platform, for the purpose to customize the overall service according to your requirements and behaviours. We do not collect personal data from users who visit our social media accounts without requesting consent for each specific case, such as at a competition or if we need additional information in other similar consumer cases. Are you interested in reading more about the social network’s personal data privacy policies? Here are links to the most common network’s privacy policies:
Processing and storage of personal data
JH’s lawful basis for processing your personal data
JH is processing your personal data at a lawful basis. It may occur that the same personal data is processed both to fulfil contractual obligations, specifically by consent or to comply to other legal obligations. This means that even if you revoke your consent and the data processing based on the consent ceases, the personal data may still be stored for other purposes. Basically, we process your information to fulfil an agreement in which you are a counterparty.
Contract partners and IT service suppliers
We use several different IT services and IT systems in our operations. In some of these, personal data is stored and processed. We are careful about your integrity and the security of the processing of your information. Some systems are installed locally on our premises and only our staff have access to the data. In the latter situations, no transfer will be made to third parties. However, some systems are cloud solutions or installed at the IT service supplier’s premises which means that we transfer personal data to them. In these situations, the supplier is the data processor and process the personal data on our behalf and act on our instructions. Certain customer events will take place outside the EU/EEA. This means that personal data may be transferred to partners in these countries for the purpose to fulfil the customer event. In these events both parties occasionally are data controllers, i.e. both parties are responsible for processing the personal data in accordance with the prevailing legislation.
Internal IT systems
Internally we process personal data in our customer database, in our CRM systems, in the systems managing our online shopping, warehouse and product delivery, and in our customer service system. These systems are used to deliver the products you have ordered from us and enable us to handle your questions and inquiries in conjunction with fulfilling these services. All collected personal data may be processed in these systems.
Marketing and personalization
Customer information can be used for marketing purposes and JH may contact you by mail, email and SMS.
If you have signed up for one of our newsletters, we use your personal data to send the newsletter to you and to personalize the content of the newsletter. The information used is based on your e-mail address and information about your purchase history. By using these data, we can provide you with the offers we think you have the greatest interest and benefit from.
In some cases, we share information with our partners to help us customize our offers and promotion for you. We enter into agreements with our partners to ensure that they provide sufficient guarantees that the requirements of the GDPR will be met.
If you participate in any of our competitions, we use your personal data to communicate with you to announce winners and deliver prizes.
We use external vendors for personalization and analysis of user behaviour on our websites and for user feedback. These companies are data processors and process personal data on our behalf and according to our instructions. The information is primarily collected through cookies and managed at anonymous and aggregated levels.
Development of services
The collected customers information is used to develop and improve our products and services. This refers to our digital services, where we analyse user behaviour to develop how we present information and offers as well as the design of functionality on our websites. Furthermore, the information is used to develop our products according to customer requirements and behaviours and, for example, addressing deficiencies or increasing security.
To do the analysis we primarily use anonymous or anonymized data at an aggregated level.
Customer service and consumer contact
We use your personal data to provide service if you contact us with questions, comments or, for example, complaints. We use your contact information, such as email address and phone number to contact you regarding your questions and concerns. We may also use other collected personal data to handle your question or case, depending on what is relevant in the individual case.
We will also process your personal data to fulfil obligations under laws and regulations, such as security and reporting to authorities.
Retention of data
JH follows good practice in Swedish trade. We retain your personal data as long as it is required for the purpose of the processing. In the customer database, personal data is stored for 3 years after you have ceased to be a customer.
If you make a complaint of a product, we will retain your information as long as the case is in progress or maximum 6 months after the case is completed.
If you subscribe to our newsletter, your contact information will be retained as long as you choose to continue receiving the newsletter.
When participating in competitions, we will delete your personal data after we have selected and announced a winner.
The same personal data can be stored in several different locations for different purposes. This mean that data that has been deleted from a system because it is no longer relevant to process, may be stored in another system based on consent or another lawful basis where personal data is still required.
JH’s technical and organizational measures for secure processing of your personal data
We take ongoing measures to comply with the principles of “data protection by design” and “data protection by default”. We continuously evaluate the risks of personal data processing and take the necessary security measures to reduce risks.
Necessary processing of personal data and processing based consent
Personal data processing that is necessary for us to fulfil an agreement with you or to fulfil a legal obligation is permitted without consent. However, to collect and process your personal data for any other purpose, you must agree to the processing. You agree to the processing of your personal data when you use our services at arvidnordquist.se.
Revocation of consent
You may at any time choose to withdraw your consent by contacting us at firstname.lastname@example.org. If you revoke your consent, we will delete the personal data and discontinue the data processing covered by the consent.
The same personal data may be processed both with a consent and on the basis, that the processing is necessary or under another lawful basis. This means that even if you revoke your consent and the processing based on the consent ceases, the personal data may remain with us for other purposes.
The right to access your personal data
If you want to make a request to access the personal data we have registered about you, you can apply for this in writing at the above address. The register extract is available on request and is free of charge once a year.
How can I apply for a registry extract?
You write and request a registry extract from JH. NOTE! You must submit your request in writing as it will contain your signature, so you cannot just send a message by email. Mark the letter ”Request for personal data extract”.
Here’s how to write:
Personal data registry extract – to the data protection manager (personuppgiftsansvarig) at Johan Hagström HAB.
I hereby apply for information under Article 15 of GDPR.
(City and date)
(Printed name, personal identification number, address)
The right to control your personal data
You are entitled to request that the information about you be deleted, supplemented or rectified. You also have the right to request that the processing of your personal data be restricted for certain purposes and, for example, not used for direct mailing or profiling.
If you want to complain
Anyone who considers that a company violates GDPR, may contact The Swedish Data Protection Authority (Datainspektionen). Find out more on their website www.datainspektionen.se.