Skip to content

Privacy Policy

Privacy Policy for AQILION AB

This Privacy Policy was published 2024-04-04. 

Index

  1. Background
  2. Definitions
  3. Processing of your Personal Data
  4. Your rights
  5. Consent to the Processing of Personal Data
  6. To whom do we transfer your Personal Data?
  7. Transfer of Personal Data to third countries
  8. How do we protect your Personal Data?
  9. Supervision and compliance
  10. Third party’s terms and conditions
  11. Changes to the Privacy Policy
  12. How do you contact us?
  1. Background

Your privacy is important to us. This policy (“Privacy Policy”) explains how AQILION AB (“Aqilion”, “we”, “us”) processes your personal data in a legal, appropriate and safe manner.

The Privacy Policy further describes when, how, and why we collect, use, transfer, and store personal data and what rights you have according to the rules in the EU’s General Data Protection Regulation (GDPR) (EU) 2916/679 with associated statutes of implementation and supplementary statutes on data protection (the “Data Protection Rules”).

The Privacy Policy applies (i) when Aqilion provides its services to you as a financer, shareholder, existing or potential innovator, or other existing or potential business contact, regardless of whether you are in contact with us as a private person or as the representative for the company or organisation you work for or on behalf of, (ii) to mailings regarding events or newsletters, (iii) to other marketing events or marketing actions, (iv) to all other contacts with Aqilion in connection to visits to our website www.aqilion.com (“Website”) or via social media platforms, and (vii) to requests or other contacts with us via e-mail or phone.

AQILION AB, Corporate Identity Number 556623-2095, c/o HETCH, Redaregatan 48, SE-252 36 Helsingborg, Sweden, is the data controller responsible for the processing of your personal data which is carried out in accordance with this Privacy Policy.

  1. Definitions

In this Privacy Policy, the term “personal data” includes any information which can be attributable to an identified or identifiable natural person, such as e.g. name, address, personal registration number, e-mail address, phone number and photo (“Personal Data”).

This Privacy Policy describes how we Process your Personal Data. The term “processing” includes e.g. our registering, storing, transmitting, and in other ways using your Personal Data in such a manner as is described in this Privacy Policy (“Processing”).

  1. Processing of your Personal Data

In the table below, you can find information about Aqilion’s Processing of your Personal Data. We describe the purpose of the Processing, i.e., why we Process your Personal Data. For each purpose, we also specify which categories of Personal Data we may Process to achieve the purpose, the legal basis for the Processing, and for how long we will Process the Personal Data.

Purpose

Categories of Personal Data Legal basis Deletion period

To provide services that you as a customer have requested.

Contact information, such as name, email address, and delivery address.

Billing information.

Information about the contract between us.

Login information to our website. 

Fulfillment of the agreement with you or the company/organization you represent. During the contract period and the following 12 months.
To be able to administer our contractual relationship with you or the company/organization you represent regarding services and/or products you provide us. Contact information, such as name, email address, and delivery address.

Billing information.

Information about your services and/or products we have bought or are considering buying.

Fulfillment of the agreement with you or the company/organization you represent. During the time we have an active business relationship with you and 12 months after the last purchase.
To comply with applicable legislation, such as accounting legislation or the Act on the Protection of Persons Reporting Irregularities. Billing information.

Information about the contract between us.

Information included in a report on irregularities submitted to us.

Legal obligation. Seven years.

A maximum of two years after the end of a follow-up of a report.

For handling any potential complaint issues. Contact information, such as name, email address, and delivery address.

Information about the contract between us.

Fulfillment of the agreement with you or the company/organization you represent.

Legal obligation.

During the contract period and the following 12 months.
To be able to market our services as well as our business through channels such as mailings, website, special offers, and via social media. Contact information such as name, email address, and delivery address.

Information about the contract between us.

Information about your device, such as IP address, when you visit our website.

Any social media usernames.

For such Processing of your Personal Data, we use the legal basis of legitimate interest, where our legitimate interest is to be able to market our services/products and our business. 12 months after your latest purchase.
To be able to provide customer service. Contact information such as name, email address, and delivery address.

Information about the contract between us.

Fulfillment of the agreement with you or the company/organization you represent. 24 months.
To enable general customer and supplier care (quality work, statistics, market and customer/supplier analysis, as well as business, method, and product development). Information about the contract between us.

 

Postal address.

For such Processing of your Personal Data, we use the legal basis of legitimate interest, where our legitimate interest is to be able to develop our business. Ten years from the date of completion of the assignment.
To be able to administer and implement an efficient recruitment process and to recruit new staff after recruitment has been completed. Name, social security number, address, contact details, photograph, professional title, current and former place of work, CV and other application documents, information on health status (if you provide such information) and certificates, grades, marks, testimonials and the like. The processing is based on a balance of interests as a legal basis, where Aqilion’s legitimate interest is to be able to evaluate your merits and personal qualities in connection with recruitment decisions. Until the recruitment process is finalized and the position is filled and for two years thereafter.

 

If you agree, we may keep your application documents for future recruitments.

To safeguard and protect the legal interests of Aqilion. Contact information, such as name and email address, correspondence, information regarding the contract between us, social security number, photograph, professional title, current and former place of work, CV and other application documents, information on health status (if you provide such information) and certificates, grades, marks, testimonials and the like. Aqilion bases such processing of your personal data on Aqilion’s legitimate interest in protecting and defending its rights in the event of a dispute. The Personal Data will be processed until the legal process is completed, if applicable.

Aqilion only Processes Personal Data that is necessary to achieve the purposes stated above and only for the time necessary to achieve those purposes. Exactly which Personal Data we Process about you depends on how you as a customer or supplier have come into contact with us and which of our services we provide to you or the company you represent, or which of your services and/or products you provide to us.

To enable Aqilion to comply with the legal obligations arising from applicable legislation or to safeguard our legal interest, we may keep the Personal Data for a longer period than stated above. However, Personal Data is never Processed longer than necessary or legally required for each purpose.

In addition to the Personal Data you provide to us, we may also collect Personal Data from third parties. These third parties vary from time to time but include inter alia suppliers of address information from public records in order to ensure we have the correct address information, and credit rating agencies or banks from where we obtain information regarding creditworthiness or information in order to conduct anti-money laundering controls.

When you are asked to provide us with Personal Data, you may choose not to do so. If you choose not to provide necessary Personal Data, this may lead to us not being able to fulfil our obligations or potential obligations towards you.

  1. Your rights

You have a right to receive information regarding the Processing of your Personal Data we carry out. Below you find a statement of the rights you can claim by contacting us. Our contact information can be found at the very end of this Privacy Policy.

Right to access

You have a right to, free of charge, request information regarding our Processing of your Personal Data. You also have a right to receive a copy of your Personal Data that we Process. Such a request shall be submitted to us in writing with a specification of which information you wish to receive. We will respond to your request without unnecessary delay. If we cannot grant you access to the information your request concerns, we will provide a reason as to why. The copy of your Personal Data will be sent to your registered address unless otherwise is agreed with you in writing. In order to ensure your identity upon a request, we may come to request more information from you.

Right to rectification

The main responsibility to ensure that the Personal Data we Process is correct lies with Aqilion as the data controller. If you inform us that the Personal Data you have provided to us is no longer correct, we will promptly correct, block or erase such Personal Data.

Right to erasure

You have the right to request that Aqilion, without unnecessary delay, erases your Personal Data. Personal Data shall be erased in the following cases:

  • if the Personal Data is no longer necessary for the purposes for which it was collected;
  • if you withdraw your consent and the Processing was based solely on consent as the legal ground;
  • if Processing is carried out for purposes of direct marketing and you oppose your Personal Data being used for such purposes;
  • if you oppose the Processing of Personal Data after a balancing of interests has been carried out and your interest outweighs ours;
  • if your Personal Data has not been Processed in accordance with the Data Protection Rules; or
  • if erasure is necessary in order to comply with a legal obligation.

There may be obligations which hinder us from immediately erasing all your Personal Data. These obligations stem from applicable legislation regarding inter alia accounting. If certain Personal Data cannot be erased due to applicable legislation we will inform you of this as well as ensure that the Personal Data will be used solely for the purpose of complying with such legal obligations and not for any other purposes.

Right to restriction

You have a right to request that Aqilion temporarily restricts the Processing of your Personal Data. Such a restriction can be requested in the following cases:

  • if you consider the Personal Data we have about you to be incorrect and in connection with this have requested rectification;
  • when the Processing of your Personal Data which is carried out is not compliant with the Data Protection Rules, but you still do not want your Personal Data to be erased but rather restricted; and
  • when we no longer need your Personal Data for the purposes of our Processing but you need it in order to establish, exert, or defend a legal claim.
  • If you have objected against the Processing of your Personal Data the use of your Personal Data may be restricted during the time of the investigation. Upon the restriction of your Personal Data, Aqilion will only store your Personal Data and for further Processing obtain your consent.

Right to data portability

You have a right to, in the cases where we Process your Personal Data with your consent or in order to fulfil contractual obligations toward you, require that we provide you with all Personal Data we have about you and which is Processed in an automated manner, in a machine-readable format, which may be inter alia an Excel-file or a CSV-file. If it is technically possible, you further have the right to require that we transfer your Personal Data to another data controller.

Right to object

You have a right to object to our Processing of your Personal Data if the Processing is based on our legitimate interest. Aqilion will in such a case ask you to specify which Processing you object to. If you object to any Processing we will only continue our Processing of the Personal Data if there are legitimate interests for Processing which outweigh your interests.

  1. Consent to the Processing of Personal Data

If you have requested to receive newsletters or similar information, we base the Processing of your contact information on your consent. You decide yourself if you wish to consent to the intend Processing and when you wish to withdraw your consent. You can withdraw your consent at any time by (i) contacting us, or (ii) following the link in the mailings.

  1. To whom do we transfer your Personal Data?

Only those individuals at Aqilion who need access to your Personal Data in order to perform their job duties will have access to the Personal Data.

To provide certain services, we use selected third parties. The sharing of your Personal Data with third parties is based on the same purposes and legal bases as they were collected for. Aqilion takes technical and organizational measures to ensure that your Personal Data is handled in a safe and secure measure. Below are the categories of recipients with whom your Personal Data may be shared:

Suppliers and subcontractors: Aqilion use third-party suppliers to manage parts of its business, such as companies that deliver technical support, management of IT systems and marketing services. Aqilion may share Personal Data with these suppliers when they perform services on behalf of Aqilion. When Aqilion uses such suppliers, it enters into a data processing agreement and takes other appropriate measures to ensure that your Personal Data is Processed securely. 

Banks and other companies that Aqilion collaborates with: Aqilion also shares your Personal Data with other independent data controllers such as banks and partners. These recipients are independent data controllers for their processing of your Personal Data.

Social media: Aqilion uses social media. When using social media, your Personal Data is collected and processed by these companies. Kindly see each company’s privacy policy for more information.

Courts, authorities, and other public bodies: Aqilion will also disclose your Personal Data if required by law, government decision or court order, or if we, as a company, reasonably believe that the disclosure is necessary to protect Aqilion’s rights.

Aqilion will not sell your Personal Data to a third party unless we have previously obtained your consent. However, we may, in the case that Aqilion decides to sell, buy, merge with another company or organisation, or in any other way reorganise the business, transfer your Personal Data to potential or actual buyers and their potential advisors. Before such transfer, we will take measures to ensure that the receiving party Processes your Personal Data in a manner that is consistent with this information.

  1. Transfer of Personal Data to third countries

As a main rule, Aqilion only Processes your Personal Data within the EU/EEA. Sometimes however, we may share your Personal Data with a party in a country outside the EU/EEA. In such a third country, the GDPR does not apply. This means that you do not automatically have the same rights and protection for your Personal Data as the GDPR guarantees. We protect your Personal Data by either basing the transfer on an adequacy decision by the European Commission or by taking on appropriate security measures, such as entering into the European Commission’s standard contractual clauses in combination with organizational and technical protective measures, to ensure that your Personal Data continue to be protected during and after the transfer. You can read more about which countries are considered to offer an adequate level of data protection on the European Commission’s website here. You can find more information regarding the standard contractual clauses here.

We conduct a risk assessment before any transfer takes place, and we implement technical and organizational protection measures to ensure an appropriate level of protection. We transfer as few Personal Data as possible and anonymize the Personal Data before the transfer, whenever possible. For more information on which protection measures we take on in individual cases, please contact us.

The following recipients outside the EU/EEA might receive your Personal Data:

Suppliers and subcontractors: We may share your Personal Data with suppliers and subcontractors located outside the EU/EEA. This may include providers of IT services, for example. Here, we list our suppliers and subcontractors outside the EU/EEA.

Microsoft Office 365: When using Microsoft Office 365, your Personal Data will be Processed by Microsoft Corporation. When Microsoft receives your Personal Data, it may be transferred to the United States. You can read more about their processing of personal data here.

You can read more about Microsoft’s transfers to third countries and about the standard contractual clauses here.

Social media: When you visit, appear on, or otherwise use Aqilion’s channels on social media, your Personal Data is also collected and processed by the company that owns the social media platform. In connection with these companies receiving personal data through the Company’s channels, the personal data may be transferred to, among other places, the United States.

LinkedIn: By using the services, your personal data is processed by Microsoft Corporation. You can read more about Microsoft’s processing of personal data here and more about their transfers to third countries here.

  1. How do we protect your Personal Data?

In order to protect your personal integrity, discover, prevent and limit the risks of a hacking attack etc., Aqilion takes several technical and organisational information safety measures. Aqilion also takes measures in order to protect your Personal Information against unauthorised access, misuse, reveals, changes and damages. Aqilion ensures that access to your Personal Information is only granted to employees who need to Process it in order to fulfil their work assignments, and that they abide by confidentiality in accordance with Aqilion’s applicable policies and routines.

  1. Supervision and compliance

If you are dissatisfied with how your Personal Data has been Processed or believe that your Personal Data has been Processed contrary to the Data Protection Rules you can at first-hand contact dpo@aqilion.com. You can also file a complaint to the supervisory authority, which currently is Integritetsskyddsmyndigheten. More information on how to file a complaint can be found at www.imy.se.

Aqilion annually reviews this Privacy Policy.

  1. Third party’s terms and conditions

Aqilion’s services may in some cases be subject to third party’s terms and conditions. Aqilion is not responsible for such a third party’s use of your Personal Data as they themselves are data controllers and responsible for the Processing of your Personal Data. Hence, it is important that you observe and read through the terms and conditions of such third parties. The same applies if there is a link on our Website to other websites.

  1. Changes to the Privacy Policy

Aqilion reserves the right to change this Privacy Policy when we deem it to be necessary in order to comply with applicable legislation. Such changes are especially warranted upon potential changes in legislation, due to statements from the supervisory authority or other authorities issuing statements pertaining to the Data Protection Rules. Further, this Privacy Policy will be updated when it is necessary due to changes in our business activities.

If Aqilion makes comprehensive changes to this Privacy Policy or changes concerning how we Process your Personal Data, you will be informed of this before such a change come into force.

  1. How do you contact us?

If you have questions pertaining to this Privacy Policy or the current Processing of your Personal Data, wish to file a request in accordance with this Privacy Policy or wish to report a violation of this Privacy Policy etc., you are welcome to contact us on the following:

AQILION AB

Company Registration Number 556623-2095

Postal address:
c/o HETCH, Redaregatan 48
SE-252 36 Helsingborg
Sweden

E-mail: dpo@aqilion.com

Phone number: +46 (0)70 664 9477