Lund- May 2018
We process and protect personal information with the utmost care and attention. Whenever we process personal data, we comply with relevant regulations, including the GDPR. (the new European regulation that will enter into force in the EU on 25 May 2018. )
Protecting the security and privacy of personal data of contact persons (each a “Business Partner Contact”) at our customers, suppliers, vendors and partners (each a “Business Partner”) is important to LifeAssays Ab, Sölvegatan 43A 22370 Lund, Sweden and its affiliated companies (together “Lifeassays”). Therefore, LifeAssays processes personal data in compliance with applicable laws on data protection and data security.
1. Categories of personal data processed, purpose of the processing and legal basis
In the context of the business relationship with LifeAssays, LifeAssays may processes personal data for the following purposes:
- Communicating with Business Partners about products, services and projects of LifeAssays or Business Partners, e.g. by responding to inquiries or requests;
- Planning, performing and managing the (contractual) relationship with Business Partners; e.g. by performing transactions and orders of products or services, processing payments, performing accounting, auditing, billing and collection activities, arranging shipments and deliveries, facilitating repairs and providing support services;
- Administrating and performing customer surveys, marketing campaigns, market analysis, sweepstakes, contests, or other promotional activities or events;
- Maintaining and protecting the security of our products, services and websites, preventing and detecting security threats, fraud or other criminal or malicious activities;
- Ensuring compliance with legal obligations (such as record keeping obligations), Business Partner compliance screening obligations (to prevent white-collar or money laundering crimes), and LifeAssays policies or industry standards;
- Solving disputes, enforce our contractual agreements and to establish, exercise or defend legal claims.
For the aforementioned purposes, LifeAssays may process the following categories of personal data:
- Contact information, such as full name, work address, work telephone number, work mobile phone number, work fax number and work email address;
- Payment data, such as data necessary for processing payments and fraud prevention, including credit/debit card numbers, security code numbers and other related billing information;
- Further information necessarily processed in a project or contractual relationship with LifeAssays or voluntarily provided by the Business Partner Contact, such as orders placed, payments made, requests;
- Information collected from publicly available resources, integrity data bases and credit agencies; and
- If legally required for Business Partner compliance screenings: information about relevant and significant litigation or other legal proceedings against Business Partners.
The processing of personal data is necessary to meet the aforementioned purposes including the performance of the respective (contractual) relationship with Business Partners. Unless indicated otherwise, the legal basis for the processing of personal data is the General Data Protection Regulation or - if explicitly provided by Business Partner Contacts – the consent of the General Data Protection Regulation.
If LifeAssays does not collect the respective personal data, the purposes described may not be met by LifeAssays.
2. Transfer and disclosure of personal data
LifeAssays may transfer personal data to other LifeAssays companies, but only if and to the extent such transfer is strictly required for the purposes mentioned above.
If legally permitted to do so, LifeAssays may transfer personal data to courts, law enforcement authorities, regulators or attorneys if necessary to comply with the law or for the establishment, exercise or defense of legal claims.
LifeAssays commissions service providers (so-called data processors), such as hosting or IT maintenance service providers, which only act upon instructions of LifeAssays and are contractually bound to act in compliance with applicable data protection law.
Recipients of personal data Recipients of personal data located in countries outside of the European Economic Area (“third countries”), in which applicable laws do not offer the same level of data protection as the laws of the respective individual’s home country.
3. Retention Periods
Unless explicitly indicated otherwise at the time of the collection of Business Partner Contact’s personal data (e.g. within a consent form accepted by Business Partner Contact), we erase personal data if the retention of the personal data is no longer necessary in relation to the purposes for which they were collected or otherwise processed and no statutory retention obligations under applicable law (such as tax or commercial law) require us to further retain personal data.
4. Right to withdraw consent
In case a Business Partner Contact declared its consent for the processing of certain personal data by LifeAssays, the Business Partner Contact has the right to withdraw the consent at any time with future effect, i.e. the withdrawal of the consent does not affect the lawfulness of processing based on the consent before its withdrawal. In case consent is withdrawn, LifeAssays may only further process the personal data where there is another legal ground for the processing.
5. Right of access to and rectification or erasure of personal data, restriction of processing, right to object to processing and right to data portability
Under applicable data protection law an affected Business Partner Contact may - provided that the respective legal pre-conditions are met - have the right to:
- obtain from LifeAssays confirmation as to whether or not personal data concerning the Business Partner Contact are being processed, and where that is the case, access to the personal data;
- obtain from LifeAssays the rectification of inaccurate personal data;
- obtain from LifeAssays the erasure of Business Partner Contact’s personal data;
- obtain from LifeAssays restriction of processing regarding the Business Partner Contact’s personal data;
- obtain from LifeAssays a copy of personal data, which the Business Partner Contact actively provided, in a structured, commonly used and machine-readable format and to request fromLifeAssays that we transmit those data to another recipient selected by the Business Partner Contact; and
- object, on grounds relating to the Business Partner Contact’s particular situation, to processing of personal data.
5. Data Privacy Contact
The LifeAssays Data Privacy Organization provides support with any data privacy related questions, comments, concerns or complaints or in case a Business Partner Contact wish to exercise any of its data privacy related rights as mentioned in Section 5 above. The LifeAssays Data Privacy Organization may be contacted at: @LifeAssays.com. The responsible Chief Data Privacy Officer of LifeAssays is:
22370 Lund, Sweden
+46 46 2865400
The LifeAssays Data Privacy Organization will always use best efforts to address and settle any requests or complaints brought to its attention. In addition, there is always the possibility to approach the competent data protection authority with requests or complaints.
The Swedish Data Protection Authority: we would we happy to help if you have any complains about your personal information. Swedish privacy legislation gives you the right to submit your complaint to the Swedish Data Protection Authority (Datainspektionen) https://www.datainspektionen.se/
Telephone: 08-657 61 00