Privacy Policy
Applies to: 42 Support, 42 Ekonomi
Your privacy matters to us.
- We only collect information necessary to operate our Services.
- We do not sell personal data.
- We use only essential cookies.
- Business customers own their data.
- You can export your data.
- Customer data is deleted 30 days after termination (subject to legal obligations and backup retention).
- We comply with the EU General Data Protection Regulation (GDPR).
This summary is provided for convenience only. The legally binding terms are set out below.
Purpose
This Privacy Policy explains how 42 Scandinavia AB collects, uses, stores and protects Personal Data when you:
- visit our websites;
- create an account;
- use our Services;
- communicate with us;
- purchase subscriptions.
This Privacy Policy does not replace our Data Processing Agreement.
Where Customer Personal Data is processed on behalf of business customers, 42 Scandinavia acts as a Data Processor.
Who We Are
Data Controller
42 Scandinavia AB
Organisation No. 556827-3204
P O Hallmans gata 3
SE-112 06 Stockholm
Sweden
Our GDPR Roles
Depending on the circumstances, 42 Scandinavia acts either as Data Controller or Data Processor.
We are the Data Controller for:
- website visitors
- prospective customers
- billing
- subscriptions
- invoices
- support enquiries
- marketing communications (where applicable)
- recruitment
We are the Data Processor for:
Customer Data uploaded into:
- 42 Support
- 42 Ekonomi
The Customer remains the Data Controller for Customer Data processed within the Services.
Personal Data We Collect
Depending on how you interact with us, we may process:
Account Information
- Name
- Email address
- Company name
- User role
- Login credentials (encrypted)
Billing Information
- Billing address
- VAT number
- Subscription information
- Payment status
Payment card information is processed by Stripe. 42 Scandinavia does not store complete payment card details.
Technical Information
- IP address
- Browser type
- Device information
- Login timestamps
- Security logs
Customer Data
Customer Data depends on the Service used.
42 Support
May include:
- names
- email addresses
- tickets
- attachments
- communications
42 Ekonomi
May include:
- accounting records
- bookkeeping information
- accounting transactions
The Customer determines what Personal Data is stored in the Services.
How We Use Personal Data
We process Personal Data to:
- provide the Services;
- authenticate users;
- manage subscriptions;
- provide customer support;
- send transactional emails;
- improve reliability;
- maintain security;
- comply with legal obligations;
- prevent fraud;
- maintain audit logs.
We do not sell Personal Data.
We do not use Customer Data for advertising.
Legal Bases
Where GDPR applies, we process Personal Data under one or more of the following legal bases:
Contract
Processing necessary to provide the Services.
Legal Obligation
Accounting, taxation and regulatory requirements.
Legitimate Interests
- Security
- Fraud prevention
- Service improvements
- Customer support
- Business administration
Consent
Only where required by law.
For example:
- optional newsletters;
- optional marketing communications.
Consent may be withdrawn at any time.
International Transfers
Where Personal Data is transferred outside the European Economic Area (EEA), appropriate safeguards will be implemented as required by GDPR.
Such safeguards may include:
- European Commission adequacy decisions;
- Standard Contractual Clauses;
- other lawful transfer mechanisms.
Further information is available upon request.
Retention
Website enquiries:
As long as reasonably necessary.
Accounts:
While active.
Customer Data:
30 days following termination unless otherwise required by law.
Backups:
Up to 90 days.
Financial records:
As required by Swedish law.
Security
We use appropriate technical and organisational measures designed to protect Personal Data.
These measures are intended to reduce the risk of:
- unauthorised access;
- accidental loss;
- destruction;
- alteration;
- disclosure.
No Internet-based service can guarantee absolute security.
Your Rights
Where GDPR applies, individuals may have the right to:
- access Personal Data;
- rectify inaccurate information;
- erase Personal Data;
- restrict processing;
- object to processing;
- receive Personal Data in portable form;
- withdraw consent where processing relies upon consent;
- lodge a complaint with a supervisory authority.
Requests should be sent to:
Data Breaches
If a Personal Data breach occurs, 42 Scandinavia will respond in accordance with applicable law.
Where required by GDPR, affected Customers and supervisory authorities will be notified without undue delay.
Children's Privacy
Our Services are intended for businesses.
They are not directed to children under 16 years of age.
We do not knowingly collect Personal Data from children.
Changes to this Privacy Policy
Material changes will normally be announced at least thirty (30) days before taking effect.
Administrative updates may take effect immediately.
The latest version will always be published on our websites.
Contact
42 Scandinavia AB
Organisation No. 556827-3204
P O Hallmans gata 3
SE-112 06 Stockholm
Sweden
Document History
| Version | Date | Description |
|---|---|---|
| 1.0 | Publication | Initial release |
