GDPR (General Data Protection Regulation) Policy at SUDEC
SUDEC (organization number: 559122-8829) is committed to protecting your integrity and processing your personal information in accordance with the Swedish and European data protection act and in line with the United Nations guidelines for data privacy, ethics and protection.
What personal information is processed?
The type of personal information we process depends on the purpose; includes and is limited to the following:
- Contact information such as name, e-mail, address, telephone number, and affiliation are needed to confirm your identity or for coordinating your information between systems to ensure that your information is consistent.
- Bank information and other probable financial information is needed for activating your subscriptions after the trial periods (SUDEC System and SUDEC Academy), payment of salary and other reimbursement, or for invoicing purposes.
- Information on your study results, records, and certifications (SUDEC Academy).
- Personal information that is required when you apply for a position at SUDEC, and for processing of employment matters.
How do we collect your personal information?
We collect all personal information from you directly. In some cases, we may collect organizational information from the publicly available sources such as the Swedish Companies Registration Office (Bolagsverket), the Swedish Tax Agency (Skatteverket), and the European e-Justice Portal.
Who has access to your personal information?
All your personal information at SUDEC is owned by you and considered as private records in accordance with the Law on Official Secrets and Public Records (2009:400).
External suppliers of IT systems may sometimes have access to your personal information after your full consent. In those cases, contracts are in place to ensure correct and legal processing. In the case of transfer outside the EU/EEC, adequate protection levels are ensured in line with the United Nations guidelines for data privacy, ethics and protection.
For how long do we retain your personal information?
We retain your personal information for as long as it is needed for the purpose for which it was collected and for as long as is required by law and other regulations. For more information, we refer to the specific descriptions for the respective registration categories.
- If you have subscribed to SUDEC System, we process your contact information during the trial period. After that, if you decide to unsubscribe, your personal information will be deleted after three days unless you consent to keep your records for future marketing purposes. If you decide to subscribe, your personal information will be processed during that specific period.
- If you are taking a course at SUDEC (SUDEC Academy), we process your personal information for as long as you are a student at SUDEC, and after your graduation, for max five years or in specific cases as long as it is required by law and other regulations.
- If you are employed, we process your personal information for as long as it is needed to manage the employment, and after that, for a maximum of five years or in specific cases as long as it is required by law and other regulations.
The same rules apply for all processing of personal information, regardless of its origin. Personal information in documents is retained in accordance with the Swedish Act of public records and archives (1990:782) and the Public Records Office regulations. In many cases, this means that your personal information will be retained for a number of years in the SUDEC records based on the type of services and mutual agreements.
How does SUDEC use the information?
The SUDEC processes personal information to fulfil its obligations as a private organization registered in Sweden with national and European obligations. We also process personal information to be able to review and develop our operations, and to comply with applicable Swedish and European laws in line with the United Nations guidelines.
The processing of personal information within SUDEC is connected to these purposes. Only necessary personal information must be processed. More details on how your specific information is processed is available to you as a stakeholder (customer, service provider, partner, employee, student, or external party) in respective specific descriptions.
What are your rights?
- You have the right to information on how we process your personal information and to have access to the information.
- You have the right to correct erroneous information.
- In certain cases, you may request to delete the information, that the processing be limited or that the personal information be moved (data portability).
- You have the right to object to the use of your personal information for marketing purposes. In certain cases, you may object to other processing of your personal information.
- You have the right to object to automated decision-making and profiling, if applicable.
- You have the right to withdraw any consent.
- If you believe that we are in violation of the rules for processing of personal information, you may file a complaint with the Swedish Authority for Privacy Protection (IMY).
Contact us
Requests for extracts from the records, requests for corrections or requests regarding any other rights must be made by you or your lawyer. Please send your request to: info@sudec.net