1. Data controller
Esgaia AB, 559270-7193, (“Esgaia”) is the controller of the personal data Esgaia processes about you and is responsible for that such processing is done in accordance with applicable data protection regulations.
2. About whom do we process personal data?
We process personal data about the following categories:
Customers, i.e. natural persons who are customers or representatives or contact persons of such.
Partners, i.e. natural persons who are partners with Esgaia or representative/contact person of such.
Suppliers, such as a representative or contact person
Visitors, i.e. natural persons who visit our website or contact us via forms on our website.
3. Purpose and Legal Basis
3.1 Performance of a contract
Esgaia processes personal data about you as a customer, partner or supplier, such as name, social security number, contact information, title, legal domicile and payment information, for the purpose of entering into and performing agreements. The information is used to, among other things, contact you, manage payments, and otherwise handle the issues relating to an agreement with you. The legal basis for the processing of your personal data is that it is necessary for the performance of the agreement to which you are a party or in order to take steps at your request prior to entering into an agreement. You are not legally obliged to provide us with personal data. The provision of personal data is however required in order to enter into an agreement with Esgaia. The legal basis for the processing of representatives’ personal data is that it is necessary for the purposes of the legitimate interests of Esgaia.
Esgaia processes personal data about you as a customer, partner, supplier or visitor, such as your name, contact information and title, for the purpose of direct marketing by sending newsletters and offers to you. The legal basis for this processing is that it is necessary in order to meet Esgaia´s legitimate interest of marketing and informing you about our services. You have always the right to object to direct marketing.
Esgaia processes personal data about you as a visitor, such as your name and contact information, for the purpose of communicating with you and otherwise handling your matter. The legal basis for this processing is that it is necessary in order to meet yours and Esgaias´ legitimate interest of contact and handling of your matter.
3.4 Legal obligations
Esgaia may also process personal data about you as a customer, partner, supplier or visitor in order to fulfil its legal obligations, for example regarding accounting and tax. The legal basis for this processing is that it is necessary for compliance with legal obligations to which Esgaia is subject.
4. Recipients of Personal Data
Your personal data may be transferred to and processed by third parties. These may be group companies, service providers, other legal advisers, auditors, consultants, courts, authorities, etc. Examples of situations when your personal data may be transferred to third parties when such action is required due to law, dispute, request for authority or decision, at own request alternatively when required to fulfil Esgaia´s legitimate interest. Esgaia still remains the data controller for the personal data that is transferred, while third parties depending on the circumstances, either become an independent data controller, joint data controller with Esgaia or Esgaia´s processor.
5. Transfer of Personal Data to Third Countries
Esgaia may process your personal data both within and outside the EU/EEA. Esgaia will and must ensure that the transfer of personal data fulfils the requirements of applicable data protection regulations.
6.1 Esgaia never stores personal data longer than necessary for the purposes of the process. Esgaia therefore regularly reviews stored personal data and deletes personal data that is no longer needed.
6.2 Esgaia generally stores your personal data for up to ten years in order to comply with legal requirements or because we have a right to do so according to our legitimate interests.
6.3 Esgaia stores personal data about you as a customer, partner or supplier as long as there is an active agreement. After the agreement has been terminated, Esgaia stores personal data for as long as a legal claim can be made in connection with the agreement or to the extent that it is necessary to save the data in order to comply with legal requirements.
6.4 Esgaia stores personal data about you as a visitor until you have objected to the processing of your personal data, however, for a maximum of three years. If you object to the processing, Esgaia will delete your personal data as soon as possible.
7. Your Rights
As a data subject, you have a number of rights concerning the processing of your personal data. If you wish to invoke your rights, you are welcome to contact Esgaia. Your rights are subject to certain conditions according to applicable data protection regulations and can be summarised as follows.
Right to Access
As a data subject you have the right to obtain confirmation as to whether or not your personal data are being processed and, where that is the case, information regarding the processing. You also have the right to get access to your personal data.
Right to Rectification
As a data subject, you have the right to obtain without undue delay the rectification of inaccurate personal data. You may also have the right to have incomplete personal data completed.
Right to Erasure and Restriction
As a data subject you have, under certain conditions, the right to have your personal data erased without undue delay. This is for example the case if the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed, you withdraw your consent and there is no longer a legal ground for the processing, or the processing is unlawful. You also have the right to obtain restriction of the processing, for example if you contest the accuracy of the personal data or the lawfulness of the processing.
Right to Data Portability
As a data subject, you have the right to receive the personal data which you have provided to Esgaia where the processing of your data is based on your consent or on an agreement with you. You also have the right to transmit such personal data to another data controller. The personal data shall be provided in a structured, commonly used and machine-readable format.
Right to Object and to Withdraw Consent
Where the processing is based on your consent, you have the right to withdraw your consent at any time. This does however not affect the lawfulness of the processing based on your consent before its withdrawal. You also have the right to object to the processing of your personal data based on balance of interests (legitimate interest). In such a case, Esgaia may no longer process your personal data, unless we demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of you as a data subject or for the establishment, exercise or defence of legal claims.
As a data subject you always have the right to object to the processing of your personal data for direct marketing purposes Esgaia will in that case cease the processing of your data for such purposes.
8. Cookies and Tracking Technologies
These cookies enable core functionality such as security, verification of identity and network management. These cookies can not be disabled.
These cookies help us understand how visitors interact with our website, discover errors and provide better overall analytics. Esgaia uses third party cookies for tracking user behavior and to analyze our internal web traffic.
You can at any time change or withdraw your consent on our website.
9. Data Protection Authority
If you are dissatisfied with how we have processed your personal data, please contact us, see our contact details in section 10. You also have the right to submit a complaint about our personal data processing to:
The Swedish Data Protection Authority
104 20 Stockholm
11. Contact Esgaia
For questions or other requests regarding personal data, please contact Esgaia's contact person regarding the processing of personal data:
Name: Anton Ljung
E-mail address: firstname.lastname@example.org