Processing of personal data

Information to you as a data subject (contact person of supplier)

Pandox AB (publ), reg. no. 556030-7885, (“Pandox”) is the controller for the processing of personal data relating to contact persons and other co-workers of our suppliers that Pandox receives in connection with our business, leasing or property management of real estate as well as when administering those situations. The supplier shall ensure that the supplier’s employees and consultants, who work with Pandox, receive this information.

1. PURPOSE OF THE PROCESSING

1.1 Pandox processes personal data for the purpose of managing the supplier relationship, contact in various questions, billing and, if applicable, error reporting and repairs regarding real estate/premises.

1.2 Personal data may also be used for business and method development, market analysis, as well as statistical and marketing purposes. Pandox may also, in certain cases, send invites to different events and similar that Pandox organises.

1.3 Pandox have through contact with the supplier, usually the data subject’s employer or contractor, obtained customary contact details such as name, telephone number, address and e-mail address.

2. LEGAL BASIS

The legal basis for the processing is that the processing is necessary for Pandox's legitimate interests to fulfil the above-mentioned purpose, and that those interests overrides the data subject's interests or fundamental rights and freedoms to not have their personal data processed.

3. CATEGORIES OF RECIPIENTS

3.1 Personal data will be transferred between companies in the Pandox Group in order to manage the supplier relationship, contact in various matters, billing, and, in applicable cases, error reporting and remedial actions.

3.2 Personal data may also be transferred to subcontractors and others who, for Pandox's behalf, perform services related to the supplier relationship and other above stated purposes of the processing.

4. TRANSFER

4.1 Pandox may transfer personal data to suppliers and partners in a third country outside of the EU/EEA. Where a transfer to a third country takes place, Pandox will ensure that appropriate safeguards have been taken and to provide the data subject with relevant information. Such appropriate measures can for example be:

i) to ensure that the parties (for example data exporter and data importer) enter into the EU Commission’s Standard Contract Clauses;

ii) if the transfer takes place to an American company in the US, ensure that the American company is certified in accordance with the EU-US Privacy Shield program; or

iii) if transfer takes place within a group of companies, that the group has adopted so called Binding Corporate Rules approved by the relevant supervisory authority.

4.2 Pandox ensures that all transfers to third parties and third countries take place in accordance with the applicable data protection legislation.

5. DURATION

Personal data is stored as long as it is necessary for the purpose of the processing, but no longer than one (1) year after the supplier relationship has ended, unless the data is required to determine, enforce or defend legal claims or law requires that the data is stored longer.

6. YOUR RIGHTS

6.1 As a data subject, you are, without cost, entitled to request information from Pandox about the processing of your personal data. Upon your request, or on our own initiative, Pandox will correct or delete incorrect personal data, and/or limit the processing of these. In addition, you are entitled to request that your personal data is not to be processed for direct marketing purposes. You also have the right to object to such processing as Pandox performs with a weighted assessment as a legal basis. If Pandox considers that processing still needs to be done, it is up to Pandox to show that there are interests that overrides your individual rights.

6.2 If you are displeased with Pandox’s processing of your personal data, please contact us or submit a complaint to the supervisory authority (The Swedish Data Protection Authority, datainspektionen.se/other-lang/in-english/).

For further details about Pandox' processing of personal data, please see https://www.pandox.se/privacy-policy/.

If you as a data subject have questions about how Pandox process your personal information, please feel free to contact us at info@pandox.se.

Pandox AB (publ), reg. no. 556030-7885, Vasagatan 11, PO Box 15, 101 20 Stockholm, is the controller of the personal data.