Privacy Policy
The policy regulates how Galleria Vintergatan (the company) handles personal data in accordance with the EU's General Data Protection Regulation (GDPR). The policy covers the handling of all personal data and includes both structured and unstructured data. The policy is embedded in all our employees.
Application and revision
- The company's board of directors is responsible for ensuring that the processing of personal data complies with this policy.
- The policy shall be established, and if necessary updated, annually by the company's board of directors.
- The company's data controller is responsible for staying informed about changes in the Data Protection Regulation and is responsible for ensuring that the policy is updated as a result of new and changed regulations.
- This policy shall be applied by all of the company's executives and employees, as well as sub-consultants and contractors who are in one way or another part of our business operations.
Organization and responsibility
The CEO is ultimately responsible for the content of the company's personal data policy and that it is implemented and complied with by all of the company's executives, employees and contractors. The CEO may delegate responsibility for the content and implementation to an appropriate person within the company.
All of the company's executives, employees and contractors are responsible for acting in accordance with the company's personal data policy.
Personal data processing
All personal data processing takes place according to the following principles:
- Legality
- Purpose limitation
- Task minimization
- Correctness
- Storage minimization
- Integrity and confidentiality
Data collection criteria
The principles for data processing mean that we only process personal data that is of direct relevant and legitimate business interest, contractually regulated or legally required. Only in exceptional cases and if necessary, other personal data is processed, which is then regulated by consent agreements.
Only personal data that is strictly necessary to conduct business operations, fulfill applicable contracts, handle personnel administration, and comply with legal requirements shall be processed and stored. When the personal data no longer meets these criteria, they shall be deleted without delay.
Handling procedures
Our data processing is continuously documented in our processing register, which is managed by the data controller. A person who is registered always has the right to receive an extract of registered data, as well as the right to correct incorrect data. Follow-up and evaluation of our processing of personal data shall take place at least annually.
Unlawful data processing
Any incidents concerning personal data that we process must be reported to the data controller without delay. The data controller must report the incident to the data controller without undue delay and no later than 72 hours. The Data Protection Authority and otherwise take necessary measures in response to the incident.
In external management, collaboration and purchasing of services
Our requirements that personal data be handled in accordance with the GDPR must always be ensured when procuring external suppliers and developing IT solutions and services, and must be part of the requirements specification and any agreements. Outsourcing of personal data handling is regulated through personal assistant agreements.
