Privacy Notice
1. Introduction
Skandinaviska Transaktionshuset Stockholm AB, company registration number 559377-2279, processes personal data relating to individuals who represent and/or act on behalf of companies with which we come into contact in the course of our business, such as existing or potential clients or buyers and sellers of the businesses and assets we broker.
References to “we”, “our” or “us” mean Skandinaviska Transaktionshuset Stockholm AB. References to “you” or “your” mean the Data Subject.
This Privacy Notice explains, among other things:
-
what Personal Data we Process;
-
why we Process it;
-
where it is stored;
-
with whom it may be shared;
-
the rights of Data Subjects under the GDPR; and
-
other information about our Processing of Personal Data.
2. Definitions
In addition to terms defined elsewhere in this Privacy Notice, the following capitalised terms have the meanings set out below, whether used in the singular or plural:
Processing: Any operation performed on Personal Data, whether automated or otherwise, alone or together with other operations. Common examples include storing, deleting, sharing, reading, recording, copying, collecting, organising, using and amending data.
GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
Personal Data: Any information which, directly or indirectly, alone or together with other information, can be linked to an identified or identifiable living individual. Common examples include names, telephone numbers, addresses, email addresses and user IDs.
Controller: The party that determines the purposes and means of particular Processing of Personal Data. A Controller may be an individual, legal entity, authority, institution or other body.
Processor: A party that Processes Personal Data on behalf of a Controller and in accordance with the Controller’s instructions.
Data Subject: The individual who can be identified through the Personal Data.
SCCs: The standard contractual clauses for the transfer of Personal Data to third countries under Commission Implementing Decision (EU) 2021/914 of 4 June 2021, or any subsequently updated version.
Third Party: Anyone other than the Controller (and persons authorised to Process Personal Data on its behalf), the Data Subject or the Processor (and persons authorised to Process Personal Data on its behalf). A Third Party may be an individual, legal entity, institution, authority or other body.
Third-Party Services: Information, services, products, systems, websites, software, networks, databases and platforms provided by Third Parties to which the Website links, or with which an individual connects or enables integration when using our Website.
Website: www.transaktionshuset.se and any subdomains.
Other GDPR-related terms not defined here have the meanings given in Article 4 of the GDPR.
3. Controller and Processor
Skandinaviska Transaktionshuset Stockholm AB is the Controller for all Processing of Personal Data carried out by us or on our behalf insofar as we determine its purposes and means. We Process Personal Data in accordance with the GDPR (and the SCCs where applicable) and the fundamental data protection principles.
Unless expressly stated otherwise, we are the Controller for the Processing described in this Privacy Notice.
Where Skandinaviska Transaktionshuset Stockholm AB Processes Personal Data as a Processor, we do so in accordance with the Controller’s instructions in the data processing agreement we enter into with that Controller.
4. How we obtain Personal Data
We most commonly receive Personal Data when:
-
someone contacts us;
-
we contact someone; or
-
we enter into an agreement, for example with a Data Subject or another Third Party.
We may also collect and Process publicly available company information and Personal Data relating to company representatives, such as the names and contact details of chief executives, beneficial owners and/or board members. Sources include the Swedish Companies Registration Office (Bolagsverket), the Swedish Tax Agency (Skatteverket), people-search services and social media such as LinkedIn.
5. Categories of Personal Data we Process
We Process only Personal Data that is adequate, necessary and relevant for the purposes for which it was collected, in accordance with the data minimisation principle. We primarily Process:
- Identification details: First name, surname and Swedish personal identity number.
- Contact details: Email address, postal address, telephone number and social media user ID, where applicable.
- Contractual details: Agreements entered into with us and relevant contractual information, including Personal Data relating to authorised signatories and/or other representatives or contact persons named in an agreement.
- Case information: Individuals’ communications with us, such as emails and text messages.
6. Legal bases and purposes for Processing Personal Data
In accordance with the purpose limitation principle, we Process Personal Data only for specific, explicit and legitimate purposes. Each instance of Processing also has a legal basis under the GDPR.
We primarily rely on one of the following four legal bases:
-
Consent: The Data Subject has consented to the Processing of their Personal Data for one or more specific purposes (Article 6(1)(a) GDPR).
-
Contract: Processing is necessary to perform a contract to which the Data Subject is a party or to take steps at the Data Subject’s request before entering into such a contract (Article 6(1)(b) GDPR).
-
Legal obligation: Processing is necessary to comply with a legal obligation to which we are subject (Article 6(1)(c) GDPR).
-
Legitimate interests: Processing is necessary for purposes relating to our legitimate interests or those of a Third Party, unless the Data Subject’s interests or fundamental rights and freedoms requiring protection of Personal Data override those interests (Article 6(1)(f) GDPR).
In some cases, providing your Personal Data is optional. If you do not provide it, however, we may be unable to provide requested assistance or handle your enquiry.
You may need to provide Personal Data to enter into a contract with us or to enable us to meet legal or contractual obligations. Unless otherwise stated, there will be no adverse legal consequences if you do not provide your Personal Data.
Where Processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of Processing based on consent before its withdrawal.
Where we rely on legitimate interests, we consider that the Processing does not unduly interfere with your privacy. We reach this conclusion by balancing the effect of the Processing on your interests and privacy against our legitimate interest in carrying it out. We never rely on legitimate interests to Process special categories of Personal Data.
Our purposes and legal bases are explained further below.
1) When you visit the Website
The Website uses essential cookies only. Further information is available in the Cookie Notice published on the Website.
If we choose to use non-essential cookies in future, such as analytics cookies, we will do so only with your consent. The legal basis for that Processing will be consent.
2) When we communicate by email, telephone or social media
You may contact us, and we may contact you, by email, telephone or social media. In doing so, we may obtain Personal Data disclosed in the communication, such as your first name, surname, telephone number, email address, social media user ID (where applicable), message content and any other information you provide.
We may also contact you using your publicly available contact details or information obtained from other public sources.
We consider that we have a legitimate interest in Processing your Personal Data so that we can communicate with you and maintain contact in relation to the matter concerned. We consider this Processing necessary for that interest and that your interests and fundamental rights and freedoms do not override it.
If you contact us, Processing your Personal Data enables us to know with whom we are communicating. Providing this information is voluntary: it is neither a legal or contractual requirement nor a requirement for entering into a contract with us. If you do not provide it, we may be unable to deal with the matter.
Legal basis: Legitimate interests.
3) When we enter into and perform an agreement with a client
When entering into and performing an agreement with a client, we Process the following Personal Data relating to the client and/or its representatives, such as authorised signatories, beneficial owners or contact persons:
-
First name
-
Surname
-
Swedish personal identity number
-
Email address
-
Telephone number
-
Employer/company represented by the Data Subject
We Process these details to enter into the agreement with the client and otherwise fulfil our contractual commitments, only to the extent necessary to perform the agreement.
Legal basis: Contract.
We also Process Personal Data to protect our legitimate interests and rights, for example to pursue payment of an overdue debt.
Legal basis: Legitimate interests.
In the course of our business, we Process accounting records such as invoices, receipts and other records that we must Process and retain under Swedish Tax Agency requirements and/or applicable law, including the Swedish Bookkeeping Act (1999:1078). These records may contain Personal Data such as first name, surname, billing address and other contact details. They are retained for as long as required by law and/or the Swedish Tax Agency.
Legal basis: Legal obligation.
4) Other purposes
On the basis of our legitimate interests, we may Process Personal Data to:
- market our services directly by sending clients information, campaigns and/or offers by email or other means of communication;
- protect ourselves against misuse, crime, fraud, unauthorised access or other damage to our property by reporting incidents and providing necessary information to relevant authorities, such as the police or the Swedish Authority for Privacy Protection; and
- inform Data Subjects about security problems or incidents involving Personal Data.
7. Location of storage and Processing
We always aim to Process Personal Data within the European Union (EU) or European Economic Area (EEA). In some circumstances, Personal Data may nevertheless be transferred to and Processed in countries outside the EU/EEA. Where this happens, we take appropriate steps to ensure a level of protection consistent with the GDPR. These may include obtaining your explicit consent, entering into an agreement with the recipient containing European Commission-approved SCCs, or confirming that the recipient country has adequate data protection laws.
We aim to safeguard your Personal Data wherever it is Processed and ensure that transfers comply with applicable data protection law.
8. Retention periods
We Process Personal Data for as long as necessary for the purposes for which it was collected, including compliance with legal, accounting and reporting requirements, in accordance with the storage limitation principle. The precise retention period depends on the type of Personal Data and the purpose for which it was collected.
Contact details of representatives of prospective clients and other interested parties, such as beneficial owners, authorised signatories and other contact persons, are stored in our CRM system for up to two (2) [unit missing in the Swedish source] after our last contact.
Personal Data relating to representatives of our clients or suppliers, collected when an agreement is entered into, is generally stored in our client or supplier register during the term of the agreement and for two (2) years afterwards.
If an agreement imposes obligations on us after it ends, such as confidentiality obligations lasting for a specified period, we retain the agreement and associated contractual details (including information about the parties and their representatives) until those obligations cease.
Where we retain Personal Data for purposes other than meeting our contractual obligations, such as complying with anti-money laundering, accounting or other statutory requirements, we keep it only for as long as necessary and/or legally required for each purpose. We may also delete Personal Data at the Data Subject’s [the Swedish source omits the word completing this phrase] if we do not need to Process it to fulfil contractual or legal obligations.
When Personal Data is no longer needed for the purposes for which it was collected, it is deleted or anonymised.
If a claim is brought against us, we may retain Personal Data until the applicable statutory limitation period expires. Similarly, if a dispute is ongoing, relevant Personal Data will be retained until it is resolved. We comply with applicable laws and regulations concerning retention in these circumstances.
9. Sharing Personal Data
We handle all Personal Data to which we have access with care and do not share it with unauthorised persons. To operate our business effectively, we may need to share your Personal Data with selected specialist companies or where necessary to comply with applicable law, including accounting, tax, banking and anti-money laundering legislation.
All sharing takes place in accordance with applicable data protection laws and regulations, with due regard for your rights and privacy.
We may disclose Personal Data to the recipients below for the purposes set out in section 6.
Authorities
We may provide necessary information to authorities such as the police, tax authorities or other public bodies where disclosure or sharing is required to fulfil our legal obligations.
Personal Data may also be disclosed in response to lawful requests or where necessary to prevent, detect or investigate criminal activity. Such disclosure protects the property, interests and safety of us and other relevant parties.
Suppliers
We may share Personal Data with suppliers, some of whom act as our Processors. This may be necessary to protect our legal interests, fulfil contractual and legal obligations, detect and prevent technical, operational or security problems, and provide and improve our services and digital channels.
We work with various categories of Processors, including server and hosting companies, CRM providers, cloud-service providers and accounting consultants. Before disclosing Personal Data to such providers, we enter into data processing agreements with them in accordance with Article 28 GDPR, including SCCs where required, to ensure secure and proper Processing.
Other Third Parties
In connection with, or during negotiations concerning, a transfer of our company’s assets, merger, sale, financing or acquisition of all or part of our business, Personal Data may be disclosed to a prospective buyer or seller involved in the transaction, including its staff and suppliers.
Legal basis for sharing
We consider that we have a legitimate interest in Processing Personal Data for the above purposes and that this interest does not unduly interfere with your privacy.
Legal basis: Legitimate interests.
10. Your rights
The following is a summary of your rights as a Data Subject under the GDPR.
Right to information: You have the right to information about our collection and use of your Personal Data, including the purposes of Processing, the categories of data concerned and any Third Parties with whom it may be shared.
Right of access: You have the right to access the Personal Data we hold about you. You may request information about its Processing, obtain a copy of the Personal Data in a machine-readable format (subject to any applicable exception to the right of access) and be informed about safeguards for international transfers. This does not mean you are entitled to receive the documents in which the Personal Data appears.
Right to rectification: You may request the correction of inaccurate or incomplete Personal Data we Process about you. At your request or on our own initiative, we will complete, correct or delete such data. Once corrected, we will notify you where doing so is not unduly burdensome.
Right to erasure: In certain circumstances, you have the right to have your Personal Data deleted, for example if it is no longer needed for its original purpose or if you withdraw consent and there is no other legal basis for Processing. Legal obligations, including those under accounting, tax, banking and anti-money laundering law, may prevent us from deleting some data immediately. Where we delete data at your request, we will inform you afterwards if possible and not unduly burdensome.
Right to restriction of Processing: In certain circumstances, you may restrict the Processing of your Personal Data. This may mean that it is only stored and not otherwise Processed, or Processed only for specific limited purposes. For example, if you ask us to correct data, you may also ask us to restrict its Processing until the correction has been made. We will inform you when the restriction ends.
Right to data portability: You may receive your Personal Data in a structured, commonly used and machine-readable format, and ask us to transmit it to another Controller where technically feasible. This right applies only to automated Processing based on your consent or on a contract to which you are a party.
Right to object: You may object to Processing based on legitimate interests. If you do, we must stop unless our interests override your interests, rights and freedoms. You may always object to Processing for direct marketing at any time. Following such an objection, we will no longer Process your Personal Data for direct marketing and, if you request it, will inform you when we have deleted the relevant data.
Right not to be subject to automated decision-making: You have the right not to be subject to decisions based solely on automated Processing, including profiling, that significantly affect you. Exceptions apply where a decision is necessary to perform a contract or is authorised by law. If an automated decision has been made, with or without profiling, you may request a review or challenge it. We do not make automated decisions, with or without profiling.
11. How to exercise your rights
Please contact us using the details below if you wish to exercise any of the rights described above in relation to Personal Data we Process.
Exercising your rights is free of charge unless your requests are excessive, repetitive or manifestly unfounded. In those circumstances, we may charge a reasonable fee to handle the request or refuse it.
Before dealing with or responding to a request, we may ask for additional information to verify your identity.
We will inform you of the outcome without undue delay and no later than one month after receiving your request. For complex requests or a large number of requests, this period may be extended by a further two months. If so, we will notify you of the extension within the first month.
Your rights are subject to restrictions and conditions under the GDPR. Some apply only in certain situations and where it is lawful and possible for us to fulfil the request.
If we cannot fulfil your request because of applicable law or another exception, we will tell you and explain why, subject to legal restrictions.
12. Changes
We regularly review this Privacy Notice to ensure that its information is accurate and up to date. We may update it as needed, with or without prior notice. You are responsible for reviewing the current version and keeping informed of any changes.
We will notify you of material changes where required by applicable law. The current version is always published on the Website.
13. Questions or complaints
If you have questions about this Privacy Notice or our Processing of Personal Data, or are dissatisfied with how we Process your Personal Data, please contact us:
Company: Skandinaviska Transaktionshuset Stockholm AB
Company registration number: 559377-2279
Postal address: Transaktionshuset, Box 1235, 172 24 Sundbyberg, Sweden
Email: info@transaktionshuset.se
If you are dissatisfied with how we Process your Personal Data, you also have the right to lodge a complaint with a relevant supervisory authority. Our supervisory authority in Sweden is:
Name: Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY)
Telephone: +46 8 657 61 00
Email: imy@imy.se
Postal address: Integritetsskyddsmyndigheten, Box 8114, 104 20 Stockholm, Sweden
Depending on your country of residence, you may be able to contact a different supervisory authority about questions or complaints concerning the Processing of your Personal Data. A list of supervisory authorities in EU Member States is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
