Privacy Notice
INFORMATION ON THE PROCESSING AND STORAGE OF PERSONAL DATA
Last updated 23.04.20.
In this Privacy Notice, you can read about how Merch-Ants Stockholm AB with corporate registration number 556631-1287 (hereinafter referred to as “we”, “our” or “us”) Processes Personal data. The information is aimed to you who are in contact with us, enter into agreements with us or visit our Websites. References to “you” or “your” refer to the Data subject whose Personal data we Process.
This Privacy Notice contains information about, among other things, the following:
DEFINITIONS
In addition to any terms defined in the running text of this Privacy Notice, the following definitions shall have the following meaning when expressed in capital letters as initial letters, whether used in plural or singular, in definite or indefinite form:
Controller: refers to the person who determines the purpose of a particular Processing of Personal data and how the Processing shall proceed. Natural persons, legal persons, authorities, institutions, or other bodies may be Controllers.
GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the Processing of Personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation).
Personal data: refers to any data that, directly or indirectly, alone, or jointly with other data, may be linked to an identified or identifiable natural living person. Common examples of Personal data are: name, telephone number, address, and email address.
Processing: refers to everything that is made with Personal data, automated or otherwise. Processing can be done through a single procedure or by combination with various measures. Examples of common Processing of Personal data are storage, erasure, sharing, loading, recording, copying, collection, organization, use, adjustment, etc.
Processor: refers to the person who Processes Personal data on behalf of a Controller, according to the Controller’s instructions.
Registered: refers to the natural person who can be identified by the Personal data.
SCC: refers to Commission implementing decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of Personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, or later updated version.
Third party: means someone other than the Controller (and the persons authorized to Process the Personal data), the Data subject or the Personal data Processor (and the persons authorized to Process the Personal data). Third parties may be a legal person or a natural person, institution, authority, or other body.
Website: refers to merchants.se and/or swedishmerch.se.
Any other GDPR-related terms not defined here shall have the same meaning in this Privacy Notice as set out in Article 4 of the GDPR.
PERSONAL DATA CONTROLLER
Merch-Ants Stockholm AB is the Controller for all Processing of Personal data carried out by us or on our behalf, to the extent that we determine the means and purposes of the Processing (in accordance with the principle of accountability).
This means, among other things, that we are the Controller of the Personal data relating to customers, contact persons, signatories and other natural persons collected by and/or provided to us in connection with the contact and/or purchase of the services/products we provide.
Unless expressly stated otherwise, we are the Controller of the Processing described in this Privacy Notice.
We Process all Personal data that we obtain with care and do not share the Personal data with unauthorized persons. Our Processing of Personal data takes place in accordance with the GDPR (and SCC where applicable) and the basic data protection principles. This Privacy Notice covers all types of Personal data, in both structured and unstructured data.
HOW WE ACCESS PERSONAL DATA
The most common ways we receive Personal data are when:
CATEGORIES OF PERSONAL DATA WE PROCESS
We only Process Personal data that is adequate, necessary, and relevant to fulfil the purpose for which it was collected (according to the principle of data minimization).
We mainly Process the following categories of Personal data:
LEGAL BASIS AND PURPOSE OF THE PROCESSING
In accordance with the principle of purpose limitation, we only Process Personal data for specific, explicit, and legitimate purposes. In addition, each Processing is legally based in accordance with the provisions of the GDPR.
Any Personal data that you provide to us or that we receive will be Processed by us as the Controller. The Personal data you provide may be used to ensure delivery to you, during credit check and to provide you with offers and information about our product range.
We Process Personal data primarily on the basis of one of the following four legal bases:
In some cases, it is optional for you to provide your Personal data to us and in other cases you may need to share your Personal data in order to enter into a contract with us or to fulfil legal or contractual obligations. Unless otherwise stated, you will not have any negative consequences if you do not provide your Personal data to us.
When data Processing is based on your consent, you can withdraw it at any time without affecting the lawfulness of Processing based on consent before its withdrawal.
When a Processing of Personal data takes place on the basis of legitimate interest as the legal basis, our assessment is that the Processing does not constitute an infringement of your right to privacy and integrity. We have found this, after balancing, on the one hand, what the Processing in question means for your interests and the right to privacy, and on the other hand the legitimate interest in the Processing in question.
Depending on the contact you have chosen to have with us, we collect, store, and handle your Personal data in different ways. Below you can read more about the legal basis and purposes of the Processing of Personal data.
This website uses cookies. The use of necessary cookies always takes place and does not require your prior consent. However, the use of non-necessary cookies takes place only if you give your consent to it. More information about our use of cookies can be found in the Cookie Notice published on the Website and on our web shops.
Legal basis for the above-mentioned Processing: Consent.
Email: When ordering our services/products via email and other email contact with us, the communication goes through our hosting provider one.com. The hosting provider acts as a Personal data Processor and enables and stores email communications to and from us. Read about one.com as an agreement as a data Processor (https://www.one.com/static/info/data-Processing-agreement-en.pdf) and how one.com to comply with GDPR (https://www.one.com/static/info-privacy-notice.do).
This is stored: Email address, date, and other information that you have chosen to enter in the email.
Storage time: We save communication with you for different periods depending on your case. If it concerns questions about information, prices, booking or other questions that do not concern you as a customer, we save it for 24 months. If it concerns an order, commitments in connection with festivals, gigs, events, web shop or other services that can be purchased from us, we store it in accordance with the Swedish Accounting Act (SFS 1999:1078).
Why we store: We save your data and communication with you in order to be able to provide adequate service and fulfill the commitments we have to you. To fulfill obligations under agreements entered into and to comply with applicable law and practice.
On our website swedishmerch.se you can make simpler orders by filling in your details and uploading a picture of what you wish to print on the product in question. Please note that it is the person who uploads the image that is responsible for obtaining all rights to print the image in the current context.
This is stored: name, social security number/org. number, address and phone number associated with the image you attach.
Storage period: In accordance with the Accounting Act. Legal basis for Processing: Legal obligation.
Delivery and fulfillment: We also Process this data in order to fulfill your order and fulfill obligations under agreements entered into with you. Legal basis for Processing: Contract.
If you have purchased services/products from us, you will receive offers, information and other marketing that we think is interesting to you. We save our customers’ email addresses in a special list of a subcontractor that we use for emailing. The subcontractor we work with is called “Get a Newsletter Scandinavia AB”.
This is stored: email address.
Storage time: If you do not wish to receive newsletters from us, you may at any time click on the unsubscribe link in the footer of emails you receive from us, or by contacting us at office@merchants.se.
Why we store: We save your data in order for you to receive our offers and to be able to inform you about events, offers, news and other commercial information (marketing purposes).
In our assessment, both we and you have a legitimate interest in the Processing of the Personal data for the above purposes. The Processing is necessary for a purpose relating to a legitimate interest, and your interest in the protection of your Personal data does not outweigh our legitimate interest. Our assessment is that the Processing in question does not infringe your fundamental rights and freedoms.
Legal basis for Processing: Legitimate interest.
We may also share your Personal data with the relevant artist/creator, who has linked to our web shop from where you have shopped. In our assessment, both you and the artist/creator in question have a legitimate interest in the Processing of the Personal data in order for the artist/creator to send you newsletters and information. The Processing takes place for the artist/creator’s marketing purposes. The Processing is necessary for a purpose relating to a legitimate interest, and your interest in the protection of your Personal data does not outweigh the legitimate interest of the artist/creator. Our assessment is that the Processing in question does not infringe your fundamental rights and freedoms.
When the artist/creator Processes your email address, the artist/creator is independent Controller regarding its Processing of your Personal data and is responsible for complying with applicable data protection legislation regarding its Processing of Personal data.
Legal basis for the above-mentioned Processing: Legitimate interest.
We may contact you, and you may contact us, by email, telephone, or social media, and in such cases, we will have access to your Personal data as stated in connection with such contact. For example, the following Personal data: first name, surname, telephone number, email address, social media user ID (if applicable), message content and other information you provide to us.
In our assessment, both we and you have a legitimate interest in the Processing of the Personal data, to enable us to know who we are talking to and to keep in touch with the case. Our assessment is also that the Processing is necessary for a purpose relating to a legitimate interest, and that your interest in the protection of your Personal data does not outweigh, and that the Processing in question does not infringe your fundamental rights and freedoms.
The provision of the Personal data in question is voluntary, which means that it is not a statutory or contractual requirement or a requirement that is necessary to enter into a contract with us, and you are not obliged to provide the Personal data, but the possible consequences of not providing such data is that we will not be able to handle the matter.
Legal basis for the above-mentioned Processing: Legitimate interest.
You can also contact us by sending us a message via the contact forms available on our Website. We will then have access to the following categories of Personal data: name, telephone number, email address and any other Personal data that you include in the message. When contacting us via our contact form, the information is sent as an email to us and stored at one.com just like direct email.
The provision of name, telephone number, email address and a message are mandatory in the contact form in order for the message in question to be sent to us. However, the provision of your Personal data through the contact form is not a statutory or contractual requirement or a requirement necessary to enter into a contract with us, and you are not obliged to provide the Personal data. The consequences of not providing such information are that the message will not be able to be sent to us.
In our assessment, both we and you have a legitimate interest in the Processing of the Personal data, to enable us to know who we are talking to and to keep in touch with the matter. Our assessment is also that the Processing is necessary for a purpose relating to a legitimate interest, and that your interest in the protection of your Personal data does not outweigh, and that the Processing in question does not infringe your fundamental rights and freedoms.
Legal basis for the above-mentioned Processing: Legitimate interest.
When we enter into a sales contract with a Customer regarding the services/products that we sell from time to time, we obtain access to the Personal data that is provided to us in connection with the purchase Process. For example, Personal data of the Customer (or if the Customer is a trader, the signatories and/or contact persons), such as name, email address, delivery address and telephone number. We Process this Personal data in order to fulfill the purchase agreement regarding the ordering of the services/products.
Legal basis for the above-mentioned Processing: Contract.
We need to Process the following data in order to deliver ordered products, handle any complaints, etc.: Customer’s name, delivery address, telephone number, email address. If the Customer is a trader, we also Process the name and telephone number of the Customer’s contact person and signatory, company name and corporate registration number (or Personal identity number if the Customer operates a sole proprietorship).
The provision of the above information is necessary for us to enter into a sales contract with the Customer in question. The possible consequences of not providing such information to us is that we are unable to enter into the contract or perform the purchase agreement.
Legal basis for the above-mentioned Processing: Contract.
The order ID and order history are Processed by us every time the Customer places an order, so that we can offer a good service.
Legal basis for this Processing: Legitimate interest.
Order ID and order history are Processed by us every time the Customer makes a complaint or calls for a right of withdrawal, in order for us to be able to fulfil our legal obligations under applicable law (such as the Distance and Off-premises Contracts Act (SFS 2005:59) and the Consumer Sales Act (SFS 2022:260)).
Legal basis for this Processing: Legal obligation.
We Process the following accounting documents within the framework of our business: invoices, receipts, and other accounting documents that we are required to Process and store in accordance with the Swedish Tax Agency’s requirements and/or legislation in force at any time, such as the Accounting Act (SFS 1999:1078).
Accounting documents may in some cases contain Personal data, such as name, address, order information and any other contact details of physically living persons (e.g., the customer, reference persons, signatories, etc.). Such data are stored for as long as the law and/or the Swedish Tax Agency require it.
Legal basis for the above-mentioned Processing: Legal obligation.
STORAGE LOCATION
We strive to store all Personal data that we Process within the EU/EEA area, in accordance with the principle of integrity and confidentiality. If Personal data is stored in a country outside the EU/EEA area, we shall ensure that such storage places ensure an adequate level of protection in accordance with the provisions of the GDPR and SCC.
STORAGE DURATION
According to the general rule, Personal data will be stored as long as it is necessary to fulfil the purposes for which it was collected. When the Personal data no longer need to be stored for the purposes, they are either deleted (erased) or anonymized, in accordance with the principle of storage limitation.
The identification data, contact details and financial data of Customers will be stored for up to seven (7) years after completion of the purchase. This is stored in order for us to be able to handle any complaints and/or returns in accordance with the agreed terms of purchase and to be able to match a payment against a receipt while we are obliged to store such accounting documentation in accordance with applicable legislation at any time.
We follow internal guidelines and written procedures regarding the deletion of Personal data, to ensure that the Processing of Personal data is carried out in accordance with the GDPR.
TRANSFER OF PERSONAL DATA
In order for us to be able to deliver a good and secure service to you, we use in some cases third parties as subcontractors, which in some cases constitute Personal data Processors. For example, it may be done to safeguard our legal interests and fulfil our contractual and legal obligations. Your data may therefore be Processed through/by third parties and sometimes also Processed outside the EU/EEA area if the supplier conducts its business from there or employs its own sub-processors from there. Examples of third-party service providers we use are: marketing agency, accounting firm, accounting software, shipping companies, web developers etc.
Before we share any Personal data with contracted service providers, we enter into a Data Processing Agreement with them in accordance with the provisions of the GDPR (or SCC if the Processor is located in a country outside the EU/EEA area). This is done to ensure the safe and correct Processing of the Personal data.
We may share Personal data with authorities if it is necessary to prevent, detect, or investigate criminal activity, to protect our interests and property, if we are required to disclose the information under applicable law, etc.
We may also transfer Personal data to supervisory authorities, other public entities, legal advisers, external consultants, and partners, in accordance with applicable data protection legislation, if this is made to enable us to comply with legal obligations or to fulfil a legitimate interest.
In the event of a merger or acquisition of our company, Personal data may be transferred to third parties involved in the merger or acquisition.
We have concluded that we have a legitimate interest in the Processing of the Personal data for the purposes set out above, and that our legitimate interest does not constitute an infringement of your right to privacy and integrity.
Legal basis for the above-mentioned Processing: Legitimate interest.
DATA SUBJECTS’ RIGHTS UNDER GDPR
The following is a summary of the privacy rights that you have as a Data subject under the GDPR:
Right to information: You have the right to receive information about our collection and use of your Personal data. We will also inform you if there is a Personal data breach that concerns your Personal data, such as a data breach, when required by the GDPR.
Right of access: You have the right to access your Personal data that we Process and information about how the Personal data relating to you is used, provided that there is no applicable exception to the right of access. In the event that we Process your Personal data, you have the right to obtain a copy of the Processed Personal data in the form of a register extract in a machine-readable format. The purpose of the register extract is to enable you to check the legality and accuracy of the data. However, this does not mean that you have the right to receive the documents containing the Processed Personal data.
Right to rectification: If we Process Personal data about you that are inaccurate or incomplete, we will, at your request or on our own initiative, complete, rectify or delete the Personal data in question. After we have corrected the data, we will notify you of this, provided that it is not too burdensome for us.
Right to erasure: You have the right to request that we delete your Personal data that we Process. We will, at your request or on our own initiative, delete your Personal data, provided that the data is no longer needed for the purposes for which it was collected and there is no legal obligation to continue storage. When we delete the Personal data at your request, we will inform you after the deletion has been carried out, provided that this is possible and not too burdensome for us.
Right to limitation of processing: In some cases, you have the right to request that our Processing of your Personal data is limited. This means that the Personal data may only be Processed in the future for the certain limited purposes. We will inform you when the limitation expires.
Right to data portability: In some cases, you have the right to request that we transfer your Personal data to you or any other third party that you designate. However, this right is only applicable if the Processing of the Personal data is carried out automatically, and if our Processing takes place for the performance of a contract to which you are a party to the contract or is based on your consent. The transfer of the Personal data to another company only takes place where technically possible. If you have the right to data portability, we will, at your request, provide your Personal data in a structured, commonly used, machine-readable format.
Right of objection: You have the right to object when your Personal data is Processed:
If you make an objection to the Processing under this right, we will cease the Processing, unless it can be demonstrated that there are compelling legitimate reasons for the data needing to be Processed that override your interests, rights, and freedoms or if the Processing is carried out for the establishment, exercise, or defense of legal claims. If so, we will inform you of the weighing of interests we have done and our interests. However, you always have the right to request that your Personal data is not Processed for direct marketing purposes. Such objections can be made at any time. If an objection to direct marketing is made, the Personal data may no longer be processed for such purposes. In such cases, we will inform you when we have deleted the Personal data if you request it.
Automated decisions: In short, automated decision-making take place automatically with or without profiling, for example through algorithms. Profiling means any form of automated Processing of Personal data where the data is used to assess certain personal qualities, in particular to analyze or predict the person's work performance, financial situation, health, personal preferences, interests, dependability, behavior, place of residence or relocations. Automated decisions may have legal consequences for the Data subject or affect the Data subject in other significant ways, and if so, the Data subject has the right not to be subject to the automated decision. If an automated decision has been made, with or without profiling, you have the right to request that the automated decision be reviewed or to contest it.
HOW TO EXERCISE THE RIGHTS
You are welcome to contact us via the contact details set out below, if you would like to exercise any of the above rights regarding your Personal data that we Process.
Exercising the rights is free of charge, provided that your requests are not exaggerated, repeated or manifestly unfounded. In such cases, we have the right to charge a reasonable fee for handling your request or the right to refuse the execution of your request.
Before we handle or respond to your request, we may request additional information from you if it is necessary for us to confirm your identity.
We will inform you of our handling of your request without delay and at the latest within one month of receiving the request. If the request is complex or, for example, we have received a large number of requests, this period may be extended by a further two months. In such cases, we will notify you of the extension within the first month of receiving your request.
If we are unable to comply with your request due to applicable law or other exceptions, we will notify you of this and inform you of the reasons why we are unable to comply with your request with the limitations imposed by law.
PERSONAL DATA BREACHES
We comply with the provisions of the GDPR regarding the handling, notification, and documentation of Personal data breaches. When required by the GDPR, we will report Personal data breaches to the Swedish Authority for Privacy Protection (IMY) within 72 hours and notify the Data subjects concerned by the Personal data breach.
UPDATES
To ensure that the information set out in this Privacy Notice is accurate and up to date over time, we review it at least once a year and update the content as necessary, in order to comply with our Processing of Personal data and applicable law. You are responsible for reviewing the contents of this Privacy Notice and keeping up to date with any changes. When required by applicable data protection legislation, we will inform you of any changes to our Processing of your Personal data. The latest version is always published on our Website.
QUESTIONS OR COMPLAINTS
If you have any questions or concerns or are dissatisfied with our Processing of your Personal data, you are always welcome to contact us.
Below are our company and contact details:
Company: Merch-Ants Stockholm AB
Registration number: 556631-1287
Phone: 08-81 90 20
Email: privacy@merchants.se
Our contact person for Personal data matters:
We have appointed a contact person for Personal data matters that you can contact if you have any questions regarding our Processing of Personal data.
Name: Larsa Gustafsson
Email: privacy@merchants.se
If you are dissatisfied with our Processing, you have the right to file a complaint with a supervisory authority. In Sweden, the Swedish Authority for Privacy Protection (IMY) is the supervisory authority:
Website: www.imy.se
Phone: 08-657 61 00
Email: imy@imy.se
Postal address: Integritetsskyddsmyndigheten, Box 8114, 104 20 Stockholm.
You can also contact the supervisory authority in the country in which you work or live.