Privacy statement
It is important to us that you know what information we collect about you, and that you feel confident that your privacy is protected with us. All processing of personal data is in accordance with the Personal Data Act, which incorporates the EU's General Data Protection Regulation (collectively, "the privacy regulation" or "GDPR"). We aim for complete transparency about what we do with your personal data. In this privacy statement, we explain how and why we process personal data about you.
1. DATA CONTROLLER
The data controller is the one who determines the purpose and means of processing personal data. Protan AS, org.nr.983 599 060, (Protan) is responsible for the processing of visitors to our website, our customers and job seekers.
Protan will have shared processing responsibility with Facebook, LinkedIn and Google respectively in those cases where we use their advertising platforms. The advertising platforms have their own guidelines for the processing they themselves do with your personal data for their own purposes, and they themselves are responsible for their own processing of personal data. Read more about this under point 2.2 (social media) and in our cookie declaration, see point 2.3 (cookies).
Our contact information is available at the bottom of the page.
2. WHICH PERSONAL INFORMATION IS COLLECTED AND WHY?
2.1 To be able to deliver our services and products
In order to follow up, send order and delivery confirmations, answer questions, process any complaints and deliver our services and products, we will process the following personal data:
Name
Company
E-mail address
Telephone number
Any personal information you include in your inquiries to us. We will also process your bank information in order to carry out invoicing, credit checks and payment follow-up.
The processing of personal data is based on our agreement with you, as well as our terms of purchase and delivery cf. (GDPR art. 6 (1) b).
2.2 Use of social media and other websites
Protan has its own profiles on Facebook, LinkedIn and Youtube to present our services, communicate and advertise.
The social media gives us access to see posts, like-clicks, followers, comments and messages, in addition to aggregated information about visits and activity on our pages and customized advertisements. Protan's user profiles have been created in accordance with the terms of use of the relevant social media.
We do not store this information ourselves, but we have access to it as long as we have our page (account) on the social media. You can delete information about you at any time, e.g. by removing content or reactions you have posted. Please note that your information is not deleted simply by you ceasing to follow our page.
In cases where our websites contain links to third party websites, products and services, the third party's privacy policy and terms apply.
2.3 Cookies
2.3.1 General
We use cookies when you visit our website, for development, function, marketing, analysis and sales.
In this privacy policy, we will describe which personal data is collected through the cookies and which legal basis the processing of personal data is based on.
You can find more information about which cookies we use, and further information about use and storage time in our cookie declaration.
2.3.2 Visits to this website and use of cookies for functionality and security
When you visit our website, the browser on your PC, mobile or tablet will automatically send the following information to our web server:
- the IP address
- date and time of access
- the name and URL of the file you have access to
- browser type and version,
- the name of your access provider
- geographical origin
This information is necessary for us to be able to ensure trouble-free connection to the website, comfortable use of our website, and to evaluate system security and stability. The legal basis for this processing is our legitimate interest in providing a good service (GDPR art. 6 (1) f).
2.3.3 Use of cookies for development and analysis
We use Google Analytics and Microsoft Azure to prepare general market analyzes based on analyzed statistics from our customers. The statistics are based on the users' actions on Protan's digital surfaces. For example, we use statistical data to group customers on the basis of invoicing, data volume and the duration of the customer relationship or to prepare reports on how our customers' location, product preferences influence the choice of product or service. The information enables a better understanding of our customers' needs so that we can improve and further develop our deliveries. The processing basis for the use of statistics is based on our legitimate interest in improving our own services and deliveries cf GDPR art. 6 (1) f.
2.3.4 Cookies for marketing purposes
If you agree to this, Protan can create its target groups for marketing based on information from its own channels which are used to adapt the offers shown to you on other websites or advertising platforms such as Facebook. This is called retargeting and typically occurs when a "pixel" (a piece of code) sets a cookie with a unique ID number on the user's browser. A list of the ID numbers is continuously shared with the selected ad network. If the person identified with an ID number in the browser visits a website where the advertising network offers its advertisements, the network will use the ID to adapt the marketing.
Protan currently uses Facebook, Episerver, AppNexus, Youtube and Doubleclick to adapt Protan's marketing to target groups who have shown an interest in Protan's services, or who, based on various parameters, are likely to find Protan's offers interesting and relevant. The transfer basis is based on the EU's standard clauses.
The targeted marketing based on the IDs involves profiling. The transfer of the ID numbers will only be done if you have consented to this. Consent can be withdrawn at any time. The processing basis for the profiling is based on Protan's legitimate interest in sending out relevant marketing, cf. GDPR article 6 (1) f. You can object or ask us to adapt this profiling by contacting us on the contact information listed in point 8.
2.4 Market surveys and customer satisfaction surveys
We also send out market analyzes if you have consented to this cf. GDPR article 6 (1) a. We will also send out customer satisfaction surveys. The processing basis for the surveys will be our legitimate interest in being able to understand our customers' needs and our own performance, and thus be able to improve ourselves, cf. GPPR article 6 (1) f.
In addition, we may process information collected on the basis of your consent. In that case, you will receive specific information about what information we collect and what it is used for when we ask for your consent.
2.5 Newsletter
If you have agreed to it, we would like to keep you updated with newsletters by e-mail. You can withdraw your consent to such marketing at any time by sending us an e-mail, see our contact information in point 8 (Contact us), or follow the unsubscribe link at the bottom of each e-mail. The processing basis for this processing is your consent, cf. GDPR art. 6 (1) a.
2.6 Job seekers
In the context of recruitment, we process personal data we have received from the job applicant in order to carry out measures at the data subject's request before entering into an agreement, cf. GDPR art. 6 (1) b. Sensitive personal data that is processed in this connection is necessary for Protan to be able to fulfill its obligations as a potential employer cf. GDPR art 9 (2) b. Any ability and personality tests, as well as online searches, are based on Protan's legitimate interest in finding the right candidate. We will only contact the job applicant's references if we have obtained consent for this (GDPR art. 6 (1) a).
2.7 Dispute
If a dispute arises between us, we will process your and other people's personal data. The processing is necessary to safeguard our legitimate interest in establishing, asserting or defending legal claims cf.GDPR art. 6 (1) f cf. art. 9 (2) f.
3. PROVISION OF PERSONAL INFORMATION
We do not pass on your personal data to others unless there is a legal basis for such disclosure. We do not disclose your personal data to others beyond what is mentioned in this section and in point 2.3 (cookies).
3.1 Suppliers
We use subcontractors to operate websites, databases, e-mails, analyze website traffic, ensure good stability and technical performance on the site. When we share personal data with our subcontractors, we enter into data processing agreements to ensure that the personal data is processed in accordance with applicable data protection legislation and our guidelines. Our data processors are not allowed to carry out processing for purposes other than our own.
3.2 Advertising platforms
Facebook, LinkedIn and Google process personal data in the USA and other countries listed in their privacy policy. The companies use the EU's standard clauses for transfer. You can get more information about how Facebook, LinkedIn and Youtube process personal data in their privacy statements. We encourage you to familiarize yourself with the privacy practices of these third parties.
3.3 Transactions
Relevant personal data may be transferred to third parties such as lawyers, advisers, buyers and potential customers in connection with the sale of real estate, share sales, disputes or other business transactions.
4. SECURITY
Protecting your personal data is a high priority task for us, and we work continuously to protect personal data and other confidential information. Our security measures include physical, technical and administrative measures.
Our employees receive training and guidance on how to handle personal data in a secure manner. We have routines and access control to prevent unauthorized loss or disclosure of your personal data. We also have procedures and have implemented measures that prevent the loss and destruction of the systems that store the personal data.
We only use recognized subcontractors who meet our security requirements and enter into data processing agreements where this is necessary.
If a (possible) breach of the privacy rules is discovered, whoever discovers the discrepancy will be reported to Protan's privacy officer, the risk of a security breach will be assessed and the Norwegian Data Protection Authority will be notified when required. You will also be notified as a user if the security breach poses a high privacy risk for you.
5. YOUR RIGHTS
The legislation gives you several rights to help you protect your privacy. These rights include:
5.1 Information on the processing of personal data
You have the right to information about how we process your personal data. The most important thing about the duty to provide information is that it must ensure that you can understand how personal data is processed, what consequences the processing may have, what rights you have and how these rights can be used. If the information has not been obtained from you, you must also receive information about which categories of personal data we process. We hope this privacy policy provides you with good information about anything you may be wondering about, and you are welcome to contact us. Our contact information can be found at the bottom of this declaration in point 8 (Contact us).
5.2 Access to own personal data
You have the right to request access to your personal data. This means that you should be informed if we are collecting and using information about you. You will also have the right to request insight into our assessment of the basis for processing for those processes that rely on legitimate interest if you ask for this. See our contact information in section 8 (Contact us).
5.3 Correction of personal data
It is important that the information we have about you is correct and up-to-date. Should information be incorrect, irrelevant or incomplete, you can contact us via the contact information mentioned in point 8 (Contact us).
5.4 Deletion of personal data
In certain cases, you have the right to request the deletion of personal data. This applies, for example, when storing the information is no longer necessary to achieve the purpose of the processing, if you withdraw consent and there is no other legal basis for the processing. See our contact information in point 8 (Contact us).
5.5 Limited use of personal data
You can request that we do not use personal data other than to establish, enforce or defend a legal claim (e.g. demand payment for an agreement), to protect another's rights or to safeguard important public interests if:
you have requested that incorrect information be corrected (until the information is corrected),
you have complained about the processing of the personal data (until you have received feedback on the complaint), or
it turns out that our processing of the information is illegal and you prefer that we store the information rather than delete it
5.6 Data Portability
You have the right to request that personal data be handed over from us and to another organization or you directly. The purpose of this right is to give you control over your own information. The right only applies to information that you yourself have provided to us, and only when we use the information to fulfill an agreement with you or the use of the information is based on your consent.
5.7 Protesting
You have the right to object to the collection and use of personal data if there are reasons related to your particular situation or in cases where we process personal data based on our legitimate interest. Targeted marketing on the advertising platforms Facebook, LinkedIn and Google can be changed by clicking on the links.
5.8 Complaint
If you have objections to the way we process personal data about you, you can complain to the Norwegian Data Protection Authority. However, we ask you to contact us via the contact information mentioned in point 8 (Contact us) first, so that we can take a position on your objections and clarify any misunderstandings, or correct the practice directly. If you are not satisfied with our complaint handling, you can appeal the matter to the Norwegian Data Protection Authority.
6. STORAGE PERIOD
We will store your personal data for as long as necessary to fulfill the purposes set out in this privacy policy, unless a longer storage period is required or permitted by applicable law. For example, we retain your name and billing information for up to five years after the customer relationship has ended due to legal requirements, and we delete your email address used to send out newsletters when you ask us to. Storage of anonymised information is not subject to such restrictions or requirements.
We also try to ensure that personal data and other customer information is updated and correct, and that we do not store information that is unnecessary in relation to the purposes for which personal data is processed.
7. CHANGES IN THE PRIVACY STATEMENT
We may need to update the Privacy Policy as our operations and services develop, and we therefore encourage you to regularly check the latest version of this Privacy Policy on our website. If we have your contact details, we will make you aware of important changes to the privacy policy.
8. CONTACT US
If you have thoughts or questions regarding this information about privacy, or you wish to assert your rights, please contact us by e-mail at [email protected]. Alternatively, you can contact us by post:
Privacy officer at Protan AS,
PO Box 420 Brakerøya
3002 Drammen