Personal data policy ewimed Sweden AB

Position

Role Name Contact information
CEO Tomas Jalrup 08 – 25 11 69
Supervisory authority Swedish Authority for Privacy Protection 08 – 657 61 00

ewimed Sweden AB, Ekbacksvägen 28, 168 69 Bromma is responsible for the handling and processing of personal data within ewimed Sweden AB (hereinafter “ewimed”).

What personal information do we collect?

Personal data includes any information whereby a natural person directly or
can be identified. ewimed collects and processes the following categories as needed
of personal information:

  • name;
  • address;
  • email;
  • phone number;
  • social security number;
  • purchase history; and
  • disease-related information.

Why do we collect personal data?

ewimed collects and processes personal data for the purposes and with the support of the
legal grounds set out in the table below.

Purpose Legal ground
Provision of products, which includes delivery and returns of orders Fulfillment of agreements
The processing is necessary to fulfill an agreement with the data subject.Legitimate interest
The treatment is necessary for ewimed’s legitimate interest in providing products to its customers.
Communication with customers or their representatives, which includes invoicing and customer service. Fulfillment of agreements
The processing is necessary to fulfill an agreement with the data subject.Legitimate interest
The treatment is necessary for ewimed’s legitimate interest in providing products to its customers.
Marketing, which includes invitations to events, sending out information via e-mail, text message and by post as well as customer surveys Legitimate interest
The treatment is necessary for ewimed’s legitimate interest of marketing its business and products.
Fulfillment of legal obligations, such as e.g. accounting obligation according to the Accounting Act (1999: 1078) Fulfillment of legal obligation
The treatment is necessary to fulfill the legal obligations of ewimed.
Training of customers or their representatives in the handling of products Fulfillment of agreements
The processing is necessary to fulfill an agreement with the data subject.Legitimate interest
The treatment is necessary for the legitimate interest of ewimed to ensure that customers use the products in a safe and efficient manner.

Where does the treatment take place?

The processing of personal data takes place mainly within the EU / EEA.

For certain purposes, ewimed can use suppliers established outside the EU / EEA. In the cases where personal data processing takes place outside the EU / EEA, ewimed has ensured that the data subjects’ rights are guaranteed and that the transfer takes place with legal support, e.g. through the use of the EU Commission’s standardized model clauses or through the supplier’s connection to the EU-US Privacy Shield. More information about Privacy Shield is available at www.privacyshield.gov.

In cases where the supplier is to be regarded as a personal data assistant, ewimed has entered into a personal data assistant agreement with that supplier.

Storage time

ewimed will not store your personal data for longer than it is necessary to fulfill the purposes for which the data was collected or as long as ewimed is ​​required to store your personal data by law or to safeguard ewimed’s legal interests, e.g. whether a legal process is in progress. Thereafter your data will be deleted.

How is personal data protected?

ewimed’s goal is that you should always feel safe when you submit your personal information to ewimed. ewimed has therefore taken the following technical and organizational security measures to protect your personal data against unauthorized access, alteration and deletion.

  • Personal data transmitted via ewimed’s website is encrypted and, whenever possible, password protected.
  • Only authorized personnel are given access to personal data.
  • Personal data stored on third-party systems is protected under personal data assistant agreements.

Rights of registrants

Registered persons have the following rights:

  • If the processing of personal data is based on consent, a registered person has the right to revoke the consent for future processing of his personal data at any time.
  • A registered person has the right to request access to and a copy of his personal data (so-called register extracts) free of charge, request correction of incorrect information and, in certain circumstances, request that personal data be deleted.
  • A data subject has the right to demand that ewimed restrict the processing of his personal data
    • meanwhile it is the duty of ewimed to uphold the accuracy of the personal data;
    • if the processing is illegal and the data subject objects to the deletion of personal data and instead requests that the use of personal data be restricted; and
    • if ewimed no longer needs the personal data for the purposes of the processing but the data subject needs the personal data to be able to establish, assert or defend legal claims.
  • A data subject has in some cases a right to data portability, i.e. to obtain personal data provided by the data subject himself in a structured, commonly used and machine-readable format. In cases where ewimed’s right to process the data subject’s personal data is based either on consent or performance of an agreement, the right to data portability also includes a right to transfer the personal data to another data controller.
  • A data subject has the right in certain cases to object to the use of his personal data. If ewimed cannot show compelling legitimate reasons that consider the interest in not having the personal data processed, ewimed must cease processing it.
  • A registrant has the right to object to direct marketing at any time. Following such an objection, ewimed may no longer use the information for that purpose.
  • A data subject has the right to lodge a complaint with a data protection authority. In Sweden, the Swedish Authority for Privacy Protection is the supervisory authority.

Changes to this Policy

ewimed has the right to change this personal data policy at any time. In the event of such changes, ewimed will publish the adjusted privacy policy on its website with information on when the changes will take effect. If ewimed implements significant changes to this personal data policy, we will, if possible, inform you in an appropriate manner.

Contact details

Questions about how ewimed handles your personal data or a request to use your rights should be sent to dataprivacy.se@ewimed.com.