Privacy Policy

1. Data Controller
Invosy Sverige AB
Business ID: 559236-7311
Cylindervägen 12, 7th floor
131 52 Nacka Strand
Sverige

Phone: 010-251 50 60
Email: kundtjanst@invosy.com

2. Person responsible for register matters
Weckström Jörgen
Email: kundtjanst@invosy.com

2. Person responsible for register matters
Invosy customer and user database

4. Registrerade personer
– Owners and employees of companies that use the Invosy software
– Visitors to the website
– Recipients of newsletters and marketing messages
– Partners and service providers

5. Purpose of processing personal data
Personal data is used for the following purposes:
– Providing software services and managing user accounts
– Customer service and communication
– Billing and contract management
– Marketing communication and newsletters (with consent)
– Website analytics and service development

The processing is based on:
– Contracts and customer relationships
– Legal obligations (e.g., accounting law)
– The data subject's consent (e.g., marketing)

6. Contents of the register
Information that may be stored in the register includes:
– Contact information: name, email address, phone number, company, and job title
– Login credentials (email address and hashed password)
– Billing information: invoices, payments, and contracts
– Interaction data: support requests, customer communication, and usage logs
– Analytics data: IP address, browser, device, and website behavior

Data may be requested to be corrected or deleted unless otherwise required by law.

7. Regular disclosure of information
Information may be disclosed to:
– Authorities (e.g., the Tax Agency)
– IT and hosting providers
– Payment and accounting service providers
– Email and analytics platforms (e.g., newsletter and analytics tools)

Data is not sold or disclosed to third parties for marketing purposes without the data subject's consent.

8. Transfer of information outside the EU
Data is primarily stored within the EU/EEA.

If data is transferred outside the EU/EEA, EU-approved safeguards are used, such as standard contractual clauses.

9. Principles for the protection of the registert
Data security is ensured through:
– Data security is ensured through:
– Secure authentication
– Management of access rights (only authorized employees have access to the data)
– Regular system updates and security checks

10. Storage and deletion of information
– Accounting records: 6 years (Accounting Act)
– Customer data: 2 years after the customer relationship has ended
– Analytics data: according to the retention periods of cookies and analytics tools

Data is deleted or anonymized when it is no longer needed for the purpose of processing.

11. Rights of the data subject
The data subject has the right to:
– Receive information about the processing of their personal data
– Review and correct their data
– Request the deletion of data if there is no legal basis for the processing
– Object to or restrict the processing of data
– Withdraw their consent (e.g., for marketing communications)
– Submit a complaint to the data protection authority

Requests for data are processed within 30 days.