Privacy Notice
Last updated: [DATE YOU PUBLISH]
This notice explains how Unifire AB handles personal data collected through unifire.com and in connection with our products and services.
Who we are
The data controller is Unifire AB, org.nr 556265-0399., Exportgatan 33D, 422 46 Hisings Backa, Sweden. For any question about this notice or about your personal data, write to le***@*****re.com.
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. Data protection enquiries are handled at the address above.
What we collect, why, and on what basis
We collect personal data for the purposes set out below. For each purpose we state the legal basis we rely on under Article 6 GDPR and how long we keep the data.
| Purpose | Data | Legal basis | We keep it for |
|---|---|---|---|
| Answering enquiries sent through our contact form or by email | Name, email address, the content of your message, and anything else you choose to include | Article 6(1)(b) where your enquiry concerns a possible purchase (steps prior to a contract); otherwise Article 6(1)(f), our legitimate interest in responding to people who contact us | 24 months from our last exchange with you |
| Sending our newsletter | Email address, the date you subscribed, and whether you opened or clicked | Article 6(1)(a) — your consent, which you may withdraw at any time | Until you unsubscribe. We keep the record of your consent for 12 months after that as proof |
| Handling orders, deliveries, support and warranty | Contact and company details, order, delivery and service records | Article 6(1)(b), performance of our contract with you; Article 6(1)(c) for the accounting records we are required to keep | For the length of the relationship, then 7 years for accounting records (bokföringslagen) |
| Understanding how the website is used | IP address, device and browser type, pages viewed, referring site | Article 6(1)(a) — your consent, given through the cookie banner | 14 months |
| Marketing and audience measurement on social platforms | Online identifiers and browsing behaviour on our site | Article 6(1)(a) — your consent, given through the cookie banner | As set out per cookie in our cookie policy |
| Keeping the site secure and available | IP address, server request logs | Article 6(1)(f), our legitimate interest in the security and availability of our systems | 12 months |
| Considering job applications | Your application, CV and our correspondence with you | Article 6(1)(b), and Article 6(1)(a) where you agree to us keeping your details on file | 6 months after the decision, unless you agree to a longer period |
Where you contact us through our website, providing your name and email address is necessary for us to reply. There is no other consequence if you choose not to provide them.
Cookies and similar technologies
We use cookies and similar technologies on unifire.com. Strictly necessary cookies are set automatically because the site cannot work without them. Everything else — preferences, statistics and marketing — is only set if you consent through our cookie banner.
You can change or withdraw your choice at any time through the “Cookie settings” link in the footer of every page. Withdrawing is as easy as giving consent and has no effect on anything done before you withdrew.
Our cookie policy lists every cookie we use, who sets it, what it does and how long it lasts.
Who we share your data with
We do not sell personal data and we do not share it with third parties for their own marketing.
We share personal data with service providers who process it on our behalf and under our instructions: our website host and IT providers, our email and newsletter provider, and our analytics and advertising providers where you have consented to those cookies. Each of them is bound by a data processing agreement under Article 28 GDPR.
We may also disclose personal data where we are legally required to do so, or where it is necessary to establish, exercise or defend legal claims. If our business or part of it is sold or reorganised, personal data may transfer as part of that transaction; we will tell you before it happens and before your data becomes subject to a different privacy notice.
Transfers outside the EEA
Some of our service providers are located outside the European Economic Area, principally in the United States. Where personal data is transferred outside the EEA, we rely on one of the following safeguards under Chapter V GDPR: an adequacy decision of the European Commission covering the recipient country or, for recipients in the United States, certification under the EU–US Data Privacy Framework; or the European Commission’s Standard Contractual Clauses, together with any additional measures required by the circumstances of the transfer.
You can request a copy of the safeguards that apply to a particular transfer by writing to le***@*****re.com.
Your rights
Under the GDPR you have the following rights in relation to your personal data:
- Access — you can ask us to confirm whether we hold personal data about you, and to give you a copy of it together with information about how we use it (Article 15).
- Rectification — you can ask us to correct data that is inaccurate, or to complete data that is incomplete (Article 16).
- Erasure — you can ask us to delete your personal data where there is no longer a good reason for us to keep it (Article 17).
- Restriction — you can ask us to pause our use of your data while a dispute about its accuracy or our grounds for using it is resolved (Article 18).
- Portability — where we process data you gave us on the basis of consent or a contract, and we do so by automated means, you can ask for it in a structured, commonly used, machine-readable format, or ask us to send it directly to another controller (Article 20).
- Objection — you can object to processing we carry out on the basis of our legitimate interests, and we will stop unless we can show compelling grounds that override your interests. Where we process your data for direct marketing, you can object at any time and we will stop without exception (Article 21).
- Withdrawal of consent — where we rely on your consent, you can withdraw it at any time. This does not affect the lawfulness of anything we did before you withdrew (Article 7(3)).
To exercise any of these rights, write to pr*****@*****re.com. We will respond within one month. If your request is complex or you have made several, we may extend that by up to two further months and will tell you if we do. There is no charge. We may ask you for information to confirm your identity before we act, so that we do not disclose your data to someone else.
Complaints
If you are unhappy with how we have handled your personal data, please tell us first — we would rather put it right. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state where you live, where you work, or where you believe the problem occurred.
The Swedish supervisory authority is Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, im*@*my.se, www.imy.se.
Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss and misuse, and we review them as our systems change.
Children
Our website and products are aimed at businesses and professional users, not children, and we do not knowingly collect personal data from children. In Sweden, where an online service is offered directly to a child and relies on consent, that consent is valid from the age of 13 (Article 8 GDPR as implemented by lag (2018:218)). If you believe a child has given us personal data, contact us and we will delete it.
Automated decision-making
We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
Changes to this notice
We review this notice at least annually and whenever we change how we use personal data. The date at the top shows when it was last updated. If we make a material change we will make that clear on the website.
