STRIA CODE Privacy Notice
Vid skillnad mellan den svenska och den engelska versionen gäller den svenska.
Effective from: [DATE]
Controller: STRIA CODE, company reg. no. [REG. NO.], Klippgatan 20, 171 47 Solna, [email protected] ("STRIA")
If this English version conflicts with the Swedish version, the Swedish version prevails.
This Notice explains how STRIA processes personal data where STRIA is the controller, for example for customer accounts, authentication, customer administration, communications, invoicing and security. Where STRIA processes personal data in a customer's systems on behalf of that customer, the Data Processing Agreement between STRIA and the customer applies instead.
1. Personal data we process
Depending on how you use STRIA, we may process:
- name, work email address and other contact information you provide;
- organisation, company registration number, role and permissions;
- account and authentication data, security settings and MFA/passkey information;
- login, session, IP address, device/browser and security event data;
- messages and other communications with STRIA;
- information concerning requests, Quotes, projects, Deliveries, access mandates and Care to the extent linked to an individual;
- invoicing and administration information;
- information required to evidence agreements, approvals and authorisation actions.
2. Sources
We primarily obtain data directly from you, from the organisation you represent, from other authorised users in the same organisation and from our systems when you use the portal.
3. Purposes and legal bases
Account, portal and customer relationship
We process contact, account and organisation information to create and administer user accounts, provide access to the portal, manage roles and administer the customer relationship.
Legal basis: STRIA's legitimate interest in entering into, administering and performing B2B customer relationships and, where applicable, performance of a contract to which the individual is a party.
Authentication and security
We process login data, IP address, security logs, MFA/passkey information and similar data to protect accounts, prevent misuse, troubleshoot and maintain security.
Legal basis: legitimate interests in information and account security.
Requests, Quotes, projects and support
We process communications and information required to handle requests, issue Quotes, administer Deliveries, support and the contractual relationship.
Legal basis: legitimate interests in providing and administering STRIA's Services and customer relationships.
Invoicing, accounting and legal obligations
We process data required for invoicing, payment follow-up, accounting and other legally required administration.
Legal basis: legal obligation and, for debt administration and enforcement, legitimate interests.
Contract evidence and disputes
We retain information on accepted versions of terms, Quote acceptance, timestamps, authority and relevant logs to evidence what was agreed and to establish, exercise or defend legal claims.
Legal basis: legitimate interests.
B2B communications
We may use work contact details for relevant information about STRIA's existing or related business services. You may object to such communications at any time.
Legal basis: legitimate interests, subject to applicable electronic marketing rules.
4. Recipients
We may disclose personal data to suppliers processing data on our behalf, such as providers of hosting/operations, communications, security, authentication, development and analytics services, invoicing/financial administration and other technical support services.
We may also disclose data to authorities or other recipients where required by law, to protect legal claims or as part of a lawful business transfer.
Suppliers may only process personal data under contract and applicable data protection law.
5. Transfers outside the EU/EEA
Some suppliers may involve personal data being made available outside the EU/EEA. Where such a transfer takes place, STRIA uses a transfer mechanism permitted under GDPR, such as an adequacy decision or the European Commission's Standard Contractual Clauses together with any additional safeguards required in the particular case. Information about the applicable transfer mechanism and how to obtain a copy of relevant safeguards is available on request using the contact details below.
6. Retention
We retain personal data only for as long as needed for the purposes above.
- Active account data is retained while the account or customer relationship remains active and thereafter for the period reasonably required for wind-down, security and contract evidence.
- Security and technical logs are retained for the period reasonably required for security, troubleshooting and incident handling.
- Contract and project records may be retained for the period needed to establish, exercise or defend legal claims.
- Accounting records are retained in accordance with applicable accounting law, normally for seven years after the end of the calendar year in which the financial year ended.
When data is no longer needed, it is deleted or anonymised unless continued retention is required by law.
7. Security
STRIA implements appropriate technical and organisational security measures considering the nature and risk of processing, including as appropriate access controls, authentication, logging, access restrictions and other safeguards suitable for the processing concerned.
No security measure can eliminate all risk. Users are responsible for protecting their credentials and following STRIA's security instructions.
8. When information is required
Certain information is required for STRIA to create and administer an account, verify authority, handle a request or comply with legal obligations. If required information is not provided, STRIA may for example be unable to create or activate the account, issue a Quote, perform an ordered Service or comply with a legal obligation. Registration and portal flows indicate which fields are mandatory.
9. Your rights
Depending on the circumstances, you may have the right to:
- information and access to your personal data;
- correction of inaccurate data;
- erasure;
- restriction of processing;
- object to processing based on legitimate interests;
- receive data in a structured format where the right to data portability applies;
- lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
These rights are not absolute and may be restricted where STRIA has a right or obligation to retain the data.
10. Automated decisions
STRIA does not make decisions about you that produce legal effects or similarly significantly affect you based solely on automated processing, unless expressly stated in connection with a specific function and the legal requirements for such processing are met.
11. Changes
We may update this Notice. The current version is published with a version date. If a change materially affects how we process personal data, we will provide information in an appropriate manner.
12. Contact
Questions about this Notice or our processing of personal data can be sent to:
STRIA CODE
Klippgatan 20, 171 47 Solna
[email protected]
Company reg. no. [REG. NO.]