In brief
Sistec processes personal data in different roles depending on the service:
- Right to Work Services (RTW): Sistec acts as a data processor.
- Booking, payment and administration: Sistec acts as an independent data controller.
- ID verification via ID scanner connected to ID06: Processing takes place under a third party's data controllership.
- Data controller
- Sistec AB, org.nr 559186‑0548
- Address
- Gustavslundsvägen 151 G, 167 51 Bromma
- Contact
- dpo@sistec.se
1. Introduction
Sistec AB is committed to the protection of personal data and processes personal data in accordance with the EU General Data Protection Regulation (GDPR). This privacy policy describes how personal data is processed within Sistec's various services and what role Sistec has in each processing activity.
This policy concerns the processing of personal data within the framework of business customer relationships.
2. Booking, Payment and Administration
2.1 What personal data is processed
Personal data that may be processed in connection with booking, payment and administration includes, for example:
2.2 Purpose and legal basis
The purposes of the processing are to:
- administer bookings
- process payments
- communicate with the customer
- fulfil contracts and legal obligations
The legal basis for the processing is contract and, where applicable, legal obligation.
2.3 Sharing of data
Personal data collected in connection with bookings is not shared with external parties, apart from technical suppliers who process data according to Sistec AB's instructions, such as providers of payment, IT and booking systems.
2.4 Storage
Personal data is stored only for as long as necessary to fulfil the purposes of the processing and in accordance with applicable legislation, such as the requirements of the Swedish Bookkeeping Act.
3. Right to Work Services
3.1 Division of roles
When providing Right to Work services, Sistec processes personal data on behalf of the customer. The customer is the data controller and Sistec is the data processor.
3.2 Agreements and instructions
The processing is carried out in accordance with the commercial agreement between the parties and the data processing agreement applicable in the individual customer relationship. Sistec applies a standardised data processing agreement, but may in some cases process personal data under the customer's own processing agreement. Sistec processes personal data only in accordance with the customer's documented instructions.
3.3 Data subjects' rights
In RTW services, the customer is responsible for fulfilling data subjects' rights under GDPR. Sistec assists the customer in accordance with the applicable processing agreement.
4. ID Verification via ID Scanner Connected to ID06
When visiting Sistec's offices, ID verification may be carried out using an ID scanner that is technically connected to the ID06 system.
Personal data processed in this context:
- is read directly into the ID06 system,
- is processed under a third party's data controllership.
Sistec AB does not have a data processing agreement or any other data processing arrangement with ID06 AB and is not responsible for third-party processing, storage or deletion of personal data in their system.
4.1 Information to data subjects
Questions about the processing of personal data in connection with ID verification and registration in the ID06 system should be directed to ID06 AB. Processing of personal data in this system takes place in accordance with ID06 AB's own privacy policies and terms.
5. Security
Sistec takes appropriate technical and organisational security measures to protect personal data, including access control, staff training and secure IT environments.
6. Data Subjects' Rights
Rights under GDPR are exercised against the appropriate party depending on the processing:
- For RTW services: against the customer as data controller.
- For booking, payment and administration: against Sistec AB.
Your rights under the GDPR
- Access.You have the right to know whether your personal data is processed and to receive a copy of it.
- Rectification.You have the right to have inaccurate or incomplete data corrected.
- Erasure.You have the right to have data erased, for example when it is no longer needed for its purpose.
- Restriction.You have the right to request that processing is restricted, for example while the accuracy of the data is being verified.
- Data portability.You have the right to receive data you have provided yourself in a structured, machine-readable format when the processing is based on consent or a contract.
- Objection.You have the right to object to processing based on a legitimate interest.
Requests can be sent to dpo@sistec.se.
If you believe your personal data is processed in breach of data protection rules, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), www.imy.se.
7. Cookies and website statistics
How the website uses cookies and similar technologies, and how to change your choice, is described in our cookie policy.
8. Changes to the Policy
This privacy policy may be updated. The version in effect at any given time is published on Sistec's website.
9. Contact
Questions about personal data processing can be directed to:
Sistec AB
Email: dpo@sistec.se