Personal data policy

Stans & Press i Olofström AB, as data controller, protects your personal privacy.

This policy describes how we collect, use, store and protect personal data in accordance with
the General Data Protection Regulation (GDPR, EU 2016/679). The policy applies to employees, job applicants, customers,
suppliers and others whose personal data we process.

These are the personal data we process

Employees:
- Name, social security number, address and contact details
- Employment contracts, salary details and bank details
- Absences, sick leave and some health data
- Information on protective equipment and authorisation
- Time reporting via Monitor ERP
- IT data related to logins and emails, for example
- Questionnaire responses from internal surveys
Suppliers and customers:
- Names and contact details of contact persons
- Correspondence history
- Business and billing information
Jobseekers:
- Name, contact details, CV and cover letter
- References and interviews
Camera surveillance:
We use CCTV in certain areas of our site to prevent and investigate
incidents. Recordings are processed according to the applicable law.

Purpose and legal basis

Purpose Legal basis
Administration of employment contracts Performance of contract and legal obligation
Payroll management and time reporting Performance of contract and legal obligation
Recruitment Legitimate interest or consent
Customer and supplier contacts Performance of contracts and legitimate interest
Compliance with health and safety requirements Legal obligation
Camera surveillance Legitimate interest (security)

Archiving times

- Employees: Up to 7 years after termination of employment
- Recruitment data: Up to 2 years after the end of the process
- Customer and supplier data: For the duration of the business relationship + 7 years
- Camera recordings: Usually 30 days

Systems and external parties

Systems where personal data are processed:

- Visma Payroll: Payroll system
- Monitor ERP: Time tracking, business system
- Outlook (Microsoft 365): Email and correspondence
- No external recruitment tools are used

External parties we share data with:

Part Purpose of the programme
Payroll agency / Visma payroll Payroll management
IT service providers Operation and support of IT environment
Occupational health services Rehabilitation, health assessment, work environment
Teqnion AB Support from the parent company in administrative matters
Authorities E.g. Tax Agency, Social Insurance Agency by law

Handling of sensitive data

Some employees handle sensitive personal data, such as:
- Health data related to sickness absence or occupational health and safety
- Any protected personal data (e.g. in case of confidentiality protection)

This information is treated with a high level of confidentiality and only by specifically authorised persons.

Your rights as an employee, jobseeker, customer and supplier

You have the right to:
- Accessing your data (register extracts)
- Request rectification or erasure
- Object to certain treatment
- Requesting a restriction
- Obtaining data in a structured format (data portability)

To exercise these rights, please contact us at Stans & Press i Olofström AB.

Security and safety

We protect personal data by:
- Restricted and controlled access
- Password protection and secure login
- Encrypted communication
- Regular backups
- Training and instructions for staff
- Procedures for incident management

Complaints

If you think your data is being handled incorrectly, you can contact
The Authority for the Protection of Privacy (IMY)
Website: www.imy.se