Privacy Policy


Pen Store Sthlm AB (“Pen Store” or “we”) care about your privacy. We therefore want to inform you about how we process your personal data and what rights you have.

This privacy policy applies to those who contact us, receive marketing from us, visit our websites (www.penstore.se, www.penstore.fi, www.penstore.no, www.penstore.dk and/or www.penstore. com), is a customer or partner with us, represents one of our customers, potential customers, suppliers or partners.



In summary, we process your personal data for the following purposes:
• Communicate with you
• Send direct marketing
• To analys your use of our websited and improve the same
• Market analysis
• Administrate our contract with you or the organisation you represent
• Comply with legal obligations


Depending on the relationship we have with you, we process your personal data for all or only some of the purposes described above. Which of these personal data processes that concern you are set out in the privacy policy.


Below you can read more about how and why we process your personal data. We describe what rights you have when we process your personal data e.g. that you have the right to lodge a complaint to the supervisory authority and that you can object to marketing at any time.
We also describe what legal basis we have for the processing and how long we store your personal information.







Below you can read more about:
Who is responsible for the processing of your personal data? 
Must you provide your personal data to us? 
Who has access to your personal data and why? 
Do we share your personal data outside the EU/EES? 
What are your rights? 
Detailed description on how we process your personal data 
Balance of interests 


Who is responsible for the processing of your personal data?
G Group AB with corporate identity number 556797-0073, is responsible (controller) for the processing of your personal data when we process your personal data for our own purposes.
If you have any questions regarding our processing of your personal data, or if you want to exercise any of your rights, please contact us at postal address Hornsgatan 98, 118 21 Stockholm, Sweden.

Must you provide your personal data to us?
We must process some personal data in order to enter into and execute your purchase and/or membership with you and to be able to comply with legal or other requirements. You must therefore provide us with this personal information.

If you do not provide such personal information, you will not be able to make purchases with us or become a member with us. You can read what personal information you have to provide in the tables below where the legal basis is stated to be “fulfill of contract” or “legal obligation”.

Who has access to your personal data and why?
Your personal data is primarily processed by us. The following third parties will have access to some of your personal information as set out below.

• To have a functioning IT system and run our business efficiently, we share your personal data with our IT suppliers. When we share your personal information with our IT providers, it is only done so that they can fulfill their obligations to us in accordance with the agreement we have.

• To administrate your payment, your personal information is processed by our payment service providers. If you choose to pay via invoice, the payment service provider may share your personal information with credit reporting agencies to assess your financial situation.

• To deliver your order and handle any returns we will share your personal information with our carriers.

• To give you and other potential customers targeted marketing, we will share your personal information with relevant third parties such as Facebook and Google as digital channel providers we use.

• If we have an agreement with you or the organization you represent, we may disclose your personal information to our third party who handles our accounting and accounting.

• If you use our website, a third party is used which analyzes the use of the website and therefore may have access to your personal data.

If you want to know more about who we share your personal data with, please feel free to contact us. Our contact details can be found in the beginning of this privacy policy.

Do we share your personal data outside the EU/EES?
We always strive to process your personal data in the EU/EEA. However, in some situations, the personal data may be transferred to and processed in countries outside the EU/EEA. In the case of personal data being processed outside the EU/EEA, there is either a decision by the Commission that the third country in question guarantees an adequate level of protection or appropriate safeguards, in the form of standard contract clauses, binding corporate rules or Privacy Shield, which ensure that your rights are protected.

If you would like to obtain a copy of the safeguards we have taken or information on where these have been made available, you may obtain this by contacting us at the contact details provided at the beginning of this Privacy Policy.

What are your rights?
Under data protection legislation, depending on the circumstances, you are entitled to a variety of rights when we process your personal data. We set these out below.

If you have any questions regarding these rights or if you want to use any of your rights, you are welcome to contact us. Our contact details can be found in the beginning of this privacy policy.

Right to withdraw consent and to object to processing
You have the right to withdraw all or part of the consent you have provided to us for our processing of your personal data.

You always have the right to object to the processing of your personal data for marketing purposes and profiling, such as newsletters and custom marketing. Read more about automated decision-making including profiling later in the policy.

You also have a right to object to our processing of your personal data when the processing is based on the legal basis legitimate interest. Read more about what balancing of interest means below. In some instances, we may continue to process your personal data even if you have objected to our processing. This can be the case if we can show compelling legitimate reasons for the processing that outweigh your interests or if it is for the purpose of establishing, exercising or defending against legal claims.

Right to access
You have the right to obtain a confirmation on whether we process your personal data. If we process your personal data, you also have a right to receive information about how we process the personal data and to receive a copy of your personal data.

Right to rectification
You have a right to have inaccurate personal data corrected and to have incomplete personal data completed.

Right to erasure (“right to be forgotten”) and restriction of processing
You have the right to have your personal data erased in certain instances. This is the case e.g. when the personal data is no longer necessary for the purposes for which it was collected or otherwise processed and where we process your personal data on the basis of our legitimate interest and we find, following your objection (see below under Right to object), that we do not have an overriding interest in continuing to process it.

You also have a right to request that we restrict our processing of your personal data. For example, when you question the accuracy of the personal data, when you have objected to our processing of your personal data based upon our legitimate interest, or where the processing is unlawful, and you oppose to the erasure of your personal data and instead want us to restrict our processing.

Right to data portability
You have a right to in certain instances be provided with such personal data (concerning you) that you have provided to us, in a structured, commonly used and machine-readable format. You also have a right to in certain instances have such personal data transferred to another controller, where technically feasible (“data portability”).

The right to data portability applies to personal data that you have provided to us in a structured, commonly used and machine-readable format if the processing is based on your consent or an agreement and the processing is automated.

Right to lodge a complaint to a supervisory authority
You have the right to lodge a complaint to a supervisory authority concerning our processing of your personal data.

Such a complaint can be filed with the authority in the EU/EEA member state where you live, work or where the alleged infringement of applicable data protection legislation has occurred. In Sweden, the supervisory authority is Datainspektionen.

Detailed description on how we process your personal data
We process personal data that we have received from you or that we have collected ourselves. Your personal data is processed as we describe in the tables below.

Here you can read more in detail why we process your personal data, what categories of personal data we process and what the legal basis for the processing of your personal data is. You can also read about how long we store your personal information.

In our cookie policy you can also read about how we use cookies. You can find our cookie policy here: www.penstore.com/cookies


General processing regardless of our relationship with you



Purpose: To communicate with you
Processing performedPersonal data we processLegal basis
• Answer and manage your communications, such as questions you ask us about our products and/or services or in connection with customer service and support• Identity and contact information

• Information you provide us with
Balancing of interest
The processing is justified by our legitimate interest to be able to communicate with you, for example in order to answer and handle questions from you.
Retention time: We store your personal data for six months from the end of our communication. The personal data can also be stored for a longer time for other purposes. See these retentation times for each purpose.


For you who receives marketing from us



Purpose: To direct marketing to you
Processing performedPersonal data we processLegal basis
• Direct marketing with offers and information

• Send information about your shopping cart if you have left our website without completing the purchase

• Create a correct unsubscribe list, in case you have unsubscribed from our marketing
• Identity and contact information

For customized communication and reminder of shopping cart, we also process:
• Surf history
• Order history
Balancing of interest
The processing is justified by our legitimate interest in sending relevant advertising to you as who is or represent a potential customer or customer to us. You are entitled to object to the marketing when the data is collected and in each sending.

Consent
If you have consented to receive marketing from us, we will send marketing on the basis of your consent. You can revoke your consent at any time.
Retention time: The personal data is stored for one year from ended customer relationship on the basis of a balance of interests. If there is no contractual relationship, data is retained for a maximum of three months if no contractual relationship arises. However, if you are a representative, we will stop storing your personal information if we become aware that you no longer represent the organization. If you have given your consent, we will send marketing until you unsubscribe from our sending. We always stop sending marketing if you unsubscribe from our sending or otherwise object to the marketing.

If you unsubscribe, we will keep your personal information on our "unsubscribe list" for the time being in accordance with marketing law rules so as not to accidentally send marketing to you again.



Purpose: Provide customized marketing in digital channels
Processing performedPersonal data we processLegal basis
• Provide customized marketing in digital channels, social media and third party websites including sharing personal data with relevant third parties such as Facebook and Google as digital channel providers we use.• Identity and contact information

• IP-address
Balancing of interest
The processing is justified by our legitimate interest in being able to share your personal information with third parties who can customize our marketing to potential customers based on information about you who are or represents our existing customer.
Your personal information is processed for this purpose only if you have not objected to marketing.
Retention time: The personal data is stored for one year from ended customer relationship. However, if you are a representative, we will stop storing your personal information if we become aware that you no longer represent the organization. We always stop the processing if you object to it.



For you who visit our websites (www.penstore.se, www.penstore.fi, www.penstore.no, www.penstore.dk and/or www.penstore.com)



Purpose: To analyze your use of and improve our site
Processing performedPersonal data we processLegal basis
• Examine and analyze how our websites (www.penstore.se, www.penstore.fi, www.penstore.no, www.penstore.dk and/or www.penstore.com) are used to be able to take improvement measures• Information from the device you use to visit our website, namely IP address, browser, operating system, Internet service provider and screen resolution. Balancing of interest
The processing is justified by our legitimate interest in being able to develop and improve our website in order to give our users a better user experience.
Retention time: Personal data is collected by placing cookies on your computer and the length of processing of the personal data varies depending on the type of cookie. Some cookies are deleted immediately after your visit to the site while some cookies are stored for a longer period of time. See more in our cookie policy.



Purpose: To provide customer account on our websites upon request
Processing performedPersonal data we processLegal basis
• To create, administrate and manage your account

• Communicate with you regarding your account

• To take security measures, e.g. ensure that only authorized logins.

• Give you the benefits of having a customer account, which includes giving you the opportunity to e.g. use pre-filled information when shopping, to see past purchases, to follow ongoing purchases and to easily manage your newsletter subscription.
• Identity and contact information

• Password

To give you the benefits of having a customer account, we also process:
• The information that you filled in the last time you shop, this includes that we store information about your name, your e-mail address and your postal address

• Order history

• Information about whether you subscribe to newsletters or not
Performance of contract
The processing is necessary for us to be able to create and administrate a customer account according to request and for you to be able to get the benefits that come from having an account, i.e. be able to provide the smoother buying experience that comes from having a customer account.
Retention time: The personal data is stored for two years from the last time you were logged in. You can delete your account at any time and we will then immediately stop storing your personal data for this purpose.



For you who are or represent a potential customer or customer to us



Purpose: To administer the purchase of our products
Processing performedPersonal data we processLegal basis
• To negotiate, enter into, administer and manage agreements with you or the organization you represent

• Make payment

• Send order and delivery confirmation
• Identity and contact information

• Order and payment information (if you are a private person or individual trader)

• Information from our communication with you
If you are a private person or individual trader:
Performance of contract
The processing is necessary for us to fulfill our agreement with you. If the personal information is not provided, you will not be able to make a purchase with us.
Social security numbers are processed for the importance of a secure identification.


If you are a representative:
Balancing of interest
The processing is justified by our legitimate interest in being able to enter into and execute agreements with the organization you represent.
Retention time: We store your personal data for one year after the contractual relationship has ended. However, if you are a representative, we will stop storing your personal information if we become aware that you no longer represent the organization.



Purpose: To handle claims
Processing performedPersonal data we processLegal basis
• Handle and initiate potential claims such as, for example, the withdrawal of purchases, complaint cases and warranty claims• Identity and contact information

• Information from our communication with you in relation to the claim

• Relevant information on you that the claim concerns
Performance of contract
The processing is necessary for us to fulfill our rights and obligations as a result of our agreement with you or the organization you represent.

Legal obligation
The processing is necessary to comply with consumer or purchasing legislation.

Balancing of interest
We also have a legitimate interest in being able to initiate and defend ourselves against potential legal claim.
Retention time: The data is stored from the initiation of the claim and as long as the process regarding the claim is ongoing. If necessary, data may be processed for as long as required by the applicable statutes of limitations. However, if you are a representative, we will stop storing your personal information if we become aware that you no longer represent the organization.



Purpose: To comply with legal obligations
Processing performedPersonal data we processLegal basis
• To comply with legal obligations such as the Accounting Act• Identity and contact information

• Payment information (if you are a private person or individual trader)
Legal obligation
The processing is necessary in order for us to comply with legal obligations such as the Accounting Act.
Retention time: The data is processed for seven to eight years in accordance with the Accounting Act. However, if you are a representative, we will stop storing your personal information if we become aware that you no longer represent the organization.



Purpose: Market analysis
Processing performedPersonal data we processLegal basis
• To carry out market surveys, such as customer satisfaction, views of our offering and potential for development

• Create reports based on answers and conclusions from surveys
• Identity and contact informationBalancing of interest
The processing is justified by our legitimate interest in being able to contact you with a request to evaluate our products and / or services in order to improve them.
Retention time: We store your personal data for six months after a survey. Data may then be anonymized to be kept in aggregate form for a longer period of time.



For you who are or represent potential partner or partner to us



Purpose: To administer the contractual relationship
Processing performedPersonal data we processLegal basis
• To negotiate, enter into, administer and manage agreements with you or the organization you represent

• Make payment
• Identity and contact information

• Payment information (if you are a private person or individual trader)

• Information from our communication with you
If you are a private person or individual trader:
Performance of contract
The processing is necessary for us to fulfill our agreement with you.
Social security numbers are processed for the importance of a secure identification.


If you are a representative:
Balancing of interest
The processing is justified by our legitimate interest in being able to enter into and execute agreements with the organization you represent.
Retention time: We store your personal data during the contract period and one year thereafter. However, if you are a representative, we will stop storing your personal information if we become aware that you no longer represent the organization.



Purpose: To handle claims
Processing performedPersonal data we processLegal basis
• Handle and initiate potential claims such as, for example, the withdrawal of purchases, complaint cases and warranty claims• • Identity and contact information

• Information from our communication with you in relation to the claim

• Relevant information on you that the claim concerns
Performance of contract
The processing is necessary for us to fulfill our rights and obligations as a result of our agreement with you or the organization you represent.

Legal obligation
The processing is necessary to comply with purchasing legislation.

Balancing of interest
We also have a legitimate interest in being able to initiate and defend ourselves against potential legal claim.
Retention time: The data is stored from the initiation of the claim and as long as the process regarding the claim is ongoing. If necessary, data may be processed for as long as required by the applicable statutes of limitations. However, if you are a representative, we will stop storing your personal information if we become aware that you no longer represent the organization.



Purpose: To comply with legal obligations
Processing performedPersonal data we processLegal basis
• To comply with legal obligations such as the Accounting Act• Identity and contact information

• Payment information (if you are a private person or individual trader)
Legal obligation
The processing is necessary in order for us to comply with legal obligations such as the Accounting Act.
Retention time: The data is processed for seven to eight years in accordance with the Accounting Act. However, if you are a representative, we will stop storing your personal information if we become aware that you no longer represent the organization.


Balance of interests
As we state above, for some purposes, we process your personal data and rely on our legitimate interest as the legal basis for the processing. The balance of interest means that we have carried out a balance of interests test where we have determined that our legitimate interest for the processing outweighs yours interests or rights which require the protection of your personal data. We have stated what our legitimate interest are in the tables above.

You are welcome to contact us if you want to read more about how we have undertaken this test. Our contact details are as stated in the beginning of this privacy policy.



__________________________________________________________

This privacy policy was adopted December 20, 2019.