Data protection regulation and Werksta Sweden’s handling of personal data

This page provides information on how Werksta processes personal data for registered persons in the archiving systems.

Controller

Werksta Sweden AB, Rinkebyvägen 11b, 182 36 Danderyd, www.werksta.se , kundcenter@werksta.se, 020 62 29 00

The Data Protection Regulation, or GDPR (General Data Protection Regulation), is a new EU joint regulation that applies throughout the EU from May 25, 2018. The GDPR replaces the Swedish Personal Data Act (PuL) and is designed to strengthen the individual’s rights.

The personal information we collect about you is necessary for us to be able to handle you as a customer, fulfill our contractual obligations and provide our services. The information may also be used for marketing through, for example, letters or mail. Personal data is stored no longer than necessary. More information about how we handle your personal information can be found below.

Cookie Policy

Cookies are small text files that are saved on your computer, phone or tablet when you visit the site. Cookies help the site remember your settings (such as user names, languages, text size and other preselecions) over a certain period of time. The idea is that you should not have to redo the settings each time you enter the site or browse between different pages.

In a cookie, it is possible to see / follow a user’s browsing and we use cookies to administrate and customize your visits to our website. You can read more about the different types of cookies that we use on the website in the other tabs on this page.

We do not save any personal information via cookies. The statistics cannot be linked to a person.

Our scripts – The cookies we use

Functional cookies

We use the cookies that are required to ensure the effective functioning of the website. These include cookies that relate to the website’s language selection and the customer chat service.

Statistical cookies

We monitor how the site is used for statistical purposes using Google Analytics. No personal information that could identify the user is sent to Google Analytics. The information that is processed for statistical purposes enables us to analyze and thereby develop our business activities and improve our customer service. You can opt out of the compilation of statistics performed with Google Analytics with a separate add-on.

Advertising Cookies

We target our advertising based on how our site is used by using the advertising features of Google Analytics, Google’s advertising services, and Facebook’s Pixel service. You can change Google’s advertising settings here and ad settings for your Facebook username here.

You can revoke your consent to the focus on advertising here.

How can you control your cookies?

To find out more about cookies, including how you can see which cookies have been placed on your device and how you can manage and delete them, visit www.allaboutcookies.org or www.minacookies.se.

You can delete all cookies that are on your computer and you can set the browser so that it does not receive any cookies. In this case, you may need to redo certain settings each time you access a site and some services and features may not work.

Privacy Policy – information on handling of personal data

Your integrity is important to us and we therefore strive to protect your personal information in the best possible way. In this document you will receive information on how we, as personal data controllers, process all personal data collected about you by us when you or the company you represent makes a purchase or submits a vehicle for service or repair,

If you have any questions regarding our processing of your personal data or if you want to exercise any of your rights that we describe below you are welcome to contact us at Werksta by sending an e-mail to GDPR@werksta.se or calling 08-622 92 00 and ask for the data controller.

1. Personal data that we process about you

The personal information we process is the information that you have provided to us or that we have collected from you or a third party.

Personal information that you have provided to us

When you as a customer enter into an agreement with us, you will provide some information about you. The information you provide may be, for example, name, registration number, social security number, insurance company, customer number, car owner number, card number and contact and address details. We may also process other personal information about you that you provide to us as a customer.

Personal information we have collected from you or a third party

When you submit a vehicle to us for service or repair, we may collect registration numbers, insurance cover and information stored in the vehicle’s computer. It is information that is mainly of a technical nature, eg. error codes and service history relating to the vehicle. We may also collect data on completed troubleshooting and what work has been done, including any products that have been repaired, replaced or installed.

When you enter into a service agreement with us, we may collect information about your purchase, your service or repair, payment and information about the vehicle’s chassis number or so-called. VIN number. We may also process your personal information which we will have access to through searches in the Swedish Transport Agency’s road traffic register, primarily contact information and registration number.

The personal data mentioned above may be processed by you even if someone else submits your vehicle to us for repair or service on your behalf. If you submit a vehicle that someone else is registered as the owner of or as a representative of a company, we treat your name, your social security number and your contact information.

Personal information that we collect through our mapping service

Our site includes the Google Maps map feature. Google treats personal data (embedded) controls according to its Privacy Policy and Terms of Use for Maps (“Additional Terms of Use for Google Maps /Google Earth). The user can locate his nearest workshop based on approximate location or location or exact location of the shipment via its terminal equipment (computer, mobile or tablet) .The exact location processing is based on consent given by the user when he / she allows his terminal equipment (computer, mobile or tablet) to send information about his location to our web service. in a form that does not allow user identification, the user can revoke their consent via the settings in their terminal equipment (computer, mobile or tablet).

Electronic services, marketing, customer acquisition and recruitment

The technical implementation of our online services requires the processing of electronic identification data. We measure the use of our online services for statistical purposes and conduct online marketing based on our user services and visitor information. Providing online services, statistics and electronic marketing is part of Werksta’s legitimate interest in conducting and developing its business. With the online services we provide, we make it easier and faster to get in touch with our customers and contact them at the right time. With the information we deal with in the statistics for online services, we can analyze and develop our business and improve our service level. With the information we deal with for electronic marketing, we can share our services on our electronic channels and guide you through our online service.

Online service information marketing and advertising is based on the data subject’s consent. Consent is expressed by continuing to use our online services after closing the cookie notification. For more information about canceling consent and using cookies, visit our cookie policy.

2. Objectives and legal basis for the treatment of your personal data

The legal basis for the processing of personal data is the Data Protection Regulation (EU 2016/679) Article 6 (1) (a), (b), (c) and (f). For the following purposes, we treat your personal data to fulfill our agreement or take action that you request before entering into an agreement:

– If you as a customer or representative of a company make a purchase, submit a vehicle for service or repair, we treat your name, personal number, registration number or other identification number on the vehicle, your customer number, your vehicle number, your contact and address details and your card number in order to administer our customer relationship including your payment. We also handle these details to fulfill our obligations arising from the agreements you have entered into with us and to provide you with the information about the products and services that you have requested from us, eg. to send service reminders during an ongoing service agreement the way you have chosen, ie. via SMS, mail or postal mailing. Processing of information stored in the vehicle’s computer may need to be processed in order to perform service and maintenance or to be able to do troubleshooting and determine and correct faults on the vehicle.

– If you request a quotation from us, we will treat your name, your contact details and details of the quotation during the period of validity of the quotation in order to be able to contact you to follow up the quotation and take action at your request before any agreement is entered.

– In order to handle any complaints or to be able to fulfill any warranty obligations that follow from our agreement with you or the company that you represent, we treat your name, your contact details, the registration number or other identification number on the vehicle, details of your purchase and completed troubleshooting and the work done, including information on any vehicles, parts or products that have been repaired, replaced or installed.

– In order to be able to determine your identity and request credit checks when this is required under the agreement, we treat information about your name and your social security number and information about your financial situation. The processing of your social security number is clearly justified with regard to the importance of a secure identification. The information is a contractual requirement and if the information stated above is not provided to us, we are not able to fulfill our agreement or fulfill our obligations in relation to you.

For some purposes, we treat your personal data on the basis of a balance of interests as a legal basis for the processing. In the balance of interests we have considered that our legitimate interest in carrying out the treatment weighs heavier than your interest and your fundamental rights of not receiving your personal data. What is our legitimate interest is shown below. If you want to know more about how we have made this assessment, you are welcome to contact us. Our contact details can be found at the beginning of this privacy policy.

For the following purposes, we treat your personal data on the basis of a balance of interests:

– If you request a quotation from us, we will treat your name, your contact details and information about the quotation with the support of our legitimate interest in being able to facilitate you as a potential customer and to send marketing to you. The purpose of the treatment is to be able to contact you and follow up the quotation and send direct marketing via e-mail, sms and postal mailings so that you can get an updated quotation with the same information and options as for the quotation’s issue. This is because it is an extensive work to produce a quote for a vehicle, with options, models and payment options.

– We treat your name and your contact details such as e-mail, phone number and address to be able to communicate with you as a customer or representative of the customer by sending direct marketing and newsletters, reminders of service and customer surveys by mail, email or SMS. Our legitimate interest is to be able to communicate with you who previously made a purchase.

– We treat your name and contact information to be able to communicate with you as a potential customer by sending direct marketing and newsletters via mail, e-mail or SMS. This applies provided that you have provided your personal data voluntarily, eg. in connection with a customer evening or the like, or that we have collected your contact information as a representative of a company or organization. Our legitimate interest in processing your personal data is to be able to communicate with you as a potential customer for marketing purposes.

If you submit the vehicle on behalf of someone else or enter into an agreement with us as a representative of a company, we may process information about your name, your contact and address information and information about the vehicle to the extent necessary to fulfill our commitments in relation to our customer. Our legitimate interest in processing your personal information is to be able to communicate with you as a contact person and to follow up who submitted the vehicle with us.

– We handle data that is linked to the vehicle, eg details of completed faults and any previous work, including information on any parts or products that have been repaired, replaced or installed to perform safe repair and service on the vehicle. The processing of such data is done for safety reasons so that the correct repair and / or service can be performed on the vehicle. We treat these data for our legitimate interest in being able to demonstrate that we meet the requirements of each vehicle manufacturer, by being able to see which previous measures have been carried out for safety reasons and for facilitating the owners of the vehicle during service.

– In addition to the processing of your personal data as stated above, we also perform treatment that is necessary to comply with applicable law, regulation or governmental decisions. E.g. We save information about your agreement with us and purchase history to the extent necessary to comply with applicable accounting law and tax legislation.

For the following purposes, we treat your personal data on the basis of your consent:

We deal with job applications we receive regarding a particular position or an open job application based on consent. When applying for a service, the recruitment of the specified contact person is handled in the ad. Some recruitments are handled by more people than the contact person in the ad. The candidate can also be moved between different recruitment steps to make it easier for the recruiter. Recruiters can also download a list of candidates with names, phone numbers and mail and create a file containing the candidates’ attached documents (CV, personal letter, portfolio, etc.), which is often done prior to an interview. Recruiters can communicate with the candidates, eg. when updating the recruitment process. Employee saves, uses and possibly disseminates your personal data in order to process your application, subscription and / or contact, and thereby becomes the personal data controller and is committed to not disclosing your personal data to unauthorized persons. However, this does not mean that they will not share your personal information with others who need them to administer your application / contact (eg external recruitment companies). Your personal data will not be distributed outside the EU / EEA. All applications are handled manually and do not go through any automated profiling.

– Our online service includes a Google Maps map feature. Google processes personal data by an independent registrar privacy policy and maps the tool user terms accordingly. With the help of the service on our website, it is possible for the user to find out the nearest location he or she has specified or the exact location sent via his terminal equipment (computer, mobile or tablet). Exact location processing is based on consent provided by the user when he / she allows their terminal equipment (computer, mobile or tablet) to send information about their location to our web service. The site is sent to Google in a form the user cannot identify. The user can withdraw their consent via the settings in their terminal equipment (computer, mobile or tablet).

3. Who can get access to your personal data?

Your personal data will only be processed by us as a starting point. However, we will share your personal information with other actors. These actors are mainly general agents and vehicle manufacturers, the Swedish Transport Agency and insurance companies.

We will also share your personal information with operators who process personal data on our behalf, so-called personal data assistants. For marketing purposes, we may share your contact information with advertising agencies and printers for example. print and distribution of mailings. For online services and online marketing, we use the advertising features of Google Analytics, Google’s advertising services, and Facebook’s Pixel service.

Our IT suppliers and any other suppliers we use may also have access to all the personal data we deal with about you, however, only to the extent that this is necessary for the purpose of fulfilling their obligations in relation to us.

Your personal data will also be disclosed to the following actors who are personally responsible for their personal data processing:

– For payment or credit information, we may share information about your card number or personal identification number, as well as information about your financial situation to payment intermediaries and credit companies.

We may disclose your personal information to insurance companies when you submit a vehicle for service or repair. We may also disclose your contact details and repair information about your vehicle to the vehicle manufacturer or the general agent. Exactly which personal data the vehicle manufacturer or the general agent deals with about you as the data controller, the vehicle manufacturer or the general agent has a responsibility to inform you about. We and our partners generally only treat your personal data within the EU / EEA. No personal data is transferred outside the EU / EEA. In addition to what is stated above, our partners, e.g. Vehicle manufacturers, general agents and insurance companies collect your personal information directly from you for your own account. For such information, our partners’ personal data controllers are responsible for informing you about the treatment.

4. how long do we save your personal data?

According to our retention policy, we never treat your personal data for a longer period of time than is permitted by applicable law, regulation, practice or governmental decisions. Personal data that we deal with in order to fulfill our agreement with you is treated as a starting point during the time it is necessary for us to be able to administer the contractual relationship and fulfill our obligations in relation to you. In order to comply with mandatory law, because you have given your consent to it or because we have the right to do so according to a balance of interests, we may, however, save your personal data for a long time in accordance with the below.

– For accounting purposes, we save information required under such law on our agreement with you for seven years, in accordance with applicable accounting legislation.

– In accordance with applicable legislation, we have the right to store your contact information for direct marketing for a period of time after your purchase or after our agreement has expired. Depending on what the agreement concerns, this time is different.

– If you request a quotation, we will save your name, contact details and details of the quotation in order to be able to contact you and follow up the quotation and send direct marketing via e-mail, text message and postal mailings during the time that the quotation is valid and during one period thereafter of a total of a maximum of twelve months from registration of the personal data and the issuance of the offer in order to facilitate for you and be able to offer you an updated quotation with the same information and options from the issue.

– If you have submitted your vehicle for repair or service, we will save your contact details for two years from the time the service or repair was carried out. We believe we have a legitimate interest in saving your information during this time, as a customer you typically expect information from us as a workshop when it is time to service your vehicle again, which normally takes 12-24 months after the previous service.

– For our online services and electronic marketing through Google Analytics, Google’s advertising services and Facebook’s Pixel service where you as a customer have provided personal information voluntarily, or e.g. in connection with a customer evening or the like, we save your name and contact information for marketing purposes for a period of maximum twelve months from that the information was received from you.

– Information in connection with job applications is saved for a maximum of seven months after the current service has been appointed.

– To be able to handle any complaints or warranty commitments, we save your name, your contact details, the registration number of your vehicle, details of your purchase, troubleshooting and the work that has been carried out and which parts or products have been repaired, replaced or installed for three years from the day the vehicle was delivered, the repair or service was carried out and from the issue of the guarantee. The personal data is saved for three years, taking into account that a vehicle is a rare purchase item and we, in order to handle your statutory right to a complaint on the vehicle, repairs or service, will need to see what work has been done and which parts or products have been repaired replaced or installed.

– We may save vehicle data relating to your vehicle, eg information about service events, during the time the vehicle is in operation. This information is only stored together with the vehicle registration number and / or chassis number and not together with your contact details. The information is saved during the time the vehicle is in operation for our legitimate interest in being able to offer future owners of the vehicle information about service and maintenance work that has been carried out on the vehicle and in order to be able to follow the vehicle’s history. This means that the data remains even if the vehicle changes owner.

Your personal data can be saved longer than stated above in so far as we are obliged to do so by law, regulation or governmental decision.

5. The rights of the registered

According to the Data Protection Ordinance, you have several rights regarding the processing of your personal data.

Revoke a given consent

A consent only needs to be obtained if we cannot support our processing of personal data on any other legal basis. If you have given consent for any treatment, eg Because we want to make treatments that go beyond the agreement or what fits within a balance of interests, you have the right to revoke all or part of a given consent at any time. The revocation of your consent does not affect the legality of consent-based processing before it is revoked.

Right to access

You have the right to receive confirmation of whether personal data concerning you is processed and to have access to information about how the personal data is processed, for example. the purposes of the treatment and the categories of personal data that the treatment applies. You also have the right to receive a copy of the personal data that is being processed.

Right to correction

You have the right to rectify incorrect personal data without undue delay, and to supplement incomplete personal data, taking into account the purpose of the processing, for example. by providing additional information.

Right to erase (the right to be forgotten)

You have, under certain conditions, the right to request deletion of your personal information from us. Such conditions exist if the personal data are no longer necessary for the purposes for which they were collected or processed, if you withdraw your consent on which the treatment is based and there is no other legal basis for the treatment, if you object to the treatment and there is no justification reasons to continue with the treatment that weighs heavier, when the personal data has been illegally processed or if the personal data must be erased in order to fulfill a legal obligation to which we are subject.

You do not always have the right to be deleted. For example, if we need your personal data in order to be able to complete an agreed contract with you or to administer a complaint case, the data need not be deleted. We may also process data linked to the vehicle, eg. details of completed troubleshooting and any work that has previously been carried out, including information on any parts or products that have been repaired, replaced or installed to be able to perform secure repair and service services on the vehicle during the time the vehicle is in operation, connected to and car registration number and / or chassis number.

Right to limitation of treatment

Under certain conditions, you have the right to request that the processing of your personal data be limited. Such conditions exist if you dispute the correctness of the data (however, only for a time that allows us to check this), if the processing is illegal and you oppose the deletion of the personal data and instead request a limitation of the use of the data, if you need the personal data to do Please be asserted or defend legal claims even though we no longer need the personal data for the purpose of the treatment or if you have objected to the treatment pending verification of whether our legitimate reasons to treat your personal data outweigh your reasons. The personal data does not need to be limited if all the information we process is accurate and necessary to fulfill an agreed contract with you.

Right to object to treatment

You have the right at any time to object to the processing of your personal data based on a balance of interests. We may no longer process personal data unless we can demonstrate mandatory justification for the treatment that outweighs your interests, rights and freedoms or whether it is for the purposes of the determination, exercise or defense of legal claims. You also have the right to object to your personal data being processed for marketing purposes. If you object to marketing, your personal data will no longer be processed for such purposes.

You cannot object to such treatment that is necessary for us to be able to fulfill an agreed agreement with you.

Right to lodge complaints

You have the right to lodge a complaint with the Swedish Supervisory Authority Datainspektionen or another competent supervisory authority that supervises the processing of personal data. You have the right to file a complaint with a supervisory authority in the country where you have your domicile, your workplace or where the alleged infringement was committed. If you believe that Werksta violates the Data Protection Ordinance and you suffered material or immaterial as a result, you may request compensation for this. The data inspection is reached by telephone 08-657 61 00, e-mail datainspektionen@datainspektionen.se and telefax 08-652 86 52. The postal address is Datainspektionen, Box 8114, 104 20 Stockholm.

Right to data portability

You also have the right, under certain conditions, to get out the personal data that you have and which you have submitted to us in a structured, generally used and machine-readable format and have the right to transfer these to another person responsible for data (data portability). The right to data portability exists when the treatment is based on an agreement or on an agreement and the processing is done automatically. You have the right to transfer the personal data directly from the company to another data controller when this is technically possible.

Contact Us

If you want to exercise your rights as described above or otherwise want to get in touch with us due to our processing of your personal data, you can do this by contacting us by mail or email. Our contact details are shown above. This information on the processing of personal data was established by Werksta Nordic AB on 2018-05-21.

6. Summary of objectives, legal basis and retention limits

Purpose Personal data processed Legal grounds Retention period Time when the retention period deadline begins to run
Prospects that has received the quotation in order to process the offer Name, contact details and quotation. To take action at your request before entering into an agreement. During the time that the quotation is valid When the quotation is submitted to the customer.
Prospects that has received a quotation in order to market. Name, contact details and quotation. Balancing of interests Twelve months from the quotation's issue When the quotation is submitted to the customer.
Other prospects Name, contact details Balancing of interests Twelve months from The data was collected from you or three months from the time that the data was collected from third parties for business customers. Collection
Administer the customer relationship, eg send reminders about service Name, contact details, vehicle details, contract details Necessary to fulfill agreement During the time of the agreement When the agreement is concluded.
Manage payment and credit information Name, contact details, card details, social security number and / or information about the data subject's financial situation when paying by credit Necessary to fulfill the agreement During the time the payment is made. This time can be different depending on whether the agreement relates to the purchase or leasing of a vehicle When payment is to be made
Perform safe repairs and service Data associated with the vehicle, e.g. details of completed troubleshooting and any previous work, including information on any parts or products that have been repaired, replaced or installed Balancing of interests During the time the vehicle is in operation When the vehicle is taken in operation
Manage promotions and fulfill warranty obligations Names, contact details and details of the vehicle such as completed troubleshooting and any work previously performed, including information on any parts or products that have been repaired, replaced or installed Necessary to fulfill the agreement and necessary to fulfill legal obligation Three years from purchase or service / repair and during the warranty period applies When the vehicle is delivered to the customer, in the case of service / repair and from the execution of the guarantee
Marketing via e-mail, SMS and postal mailings Name and contact details Balancing of interests. The company has a legitimate interest in sending marketing to existing or previous customers Customer who has performed service or repair: Two years When the latest service or repair was done
Treat yourself as a contact person (representative) for our customer Name, contact and address details and details of the vehicle Balancing of interests During the time of the agreement When agreements are made
Job applications we receive regarding a particular position or an open job application Name, telephone number and e-mail and create a file containing the candidates' attached documents (CV, personal letter, portfolio, etc.) Consent Information in connection with job applications is saved for a maximum of seven months After the current service has been appointed
For our online services and electronic marketing through Google Analytics, Google's advertising services and Facebook's Pixel service where you as a customer have provided personal information voluntarily, or e.g. in connection with a customer evening or similar Your name and contact details for marketing purposes Consent For a maximum of twelve months Beginning from when the information was received from you.