InExchange respects your privacy. This Privacy Statement outlines your rights to privacy and our commitment to safeguarding your personal data.
InExchange is a European corporation, with legal entities, business processes, management structures and technical systems that cross borders. InExchange delivers software and services to private and public businesses (Customers) in Europe.
InExchange head office is located in Skövde. and is subject to European privacy legislation, including the General Data Protection Regulation (GDPR).
All major decisions regarding privacy in InExchange are made at a corporate level supervised by the Data Protection Officer (DPO).
How and when does the privacy statement apply?
This Privacy Statement applies to all business processes in InExchange and to all InExchange websites, domains, mobile solutions, cloud services and communities as well as InExchange branded websites. Service specific appendices will be found in the Terms of Service, data processing agreements or equivalent information for the specific service in question.
The Privacy Statement provides information about data processing carried out by InExchange when InExchange determines the purpose and means of the processing (InExchange act as data controller). It also provides information on data processing InExchange do on behalf of our Customers based on their instructions (the Customer as data controller and InExchange as data processor).
Personal data is information that can identify you as a person, such as an email address, street address or phone number etc. Processing your personal data is necessary for us to serve our Customers. Please do not use InExchange Sites or our services if you do not agree with how we process personal data according to this Privacy Statement.
Whoes personal data does InExchange process?
InExchange process data about jobseekers, contact persons and software users among our Customers, including persons representing potentially new Customers that approach us via InExchange Sites or other channels. Our statement in these regards is to be found in the data controller section.
We also process data about our Customers’ employees and other persons’ data of which the Customer controls. Our statement in these regards is to be found in the data processor section.
In this Statement data subjects may also be referred to as persons or you.
How does InExchange Process Personal Data as Data Controller
When a InExchange subsidiary determines the purpose and means of processing your data, this company act as data controller. This includes scenarios where InExchange collects personal data in the context of you being a job seeker, you being a representative for a Customer or Lead, or when you are a software user.
Why we process your personal data
About Customer contacts and software users
To manage our Customer relations in general and to meet our Customer commitments, InExchange needs information about you in your role as Customer contact person or user of a service. The purposes of processing this personal data are:
a. Execute sales and contract process to Customers
b. Provide requested offers on products and services to Customers
c. Perform deliveries in accordance with agreements made with you or Customers
d. Offer support to users of our products and services
e. Improve and develop the quality, functionality and user experience of our products, services and InExchange Sites
f. Detect, mitigate and prevent security threats and perform maintenance and debugging
g. Prevent abuse of our products and services
h. Process orders, invoicing, payments and other financial follow-up
i. Create interest profiles in order to promote relevant products and services
j. Operate user communities to educate and enable interaction between users and InExchange
The legal ground for processing personal data according to the above-listed purposes in letter a) to i) is mainly because InExchange has a legitimate interest in processing your personal data from a business perspective in a manner that we believe do not conflict with your privacy rights or freedoms. The legal ground for processing personal data according to the purpose listed in letter j) is your consent.
InExchange process personal data about Leads for marketing purposes. In order to provide targeted and relevant content to potential Customers, InExchange builds an interest profile based on your movement, choices and actions on InExchange Sites as well as your response to marketing content per email. The legal grounds for such processing is mainly your consent.
You can read more about how we create such profiles, how you can adjust the profile as well as withdraw your consent in the sections below.
If you are a jobseeker, we process personal data in order to evaluate your potential to become a InExchange employee. The legal grounds for such processing is your consent.
In order to monitor access to our premises, we process personal data about visitors. The processing is based on our legitimate interest to protect our business secrets, employees, premises and you as a visitor. You will be informed of your rights in this context when you register in our electronic visitor system.
How we collect your personal data
In general, InExchange collects personal data directly from you or other persons linked to our Customer. These persons may be a manager or colleague. If the Customer you work for purchases InExchanges products or services via a InExchange partner company, we may collect information about you from the partner company.
In some cases, we may also collect information about you from other sources. These sources may be third-party data aggregators, InExchange marketing partners, public sources or third-party social networks. InExchange will be able to combine personal data about you obtained from one source with data obtained from another source. This gives us a complete picture of you, which also gives us the possibility of serving you in a more relevant way with a greater degree of personalisation.
Automatic data collection polls
InExchange uses different digital tracking technologies to collect information about your movements on InExchange Sites and when interacting with us.
Cookies and pixel tags
Pixel tags are scripts that executes when a user lands on a website or opens an email. The pixel itself is not visible and can only be seen in the HTML of the site or email. It calls an application on a server that will cause a third party cookie to be downloaded to your computer or registers that the email has been opened.
If you would like to know more about cookies and how they work, please visit www.allaboutcookies.org.
InExchange uses the digital marketing software, Eloqua, provided by Oracle that places cookies in order to recognize a return visitor as a unique user. Eloqua is used to register your behaviour on our sites and how you interact with us per email in order to increase the likelihood of providing marketing content according to you and our Customer’s interest. The cookies placed by Eloqua cannot access, read or modify any other data on your computer. InExchange is committed to ensure you a right to adjust your interests and to manage the extent of digital marketing from us through a subscription management system.
Google cookies and technologies
Google Analytics: This cookie allows us to see information on user website activities including, but not limited to page views, source and time spent on a website. The information is depersonalized and is displayed as numbers, meaning it cannot be traced back to individuals. This will help to protect your privacy. Using Google Analytics we can see what content is popular on our websites, and strive to give you more of the things you enjoy reading and watching.
Google Analytics Remarketing: Places cookies on your computer which means that after you leave our website, Google can show you advertisements about InExchange that you might be interested in, based on your previous behaviour on our website. This information is not personally identifiable.
Google AdWords: By using Google AdWords code, we are able to see which pages helped lead to contact form submissions. This allows us to make better use of our paid search budget. This information is not personally identifiable.
Google Adwords Remarketing: Places cookies on your computer which means that after you leave our website Google can show you advertisements about InExchange that you might be interested in, based on your previous behaviour on our website. This information is not personally identifiable.
You can prevent the information generated by the Google cookie about your use of our Sites from being collected and processed by Google in the future by downloading and installing Google Analytics Opt-out Browser Add-on for your current web browser. This Add-on is available at tools.google.com/dlpage/gaoptout.
Facebook Remarketing: the Facebook pixel tag places cookies on your computer which can send an alert back to Facebook telling Facebook that you have checked out the website. We then assume that you have an interest for InExchange and the content on this site. When visiting Facebook, you will then be exposed to information or adds with similar content. Please use your privacy settings on Facebook to limit exposure to marketing of this kind.
What personal data we process
The type of personal data that InExchange process about you may be:
- Basic contact details such as name, address, telephone number and email.
- Demographic Information such as date of birth, age and gender
- Employment information such as employer, title, position including preferences and interests in professional context
- Feedback, comments or questions about InExchange or concerning our products and services
- Photos or video of you recorded at our premises
- Content you have uploaded such as photos and video
- Unique user information such as login ID, username, password and security questions
- Financial information such as credit card information
- Traffic information as provided by your web browser such as browser type, device, language and the address of the website from which you arrived and other traffic information such as IP address
- Clickstream behaviour and movement on InExchange Sites and in our products and services
- Email behaviour such as which emails from InExchange you open when and how
- Other personal data contained in your profile that you have freely given away on third party social networks such as LinkedIn etc.
As data controller, InExchange does not process sensitive personal data about you.
How we share your personal data
InExchange may share your personal data with external third parties in the following contexts:
InExchange user communities
If you make a post, comment or similar on InExchange user communities or other forums on InExchange Sites, such information can be read and used by anyone with access to such forums and used for purposes over which neither InExchange nor you have control. InExchange is not responsible for any information you submit on such forums or InExchange Sites. InExchange will not post any comment, testimonial or similar made by you without your prior consent.
InExchange may share your personal information with our partners in the event this is legitimate from a business perspective and according to applicable privacy legislation. For example, if you purchase a product or service on behalf of your employer that InExchange provides through one of our certified partners. In this regard, InExchange and our partner may share personal data in order to be able to provide the product or service to the Customer.
The police and other authorities may demand the handover of personal information from InExchange. In these cases, InExchange will only hand over the data if there is a court order etc. to do so.
In connection with mergers, acquisitions or divestiture of all or parts of InExchange business, the acquiring entity, as well as its consultants, will obtain access to data managed by the InExchange entity/entities involved and this may in some cases include personal data. In such cases, external parties will enter into a NDA with InExchange.
Right to opt-out of marketing communications
You have the right to opt-out of receiving marketing communications from InExchange and can do so by either:
(a) Following the instructions for opt-out in the relevant marketing communication,
(b) Change your op-in/opt-out preferences under the relevant edit account section if you have an account with InExchange, or
(c) Contacting us via e-mail, firstname.lastname@example.org
Please note that even if you opt-out from receiving marketing communications, you may still receive administrative communications from InExchange, such as order confirmations and notifications necessary to manage your account or the services provided to Customers.
You have the right to access your personal data by requesting an overview of the personal data we process about you and you may have a right to data portability. You also have the right to request that InExchange corrects inaccuracies in your personal data. If you have an account with InExchange for a InExchange Site, this can usually be done through the appropriate ”your account” or ”your profile” sections on the applicable InExchange Site or service.
Further, you have a right to request deletion of personal data, and to restrict or object to our processing of your personal data according to this Privacy Statement or other service specific terms.
Please use email@example.com to file all requests as mentioned in this section.
Finally, you also have a right to file a complaint with the data protection authorities with regards to our processing of your personal data.
How does InExchange protect and store personal data?
How we keep your personal data secure
InExchange takes the trust you and our Customers place in us very seriously. InExchange is committed to preventing unauthorized access, disclosure or other deviant processing of personal data. InExchange shall ensure the confidentiality of personal data we process, maintain the personal data integrity and secure its availability according to applicable privacy legislation.
As part of our commitments, we utilize reasonable and appropriate organizational, technical and physical procedures and measures to safeguard the information we collect and process, taking into account the type of personal data and risk posed to you and our Customers upon breach. Since root causes for privacy breaches are most likely to be found internally, we believe that building a strong corporate culture where respect for and awareness around privacy among our employees are fundamental to ensure lawful processing and protection of your data The following measures are of particular importance in this regard:
- The Data Protection Council governing lawfulness of processing and privacy policies for InExchange. The council is staffed with internal privacy and information security experts supervised by the Corporate Data Protection manager.
- A lawyer being appointed as Data Protection Officer acting as advisor and controller in privacy matters
- eLearning privacy courses that are mandatory for all employees
- Mandatory procedures for keeping records of processing activities and assessing risks for data subjects applies to all InExchange subsidiaries
- Data processing agreements with subcontractors that process data on behalf of InExchange
- Classification of personal data to ensure implementation of security measures equivalent to risk assessment
- Assess the use of encryption and pseudonymisation as risk mitigating factors.
- Limiting access to personal data to those that need access to fulfil obligations according to law or service agreement etc.
- Manage systems that detects, restores, prevents and reports privacy incidents.
- Use security self-assessments to analyze whether current technical and organisational measures are sufficient to protect personal data, taking into account the requirements outlined in applicable privacy legislation.
- Premises protected by access control and video surveillance systems
How long we store your personal data
InExchange will only retain your personal data for as long as necessary for the stated purpose, while also taking into account our need to answer queries or resolve problems and to comply with legal requirements under applicable laws.
This means that InExchange may retain your personal data for a reasonable period after you and our Customer’s last interaction with us. When the personal data that we collected is no longer required we erase it. We may process data for statistical purposes, but in such cases, data will be pseudonymised or anonymised.
How does InExchange protect and store personal data as data processor?
InExchange provides many different services to its Customers. Most of our services involves processing of the Customers’ data, hereunder their personal data. The purposes of processing is determined by our Customers not by InExchange . Making the Customer the data controller. InExchange do in such cases act as data processor and process the data on behalf of and according to instructions given by the Customer. The relation between the Customer as data controller and InExchange as data processor shall be regulated by a data processing agreement.
Customer and InExchange obligations
When the Customer act as data controller the Customer shall, according to applicable privacy legislation, ensure the legal grounds for processing the personal data. Further, the Customer shall assess and establish ownership to the risks posed to data subjects by processing their personal data. Another important aspect of the Customer’s duty as data controller is to comply with the information duty towards data subjects.
InExchange is a natural part of the Customers duties as data controller, in the sense that InExchange services constitutes parts of the processing of personal data that the Customer must ensure are compliant with applicable privacy legislation. Thus, when InExchange processes personal data on behalf of its Customers, we must do so in accordance with privacy legislation applicable for data processors.
In short, the Customer and InExchange are obligated to cooperate to ensure privacy for data subjects. InExchange shall provide the information necessary for the Customer to be compliant with applicable privacy legislation.
In what manner does InExchange use subcontractors?
InExchange uses subcontractors to process personal data and may export your or our Customers data outside the EU in this regard. These subcontractors are typically vendors of cloud services or other IT hosting services.
When using subcontractors, InExchange will enter into a data processing agreement (DPA) with subcontractors in order to safeguard your privacy rights and to fulfil our obligations towards our Customers. When subcontractors are located outside the EU, InExchange ensures legal grounds for such international transfers on behalf of you or our Customers, hereunder by relying on Privacy Shield (US) or using the EU Model Clauses.
InExchange relies on some strategic external third parties to support our business processes and to provide our cloud services. These third parties include but are not limited to:
-Oracle (US), provider of Eloqua as our marketing automation tool
-Google (US), provider of our email, office automation and file storage solution
-Tele2 Business (SWE), provider of our hosting solution
-Zendesk (US), provider of our customer support system
Changes to this statement
If we modify our Privacy Statement, we will post the revised statement here, with an updated revision date. We encourage you to review the Statement regularly. If we make significant changes to our Statement that materially alter our privacy practices, we may also notify you by other means, such as sending an email or posting a notice on our corporate website and/or social media pages prior to the changes taking effect.
The last update of this Privacy Statement was January 16th, 2018.
How to contact us
We value your opinion. If you have any comments or questions about our Privacy Statement, any unresolved privacy or data use concerns that we have not addressed satisfactorily, or concerning a possible breach of your privacy, please send them to firstname.lastname@example.org. You can also send it in writing to InExchange Data Protection Manager, Box 133 541 23 Skövde.
We will handle your requests or complaints confidentially. Our representative will contact you to address your concerns and outline the options regarding how these may be resolved. We aim to ensure that complaints are resolved in a timely and appropriate manner.