Privacy Policy
INTRODUCTION
Welcome to ComplyLog’s privacy policy. ComplyLog is a brand owned by Euronext Corporate Services Sweden AB, a company located at Holländargatan 17, 111 60, Stockholm, Sweden affiliated company of Euronext Corporate Services and of the Euronext NV’s Group, Euronext N.V. being a Dutch company located at Beursplein 5, 1012 JW, Amsterdam, the Netherlands.
Our services are mainly provided on a contractual basis to corporate subscribers, therefore as an individual user, you will be entitled to use the services on the basis we have agreed with the relevant corporate subscriber. We also collect personal data from non-users when you sign for a demo.
Euronext Corporate Services Sweden AB is a global company, offering a global service to its users and customers. This policy is drafted with reference to the EU General Data Protection Regulation (from 25th May 2018) (together the “Data Protection Legislation”). Euronext Corporate Services Sweden AB believes that compliance with the data protection principles outlined in the Data Protection Legislation creates a strong framework to ensure that individuals’ personal data is secured, protected and used appropriately.
This policy addresses how Euronext Corporate Services Sweden AB uses, transfers and stores the personal data we collect about individuals (“Users”) when they access our website or any instance of our online applications (the “Portal”), or use any of our services or products (collectively, the “ComplyLog Products”), or otherwise have their personal data submitted to us in accordance with this policy.
By using any of the ComplyLog Products and/or you or a corporate subscriber you work for agreeing to our terms and conditions, users are accepting the practices and guidelines set out in this document (the “Policy”), so please take a few minutes to read it over carefully.
When we refer to Euronext Corporate Services Sweden AB, “we” or “us” in this Policy, we are referring to Euronext Corporate Services Sweden AB and its affiliates together with, as applicable, the ComplyLog Products.
Please also use the Glossary to understand the meaning of some of the terms used in this privacy policy.
This Privacy Policy was last updated on 20th of June 2024.
Table of content
- IMPORTANT INFORMATION AND WHO WE ARE
- Purpose of this privacy policy
- Controller / Processor
- Contact details
- Changes to the privacy policy and your duty to inform us of changes
- THE DATA WE COLLECT ABOUT YOU
- Personal we collect
- If you fail to provide personal data
- HOW IS YOUR PERSONAL DATA COLLECTED?
- HOW WE USE YOUR PERSONAL DATA
- Global framework
- Purposes for which we will use your personal data
- Cookies
- Change of purpose
- DISCLOSURES OF YOUR PERSONAL DATA
- INTERNATIONAL TRANSFERS
- DATA SECURITY AND CONFIDENTIAL INFORMATION
- DATA RETENTION
- YOUR LEGAL RIGHTS
- Your rights
- No fee usually required
- What we may need from you
- Time limit to respond
- GLOSSARY
1. IMPORTANT INFORMATION AND WHO WE ARE
1.1 Purpose of this privacy policy
This privacy policy aims to give you information on how Euronext Corporate Services Sweden AB collects and processes your personal data through your use of the ComplyLog Products, including any data you may provide through the Portal when you register for an account or request for a demo.
It is important that you read this privacy policy together with any other privacy notice(s) or fair processing notice(s) we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This privacy policy supplements the other notices and is not intended to override them.
1.2 Controller / Processor
For the purposes of the Data Protection Legislation, where we are the party that determines the purposes for which, and the manner in which, any personal data is processed, the Data Controller of any such personal data is Euronext Corporate Services Sweden AB with the corporate registration number 559141-7083 located at Holländargatan 17, 111 60, Stockholm, Sweden. However, we may also collect or be provided with certain personal data pursuant to our agreements with our customers and partners who remain the Data Controller of that personal data – in this case, we act as a data processor of the relevant customer or partner. Where we act as a Data Processor of any personal data, we will process such personal data in accordance with this Privacy Policy, our Terms and Conditions and the relevant data controller’s instructions.
We rely on the Euronext Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this privacy policy. If you have any questions about this privacy policy, including any requests to exercise your legal rights, please contact the DPO using the details set out below.
1.3 Contact details
Full name of legal entity: Euronext Corporate Services Sweden AB (a company registered in Sweden with company number 559141-7083 whose registered office address is Holländargatan 17, 111 60, Stockholm, Sweden.
Name and title of our Data Protection Officer: gdpr@complylog.com
Email address: gdpr@complylog.com
Postal address: 14 place des reflets – CS 30064 – 92054 Paris la Défense Cedex
You have the right to make a complaint at any time to Datainspektionen], the supervisory authority for data protection issues in Sweden (imy@imy.se). We would, however, appreciate the chance to deal with your concerns before you approach Datainspektionen, so please contact us here: gdpr@complylog.com – in the first instance.
1.4 Changes to the privacy policy and your duty to inform us of changes
This version was last updated on the date stated at the beginning of this privacy policy. We reserve the right to amend this privacy policy from time to time as required to ensure its accuracy.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
2. THE DATA WE COLLECT ABOUT YOU
2.1 Personal we collect
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). For the full definition of personal data, please see paragraph 10.
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
- Identity Data includes your name.
- Contact Data includes your mobile phone number, telephone number and your email address.
- Corporate Subscriber Data includes the name of the corporate subscriber authorising your access to our Portal and your job title.
- Technical Data includes your internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, pages viewed on any Euronext Corporate Services Sweden AB.
- Products and date and time of those viewings, and other technology on the devices you use to access any ComplyLog Products.
- Profile Data includes your username and password.
- Usage Data includes information about how you use the Portal.
- As a user of Euronext Corporate Services Sweden AB The Company is legally obligated under article 18 of the EU Market Abuse Regulation No 596/2014 (“MAR”) to collect and store personal data from you such as: (i) name and surname, (ii) personal identification number, (iii) surname by birth, (iv) private and work phone number, (v) position, and (vi) home address.
We may also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data may be derived from your personal data, but is not considered personal data in law, as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of Users accessing a specific Portal feature.
We may also anonymise data (Anonymised Data) that we collect, use and share for the purposes of providing support to you, a corporate subscriber and other Users of ComplyLog Products. Like Aggregated Data, this data does not directly or indirectly reveal your identity.
However, if we combine or connect Aggregated Data or Anonymised Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.
We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.
2.2 If you fail to provide personal data
Where we need to collect personal data by law, or under the terms of a contract we have with the corporate subscriber authorising your access to our Portal and you fail to provide that data when requested, we may not be able to allow you access to ComplyLog Products. In this case, we will let you know if access to ComplyLog Products is denied.
3. HOW IS YOUR PERSONAL DATA COLLECTED?
3.1 We use different methods to collect data from and about you including through:
3.1.1 Direct interactions. You, or a third party authorised by your employer will or will arrange to provide your Identity, Contact, Employment and Profile Data when registering an account with us or requesting access to ComplyLog Products. You may also provide us with this information when corresponding with us by telephone, phone, email, social media or otherwise.
3.1.2 Automated technologies or interactions. As you interact with any ComplyLog Products, we may automatically collect Technical Data and Usage Data. We collect this personal data by using cookies, server logs, web beacons/pixels and other similar technologies.
3.1.3 Third parties. We may receive personal data about you from various third parties, e.g. your employer or a corporate subscriber, as set out below:
3.1.3.1 Identity, Contact and Corporate Subscriber Data from the corporate subscriber authorising your access to any ComplyLog Products to whom we are providing services.
3.1.3.2 Identity, Contact and Corporate Subscriber Data from or on behalf of your employer who has authorised your access to any ComplyLog Products or provided us with your personal data as a result of your employer providing services to a corporate subscriber.
3.1.3.3 Identity, Contact, Corporate Subscriber, Technical, Profile and/or Usage Data from the provision of support service provided (as detailed in paragraph 10.6).
3.1.3.4 Identity, Contact and Corporate Subscriber Data from a third party who has been expressly permissioned by you, your employer or a corporate subscriber
4. HOW WE USE YOUR PERSONAL DATA
4.1 Global framework
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
4.1.1 Where we need to allow you to access any ComplyLog Product and to provide support services.
4.1.2 Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests. For example, our legitimate interests may include the administration and management of our business and the provision of our services to the corporate subscriber authorising your access to any ComplyLog Product.
4.1.3 Where we need to comply with a legal or regulatory obligation.
Please see paragraph 10.2 to find out more about the types of lawful basis that we will rely on to process your personal data.
Generally, where applicable, we obtain, collect and process your personal data on the basis of consent for some specific marketing purposes (i.e. proposal of products & services, invitation to events…).
4.2 Purposes for which we will use your personal data
We use your personal data in the following ways:
4.2.1 personal data that you provide to us is used to:
4.2.1.1 provide you with access to the information and services that the corporate subscriber authorising your access to our Portal requests from us
4.2.1.2 provide services to your employer or the corporate subscriber authorising your access to our Portal
4.2.1.3 provide support services to you
4.2.1.4 manage and administer our business
4.2.1.5 review and improve our services
4.2.1.6 To provide you with promotional communications, such as email, to the extent that you have provided consent to receive such communications under applicable law, to notify you about changes to the ComplyLog Products.
4.2.1.7 To provide you with an SMS service that provides you a security token that allows you to access the Portal.
4.2.2 personal data that we receive from third parties may be combined with the personal data that you provide to us and used for the purposes described above.
4.2.3 personal data about your use of any ComplyLog Product is used to:
4.2.3.1 administer the ComplyLog Product and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes
4.2.3.2 provision of support services to you
4.2.3.3 improve the Portal to ensure that content is presented in the most effective manner for you and for your computer or mobile device
4.2.3.4 improve other websites we operate
4.2.3.5 refine the provision of the services offered on the Portal and to assist in the development of new services
4.2.3.6 allow you to participate in interactive features of the Portal, when you choose to do so
4.2.3.7 as part of our efforts to keep the Portal safe and secure
4.2.3.8 provide services to your employer or a corporate subscriber
4.2.3.9 provide services to a third-party that has been expressly authorised to access ComplyLog Products by you, your employer or a corporate subscriber
4.3 Cookies
The Portal uses cookies to distinguish you from other Users of the Portal. This helps us to provide you with a good experience when you use the Portal and also allows us to improve the Portal.
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of the Portal may become inaccessible or not function properly.
List of third party Cookies
Third Parties | Purposes |
HubSpot | Functional and Analytics |
Segment | Analytics |
Leadfeeder | Analytics |
Google Analytics | Analytics |
Google Adwords | Advertising |
Advertising | |
Microsoft Ads | Advertising |
You can decide if a cookie from ComplyLog websites can be stored on your device. ComplyLog recommends that you leave the cookie active. By blocking, turning off or otherwise rejecting the cookie, some web pages may not display properly, or the user will not be able to use any website services that require you to sign in. At any moment, you can delete cookies through the configuration of the consent and privacy options available in your browser.
Cookie Removal Instructions:
As part of our commitment to privacy and compliance with the General Data Protection Regulation (GDPR), we want to provide you with information on how to remove cookies from your browser. To remove cookies from the main browsers, please follow the instructions below:
Google Chrome:
- Open Chrome and click on the three-dot menu icon in the top-right corner.
- Select “Settings” from the drop-down menu.
- Under the “Privacy and security” section, click on “Clear browsing data.”
- Select the time range for which you want to remove cookies.
- Check the box next to “Cookies and other site data.”
- Click on the “Clear data” button to remove the cookies.
Mozilla Firefox:
- Open Firefox and click on the menu button (three horizontal lines) in the top-right corner.
- Select “Settings” from the menu.
- In the left sidebar, click on “Privacy & Security.”
- Under the “Cookies and Site Data” section, click on the “Clear Data” button.
- Check the box next to “Cookies and Site Data.”
- Click on the “Clear” button to remove the cookies.
Safari:
- Open Safari and click on “Safari” in the top menu.
- Select “Settings” from the drop-down menu.
- In the Preferences window, click on the “Privacy” tab.
- Click on the “Manage Website Data” button.
- In the new window, select the website(s) for which you want to remove cookies.
- Click on the “Remove” button, then click “Done” to confirm.
Please note that the above instructions may vary slightly depending on the browser version you are using. If you are using a different browser, we recommend referring to the browser’s documentation or support website for specific instructions.
4.4 Change of purpose
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us at gdpr@complylog.com.
If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
5. DISCLOSURES OF YOUR PERSONAL DATA
5.1 We may disclose your personal data to other companies of the Euronext NV’s Group from which Euronext Corporate Services Sweden AB is a subsidiary.
5.2 We may also disclose your personal data to third parties in relation with the purposes for which personal data are processed including:
- regulatory authorities and law enforcement agencies;
- our trusted third party service providers and our IT service providers;
- third parties involved in financial market activities;
- third parties involved in hosting or organizing events or courses;
- professional advisors such as tax or legal advisors, consultants and accountants, and
- any prospective buyers of Euronext Corporate Services Sweden AB or the business of Euronext Corporate Services Sweden AB.
5.3 We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
6. INTERNATIONAL TRANSFERS
We store and process your personal data on servers located within the European Economic Area (the “EEA”). We only transfer your personal data outside the EEA where the European Commission has decided that the third country in question ensures an adequate level of protection in line with EEA data protection standards or where there are appropriate safeguards in place to protect your personal data.
We may transfer the personal information we collect about you to recipients in countries other than the country in which the information originally was collected. Those countries may not have the same data protection laws as the country in which you initially provided the information. When we transfer your information to recipients in other countries (such as the U.S.), we will protect that information as described in this Privacy Policy and will comply with applicable legal requirements providing adequate protection for the transfer of personal information to recipients in countries other than the one in which you provided the information, including by selecting service providers that are located in a country recognized by the European Commission as providing an adequate level of data protection or by implementing appropriate safeguards based on the European Commission’s Standard Contractual Clauses, where applicable. Subject to applicable law, you may obtain a copy of these safeguards by contacting us as indicated below.
7. DATA SECURITY AND CONFIDENTIAL INFORMATION
We have put in place appropriate security measures (commensurate with the sensitivity of the personal data we process) to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
Euronext Corporate Services Sweden AB employs encryption technology to protect certain transmissions of data to/from the Services, but e-mail and other communications are not encrypted. You should not send any personal or identifying information, such as bank or credit card details via email. By employing e-mail or other insecure electronic communication means you acknowledge that you have no expectation of privacy with respect to the information delivered thereby and that Euronext Corporate Services Sweden AB will not be responsible for any loss or damage that could result from interception by third parties of any information so sent.
8. DATA RETENTION
How long will you use my personal data for?
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, reporting, regulatory or contractual requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
In some circumstances you can ask us to delete your data: please see paragraph 9 below for further information.
Please be aware that we keep personal data for Users of ComplyLog Products (including Identity Data, and Usage Data) for audit purposes whilst the relevant corporate subscriber is contracted to us and as required by any regulatory requirements applicable to the relevant corporate subscriber.
We may be subject to contractual requirements that specify how long we can keep your personal data for (for example, in our contract for the supply of services to the corporate subscriber authorising your access to any ComplyLog Products).
9. YOUR LEGAL RIGHTS
9.1 Your rights
The table below sets out the rights which you have to address any concerns or queries with us about our processing of your personal data. Please note that these rights are not absolute and are subject to certain exemptions under applicable data protection law.
RIGHT | FURTHER INFORMATION |
RIGHT TO BE INFORMED | You have the right to know your personal data is being processed by us, how we use your personal data and your rights in relation to your personal data. |
RIGHT OF ACCESS | You have the right to ascertain what type of personal data Euronext Corporate Services Sweden AB holds about you and to a copy of this personal data. |
RIGHT TO RECTIFICATION | You have the right to have any inaccurate personal data which we hold about you updated or corrected. |
RIGHT TO ERASURE | In certain circumstances you may request that we delete the personal data that we hold on you. You have also the right to give post-mortem instructions regarding your personal data. |
RIGHT TO RESTRICTION OF PROCESSING | You have the right to request that we stop using your personal data in certain circumstances including if you believe that the personal data we hold about you is inaccurate or that our use of your personal data is unlawful. If you validly exercise this right, we will store your personal data and will not carry out any other processing until the issue is resolved. |
RIGHT TO OBJECT | Where we rely on our legitimate interests to process your personal data, you have a right to object to this use. We will desist from processing your personal information unless we can demonstrate an overriding legitimate interest in the continued processing. |
RIGHT TO DATA PORTABILITY | In case the processing is based on your consent or a contract conclude with you, you may request us to provide you with certain personal data which you have given us in a structured, commonly used and machine-readable format and you may request us to transmit your personal data directly to another controller where this is technically feasible. |
You can exercise any of these rights by:
By sending an email to the following address:
gdpr@complylog.com
You have the right to make a complaint at any time to Datainspektionen the Swedish supervisory authority for data protection issues (imy@imy.se). We would, however, appreciate the chance to deal with your concerns before you approach Datainspektionen, so please contact us here: gdpr@complylog.com – in the first instance.
9.2 No fee usually required
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive.
9.3 What we may need from you
We may need to request specific information from you to help us to confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
9.4 Time limit to respond
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or if you have made a number of requests. In this case, we will notify you and keep you updated.
10. GLOSSARY
TERM | DEFINITION |
Controller |
Means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law. |
Cookie |
A cookie is an online identifier. |
Data Protection Authority (DPA) |
An official or body that ensures compliance with Data protection laws and investigates alleged Breaches of the laws’ provisions. |
Data Subject |
An identified or identifiable natural person. |
Lawful Basis |
Legitimate Interest means conducting and managing our business in our interests, or the interests of a third party. Our interests could include, for example, our internal administrative purposes or ensuring network and information security. Whether a particular legitimate interest may exist can also depend on the relationship we have with you. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests or the interests of a third party. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us. Performance of Contract means processing your data where it is necessary for the performance of a contract. Such contract may exist with you, your employer or corporate subscriber with whom you or your employer have a business relationship. Alternatively, it may be necessary to take steps at your request before entering into such a contract. Comply with a legal or regulatory obligation means processing your personal data where it is necessary for compliance with a legal or regulatory obligation that we or a corporate subscriber may be subject to. Consent means your clear, unambiguous consent for a specific purpose, for example, for marketing and promotional materials. |
Personal Data |
Means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. |
Processing |
Means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. |
Processor |
Means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller. |