Privacy Policy

This privacy policy outlines the processing of personal data conducted by Mandales AB, corporate identity number 559007-5494 (“Mandales”).

We process personal data in order to offer our products to companies. In order to do this, we need to collect and process some personal data. Mandales is the data controller for the personal data that we collect and process. As a data controller, we always process your personal data in accordance with this policy. You can always expect us to process your personal data safely and in accordance with data protection regulation. You are welcome to contact us at any time if you have any questions regarding your personal data. You can send an email to gdprofficer@mandales.com or call us on +46 (0)702 17 84 34.

This privacy policy outlines how we collect and process the personal data of anyone who is a contact person for or a representative of our past, present, and potential customers or suppliers (“contact person/representative”) and of those visiting our website or another digital channel. It also describes your rights towards us and how to exercise them.

“Personal data” is any information that can be directly or indirectly linked to a living physical person.

1. Personal data collected about you

Mandales collects various data about you who are a contact person/ representative. We describe the categories of personal data we process below. We collect only the personal data that is strictly necessary to fulfil the purpose of processing.

Identity data. This is data that identifies you as a person, such as your full name. If you visit or place an order on our website, we also process your IP address.

Contact details. This is data that enables us to contact you and supply you. Contact person/representative may need to provide their email address, phone number, and the address of their client/employer.

Company details. This is data on your client/employer if you are acting as a contact person/ representative. We require data such as the company’s name and corporate identity number, your title, and details of your authority to represent the company.

Purchase information, including order and delivery details. These are details of the purchases you make, including the products you buy, payment method and payment status, receipt, and other details relating to your purchases and agreements with us, as well as product details and delivery information prior to a purchase.

Information in communications between us. This is information that we receive in connection with communication between us, personal data sent to us by email or regular post, or information we receive over the phone or otherwise. Please note that we receive all information you send to us. This information may include details of your dealings, a course of events, dissatisfaction, and complaints.

Promotions, discounts, and bonus information. These are details about promotions and discounts that you are entitled to or have used.

Information about customer type and customer status. This is information regarding details as to whether you have opted to receive direct advertising. In addition, information is processed regarding the types of products you like (customer segment).

2. How your data is collected

Information you submit to us. The majority of information is provided to us by you, such as when you place an order on our website, by email, or over the phone. It is your choice whether or not you give us this information, but some of these details are necessary to enable us to fulfil our agreement with your client/employer. For example, a contact person/representative need to provide their name and contact details so that we can get in contact.

Information we collect about you. If you are a contact person/representative., we may also obtain personal data from your client/employer or the company you represent.

Information collected in other ways. Sometimes, data may be collected from people other than you. For example, if necessary, we may collect information from third parties such as sources with a personal address register in order to check that the details you have provided are current and correct.

3 How your data is used

Providing products and concluding and executing agreements

Purpose and legal basis:
• Enabling the purchase of our products via various channels
Confirming the identity of the orderer
Managing purchases, including sending order confirmations and delivering products
Managing payment methods
Managing the customer relationship, including customer queries and complaints, as well as warranties

If you are a contact person/representative, processing is based on our legitimate interest to fulfil the agreement with your client/employer. Furthermore, processing is based on our legitimate interest in managing complaints and customer enquiries.

Personal data:
• Identity data
• Contact details
• Company details
Purchase information
Order and delivery details
Discounts (where relevant)
Information in communications between us

Fulfilling our legal obligations

Purpose and legal basis:
Your personal data is processed to enable us to fulfil our legal and regulatory obligations, including bookkeeping and accounting requirements. The basis for this processing is the fulfilment of the company’s legal obligations.

Personal data:
• Identity data and contact details
Company details
Data stated on invoices, orders, agreements, and transaction documents
Other data necessary for this purpose

Managing and defending legal claims and safeguarding our legal rights

Purpose and legal basis:
Where applicable, your personal data may be processed in order for us to:

  • investigate and respond to a legal claim, such as in the context of a dispute with you or a third party; and
  • safeguard our legal rights and interests, such as to ensure regulatory compliance or to fulfil audit obligations, as well as to provide information in connection with an acquisition, merger, or sale of our business.

Your personal data will be used only to the extent necessary in the individual case in order to satisfy this purpose. Processing takes place on the basis of our legitimate interest to defend ourselves against or to manage a legal claim, as well as to safeguard our rights, provided that our interests outweigh yours.

Personal data:
All data that is necessary for the purpose, which depends on the individual case.

Evaluating our business and following up customer relationships

Purpose and legal basis:
Create aggregate statistics on, for example, customer types, sales, and responses to and the use of promotions, as well as to conduct surveys with the aim of analysing and evaluating the business. When generating statistics and reports, your personal data is used in aggregate form in that the data does not identify you as a person.

This processing is based on our legitimate interest in improving and developing our business.

Personal data:
• Identity data
• Customer type and customer status
• Purchase information

Marketing our products and informing people about our business

Purpose and legal basis:
To inform contact people/representatives via direct marketing about our products and promotions that we feel are relevant to existing customers
To inform potential customers via direct marketing about our products and promotions
To inform companies about our business and activities that we organise or participate in

Processing takes place based on our legitimate interest in marketing and informing companies about our business, tending to our customer relationships, and encouraging existing customers to choose to purchase from us again.

In addition we use personalisation in our social media and web advertising communications on other websites. We use cookies for personalisation and to analyse usage patterns. You can read more about our cookie policy here.

When you provide us with your email address, you consent to electronic marketing pursuant to the Marketing Act. If you no longer wish to receive such communications, follow the instructions in the email you receive from us or contact gdprofficer@mandales.com.

Personal data:
• Identity data and contact details
• Company details
• Purchase information
• Customer status
• Information on usage patterns and navigation on our website (cookies)

Communicating with you in connection with enquiries

Purpose and legal basis:
To receive, respond to, and manage questions from stakeholders, customers, and visitors to our digital channels –  this processing is based on our legitimate interest in responding to queries

Personal data:
• Identity data and contact details
• Information in communications between us

Managing supplier agreements and external partnerships

Purpose and legal basis:
• To negotiate and conclude supplier agreements/partnerships
• To manage the contractual relationship

Personal data:
• Identity data and contact details
• Information in communications between us
• Contract information
• Data prior to, during, and after the conclusion of the agreement

4. How long your data is saved

Your personal data is saved for only as long as it is required for us to fulfil the purpose of its processing. Below are some estimated storage periods, or the criteria used to determine this period. Storage periods do not apply if there are other circumstances that require us to store personal data for a longer period, such as when managing a complaint or other queries from you regarding a purchase, or in order for us to raise or defend a legal claim.

Providing products and concluding and executing agreements. The personal data of contact people/representatives is retained until the purchase has been completed and our obligations, such as delivery and payment, are fulfilled and for a period of 36 months thereafter. The personal data of contact people/representatives is stored for as long as is deemed necessary pursuant to the above criteria.

Marketing our products and informing people about our business. We process the personal data of contact people/representatives for 36 months following their client/employer’s last purchase. If you have subscribed to electronic mailings, your email address will be stored for this purpose until you unsubscribe.

Fulfilling our legal obligations. We store data for seven years plus one year to fulfil our bookkeeping and accounting requirements.

Managing and defending legal claims and safeguarding our legal rights.

Evaluating our business and following up customer relationships. Personal data used to create statistics and reports is based on customer and sales data that is no older than 36 months from the completion of the agreement. The statistics and reports themselves do not contain personal data.

Communicating with you in connection with enquiries. Personal data in communications between you and Mandales in connection with enquiries is stored for six months after the case is concluded.

5. Sharing your data with others

We sometimes need to share your personal data with other parties for the purpose of processing your personal data. We outline the categories of recipients that we may share your personal data with below. We share your personal data only when actually necessary.

People who work with us. Your personal data may be shared with people who work at Mandales, but only those who need access to the data in order to do their work.

Suppliers and subcontractors. Your personal data may be transferred to or shared with selected companies that supply us with various services. In order for us to provide our products we need these companies’ services, such as:

• IT services to provide and support systems, email, and websites/platforms
• Logistics services for order management, picking, and packing
• Shipping company services for delivery
• Services for sending order confirmations, delivery notes, marketing, etc.
• Insurance company services (where applicable)
• Services from external advisors, such as lawyers (where applicable)
• Product manufacturer services (where applicable)

Public authorities and courts. We may provide necessary information to relevant Swedish and foreign public authorities such as the Swedish Tax Agency, the police, border authorities, or other public authorities if required by law or in the event that you have agreed to our doing so.

Payment partners. To facilitate your payment in connection with an order placed on our website, we co-operate with a bank or payment service institution. If you choose a payment method other than direct payment, we will transfer the payment request once the purchase agreement is concluded with the partner.

6. Your data may be processed outside the EU/EEA

Mandales processes your personal data within the EU/EEA and will always strive to ensure it remains this way. Should your personal data need to be transferred to a company outside the EU/EEA (such as due to individual circumstances or a change of supplier), we, as controllers, have a responsibility to ensure that we take measures to ensure that your data remains protected.

You should be aware that other rules may apply to your personal data outside the EU/EEA that may offer poorer protection. However, Mandales will ensure that all reasonable legal, technical, and organisational measures are in place to ensure that your personal data is handled securely and with an adequate level of protection (e.g. approved standard clauses). You are welcome to contact us at any time if you have any questions regarding the applicable security measures.

7. Your rights

This is your personal data. Consequently you are entitled to receive information about and to have a say about how we process your personal data. Below is some information on your rights. To exercise these rights, please contact us at Mandales.

Accessing your data. You can request a copy of your personal data and information about how it is collected, used, shared, etc. at any time.

Moving your data. You are entitled to move the personal data that you provided to us to another data controller.

Correcting incorrect data. You are entitled to request that incorrect data be corrected. Furthermore, you are entitled to supplement incomplete personal data.

Erasing data. In some cases, you are entitled to request that your personal data be erased if it is no longer necessary for the purpose for which it was collected, or if there is no longer a legal basis for its processing.

Revoking your consent. Where we process your personal data on the basis of your consent, you may revoke this consent at any time. Your revocation does not affect the legality of our processing up to the point of your revocation.

Declining direct marketing. You always have a right to opt out of marketing from us. Please contact us for assistance. If you have consented to electronic mailings, you can use the unsubscribe link in the email.

Limiting the use of data. You are entitled to request that the processing of your personal data be limited until incorrect data is corrected or an objection from you has been investigated.

Objecting to processing. You are entitled to object to the processing of your personal data for legitimate interests. In such cases, we must either prove that we have legitimate reasons to process your personal data that outweigh your interests, or cease the processing of your personal data. You are welcome to contact us at any time for more information regarding this balance of interests.

You should be aware that there may be additional requirements or regulations that limit or extend your rights. For example, legal obligations may prevent us from disclosing or moving some of your data or from immediately erasing your data.

8. Changes to this policy

Mandales reserves the right to revise this privacy policy at any time. The document states when the policy was last revised. When changes are made to this privacy policy, we will publish the latest version on our website. You are therefore recommended to read this privacy policy on a regular basis to familiarise yourself with any changes. If we change this policy significantly from what was stated when we collected your personal data, we will notify you of such changes. In the case of more extensive changes to this privacy policy, we will inform you specifically of this. If you add personal data about other people, you are responsible for Mandales also processing their personal data in accordance with this privacy policy and applicable terms and conditions.

9. Technical/organisational measures

Mandales takes ongoing measures to ensure that we satisfy the principles of inbuilt data protection and data protection as standard. Mandales continually evaluates the risks of its data processing and takes necessary security measures to mitigate these risks. We regularly train our staff in data protection.

10. Contact details

If you have any questions regarding GDPR, please send an email to gdprofficer@mandales.com or call +46 (0)702 17 84 34. You can also write to us at: Mandales AB, Box 532 13, SE-400 16 Gothenburg, Sweden

11. Complaints

You are entitled to write to the Swedish Data Protection Authority to complain if you feel that we have handled your personal data incorrectly. Find out more at www.imy.se

This policy was last updated 2023-06-21.