This policy explains what personal data DP Patterning AB collects, why we collect it, how long we keep it and what rights you have. It applies to dppatterning.com and to the contact we have with customers, suppliers, applicants and other business contacts.
Cookies and website measurement are described separately in our Cookie Policy.
1. WHO WE ARE
DP Patterning AB is the controller for the personal data described here.
DP Patterning ABHammargatan 41603 63 NorrköpingSwedeninfo@dppatterning.comWrite to that address for anything in this policy, including requests to see, correct or delete your data.
Our activities do not require us to appoint a data protection officer, and we have not appointed one. Questions about personal data go to the address above.
2. WHAT WE COLLECT AND WHY
2.1 When you request a sample
Our sample request form asks for your name, company, email address, phone number, country, industry or application area, the type of sample you want, what you are developing, how the sample will be used, expected volume or project stage, timeline, and any comments you add.
We use this to judge whether we can help, to prepare a technical answer, to produce and send the sample, and to follow up afterwards.
The fields marked as required are the ones we need in order to answer at all. Without them we cannot handle the request. The rest is optional and only helps us give a better answer.
Legal basis: taking steps at your request before entering into a contract, Article 6(1)(b) of the GDPR, and our legitimate interest in answering a business enquiry, Article 6(1)(f).
Please do not put confidential or export-controlled technical information in the form. If your project needs that level of detail, say so and we will put a confidentiality agreement in place first.
2.2 When you contact us by email or phone
We process your name, contact details and whatever you choose to write to us, so that we can answer and keep track of what was agreed.
Legal basis: our legitimate interest in handling business correspondence, Article 6(1)(f).
2.3 When we work with you as a customer or supplier
We process the contact details of the people involved on both sides, the correspondence, order and delivery records, and the invoicing information needed to complete the transaction.
Legal basis: performance of the contract, Article 6(1)(b), where you are the counterparty in person, and otherwise our legitimate interest in managing the business relationship, Article 6(1)(f). Accounting records are kept because the law requires it, Article 6(1)(c).
2.4 When you apply for a job
We process your application, CV, references and the notes we take during the process.
Legal basis: taking steps before entering into an employment contract, Article 6(1)(b), and our legitimate interest in documenting a fair recruitment process, Article 6(1)(f).
Do not include health data, trade union membership or other special category data in an application. If you send it anyway, we will delete it.
2.5 When you visit our website
We use cookies and similar technologies for analytics and advertising measurement, and a service that identifies the company behind a visit from the network it comes from. That service is aimed at organisations, but the combination of a company and a browsing pattern can in some cases relate to a person, so we treat it as personal data.
Legal basis: your consent, Article 6(1)(a), given through the cookie banner. You can withdraw it at any time.
The Cookie Policy lists every cookie, what it does and how long it lasts.
2.6 When you meet us at a trade show
We process the contact details you give us and a short note on what we discussed, so that we can follow up.
Legal basis: our legitimate interest in following up a business contact, Article 6(1)(f).
3. WHERE THE DATA COMES FROM
Most of it comes from you. Some comes from the company you work for, for example when a customer names you as a contact. Some comes from public sources such as company websites, professional networks and company registers, when we research a market or check a supplier.
4. WHO WE SHARE IT WITH
We do not sell personal data and we do not share it for anyone else's marketing.
We do share it with suppliers who process it on our behalf, under written data processing agreements:
- our website platform and hosting provider
- the database behind our web forms
- Pipedrive, our CRM and web form provider, which hosts the contact and sample request forms on this site and stores what you submit through them
- our email, file storage and office software provider
- the analytics and advertising services listed in the Cookie Policy
- transport companies, when a sample is shipped to you
We also share data when we have to: with accountants and auditors, with legal advisers if a dispute arises, and with authorities where the law requires it.
5. TRANSFERS OUTSIDE THE EU AND EEA
We keep processing inside the EU and EEA where we can. Some of our suppliers, in particular the American providers of analytics, advertising and office software, may transfer data to the United States. Where that happens we rely on the EU-US Data Privacy Framework, or on the European Commission's standard contractual clauses together with an assessment of the safeguards in place.
If you ship or receive samples outside the EU, the contact details on the shipping documents travel with the shipment.
6. HOW LONG WE KEEP IT
- Sample requests and enquiries that do not lead anywhere
- Two years from our last contact.
- Customer and supplier relationships
- For the length of the relationship, then two years, so that we can handle questions and claims that come up afterwards.
- Accounting records
- Seven years, as required by the Swedish Accounting Act.
- Job applications
- Two years after the recruitment closes, so that we can answer a claim under the Discrimination Act. We ask separately if we may keep your application longer for future openings.
- Website analytics
- As set out in the Cookie Policy.
When a period ends we delete the data or anonymise it so that it can no longer be traced to you.
7. HOW WE PROTECT IT
Access is limited to the people who need it for their work, through personal accounts rather than shared ones. We apply technical and organisational measures appropriate to the risk, and we review them when systems or working methods change. Our suppliers are contractually bound to protect the data they process for us. If a breach occurs that is likely to put your rights at risk, we notify the Swedish Authority for Privacy Protection within 72 hours and we tell you directly where the law requires it.
8. YOUR RIGHTS
You have the right to:
- ask what data we hold about you and get a copy
- have inaccurate data corrected
- have data deleted, where we have no continuing reason to keep it
- ask us to restrict how we use it while a question is being resolved
- object to processing we base on legitimate interest, including profiling
- receive data you gave us in a portable format, where processing is based on consent or on a contract
- withdraw consent at any time, without affecting what was lawful before
Write to info@dppatterning.com. We answer within one month. If your request is complex we may extend that by two months and will tell you why. We may ask you to confirm your identity first, so that we do not hand your data to someone else.
If you think we handle your data incorrectly, tell us, and you also have the right to complain to the supervisory authority:
Integritetsskyddsmyndigheten (IMY)Box 8114104 20 Stockholmimy@imy.se9. AUTOMATED DECISIONS
We do not make decisions about you by automated means alone, and we do not profile you in a way that has legal or similarly significant effects.
10. CHILDREN
This site is aimed at businesses. We do not knowingly collect data from children, and nothing here is directed at them.
11. CHANGES TO THIS POLICY
We update this policy when we change how we work with personal data. The date at the top shows when it last changed. If a change matters to you, we will say so where you are most likely to see it.