Collecting anonymous information
Draft integrity policy for PostNord's Digital channels
PostNord AB (publ) and its group companies ("PostNord" or "we") takes the personal integrity of the visitors of our websites and the users of the services offered by PostNord on these websites, our apps, our platforms in social media and our customer service (”Digital Channels”) seriously.
Our objective is that you should feel confident that your personal integrity is respected and that your personal data is processed correctly. We ensure that personal data processed by PostNord is processed solely for its pre-defined purposes and is protected against unauthorized access. All personal data processing within PostNord is undertaken in accordance with applicable data protection legislation. Within the EU/EEA, the general data protection regulation will apply as per May 2018 (“GDPR”)1.
This integrity policy applies generally to all of PostNord’s Digital Channels. In the event that another, more specific, integrity policy is published on a Digital Channel which is provided by an affiliate or another legal entity within the PostNord Group, that integrity policy shall take precedence over this integrity policy.
In addition to the personal data processing being undertaken through PostNord’s Digital Channels, we are also processing your personal data, both in your capacity as sender and recipient, when we are performing the services offered by PostNord via its Digital Channels and other channels. If the terms of any of these services contain more specific provisions on personal data processing, these terms shall take precedence over this integrity policy for that specific service.
1. What is personal data and what is processing of personal data?
Personal data is any information that directly, or indirectly together with other information, may be used to identify a living, physical individual. This means that a range of different types of information, such as but not limited to name and contact details, IP addresses, competition entries, selections and behavior, is considered personal data.
Processing is everything that is done with the personal data. Any action taken with the personal data, irrespectively of whether the action is automated or not, such as but not limited to collection, registration, organization, structuring, storing, adaptation or modification, compilation, reading, use, disclosure through transfer, dissemination or other provision, adjustment or assembling, restriction, erasure or deletion.
2. PostNord's processing of personal data
2.1 What categories of personal data is processed and when is it deleted?
When you are visiting/using one of our Digital Channels or its services, or are communicating with us in our Digital Channels, we may collect information about you, among those name, address, postal address, email address, phone number, identification information, information on your use of PostNord’s services and products, transaction data and for certain services also photos and location data. Where applicable, personal identification number and credit card details may also be processed. Further, PostNord may collect technical information about the device you are using to obtain access to PostNord’s Digital Channels, among them IP address, unique device ID, type of web browser and cookie information. The collection of data mentioned herein is done, inter alia, when you are submitting your personal data in different forms on our Digital Channels or its services, communicating with PostNord and others via PostNord’s platforms in social media, submitting feedback in our contact forms or via telephone, downloading reports from PostNord’s websites or register for events organized by PostNord.
If you participate in contests and other marketing activities that we organize, your entry and other personal data that you choose to submit to us may be processed. When you contact us through customer service functions in our Digital Channels, e.g. when making a complaint or return, we will process your contact details and case information.
If you are visiting or communicating with us through our social media accounts (i.e. third party platforms such as, inter alia, Facebook and Twitter), PostNord may receive information on your profile and your interactions on such platform from the third party platform provider.
PostNord has placed so-called ”cookies” on several of our Digital Channels. Through these, information on how you are using the Digital Channel in question is collected. You can find more information on which cookies PostNord has placed on our Digital Channels, and how to remove these cookies.
PostNord will only process personal data for as long as it is necessary to fulfil the purposes of the processing or to fulfil PostNord’s legal obligations.
2.2 For which purposes is personal data processed?
Personal data concerning you, which is collected in connection with your use of the Digital Channels and their services, will be processed by PostNord or its group companies, or their respective sub-processors, for the following purposes.
- In order for us to provide the products and services you have purchased, and to administer our agreement with you;
- In order for us to communicate with you through our customer service, email forms and our social media accounts;
- To administer marketing activities such as contests and winnings, etc.;
- For marketing purposes, among those marketing via mail, email and sms/mms (which you can opt-out from by clicking a link in each message sent through email or sms/mms);
- To analyze and group visitors based on selection, prioritization and preferences, meaning that so-called profiling is undertaken, in order to provide you with relevant and tailored information, recommendations, ads and offers. It is possible that data from your use of different Digital Channels from PostNord and its group companies is merged for this purpose, and for the purpose of developing products and services;
- To process your payment or to prevent or detect fraud;
- To obtain statistics over the use of our Digital Channels and their respective services; and
- To maintain, develop, test and improve our Digital Channels and the technical platforms they are provided on.
2.3 Legal basis and compelling interests for the data processing
PostNord will always adhere to applicable data protection legislation when processing your personal data. We process your personal data when this is necessary in order to perform an agreement with you or to respond to a customer service request you have made, and when we have a legitimate and compelling interest for processing your personal data, e.g. an interest to market ourselves to visitors of our Digital Channels or an interest in developing our Digital Channels. If PostNord’s processing of personal data requires your consent, we will obtain your prior consent to such processing, by having you actively tick a box.
3. Security measures for protection of personal data
A high level of security for your personal data is of utmost importance to PostNord, and we have in place appropriate technical and organizational security measures to protect your personal data from unauthorized access, modification, dissemination or destruction.
PostNord’s duty of confidentiality as set forth in the Swedish Postal Services Act (Sw: postlagen, SFS 2010:1045) applies to mail, but other information about PostNord’s customers is also treated confidentially. Address information in our directory for mail delivery may in some instances be handed over to authorities based on an obligation in law or other regulation.
4. Limitations in the transfer of personal data
PostNord may engage external partners (suppliers) to perform services on behalf of PostNord, e.g. to provide IT services, payment services or to assist in marketing, analysis or statistics. The performance of these services may entail such parties, both within and outside of the EU/EEA, obtaining access to your personal data. Companies which are processing personal data on behalf of PostNord are obliged to sign an agreement with PostNord in order to ensure a high level of protection for your personal data. For partners located outside the EU/EEA, additional protective measures are undertaken, e.g. the signing of an agreement which includes the European Commission’s model clauses for data transfers, which can be found on the European Commission’s website.
PostNord may transfer personal data to a third party, such as the police or other authority, in the course of an investigation or otherwise when so obliged by law or governmental decision.
PostNord will not transfer your personal data except as otherwise set forth in this clause 4.
5. Use of information from you mobile device
PostNord offers certain services, which require access to information from your mobile device (such as, inter alia, your mobile phone or tablet). It may for example be photos or location data. PostNord will never collect this data, unless you have given your explicit consent hereto.
Below you will find information on how PostNord may use information from your mobile device, if you have consented to such use.
PostNord will never collect or use information on the location of your device, unless you have expressly given us your consent.
Photos and camera:
PostNord will not gain access to your photos or your camera without first obtaining your explicit consent and we will never import the picture library on your mobile device. If you give PostNord permission to access the photos on your mobile device, we will only have access to the photos that you have explicitly given us permission to use.
PostNord will not import the contacts stored on your mobile device unless you have explicitly consented hereto.
PostNord will never get access to the microphone on your mobile device unless you have explicitly consented hereto.
6. External links
This integrity policy applies to information that PostNord is processing about you within the scope of our Digital Channels. PostNord’s Digital Channels may sometimes contain links to external websites or services which are not controlled by PostNord. If you follow a link to an external website, you are urged to review the principles for data processing and cookies applicable to the website in question.
7. Right to information and the right to file complaints
You have the right at any point in time, in accordance with applicable data protection legislation, to request access to the personal data concerning you which we are processing, to have incorrect personal data corrected, to request that PostNord ceases its processing of your personal data, to have the processing of your personal data limited, to exercise your right to data portability and to object to our processing of your personal data. Please contact PostNord on the address set forth in section 9 below if you wish to exercise any of these rights.
You are also entitled to, at any point in time, file a complaint with the applicable supervisory authority, if you believe that our processing of your personal data is in breach of applicable data protection legislation.
8. Processing of personal data concerning children
PostNord’s Digital Channels are not intended for children and PostNord is thereby not knowingly collecting personal data pertaining to children. If you are a legal guardian and learns that your child has submitted personal data to PostNord, we ask that you contact us on the address stated in section 9 below so that you can exercise your rights to, inter alia, correction or deletion.
9. Contact information
The PostNord entity listed as the responsible entity for the Digital Channel in question is the data controller for personal data processed in relation to that Digital Channel. Where applicable, other legal entities within the PostNord Group may furthermore be data controllers for personal data processing in accordance with the terms of the respective service or function. If you have questions about PostNord’s processing of your personal data, or if you want information on and contact details to the data controllers in other companies within the PostNord Group, please contact PostNord’s Data Protection Officer on firstname.lastname@example.org or via mail to:
Data Protection Officer
105 00 Stockholm
10. Amendments to this integrity policy
PostNord may from time to time make amendments to this integrity policy. The current version of the integrity policy is always available on PostNord’s websites.
1 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.