Privacy policy for Arctic Group AB

    Privacy policy for Arctic Group AB

    Introduction

    At Arctic Group, we value your personal privacy. This privacy policy explains which personal data we process, why we do so, how long we store it, and what rights you have under the General Data Protection Regulation (GDPR).

    Data Controller and Contact

    Data Controller: Arctic Group
    Email: dataskydd@arcticgroup.se

    If you have questions about how we process personal data or wish to exercise your rights, the easiest way to contact us is via the email address above.

    What personal data we collect

    The data we collect depends on the context. It may include:

    • Contact details: name, email address, phone number, employer, and job title.
    • Customer and contact details: correspondence, meeting notes, orders, participation in events or training.
    • Marketing and event details: registrations, areas of interest, consents, and opt-outs.
    • Technical information: IP address, device information, page views, clicks in newsletters, and cookies (see the cookies section below).
    • We generally do not process sensitive personal data. If you voluntarily provide, for example, allergy information before an event, it will only be used for that purpose and deleted afterward.

    Automated decision-making and profiling. We do not use automated decision-making or profiling that has legal or significant consequences for you. All decisions concerning your relationship with us are made with human involvement.

    Why we process your data

    We use personal data to:

    • Deliver ordered services and fulfill agreements
    • Manage customer relationships, support, and administration
    • Invite you to events and training sessions
    • Send relevant information, newsletters, and invitations
    • Improve our website and communication
    • Comply with legal requirements, such as accounting

    Processing is based on agreements, legitimate interest (e.g., customer relationships and marketing), or consent (e.g., newsletters). You can withdraw your consent or object to direct marketing at any time.

    How long we store data

    We only keep data for as long as it is needed for its purpose:

    • Customer and contract information: during the contract period and up to three years thereafter.
    • Accounting records: seven years as required by law.
    • Event-related data: normally up to 36 months after the event for follow-up, future invitations, and marketing communication, unless you object.
    • Newsletter data: until you unsubscribe or we determine it is outdated.
    • Technical logs: the shortest possible time for security and statistical purposes.

    Who has access to the data

    We only share personal data with:

    • Service providers (e.g., IT, CRM, or newsletter platforms) that process data on our behalf under data processing agreements.
    • Partners for joint events, if necessary for administration or follow-up.
    • Authorities, if required by law.

    We never sell your personal data.

    Transfer outside the EU/EEA

    In some cases, we may use providers that process personal data outside the EU/EEA, for example, for cloud services or analytics tools. If such a transfer occurs, we always ensure there is a legal basis and adequate safeguards, such as the EU Commission’s Standard Contractual Clauses and other technical and organizational security measures.

    We only choose providers that comply with EU data protection requirements.

    Security

    We protect your personal data through appropriate technical and organizational measures. Access is only granted to individuals who need the data for their work, and we use security solutions such as login, encryption, and logging where relevant.

    Cookies

    We use cookies and similar technologies on our website to provide a good user experience, analyze traffic, and improve content. You can choose to accept or decline cookies in your browser or via our cookie banner. Read more in our cookie policy on the website.

    Your rights

    You have the right to:

    • Access your personal data (data subject access request)
    • Have incorrect data corrected
    • Have data deleted in certain cases
    • Object to processing for direct marketing
    • Request restriction or data portability where applicable

    Contact us at dataskydd@arcticgroup.se if you wish to exercise any of these rights. We will respond as soon as possible, normally within 30 days.

    Newsletters and email communication

    We occasionally send newsletters and invitations to individuals who have shown interest in our services or events. You can unsubscribe at any time via the link in the emails or by contacting us.

    For existing customers, we may also send necessary information related to our services and collaborations.

    To respond to a question or fulfill a request from you, we may need you to provide personal information such as name, address, email address, and phone number. This information is used solely to contact you.

    Personal data provided in job applications is used only for recruitment purposes.

    Links to other websites

    Our website and our communications may contain links to other websites. We are not responsible for how these websites handle personal data, so we recommend that you read their own privacy policies.

    Changes to the Privacy policy

    We may update this privacy policy from time to time. The latest version is always available on our website.
    Last updated: December 2025

    Contact

    Questions about privacy or how we process personal data?
    Email: dataskydd@arcticgroup.se