Adcyma AB (“we,” “us,” “our”) is committed to ensuring the privacy and protection of personal data. This policy outlines our approach to data protection and sets out the principles we follow in ensuring our services comply with the General Data Protection Regulation (GDPR) (EU) 2016/679. This policy applies to all personal data we process in connection with our identity and access management (IAM) services.
This policy applies to the personal data we process about our customers, website visitors, users of our services, and any third parties whose data we manage. It applies to all employees, contractors, and third-party providers of Adcyma AB who have access to personal data.
We adhere to the following principles in relation to the processing of personal data:
We ensure that personal data is processed only when there is a lawful basis for doing so. The lawful bases for processing personal data may include:
Under the GDPR, individuals have certain rights regarding their personal data. We ensure that data subjects can exercise the following rights:
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risks posed by the processing of personal data. These measures include:
We retain personal data only for as long as necessary for the purposes for which it was collected or as required by law. Once the retention period has expired, personal data is securely deleted or anonymized.
Where we engage third-party service providers to process personal data on our behalf (subprocessors), we ensure that they comply with GDPR standards through data processing agreements. We remain responsible for the processing of personal data by our subprocessors.
Visit www.adcyma.com/agreements/subprocessors for more information about our subprocessors.
If personal data is transferred outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place to protect the data, such as:
In the event of a personal data breach, we will notify the relevant supervisory authority without undue delay, and no later than 72 hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. If the breach poses a high risk to individuals, we will also notify the affected individuals without undue delay.
We maintain documentation of all processing activities, including the categories of personal data processed, the purposes for processing, and the recipients of personal data. We also conduct data protection impact assessments (DPIAs) when necessary to ensure that new or significantly changed processing activities comply with GDPR requirements.
We provide regular data protection training to all employees and contractors who handle personal data. This training covers GDPR principles, data subject rights, and security procedures.
We may update this GDPR compliance policy from time to time to reflect changes in legal requirements or our practices. Any changes will be posted on our website, and where appropriate, we will notify you of significant changes by email.
If you have any questions about this GDPR Compliance Policy or wish to exercise your rights, please contact us:
Effective Date: 2024-09-22
Last Updated: 2024-10-13