Privacy Policy
This policy (the “Privacy Policy”) describes how Accumeo AB (“Accumeo”) collects, processes and protects personal data relating to persons who use Accumeo’s platform (the “Platform”).
The Privacy Policy applies from the time it is published on accumeo.com. Updates are published on accumeo.com, and the Customer is informed by email of material changes.
Personal data means information that directly or indirectly can identify a natural person. Information that has been anonymised or aggregated in such a way that it cannot identify a particular natural person, even with the aid of other information, is not covered. The terms used in the Privacy Policy have the same meaning as in the Terms of Use, unless the context indicates otherwise.
The Privacy Policy is available in Swedish and in English. In the event of any discrepancy between the versions, the Swedish version prevails.
1. Data Controller
Accumeo AB, Swedish registration number 559314-0071, is the data controller for the processing of personal data carried out via the Platform and within the framework of the services provided under the Terms of Use. Accumeo can be contacted at info@accumeo.com.
2. Data Processed
2.1 Data provided by the Customer
Accumeo collects and stores data provided in connection with registration on the Platform and data the Customer provides when using the Platform, for example when carrying out a transaction or when using other services or tools that Accumeo provides. The data includes, among other things:
- Data provided on registration on the Platform, consisting of an email address and, in some cases, a telephone or mobile number as well as first and last name.
- In the case of transactions through the Platform: personal identity number, financial data such as bank account number and, where applicable, registered address.
- Data on the Customer’s use of the Platform.
- Data on whether payment for transactions has been made.
- Information and correspondence sent to Accumeo, for example feedback or information provided to Accumeo’s customer service.
- Documentation that Accumeo requests in order to meet its obligations under the rules on measures against money laundering and terrorist financing. The Customer may, for example, need to evidence their registered address, verify their identity and answer questions in Accumeo’s know-your-customer form.
Providing the data required for registration, for carrying out a transaction and for customer due diligence is a condition for Accumeo to be able to enter into and perform the agreement with the Customer. If the data is not provided, Accumeo cannot give the Customer access to the Platform or carry out transactions.
2.2 Data collected automatically by Accumeo
When the Customer uses the Platform or other services provided by Accumeo, or clicks on links in newsletters from Accumeo or on the Platform, data is collected automatically from the computer, mobile telephone or other device used. Such data is linked to an individual customer only where the Platform is used by a registered customer. The data consists of connection data, page view statistics, IP address, traffic to and from the Platform, advertisement data, referring URL and standard log data from web logs.
2.3 Data from third parties
Accumeo may obtain additional data about the Customer from third parties, such as suppliers or data providers, and add that data to Accumeo’s records. The data may include credit information and information from courts or public authorities. Such data is obtained only to the extent permitted by law.
3. Purposes and Legal Bases
Accumeo processes the Customer’s personal data for the following purposes and on the following legal bases:
- To give the Customer access to the Platform, provide customer service and information about the Customer’s account, enable transactions to be carried out and give access to the tools and services Accumeo offers from time to time. Legal basis: performance of the agreement with the Customer.
- To send information about content on the Platform, about previous transactions and about updates to the Platform, the Terms of Use, the Privacy Policy or Accumeo’s services. Legal basis: performance of the agreement with the Customer and, as regards information Accumeo is required by law to provide, legal obligation.
- To administer, provide, develop and ensure the technical functionality of the Platform. Legal basis: Accumeo’s legitimate interest in providing a secure and efficient service.
- To monitor that the Platform is not used in breach of the Terms of Use and to protect the rights of Accumeo or others under the Terms of Use, for example to prevent, detect and investigate security incidents and unauthorised activity. Legal basis: Accumeo’s legitimate interest in protecting the business and its users, and legal obligation as regards incident handling.
- To market Accumeo’s services and products to existing customers by email or otherwise. Legal basis: Accumeo’s legitimate interest in marketing similar services. The Customer may object to direct marketing at any time, after which processing for that purpose ceases.
- To compile statistics, carry out market and customer analyses and pursue business and methodology development. Legal basis: Accumeo’s legitimate interest in developing the business. The data is aggregated or pseudonymised where possible.
- To enable financing or a transfer of all or part of Accumeo or its business. Legal basis: Accumeo’s legitimate interest in being able to carry out such a transaction.
- To meet obligations under the rules on measures against money laundering and terrorist financing, including customer due diligence and screening against sanctions lists and lists of politically exposed persons (PEP). Legal basis: legal obligation.
- To meet obligations under securities, accounting and tax legislation, including the documentation of orders and transactions and reporting to the Swedish Tax Agency. Legal basis: legal obligation.
- To use cookies and similar technologies. Legal basis: the Customer’s consent, except for cookies that are necessary to provide the service the Customer has requested. See Section 6.
Where processing is based on Accumeo’s legitimate interest, Accumeo has carried out a balancing test and concluded that that interest outweighs the Customer’s interest in the data not being processed.
Accumeo does not take decisions based solely on automated processing, including profiling, that produce legal effects concerning the Customer or similarly significantly affect the Customer.
4. Objection and Withdrawal of Consent
A Customer who does not wish to receive communications from Accumeo may contact Accumeo at info@accumeo.com and object to the processing. The Customer always has the right to object to direct marketing.
Where processing is based on the Customer’s consent, that consent may be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. Processing based on contract or on a legal obligation cannot be withdrawn, and if the Customer objects to such processing, Accumeo may be prevented from giving the Customer access to the Platform, to the services or to customer support.
5. Disclosure of Personal Data
Accumeo does not sell the Customer’s personal data and does not disclose it to third parties for marketing purposes without the Customer’s express consent. Disclosure takes place only in accordance with applicable law.
In order to perform its obligations under the Terms of Use and for the purposes set out in Section 3, Accumeo may share the Customer’s personal data with:
- The securities company on whose behalf Accumeo provides its services. That company is an independent data controller for the processing it carries out within its authorised business, including the documentation of orders and measures against money laundering, and provides its own information about that processing.
- Companies within the same group as Accumeo, for the provision of shared services and in order to detect and prevent breaches of Accumeo’s policies.
- Subcontractors engaged by Accumeo for the business, including IT suppliers, cloud service providers, payment institutions and other companies that handle incoming and outgoing payments in connection with transactions and the sending of communications to the Customer. These process personal data as processors on behalf of Accumeo, under data processing agreements and only on Accumeo’s instructions.
- The counterparty to a transaction and the company whose shares the transaction concerns, to the extent necessary to carry out the transaction and to register the change of ownership.
- Supervisory authorities, law enforcement authorities, other public authorities and authorised third parties, in order to respond to requests in connection with investigations or other activities that may give rise to liability for Accumeo or the Customer. To the extent permitted by law, Accumeo discloses the data that is relevant and necessary, such as name, personal identity number, email address and IP address.
- A prospective acquirer, if Accumeo is to be sold or merged with another company. Disclosure is limited to what is necessary for the transaction and takes place subject to confidentiality.
If the Customer’s personal data is to be used or disclosed for purposes other than those set out in the Privacy Policy, Accumeo informs the Customer of this in advance.
6. Cookies
When the Customer visits or uses the Platform, Accumeo and Accumeo’s suppliers may use cookies, web beacons and similar technologies. Cookies that are not necessary to provide the service the Customer has requested are used only with the Customer’s consent, which the Customer gives and may change at any time in the cookie settings on the Platform. Further information on which cookies are used and how long they are stored is set out in Accumeo’s cookie policy.
7. Access to and Correction of Personal Data
The Customer’s password is the key to the Customer’s account and should consist of unique numbers, letters and characters. The Customer must not disclose the password to anyone else. The Customer is responsible for activity carried out through the Customer’s account and must notify Accumeo immediately if the password has been compromised for any reason.
The Customer can view and change certain personal data in the account settings on the Platform and must update the data or notify Accumeo’s customer service if the personal data changes or is incorrect.
8. Security and Transfers to Third Countries
Accumeo applies physical, technical and organisational security measures, adapted to the scope and sensitivity of the personal data processed, to prevent unauthorised access, unauthorised use, loss, deletion or other damage. Examples of such measures are encryption and pseudonymisation of data, firewalls and access controls.
Accumeo processes the Customer’s personal data within the EEA as a starting point. If personal data is transferred to a country outside the EEA, the transfer is made only to a country that the European Commission has decided provides an adequate level of protection, or on the basis of appropriate safeguards, primarily the European Commission’s standard contractual clauses together with any additional safeguards required following an assessment in the individual case. The Customer may request information about which transfers take place and a copy of the safeguards applied.
9. Retention Periods
Personal data is retained only for as long as is necessary for the purpose for which it is processed. The following applies as a starting point:
- Data relating to the customer relationship is retained for the term of the agreement and thereafter for as long as is needed to establish, exercise or defend legal claims.
- Customer due diligence documentation and data on transactions is retained for five years under the rules on measures against money laundering, calculated from the end of the business relationship or from the date the transaction was carried out.
- Documentation of orders and services under the securities rules is retained for at least five years.
- Accounting records are retained for seven years under the Swedish Accounting Act.
- Data processed for direct marketing is retained until the Customer objects to the processing.
- Log and usage data is retained for [twelve months], unless it is needed for longer in order to investigate an incident.
At the Customer’s request, Accumeo closes the Customer’s account and erases the Customer’s personal data, with the exception of data that Accumeo is required by law to retain or that is needed in order to handle a dispute or to ensure compliance with the Terms of Use. Accumeo may also close accounts that are used in breach of the Terms of Use. Data that cannot be erased is anonymised or pseudonymised.
10. The Customer’s Rights
The Customer has the right to obtain information about which personal data Accumeo processes about the Customer by requesting a copy of the data. The request must be made in writing and is free of charge.
The Customer also has the right to request rectification of inaccurate personal data, erasure of personal data and restriction of processing. The Customer has the right to object to processing based on Accumeo’s legitimate interest and always has the right to object to direct marketing. The Customer has the right to receive the personal data the Customer has provided, and which is processed on the basis of contract or consent, in a structured, commonly used and machine-readable format, and to have that data transmitted to another data controller.
A Customer who wishes to exercise any of these rights should contact Accumeo at info@accumeo.com and state their full name and the email address used on registration. Accumeo responds to a request without undue delay and no later than within one month. If the request is complex or if several requests have been made, that period may be extended by two months, in which case the Customer is informed of the extension and the reasons for it within one month.
The Customer has the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), which is the supervisory authority for the processing of personal data in Sweden.
11. Contact Details
For questions about Accumeo’s processing of personal data, the Customer may contact Accumeo at info@accumeo.com.
This English text is a translation provided for convenience. The Swedish version is the legally binding version; in the event of any discrepancy, the Swedish version prevails.