Skip to content

Privacy Policy

Coredeq AB. Data protection and privacy.

Data Protection

Coredeq is committed to protecting the privacy of users and their customers. We stay updated on developments in data protection laws to ensure that you can trust the security of your personal data when using our platform.

This page is intended to explain what the rules entail, how they apply to your use of the Coredeq platform, and what measures we have taken to comply with them. This is not intended to constitute legal advice.

You should review this document along with our privacy policy and consult a legal specialist if you need advice or more information.

General Data Protection Regulation (GDPR)

Regulation (EU) 2016/679, more commonly known as the General Data Protection Regulation (GDPR), is an EU regulation aimed at harmonizing data protection laws within the EU.

GDPR focuses on giving individuals more control over how their data is used by companies and making the collection and processing of data more transparent.

GDPR was directly incorporated into UK legislation after the end of the Brexit transition period, meaning that UK businesses and other entities subject to UK law still have to comply with its provisions through "UK GDPR".

Basic GDPR Concepts

Controller and Processor

GDPR imposes different obligations on an individual depending on whether they are a controller or a processor of personal data.

A controller is an entity that determines to process personal data and makes decisions about the grounds for processing and the methods to be used. Controllers have certain obligations regarding personal data that you should familiarize yourself with before collecting personal data from your customers.

A processor is an entity that processes data for and on behalf of a controller. They do not make independent decisions about data or its processing, as they only process it on behalf of the controller and must follow all instructions given by the controller.

When you use the Coredeq platform, you are a controller. You have control over the data you upload to the Coredeq platform, what you do with that data, and why. As a result, you are responsible for ensuring that you have a lawful basis for processing data and that you do not retain the data longer than necessary.

You should ensure that you understand your obligations as a controller and update your own systems and policies to enable lawful transfer of personal data to Coredeq.

Coredeq is a data processor. We store and process data that you have collected under your instructions via the Coredeq platform. We will never use any personal data that you have uploaded to the Coredeq system for our own purposes or without your instruction.

Legal Basis for Processing

Personal data may only be collected and processed if there is a legal basis for it. The permissible legal bases are specified in the GDPR.

As a controller, Coredeq relies on our customers to choose the appropriate legal basis for the collection and processing of personal data, and to put in place appropriate notices or consents. Before using the Coredeq platform, you should take the time to identify which legal bases may be available to you, and only collect and process personal data to the extent necessary to fulfill the legal basis. You should not change the basis under which you have collected personal data without very good reasons, so it is important to understand the requirements of the different bases and ensure that you choose the correct basis from the outset.

Data Subject Access Rights

GDPR grants data subjects (i.e., your customers) certain rights concerning their personal data, including the right to access, correct, and/or delete any data relating to them.

Coredeq has implemented systems for you to be able to inform us if you receive such a request from a data subject, and for us to inform you if we receive such a request. You should familiarize yourself with the obligations that will be imposed on you, including related to any personal data you hold on your own systems or services other than Coredeq.

Data Protection

We have implemented security measures and measures to ensure that all personal data we handle is stored securely. We regularly test our products for bugs and vulnerabilities.

We also have procedures for regular backup systems, data recovery, and data protection to minimize the risk of corruption or loss of personal data.

Measures We Have Taken to Ensure GDPR Compliance

We take our responsibilities as a data processor seriously. We have implemented a number of procedures and taken several measures to help ensure that we comply with GDPR, such as:

  • Our data protection agreement uses the standard contractual clauses required to lawfully transfer personal data to us in the USA.
  • We have tools designed to detect data breaches and inform our customers as soon as possible.
  • We can handle requests for access to personal data and requests for deletion of personal data, and inform you when a data subject has made such a request to us.
  • We have evaluated and documented the personal data that we process on your behalf.
  • We encrypt personal data at rest and in transit, and have implemented other security measures to ensure an appropriate level of security in processing your personal data.

Updated: April 11, 2024