Privacy notice

 

 

This privacy notice covers all legal entities within the Joulin and explains how we use the personal information we collect about you when using our website, when you are applying for a job, or when you are an employee within Joulin.

 

What information do we collect about you?

We collect information about you when you register with us, place an order for products or services, or provide shipping details. We also collect information when you voluntarily complete customer surveys, provide feedback, or apply for a job. Website usage information is collected using cookies. We may also collect contact information on tradeshow visits.

 

In particular, we may collect and process the following categories of personal data:

a) Name, gender, and email address.

 

b) Your contact details, registration details, as well as your company name and position, and business location, including address, phone number, company identification number, and email address.

 

c) Information on your requests and Joulin products purchased.

 

d) Communication
We record and store your communications with us by email or other means. When you make a telephone communication, our customer service records your questions or complaints in our database. We may also, where appropriate, record the phone call, of which you would be informed in advance

 

e) Information collected when you use our websites and other digital media, if any.
When you visit our websites, we may record your IP address, browser type, operating system, source website, and web browsing behavior

 

f) Information related to social networks
Depending on your social network settings we may receive information from your social network provider. For example, when you identify yourself with a social network account to use our services, we may receive your social network profile including contact details, interests, and contacts. For more information on the personal data we receive from your social media provider and how to modify settings, please refer to your social media provider's website and privacy policy

 

g) Information you choose to share with us
You can choose to share information with us, for example, by giving us a comment on social media when completing a customer survey or submitting your data to participate in an event

 

Your personal data will only be used for the following purposes

We use information about you to process your order, administer your account, and email you information about other products and services that we believe may be of interest to you. We also use the information collected from the website to personalize your repeated visits to our website and transmit your personal information to our group of companies so that they can offer you their products and services. Joulin will only share your information for marketing purposes within the Joulin and our distributors.

 

For candidates and employees, the information we have includes your application and references, your employment contract and any modifications thereto, correspondence with or about you, such as letters confirming your salary for a mortgage operation, information necessary for payroll purposes, benefits, and expenses; contact and emergency contact details; records of vacation, illness, and other absences; information necessary for the policy of monitoring equal opportunities; and records related to your professional history, such as training records, records or other performance evaluations and, where applicable, disciplinary and complaints.

 

In particular, the processing may also be carried out for the following purposes:

 a) Carry out the necessary commercial and administrative procedures with the users of the web and our clients

 

b) Contact you for contract negotiations and to process your inquiries

 

c) In case of formalizing contracts, or accepting a quote, the data is used to process the corresponding services, orders, collection and delivery notes, etc. In this respect, your data may be shared with third-party providers and, if necessary, we will share your payment data with the relevant financial institution

 

d) Send commercial advertising communications by email, social networks, or any other electronic or physical means, in case you have expressly consented to the sending of such commercial communications electronically. If you are a Joulin customer, we may send you commercial information related to the services you have contracted

 

e) Contact you to respond to your inquiries and process your complaints

 

f) Contact you to get your opinion about the service provided or the quality of our services

 

g) Similarly, the data collected during your navigation are processed with the purpose of providing access to the online contents of the web, as well as attending to the requests of the users of the web, keeping a statistical record of visits (IP addresses, browser data, country, page accessed, etc.) in order to facilitate us to develop better services and products, optimize our offer, provide more efficient customer service, and improve the design and content of our websites

 

h) The data of Clients and/or Suppliers will be treated, within the contractual relationship that binds them with the Company, in compliance with the administrative, fiscal, accounting, and labor obligations that are necessary under current legislation

 

i) The data you provide us through our interactive Chat tool (chatbot) will be used to manage your requests, as well as, if you give us your express consent, include them in a database to segment them and create profiles according to your interests and to be able to proceed subsequently to carry out actions or commercial communications, as well as to improve our solutions or services

 

j) Objection or revocation. You may object or revoke your consent to receive marketing communications at any time by following the instructions in the relevant marketing communication or by contacting us via email at privacyofficer@piabgroup.com.

 

k) In case of completing any of the forms provided on our website or in any other means, it will be necessary to provide certain personal data, which will be processed for the purpose for which they are requested.

 

l) The personal data of our employees will be used for the fulfillment of the corresponding labor and contractual obligations.

 

In accordance with the prevailing laws on electronic commerce and communication, we inform you that Joulin does not perform SPAM practices, therefore, it does not send commercial emails by email if it does not have the necessary legitimacy. In any case, you will always have the possibility to withdraw your consent to receive communications from us.

 

We will not process your personal data for any other purpose than those described except by legal obligation or regulatory requirement.

 

You will not be subject to decisions based on automated processing that produce effects on your data.

 

What is the legal basis for processing? 

The legal basis for processing your personal data is your consent granted to carry out the purposes described above and that will be requested at the time you request information, or by checking the corresponding box when collecting your data in any of our personal data collection forms.

 

In the event of a contractual relationship between the user, client, supplier, or employee and the Company, the legal basis will be the contractual obligations that will have been generated, as well as, where appropriate, the fulfillment of the corresponding legal obligations.

 

In the event that you do not provide us with your personal data or if you do not accept this privacy policy, Joulin will not carry out the processing of your personal data, but may also imply the impossibility of receiving information from the Company's services or, where appropriate, of fulfilling the contractual obligations between you, your company, and Joulin.

 

How long do we store your personal information?

The personal data you provide will be kept for the time necessary to manage the information you request from us, as well as to manage the services you request from us or, for the fulfillment of any contract that is generated between Joulin and third parties. In the event that we have your personal data in our database for the sending of commercial information, they will be kept as long as the necessary legal basis that legitimizes the processing is maintained. You may revoke your consent at any time in order not to receive commercial information.

 

Once the data has met the needs for which they were collected, we will delete them. However, we will keep your data longer if it is necessary for compliance with legal obligations. Likewise, it may be necessary to keep them for the time necessary for the prescription of the legal responsibilities that are generated.

 

We normally store B2B contacts (customers, distributors, or other contact persons) 10 years after the last contact or when the person requests the deletion of their data.

 

The data you provide us to start a selection process will be kept for a maximum period of one year. Subsequently, if you have not joined Joulin or are not part of a selection process, they will be deleted, and we will not keep a copy.

 

The personal data of our employees will be kept for the duration of their employment with Joulin and subsequently for the periods provided by law.

 

Security back-ups

All production data is deleted in accordance with their retention periods respectively. For security reasons we keep data in encrypted back-ups also after data has been deleted from our production environment. In any event, Joulin will honour “the right to be forgotten” as well as our set retention periods, but it will not take effect fully until the last backup cycle has been completed. In order to comply with Article 32 in GDPR, this is not considered a violation of Article 17 in GDPR.


In the event of a recovery of data from an encrypted back-up, we keep a register of erased data (anonymous Record ID only) in order to exclude that data from any recovered data.

 

Who has access to the information about you?

Only authorized Joulin employees and distributors have access to personal information. Authorized IT staff may audit and monitor equipment, systems, and network traffic for security, compliance, and maintenance purposes. For applicants and employees HR and authorized managers have access and can process personal data.

 

The categories of recipients to whom your Personal Data may be communicated are as follows:

 a) appointed third-party processors, such as IT providers, consultants and advisors, and other companies providing ancillary services

 

b) social media providers, marketing agencies, and fraud detection service providers

 

c) entities and public authorities, exclusively for the purpose of complying with the corresponding legal obligations

 

d) other suppliers to whom, where appropriate, your personal data may be transferred, such as financial institutions, insurers, logistics/transport service providers, among others

 

The data you provide may be incorporated into our database which is integrated into the information systems of the Joulin, whose parent company is Piab AB, based in Sweden. Therefore, the data may be known by the other companies of our Group, where appropriate for operational reasons.

 

In any case, all the third parties mentioned above will have previously signed the corresponding Data Processing Agreement following our instructions in accordance with current regulations on the protection of personal data, will be subject to the duty of professional secrecy, or will act in compliance with a legal obligation.

 

The information you provide to us both through this website and through the application will be hosted on Joulin's servers.

 

How to exercise your rights as a data subject

If you wish to exercise the rights that GDPR grants you, please send us an email to privacyofficer@piabgroup.com indicating in the subject, the right you want to exercise and attach a copy of your national identity document or passport.

 

The Rights that the current regulations recognize and that, where appropriate, you can exercise are:

 

Right to Access

You have the right to have Joulin inform you whether or not your personal data is being processed, and in the event that the processing is confirmed, it will enable your access by providing you with the following information:

  • The purposes of the treatment.
  • The categories of data in question.
  • The term or criteria of conservation of the data.

 

Right to rectification

You have the right to have Joulin rectify your data when it is inaccurate or incomplete by means of an additional amending declaration.

 

Right to be forgotten
You have the right to have Joulin delete your data, when:

  • The treatment is illegal
  • You have withdrawn your consent
  • They are no longer needed in relation to the purposes for which they were collected or processed
  • You have exercised a right of objection and other legitimate reasons for the treatment do not prevail
  • The data must be deleted to comply with a legal obligation of Joulin

 

You will not have the right to have Joulin delete your data when the treatment is necessary:

  • To exercise the right to freedom of expression and information
  • To comply with a legal obligation of Joulin
  • For the formulation, exercise or defense of claims
  • For public interest based on current legislation for reasons of public health or for historical, statistical, or scientific research purposes

 

Right to Data Portability:
You have the right to have Joulin transmit your data to another data controller or to yourself, through a structured, commonly used, and machine-readable format, when the treatment is carried out by automated means and is based on:

  • A consent for specific purposes.
  • The execution of a contract or pre-contract communication with you.

 

The right to data portability shall not apply where:

  • Transmission is technically impossible
  • Transmission may adversely affect the rights and freedoms of third parties
  • The processing has a purpose of public interest based on current legislation

 

Right of Restriction of Processing:
You have the right to request restriction of processing where one of the following applies:

  • the accuracy of the personal data is contested by you, for a period enabling Joulin to verify the accuracy of the personal data;
  • the processing is unlawful, and you oppose the erasure of the personal data and request the restriction of their use instead;
  • Joulin no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise, or defense of legal claims;
  • you have objected to processing pending the verification of whether the legitimate grounds of the controller override those of the data subject

 

Joulin may continue to process your data as long as legitimate interest prevails over your interests or the rights and freedoms of you.

 

Joulin must inform you of the right to object or restrict the processing of your data explicitly, clearly, and separately from any other information, at the time of the first communication.

 

Right to object:
You have the right to object to the processing of your personal data and ask Joulin to stop processing your personal data if is being processed for the purpose of:

  • direct marketing
  • scientific/historical research and statistics
  • Joulin’s legitimate interest

If you object to direct marketing, Joulin will stop using your personal data and comply with your request.

 

Joulin may continue to process your data as long as legitimate interest prevails over your interests or the rights and freedoms of you.

 

Joulin must inform you of the right to object or restrict the processing of your data explicitly, clearly, and separately from any other information, at the time of the first communication.

 

Right, not to be subject to profiling:
You have the right not to be subject to profiling for the purpose of which is to make individual decisions based on automated data processing and aimed at assessing, analyzing, or predicting the following personal aspects:

a) Professional performance

 

b) Economic situation

 

c) Health

 

d) Personal preferences or interests

 

e) Reliability

 

f) Behavior

 

g) Location or movements of the person

 

When profiling is based solely on automated processing, you will have the right to be informed if the decision that can be taken is likely to produce legal effects that significantly affect you.

 

You will have the right to obtain human intervention from Joulin, to express your point of view, and to challenge the decision, if the treatment has been authorized by:

  • The explicit consent from you
  • A contract between Joulin and yourself or your company

 

It shall not apply to the right not to be subject to profiling where the decision that may be taken as a result of profiling is authorized by:

  • the explicit consent from you
  • a contract between Joulin and yourself or your company
  • processing is based on current legislation.

 

How will we use the information about you?
We use the information about you to process your order, manage your account, and email you information about other products and services we think may be of interest to you. We also use information collected from the website to personalize your repeat visits to our website and pass on your personal information to our group of companies so that they may offer you their products and services. Joulin will only share your information for marketing purposes within the Joulin and with our distributors.

 

For applicants and employees, the information we hold includes:

  • your application form and references
  • your contract of employment and any amendments to it
  • correspondence with or about you, for example, letters to you about a pay rise or, at your request, a letter to your mortgage company confirming your salary
  • information needed for payroll, benefits, and expenses purposes
  • contact and emergency contact details
  • records of holiday, sickness, and other absences; information needed for equal opportunities monitoring policy
  • records relating to your career history, such as training records, appraisals, other performance measures, and, where appropriate, disciplinary and grievance records

 

The use of AI, artificial intelligence within Joulin

Joulin is using an AI-based application (Pixie - from Piab) for two purposes; to write conference notes for online conferences on Microsoft Teams, and to make extended searches for personal data within our HR and CRM systems.

 

When writing conference notes, the user will always be advised that the meeting is being recorded by AI and also has the option to leave the meeting before the recording starts. The legal basis for using AI to record meeting notes is “consent” and Joulin will store these notes in its own storage location in accordance with our retention policy.

 

If you wish to withdraw your consent, please contact privacyofficer@piabgroup.com including the specific meeting notes for which you wish to withdraw your consent.

 

When making extended searches for personal data, the search will include using AI to find other public information online to supplement the data stored in Joulin’s own systems within the EU. For the extended online search, we will only use basic information such as name, company name, and country of residence. This basic information will be transferred to ChatGPT and processed in the US before being returned to us. All other personal data will be contained in Joulin’s own systems within the EU. The legal basis for this processing is our “legitimate interest” and Joulin will store these searches in its own storage location in accordance with our retention policy.

 

If you wish to exercise your right to not be subjected to this extended search via AI, please contact privacyofficer@piabgroup.com.

 

Transfer of personal data to third countries
In some situations, Joulin and/or a subsidiary may transfer personal data to countries outside of the EU/EES. In these situations, Joulin and/or the subsidiary will take the necessary measures to protect your personal data in accordance with applicable requirements, for example, by requiring the receiving party to protect your personal data in accordance with applicable data protection regulations.

 

Specifically, customer (B2B) data is collected and stored in the central IT system Salesforce. The databases are situated in the USA (Dallas and Phoenix). Also, as mentioned above, we use Pixie and ChatGPT for extended searches where we transfer basic personal data to ChatGPT. All of our transactions with ChatGPT are stored on OpenAI's servers.

 

For employees, we have in place safeguards including an IT security policy and HR records storage instructions to ensure the security of your data.

 

Marketing
We would like to send you information about our products and services of ours and other companies in our group that may be of interest to you based on legitimate interest. If you do not wish to receive marketing information or material, you may opt-out whenever you want to. You have a right at any time to stop us from contacting you for marketing purposes or giving your information to other members of the Joulin. If you no longer wish to be contacted for marketing purposes, please contact privacyofficer@piabgroup.com.

 

Any communication sent will be incorporated into Joulin's information systems.
In the event that you provide us with your personal data and accept this privacy policy, the User expressly consents to the Company carrying out the following activities and/or actions, unless the User indicates otherwise:

a) The sending of commercial and/or promotional communications in response to your request for information by any means you have provided us

 

b) The sending of any information, including commercial information about news, events, fairs, etc., and all that information related to our activities and related to the products purchased or services contracted by our customers

 

The User is informed that the means enabled by the company to communicate with customers and others affected are corporate landlines and mobile phones and corporate or customer service email provided on our website.

 

If you submit personal information through a means of communication other than those indicated on this website or, by any other means provided by the Company, it will be exempt from liability in relation to the security measures provided by the means in question.

 

Resumes
We will only accept the Curriculum (CV) that you send us through the "work with us" section of our website. In the event that the User sends his CV to Joulin, we inform him that the data provided will be processed to make him participate in the selection processes that may exist, carrying out an analysis of the applicant's profile with the aim of selecting the best candidate for the vacant place in the Company. We inform you that we will only accept your CV if you send it to us electronically so that resumes sent or delivered on paper will not be accepted. In case of any modification in the data, please inform us in writing as soon as possible, in order to keep your data duly updated.

 

We inform you that your CV and the data it contains will be kept for a maximum period of two years (or longer if there is a legal obligation to do so), after which the data will be deleted, guaranteeing total confidentiality both in the treatment and in its subsequent destruction. In this sense, after the aforementioned period and, if you wish to continue participating in the Joulin selection processes, please send us your CV again.

 

However, in the event that you are hired by Joulin, your CV will be kept, along with the rest of your employment record as long as your contractual relationship with the Company is maintained.

 

Access to your information and correction
You have the right to request a copy of the information that we hold about you. If you would like a copy of some or all of your personal information, please email or write to us at the address below. For your security and privacy, we must make sure who is asking and where to send the information by asking for credentials. We want to make sure that your personal information is accurate and up to date. You may ask us to correct or remove information you think is inaccurate. You have the right to request, at any time, to have all your information deleted from our records. To request to have your information deleted, contact privacyofficer@piabgroup.com.

 

Cookies
When you visit our website, we may send "cookies" to your computer. A cookie is a small text file or piece of data that a website that you visit can place or save onto your computer. Cookies do not contain any personally identifiable information. However, if you provide such personally identifiable information to us (such as by registering for an Internet-related service or password provided by us), such information may be linked to the data stored in the cookie. There are two types of cookies. The first type saves a file for a longer period onto your computer, and it can remain on your computer after you shut it off. Such a cookie could, for example, be used to tell a visitor what information on the website has been updated since his or her last visit to that website. The second type of cookie is called "session cookie". While you are visiting a website, session cookies are temporarily stored in your computer's memory. This could be done, for example, to keep track of what language you have chosen on the website. Session cookies are not stored for a long period of time on your computer since they disappear when you close your web browser.

 

We may use third parties to assist us in collecting or processing information obtained through cookies.

 

We may use cookies for several reasons, such as:

  • to compile anonymous statistics related to patterns and trends of browsing;
  • to analyze sales data;
  • to conduct marketing research;
  • to user adapt website content or functions;
  • to aid or track site visits of users of certain Internet-based services;
  • to enable users with passwords to re-enter certain web pages without having to re-type previously typed information.

 

Your choices regarding cookies

  • If you have not given your consent to the use of cookies, no cookies will be placed on your device
  • If you would like to delete cookies or instruct your web browser to delete or refuse cookies, please visit the help pages of your web browser
  • Please note that if you delete cookies or refuse to accept them, you might not be able to use all the features we offer, you may not be able to store your preferences, and some of our pages might not display properly

 

Other websites

Our website contains links to other websites. This privacy policy only applies to the website within Joulin. When following links to other websites, you should read their privacy policies.

 

Joulin declines any responsibility for the use of your personal data by third parties. The use of these websites is done at your own risk

 

Changes to our privacy policy
We keep our privacy policy under regular review and we will place any updates on this web page. This privacy policy was last updated on December 18, 2023.

 

How to contact us?
Please contact us if you have any questions about our privacy policy or information we hold about you in Joulin:

Email to privacyofficer@piabgroup.com
Or
Piab AB
Privacy Officer
Vendevägen 89
SE-182 32 Danderyd
Sweden
Phone: +46 8 630 25 00