Privacy Policy
Date (28.10.2020) Version [1.3] Revision date [15.1.2021]
Version 1.0. Last updated: 5 October 2020
1. ABOUT THIS PRIVACY POLICY
1.1 Definitions
Account: The Customer is provided with an Account. An Account is necessary to access the Products. The Account will be accessible through a set of credentials, consisting of a username and password combination for authorization.
Axess Digital: Axess Digital AS with business registration no. 923 232 001, and registered office address Oscar Hanssens veg 5, 6415 Molde, Norway.
Customer: The legal entity that has entered into an agreement with Axess Digital to purchase Axess Digital’s products or services.
Bridge: Axess Digital’s front-end system, Axess Bridge™, at bridge.axess.no is a web based portal that enables the End Users to log in to the Account and access any licenses connected to the Account.
End User: A physical person connected to the Customer as an employee or by other means, and which has been given authorization to use Bridge, a Product or otherwise be in contact with Axess Digital on behalf of the Customer.
GDPR: Regulation (EU) 2016/679 of the European Parliament and the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (this regulation is referred to as GDPR which is an abbreviation of the General Data Protection Regulation)
SaaS: Software-as-a-Service is a software distribution model in which a third-party provider such as the Supplier hosts software applications such as the Products and makes the Products available to customers such as the Customer with its End Users over the Internet. Instead of a one-time-transaction the Customer subscribes to the Product and pays the Supplier a recurring fee called the License.
Personal data: Any information relating to an identified or identifiable natural persons, see GDPR article 4 (1).
Products: The standard software products developed by Axess, which Axess Digital supplies separately or jointly to the Customer, pursuant to the agreed upon terms in the agreement with the Customer. The Products may be standalone applications or features that may be licensed (subscribed to) separately or as packages. A detailed description of each Product with prices and license period may be found on Axess Digital’s websites, see https://www.axessgroup.com/digital/ and bridge.axess.no.
1.2 Introduction
Our Products are sold as SaaS, and it is up to the Customer how the Products are used. If the Customer chooses to store or otherwise process personal data through one of our Products, this will be accessible for Axess Digital and our sub-suppliers. Our Products have no purpose or aim to process personal data, and Axess Digital has no control or insight in how the Customer uses our Products.
The only exception is Bridge, which is the interface between the Customer and Axess Digital. Axess Digital is the supplier of Bridge, as well as all Products and services made available through and which can be administered in Bridge. To a small degree, it is necessary for Axess Digital to process personal data in and through Bridge, in order for Bridge to function as the interface it is intended for. For all intents and purposes, the processing described in this Privacy Policy is for the processing in Bridge, not our Products.
In the event Axess Digital should offer a specific Product at a later time, which processes personal data in another way than described in this Privacy Policy, a separate Privacy Policy will be created and made available for all potential End Users for such Product.
Axess Digital is committed to your privacy and want your personal data to be private and secure.
1.3 Overview
In this Privacy Policy, Axess Digital explains:
- What personal data Axess Digital collects and how
- The purpose of collecting your personal data
- Disclosure of data to third parties
- Axess Digital’s security measures when processing your personal data
- Your rights as a data subject
Axess Digital is a Norwegian company. Axess Digital adheres to relevant Norwegian privacy law and meet the requirements of applicable laws and regulations within the EU/EEA. Axess Digital will ensure that your privacy rights and our processing of your personal data is held to the highest standard. Axess Digital offers Products with additional services according to requirements in the GDPR.
1.4 The Account and Bridge
Axess Digital may process personal data related to physicals persons that may be identified by using the Account. This Privacy Policy is relevant to you if you are a data subject that may be identified by the username used to log-in to the Account.
Axess Digital may process personal data related to the End Users that a Customer chooses to connect to Bridge. This Privacy Policy is relevant to you if you are an End User of Bridge with Account access.
For the purposes described in this Privacy Policy, Axess Digital is the controller, which collects and processes data as described herein. It is important for Axess Digital that you read this Privacy Policy thoroughly. We want you to be aware of your rights so you can help Axess Digital improve our policies. If you do not accept this Privacy Policy, you will not be able to access or use Bridge or any other Products as they rely on the use of Bridge.
1.5 Contact Information
If you have any requests concerning your personal data or any queries with regards to this Privacy Policy, please contact Axess Digital by reaching out to our Data Protection Officer at: privacy@axessgroup.com.
2. WHAT PERSONAL DATA WE COLLECT AND HOW
Axess Digital collects different types of personal data about End Users. It is up to the Customer which End Users Axess Digital collects personal data about. As far as Axess Digital is concerned, it is freely optional to be an End User of Bridge.
The personal data Axess Digital collects can be divided into three groups:
-
Minimum personal data needed to register an Account (these can be generic, non-personal data if the Customer chooses):
- · Your first name and surname
-
· Email address
- · Password
- · Place of work/employer (Associated Customer)
- · Installation access (location)
- · Picture of signature
- · Telephone number
- · Language
-
Personal data which may be generated while you use Bridge or a Product:
-
· Information about your mobile device:
- IP-address
- Hardware Manufacturer
- Operating system
-
· Application usage statistics
-
Personal data concerning yourself that you might choose to provide Axess Digital with through the Account or by other means whilst using Axess Digital’s Products and services, for example:
- Place of work such as boat or rig
- Occupation or position
- Other details you actively choose to provide through Bridge or your contact with Axess Digital directly
- To manage the agreement between Axess Digital and the Customer and the agreement with you as the End User
- To communicate with the Customer of Axess Digital including the Customer’s End Users, by answering service requests or providing any necessary and agreed upon assistance for the Products or Bridge.
- To ensure the technical functionality of Bridge with connecting Accounts and Products for each End User to fulfil the agreement with the Customer or the End User.
- To be able to control and monitor Bridge’s user base and prevent fraudulent activity or similar.
Axess Digital processes personal data in order to make it possible to enter into and to fulfill the agreement with the Customer. As Axess Digital and the Customer are two separate controllers, Axess Digital’s legal basis for processing personal data is through the agreement between Axess Digital and the Customer that includes this EULA and Privacy Policy (these two documents are presented to you as the agreement between Axess Digital and you as the End User). It is the Customer’s choice which End Users are connected to Bridge through authorization and access via the Account.
In the event the Customer decides to use a generic business email address and not a personal email address related to an identifiable natural person, then the processing of personal data in Bridge will be limited accordingly. Using a generic email address rather than a personal one, will not limit the Customer’s user experience of Bridge.
To prevent fraudulent activity in or in relation to Bridge, Axess Digital’s legal basis for processing is Axess Digital’s legitimate interest. This legitimate interest is Axess Digital’s desire in keeping Bridge secure and keeping the integrity and confidentiality of the underlying software behind Bridge, the data related to Bridge and the Products, whether personal data or data otherwise considered commercially sensitive.
Furthermore, Axess Digital may process your personal data when Axess Digital is legally obliged to do so, or if it is necessary to establish, exercise or defend a legal claim.
Axess Digital will also ask you as the End User to have read and accepted this Privacy Policy as well as the End User License Agreement from Axess Digital (these two documents are the agreement between the End User and Axess Digital). You will on Bridge be presented with a link to this Privacy Policy as well as End User License Agreement in order to make sure each End User has been informed about how and why Axess Digital processes personal data.
5. DISCLOSURE OF DATA TO THIRD PARTIES
Except in the instances described below, Axess Digital does not disclose collected personal data to third parties.
Axess Digital may disclose user base demographics and similar non-personal data to third parties. Such aggregated data does not identify any individuals and will not be linked to any personal data.
Your personal data is not transferred out of the EU/EEA by Axess Digital or our subcontractors unless you contact a sub-supplier outside the EU for support.
The personal data is stored in Microsoft Azure on servers within EU.
The sub-supplier Axbit AS are developing the Products and provide support regarding the Products to End Users.
Freshworks Inc. stores e-mail and name including any meta data stored in the signature field of an e-mail.
6. STORAGE AND PERSONAL DATA DELETION
Upon your request or otherwise when the personal data Axess Digital has collected is no longer necessary for the purposes described above, for instance in the event the End User’s authorization to use Bridge is removed by Customer or by another authorized End User, the personal data concerning you will be erased unless Axess Digital must store such data longer due to local legal obligations..
Personal data with the exception of approvals, results or discoveries from inspections related to an Account, will be erased no later than after 12 months after an Account has been deactivated or the Customer relationship has been terminated unless Axess Digital must store such data longer due to local legal obligations.
7. YOUR RIGHTS
This Privacy Policy is adherent to Norwegian law and falls under Norwegian jurisdiction. As such, you are entitled to certain rights. Please refer to the contact details provided in the first section (see section 1.5) if you wish to make use of or need assistance regarding the rights listed below.
Terminate the agreement with Axess Digital: If you wish to terminate the agreement with Axess Digital or to terminate your right to use the Products or to terminate your account needed to access the Products, Axess Digital will delete your account access and related personal data (unless Axess Digital must store such data longer due to local legal obligations) without undue delay after receiving an e-mail from you with such written request.
Consent: To the extent Axess Digital’s processing of your personal data relies on your consent, you may withdraw said consent at any time. If you wish to withdraw your consent, Axess Digital will stop any processing activities related to such consent and delete your related personal data without undue delay. The withdrawal of consent does not affect the legality of Axess Digital’s processing of your personal data based on the consent before it was withdrawn.
Access: You can at any time request access to the personal data relating to you. You can also request information about how Axess Digital collects personal data at any time.
Erasure and rectification: You can at any time request that Axess Digital erases or rectifies any of the personal data relating to you that Axess Digital has collected.
Objections: You may likewise request a restriction of the processing of your personal data or object to the processing of your personal data, but this may affect your user experience in Bridge or the Products. For Axess Digital’s processing activities that are based on legitimate interests as legal basis, you may object to such processing on ground relating to your particular situation, by contacting Axess Digital with using the email stated in section 1.5.
Data Portability: In the event Axess Digital’s collection and processing of your personal data is based on automatic means and Axess Digital’s legal basis is your consent or an agreement with you, you may request that the personal data concerning you and which you have provided Axess Digital with, be transmitted to you or to another data controller.
Complaints: You have the right to lodge complaints with the Norwegian Data Protection Authority (Datatilsynet).