Privacy Policy

General

BENIFY AB'S Privacy Policy

As part of our business, we process personal data about you both as a data controller and as a data processor. Your privacy is important to us and we are keen to be transparent about what personal data we process about you and why.

This privacy policy describes who is responsible for the processing of your personal data, what personal data we process about you, why we process your personal data, how long and where we store your personal data, and how we have gained access to the personal data, if we have not received this information from you.

 

 

Part I – Information on how we process personal data about you as a data controller

Personal data processed in connection with the marketing of our products (workshops, events, newsletters, press releases or other communications)

Who is responsible for the processing of your personal data

Benify AB with registration number 556595-0317 is the data controller for the processing of your personal data.

What personal data we process about you

We process personal data about you in the form of your name, job title, preferred language, e-mail, telephone number, workplace address, and any other contact details. In cases where we photograph and/or film at our events and seminars, we also process data about you in the form of images and recorded material. Should we use images and recorded material for, for example, marketing purposes where you appear, we will have obtained your prior consent.

Personal data processed in connection with the marketing of our products (workshops, events, newsletters, press releases or other communications)

How we collect your personal data

We have collected this personal data from you when (i) the organization you represent became, or was about to become, a client of ours, (ii) you contacted us in some other way, (iii) you voluntarily participated in one of our surveys, or (iv) you wish to receive communication in the form of e.g. newsletters and invitations to events from us.

Why we process your personal data

We process your personal data in order to communicate with you and send you marketing material in your professional capacity. We communicate with you to provide information about our services and products and when your company is in a contractual negotiation with Benify. Such processing is based on a balance of interests and Benify’s legitimate interest to maintain a business relationship with your employer and to be able to communicate with you in your professional role regarding, e.g. events and workshops that we believe may be of interest to you. If you want more information about the balance of interests, you can contact our data protection officer.
If you have given your consent, we will instead process your personal data for the above-mentioned purposes based on your consent.

Who will get access to your personal data

Other companies within the Benify group will, if necessary, process your personal data. Personal data may be shared with IT providers who process data on our behalf, so-called data sub-processor. For example, cloud service providers may have access to your personal data. We have signed data processing agreements with them, which means, among other things, that they are obliged to process your personal data securely, accurately and with confidentiality.

How long we process and save your personal data

Benify processes and stores your personal data until you opt-out of receiving our communications. Thereafter, the personal data is stored for three months, after which it is deleted. If you subscribe to our news, we store your personal data until the day you choose to unsubscribe.

Personal data processed within the framework of our customer assignments, partners and suppliers

Who is responsible for the processing of your personal data

Benify AB with registration number 556595-0317 is the data controller for the processing of your personal data.

How we collect your personal data

The personal data we process has been provided to us by (i) customers, (ii) partners, (iii) suppliers, (iv) other parties related to the project, or (v) collected from private or public registers or other sources.

What personal data we process about you

We process data about you in the form of your name, email address, telephone number, employment ID, job title, employer and workplace and any other contact details.

Why we process your personal data

We process your personal data to fulfil a contractual obligation in connection with our project planning, project management and follow-up of the project and documentation of the progress of the project. We also process your personal data when you act as a contact person for our customers, partners or suppliers. On the basis of a contractual obligation, we also process personal data in order to manage and administer invoicing, reminders and payments, and to be able to handle and administer our accounting and our accounts receivable arising within the framework of a project.

We process your personal data on the basis of a balance of interests and Benify’s legitimate interest in generating new business, initiating new collaborations with our partners and to retain and maintain existing customer relationships. Furthermore, we process your personal data in connection with internal training and documentation of projects as well as in case of issues arising on the basis of Benify’s legitimate interest, as the above activities are a prerequisite for the business and for the daily operation.

We also process your personal data on the basis of a legal obligation to comply, where applicable, with the rules on protection against money laundering and terrorist financing.

Who will get access to your personal data

Other companies within the Benify group will, if necessary, process your personal data. Personal data may be shared with IT providers who process data on our behalf, so-called data sub-processor. For example, cloud service providers may have access to your personal data. We have signed data processing agreements with them, which means, among other things, that they are obliged to process your personal data securely, accurately and with confidentiality.

How long and where we store your personal data

The personal data that we process in order to fulfil our agreement with you or the customer, partner or supplier you are employed by is processed for as long as it is necessary for us to administer the contractual relationship. For personal data received from our suppliers, such personal data is deleted three months after a supplier has been terminated, or when the contact details of the contact person have been updated by the supplier.

As regards our customer assignments, we save personal data relating to a project for ten years, with reference to the limitation period in the Limitations Act, after such an agreement has been terminated or expired.

Personal data relating to invoicing and/or payment and where processing is necessary under the Accounting Act, we retain personal data for seven years in accordance with the Accounting Act.

Personal data processed in connection with feedback, questionnaires and surveys of various kinds

Who is responsible for the processing of your personal data

Benify AB with registration number 556595-0317 is the data controller for the processing of your personal data.

What personal data we process about you

We process data about you in the form of your name, job title, email address, telephone number, location data and any other contact details. Your connection data and language are automatically stored by the system, other personal data is collected from you when they are relevant for surveys of various kinds.

Why we process your personal data

We process your personal data on the basis of your consent for the purpose of collecting user insights from you. When you register to participate in our future research studies such as user tests, interviews and surveys, we process your personal data. We also process your personal data when you choose to be part of our user panel aimed at improving your experience as an end user.

Furthermore, we process your personal data within our feedback module where you can write what you think about our platform and our services in a free text field. We also process this personal data with the support of your consent.

Who will get access to your personal data

Other companies within the Benify group will, if necessary, process your personal data. Personal data may be shared with IT providers who process data on our behalf, so-called data sub-processor. For example, cloud service providers may have access to your personal data. We have signed data processing agreements with them, which means, among other things, that they are obliged to process your personal data securely, accurately and with confidentiality.

How long and where we store your personal data

Unless you withdraw your consent, which you can do at any time, your personal data processed within the framework of our research studies will be stored for one (1) year and the personal data processed within the framework of the feedback module will be stored for three (3) years locally by us. Unless you withdraw your consent, we will store your personal data for user insights for ninety (90) days after which it will be deleted.

Personal data processed in connection with your visit to our premises

Who is responsible for the processing of your personal data

Benify AB with registration number 556595-0317 is the data controller for the processing of your personal data.

What personal data we process about you

We process personal data about you in the form of name, email, job title and any other contact information.

Why we process your personal data

When you visit one of our offices, we process your personal data on the basis of a balance of interests and our legitimate interest to maintain security and protect all persons present in the event of a fire, for example, but also to prevent theft and be able to contact you during and after your visit.

How long and where we store your personal data

After you have visited us, your personal data is stored for three months after the last visit to ensure that we can reach you if something should have happened during your visit.

Personal data processed in connection with the application for employment

Who is responsible for the processing of your personal data

Benify AB with registration number 556595-0317 is the data controller for the processing of your personal data.

What personal data we process about you

Name, date of birth, employment ID, social security number, email, financial information, age, photo, education, education grades, job ratings, professional experience, language, country, job title and other details you provide about yourself in your application. We also carry out personality tests and logic tests for certain categories of candidates. In cases where such tests are carried out, we provide information about the processing of such personal data before the start of the test and ask for your consent to such processing.

Why we process your personal data

When you apply for employment with us, we process your personal data (i) to fulfil our obligations and comply with your and our rights under labour law with the purpose of being able to safeguard each party’s rights under the Discrimination Act, (ii) on a balance of interests with the purpose of collecting and reviewing your CV, cover letter, certificates and diplomas to assess and consider different candidates based on experience, merits and study results and to administer the invitation and booking of time for interview(s), and (iii) based on your consent for the purpose of conducting recruitment tests as part of the recruitment procedure and to save your personal data in a candidate pool for future positions.

For your information, you do not have to provide your personal data to us as it is neither a legal nor a contractual requirement. However, if you do not provide the personal data requested in the recruitment process, we will not be able to fulfil our commitments and carry out the recruitment process.

Who will get access to your personal data

Other companies within the Benify group will, if necessary, process your personal data. Personal data may be shared with IT providers who process data on our behalf, so-called data sub-processor. For example, cloud service providers may have access to your personal data. We have signed data processing agreements with them, which means, among other things, that they are obliged to process your personal data securely, accurately and with confidentiality.

How long and where we store your personal data

As our processing of your personal data is based on a balance of interests, we do not, as a general rule, process your personal data after the recruitment process is over.

If you have participated in a recruitment process with us, we need to save your personal data for at least two years (or during the limitation period specified in each country’s discrimination law) after the end of the application procedure in order to possibly be able to safeguard our rights and obligations under the Discrimination Act.

If you consent to the continued processing of your personal data, for example in a candidate pool, for future recruitment opportunities, we will process your personal data for this purpose until you withdraw your consent or the purpose has ceased.

Personal data that we process through the use of cookies

Benify uses so-called cookies to facilitate the use of our website. For more information, please see Benify’s Cookie Policy which is available on our website.

Part II – Information on how we process your personal data in our benefits portal as a data processor

Who is responsible for the processing of your personal data

Benify offers a digital benefits portal in which our customers, as your employer, can manage and visualize compensation and other benefits for you. This means that your employer acts as a data controller for your personal data. Thus, Benify AB with registration number 556595-0317 acts as a data processor on behalf of your employer.

As part of our business, Benify only processes personal data about you that your employer has provided to Benify, or that you choose to provide within the digital benefits portal. When you log in to the benefits portal for the first time, you will be provided with information about your employer’s role as data controller, Benify’s role a data processor, and how and why Benify processes your personal data.

What processing measures we use when processing your personal data

Benify customizes the digital benefits portal according to your employer’s specific wishes. Therefore, the processes for the processing of your personal data may differ depending on which personal data your employer has commissioned Benify to process. Benify only processes your personal data in accordance with your employer’s instructions and/or in accordance with applicable law. When Benify processes your personal data on behalf of your employer, the following processing operations are mainly, but not limited to, carried out:

  • Your employer sends your personal data to Benify. Your personal data is imported into the benefits portal and presented to you to visualize your total compensation and enable you to place orders for benefits.
  • At your request, for example when you place an order for a benefit in the benefits portal, your personal data will be transferred to the relevant benefit suppliers and ultimately returned to your employer for reporting purposes.
  • In cases where your employer has approved the processing of your personal data to develop new tools, products and services and to perform testing and troubleshooting in the benefits portal, Benify uses anonymized, aggregated or pseudonymized data.
  • In cases where you contact our customer service, we process the personal data provided by you for the specific customer service case.
  • In cases where your employer provides benifyDeals to you, the following processing operations take place: benifyDeals provides and communicates discounts from well-known brands to you as an end user via e-mail to the e-mail address provided to us by your employer. We consider this communication as direct marketing, which requires an active consent from you as an end user. We obtain your consent the first time you log in to the benefits portal. If you do not consent, no mailings will be made. You can withdraw your consent to benifyDeals at any time; either in the benefits portal or directly via the link in the received email.

 

Cookies
In the benefits portal, we use cookies, which are small files downloaded to your computer, to improve your user experience. The cookies we use are divided into different categories, namely (i) required cookies, (ii) preference cookies, and (iii) statistics cookies. All cookies require your consent except for required cookies and the cookie that saves your current cookie settings. The latter cookies are based on Benify’s legitimate interest.

The categories of cookies we use may include:

  1. Required cookies make the benefits portal usable by enabling basic features such as page navigation and access to secure parts of the benefit portal. The benefits portal cannot function properly without these cookies.
  2. Preference cookies allow the benefits portal to memorize information that changes the way the benefits portal behaves or looks, such as your preferred language or the region you are in.
  3. Statistics cookies help us understand how you interact with the benefits portal by collecting and reporting static anonymous data.

Your consent to cookies and your choice of cookie settings are stored in a specific and necessary cookie. Your consent to cookies is valid for twelve months, after which you need to give your consent again. You can change your cookie settings or withdraw your consent at any time via your user account in the benefits portal. Cookies can also be managed via your browser settings.

What personal data do we process about you

We process personal data about you as a data processor on behalf of your employer in the form of name, email address, postal address, workplace, employment data (e.g. role, employee number or other identification), social security number, compensation data (e.g. salary, vacation, pension and car benefits), and telephone number.

Why we process your personal data

We process your personal data on behalf of your employer and to fulfil the contractual obligation that Benify has entered into with your employer. Furthermore, we process your personal data to enable you and your employer to use our benefits portal and all associated services, to enable your employer to communicate with you, to clarify all your benefits and to offer you benefits from our third-party suppliers and, where applicable, discounts via benifyDeals.

For more information, please contact your employer.

Who will get access to your personal data

Independent third-party supplier

The benefits portal, offers you products and services from third-party suppliers independent from Benify. The third-party suppliers do not act as subcontractors to Benify but as partners, meaning that when you make a purchase through the benefits portal, the third-party supplier becomes your single direct contractual party with regard to the purchase. In order for you to be able to make a purchase in the benefits portal, you need to confirm that the third-party supplier will have access to your personal data required to complete the purchase and confirm that the third-party supplier is entitled to process your personal data in order to fulfil its commitment to you. Once you confirm the order, Benify will send the order to the third party supplier and provide them with your personal data relevant to the purchase. Accordingly, Benify will transfer the personal data required in connection with the purchase to the relevant third-party supplier. Once you have completed an order, the third-party supplier acts as data controller for the personal data that has been transferred. The third-party supplier is thus responsible for determining the purposes and means of processing the data.

Data processors of Benify

Other companies within the Benify group will, if necessary, process your personal data. Personal data may also be shared with IT suppliers who process data on our behalf, so-called sub-processors. For example, cloud service providers may have access to your personal data. All subcontractors acting as sub-processors to Benify must sign a separate data processing agreement with Benify. According to the Data Processing Agreement, the sub-processor undertakes to comply with the same requirements and applicable data protection legislation as those imposed on Benify by your employer. Benify is obliged to inform your employer if a sub-processor is engaged to process your personal data. Your employer has the right to object toto the processing of personal data provided by your employer by such a sub-processor. Please note that sub-processors marked with an asterisk* are only relevant if your employer has ordered a specific Benify service.

See below the complete list of all data processors.

Benify AB sub-processors

CompanyProcessing activityStorage locationProcessing location
Data processors Benify AB
Expenses Benify AB*Payment service supplier (Benify Group)EUEU
UAB Benify OperationsSupplier of internal services (Benify Group)EUEU
Lifeplan AB*Consulting partner in pension & insurance
(Benify Group)
EUEU
SFDC Ireland Limited (Salesforce)Supplier of customer case management systemsEUEU/US
Adyen N.V.*Supplier of direct payment functionalityEUEU
COOR Service Management AB*Supplier of receipt managementEUEU
IP Only ABProvider of Contact
center system
EUEU
Atlassian Inc.Provider of customer issue management systemEUEU/USA
Boost.aiProvider of support chat platformEUEU

 

Data processors Benify BV

Benify ABOperation of the Benify applicationEUEU

 

Data processors Benify France Sarl

Benify ABOperation of the Benify applicationEUEU

 

Data processors Benify DE GmbH

Benify ABOperation of the Benify applicationEUEU

 

Data processors Benify AS

Benify ABOperation of the Benify applicationEUEU

 

Data processors Benify OY

Benify ABOperation of the Benify applicationEUEU

 

Data processors Benify A/S

Benify ABOperation of the Benify applicationEUEU
Telehuset A/SAlternative customer service supplierEUEU

 

How long and where we store your personal data

We process your personal data during the time that you are employed by your employer and your employer is a customer of Benify. Your personal data is also stored during the time that Benify must maintain it to comply with applicable legal requirements, e.g. regarding archiving of accounts. Your personal data is stored at data centres in Gothenburg.

How we protect your personal data

It is important to Benify that your personal data is handled securely and protected from unauthorized access, alteration and/or destruction. We take appropriate security measures to ensure that your personal data is protected at all times. We also adhere to generally accepted standards and frameworks to protect your personal data.

To ensure a structured and strategic approach to information security, Benify has fully implemented an information security management system in accordance with ISO/IEC 27001, which includes both administrative and technical security controls. Benify is certified according to the standards ISO/IEC 27001:2013, ISO/ICE27018:2019 and ISO/ICE27701:2019. Furthermore, we issue ISAE3000 (SOC 2 type II) reports and we are also part of the Cloud Security Alliance STAR program.

The certification process has been carried out by an independent external certification organization accredited by an accreditation body.

For more information see Benify Security Page which is available on our website.

Part III – Transfer of personal data to third countries

All our processing and storage within the Benify software service takes place within the EEA, more specifically Sweden, and no processing regarding personal data provided by our customers (and your employer) via the user file is carried out in third countries.

However, in accordance with the European Court of Justice’s Schrems-II judgment, a potential transfer to a third country may occur. This is because Benify as part of our services offers support systems both for you as an end user and for customer contact. These systems are provided by Salesforce and Atlassian. If your employer or you as an end user contact Benify’s customer service, a case is registered with the data required for the specific case, which is provided by you or your employer. Thus, activity by you or your employer is required for the data to be subject to a potential third country transfer. It is only the personal data provided by you or your employer for the specific customer service case that could potentially be considered as a third country transfer.

Despite this minimal risk that any third country transfers could occur, Benify has taken adequate organizational and security precautions. Furthermore, Benify has taken additional precautions as we have contractually regulated that personal data that Atlassian and Salesforce reach via Benify may only be stored in and accessed from the EU and both Salesforce and Atlassian have joined the new framework for data protection, the EU-U.S. Data Privacy Framework, DPF.

Part IV – Your rights

As a data subject, you have several rights to exercise when Benify acts as a data controller under the GDPR. Benify ensures that the below rights are fulfilled when a request is made to us. In order for you to exercise the rights listed below, please contact dpo@benify.com. Please note that we may need to request additional information, if necessary, to verify your identity in relation to your personal data.

When Benify acts on behalf of your employer as a data processor, you have the rights listed below, but then you should exercise the rights against your employer and not against Benify. In some cases, you have the right to obtain a copy of the personal data processed by your employer (“right of access”). Your employer may request assistance from Benify to fulfil your request. Please contact your employer for more information on how to exercise your rights.

Right to withdraw your consent and object to processing

If we process your personal data based on your consent, you have the right to withdraw your consent at any time. You have the right, under certain circumstances, to object to our processing of your personal data. If you exercise your right to object to our processing, which you can do when the processing is based on a balance of interests, we will only be able to continue processing if we can demonstrate that there is a legitimate interest for us to process the data and if our interests outweigh yours.

Right of access to your personal data

You have the right to obtain information, from us, as to whether your personal data is processed by us, what personal data we process about you and how your personal data is processed. Furthermore, you have the right to request a copy of the personal data processed by us.

Right to rectification of your personal data

You have the right to obtain from us, without undue delay, the rectification of inaccurate personal data that we process about you. You also have the right to supplement incomplete personal data with regard to the purpose for which we process your personal data by providing us with additional personal data.

Right to erasure (“right to be forgotten”)

You have the right to have your personal data erased without undue delay and we have an obligation to erase your personal data without undue delay if, for example, your personal data is no longer necessary for the purpose for which it was collected or if you object to processing based on a balance of interests (e.g. marketing).

Right to restriction

You have the right to request that the processing of your personal data shall be restricted, for example if you object to the accuracy of certain personal data or to processing for a specific type of purpose.

Right to data portability

You have the right to obtain your personal data that we process about you in a structured, commonly used and machine-readable format for the purpose of transmitting the personal data to another controller by you or Benify where the processing of your personal data is carried out by automated means on the basis of your consent or for the performance of a contract with you.

Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with the competent supervisory authority if you consider that the processing of your personal data is being processed unlawfully or incorrectly by us.

Part VI – Our contact details

If you would like to contact us regarding our processing of your personal data, please contact the data controller below or our data protection officer.

Benify AB Box 24101
104 51 Stockholm
info@benify.com

Data Protection Officer:
Jannika Törnqvist
dpo@benify.com

This Privacy Policy is undergoing an annual review and was last updated as of March 26th 2024.