This Privacy Statement outlines your rights to privacy and our commitment to safeguarding your personal data.
Simple Sign International AB (Simple Sign) is a Swedish corporation, with its headquarters in Stockholm. Simple Sign delivers software and services to private and public businesses (Customers) in Europe. Simple Sign International AB is subject to European privacy legislation, including the General Data Protection Regulation (GDPR).
All major decisions regarding privacy in Simple Sign are supervised by our two Data Protection Officers (DPO:s). This Privacy Statement is available on SimpleSign.io, Simplesign.se homepage at the bottom.
- 1. How and when the Privacy Statement apply
- 2. Whose personal data we process
- 3. How we process personal data as data controller?
- 4. Data collection tools
- 5. What type of personal data we process
- 6. These are your rights
- 7. How we protect and store personal data
- 8. How we protect and store personal data as data processor?
- 9. Subcontractors
- 10. Statement changes
- 11. Contact us
How and when the Privacy Statement apply
This Privacy Statement applies to all digital products & services provided by Simple Sign International AB.
The Privacy Statement provides information about data processing carried out by Simple Sign when Simple Sign determines the purpose and means of the processing (Simple Sign act as data controller). It also provides information on data processing Simple Sign do on behalf of our Customers based on their instructions (the Customer as data controller and Simple Sign as data processor).
Personal data is information that can identify you as a person, such as an email address, street address or phone number etc. Processing your personal data is necessary for us to serve our Customers. Please do not use Simple Sign services if you do not agree with how we process personal data according to this Privacy Statement.
Whose personal data we process
Simple Sign manage personal data about users, recipients and contact persons or software users tied to our Customers. In addition we process personal data about persons representing potential Customers (leads) that approach us via our websites or other lead generating channels. Our statement in these regards is to be found in the data controller section.
We also process data on behalf of our Customers of which the Customer controls. Our statement in these regards is to be found in the data processor section.
In this Privacy Statement data subjects may also be referred to as persons or you.
How we process personal data as data controller?
When a Simple Sign subsidiary determines the purpose and means of managing your personal data, this company act as data controller. This includes scenarios where Simple Sign collects personal data in the context of you being an employee, job seeker, you being a representative for a Customer or Lead, or when you are a software user.
Why we process your personal data
About Customer contacts and software users
To manage our Customer relations in general and to meet our Customer commitments, Simple Sign needs information about you in your role as Customer contact person or user of a service. The purposes of processing this personal data are:
- Execute sales and contract process to Customers
- Provide requested offers on products and services to Customers
- Perform deliveries in accordance with agreements made with you or Customers
- Offer support to users of our products and services
- Improve and develop the quality, functionality and user experience of our products and services.
- Detect, mitigate and prevent security threats and perform maintenance and debugging
- Prevent abuse of our products and services
- Process orders, invoicing, payments and other financial follow-up
- Create interest profiles in order to promote relevant products and services
- Operate user communities to educate and enable interaction between users and Simple Sign
The legal ground for processing personal data according to the above-listed purposes in letter a) to i) is mainly because Simple Sign has a legitimate interest in processing your personal data from a business perspective in a manner that we believe do not conflict with your privacy rights or freedoms.
The legal ground for processing personal data according to the purpose listed in letter j) is your consent.
Simple Sign process personal data about Leads for marketing purposes. In order to provide targeted and relevant content to potential Customers, Simple Sign builds an interest profile based on your movement, choices and actions on Simple Sign:s websites as well as your response to marketing content per email. The legal grounds for such processing is mainly your consent.
You can read more about how we create such profiles, how you can adjust the profile as well as withdraw your consent in the sections below.
If you are a job seeker
If you are a jobseeker, we process personal data in order to evaluate your potential to become a Simple Sign employee. The legal grounds for such processing is your consent.
In order to monitor access to our premises, we process personal data about visitors. The processing is based on our legitimate interest to protect our business secrets, employees, premises and you as a visitor. You will be informed of your rights in this context when you register in our electronic visitor system at Epicenter (Headquarters in Stockholm, Sweden).
How we collect your personal data
If you are a jobseeker, we process personal data in order to evaluate your potential to become a Simple Sign employee. The legal grounds for such processing is your consent.
In general, Simple Sign collects personal data directly from you or other persons linked to our Customer. These persons may be a manager or colleague. If the Customer you work for starts a trial or test any of services we may collect information about them and if they add you as a user we also store your information.
If you received a contract from an existing Simple Sign user and then you select to store your contract online on Simple Sign, then we collect your personal data, even though this data was pre-added by the other contract party. This we do in order to activate your account for your convenience.
Please see the paragraph describing automatic data collection tools for more information on how these technologies function and your rights in this context.
In some cases, we may also collect information about you from other sources. These sources may be third-party data aggregators, SimpleSign:s marketing partners, public sources or third-party social networks.
Simple Sign will be able to combine personal data about you obtained from one source with data obtained from another source. This gives us a complete picture of you, which also gives us the possibility of serving you in a more relevant way with a greater degree of personalisation.
Data collection tools
Simple Sign uses different digital tracking technologies to collect information about your movements on Simple Sign Sites and when interacting with us.
Cookies and pixel tags
Cookies are small text files that contain a string of characters and uniquely identifies a browser.
Pixel tags are scripts that executes when a user lands on a website or opens an email. The pixel itself is not visible and can only be seen in the HTML of the site or email. It calls an application on a server that will cause a third party cookie to be downloaded to your computer or registers that the email has been opened.
If you would like to know more about cookies and how they work, please visit www.allaboutcookies.org.
Google cookies and technologies
Google Analytics: This cookie allows us to see information on user website activities including, but not limited to page views, source and time spent on a website. The information is depersonalized and is displayed as numbers, meaning it cannot be traced back to individuals. This will help to protect your privacy. Using Google Analytics we can see what content is popular on our websites, and strive to give you more of the things you enjoy reading and watching.
Google tag manager: This helps us track some of the individual clicks you do on our website in order for us to more clearly see what you are interested in. It also helps us understand if some areas of our website is not performing well, in terms of marketing.
Google Analytics Remarketing: Places cookies on your computer which means that after you leave our website, Google can show you advertisements about Simple Sign that you might be interested in, based on your previous behaviour on our website. This information is not personally identifiable.
Google AdWords: By using Google AdWords code, we are able to see which pages helped lead to contact form submissions. This allows us to make better use of our paid search budget. This information is not personally identifiable.
Google Adwords Remarketing: Places cookies on your computer which means that after you leave our website Google can show you advertisements about Simple Sign that you might be interested in, based on your previous behaviour on our website. This information is not personally identifiable.
You can prevent the information generated by the Google cookie about your use of our Sites from being collected and processed by Google in the future by downloading and installing Google Analytics Opt-out Browser Add-on for your current web browser. This Add-on is available at //tools.google.com/dlpage/gaoptout.
Facebook Remarketing: the Facebook pixel tag places cookies on your computer which can send an alert back to Facebook telling Facebook that you have checked out the website. We then assume that you have an interest for Simple Sign and the content on this site.
When visiting Facebook, you will then be exposed to information or adds with similar content. Please use your privacy settings on Facebook to limit exposure to marketing of this kind.
LinkedIn Remarketing, Analytics Global and tags: the LinkedIn pixel tag places cookies on your computer which can send an alert back to Linkedin telling LinkedIn that you have checked out the website. We then assume that you have an interest for Simple Sign and the content on this site.
When visiting LinkedIn, you will then be exposed to information or adds with similar content. Please use your privacy settings on LinkedIn to limit exposure to marketing of this kind.
Intercom is the provider of the chat that you can find on our website: simplesign.se and simplesign.io. The Intercom pixel tag places cookies on your computer which can send an alert back to Intercom. Intercom helps us track different events you do on the website so we can give you a better user experience. For e.g. if you visit a particular part of the website we can automatically give you feedback and hep directly via the chat.
We may also use Intercom as a medium for communications, either through email, or through messages within our product(s). As part of our service agreements, Intercom collects publicly available contact and social information related to you, such as your email address, gender, company, job title, photos, website URLs, social network handles and physical addresses, to enhance your user experience. For more information on the privacy practices of Intercom, please visit //www.intercom.com/terms-and-policies#privacy.
If you would like to opt out of having this information collected by or submitted to Intercom, please contact us.
What type of personal data we process
The type of personal data that Simple Sign process about you may be:
- Basic contact details such as name, address, telephone number and email.
- Demographic Information such as date of birth and age
- Employment information such as employer, title, position including preferences and interests in professional context
- Feedback, comments or questions about Simple Sign or concerning our products and services
- Content you have uploaded such as photos and video
- Unique user information such as login ID, username, password and security questions
Or go to: //stripe.com/us/privacy
- Traffic information as provided by your web browser such as browser type, device, language and the address of the website from which you arrived and other traffic information such as IP address
- Clickstream behaviour and movement on Simple Sign websites and in our products and services
- Email behaviour such as which emails from Simple Sign you open when and how. This is mostly collected via Intercom.
- Other personal data contained in your profile that you have freely given away on third party social networks such as LinkedIn, Google etc.
As data controller, Simple Sign does not process sensitive personal data about you.
Sharing of your personal data
Within the organisations of Simple Sign International AB
As Simple Sign always want to provide the best possible customer service and overall experience, most of our team is connected directly with the different chat or support services we provide.
In order to maintain a complete overview and insight into which Customers and contact persons have relations with within Simple Sign we will therefore share your personal data when needed among our team (Sales, Marketing, Development, Support etc.).
Outside of Simple Sign
Simple Sign may also share your personal data with external third parties in the following contexts:
Simple Sign may share your personal information with our partners in the event this is legitimate from a business perspective and according to applicable privacy legislation.
For example, if you purchase a product or service on behalf of your employer that Simple Sign provides through one of our certified partners. In this regard, Simple Sign and our partner may share personal data in order to be able to provide the product or service to the Customer.
The police and other authorities may demand the handover of personal information from Simple Sign. In these cases, Simple Sign will only hand over the data if there is a court order etc. to do so.
In connection with mergers, acquisitions or divestiture of all or parts of Simple Sign’s business, the acquiring entity, as well as its consultants, will obtain access to data managed by the Simple Sign entity/entities involved and this may in some cases include personal data. In such cases, external parties will enter into a NDA with Simple Sign.
These are your rights
Right to opt-out of marketing communications
You have the right to opt-out of receiving marketing communications from Simple Sign and may do so by either:
(a) Use your easy to use solution for DSR (Data subject Request). Go to: //esign.simplesign.io/gdpr/21/5b057d94e62b8
(b) Following the instructions for opt-out in the relevant marketing communication
(c) Contacting us via e-mail on email@example.com
Please note that even if you opt-out from receiving marketing communications, you may still receive administrative communications from Simple Sign, such as order confirmations and notifications necessary to manage your account or the services provided to Customers.
Your basic rights
You have the right to access your personal data by requesting an overview of the personal data we process about you and you may have a right to data portability.
You also have the right to request that Simple Sign corrects inaccuracies in your personal data. If you have an account on Simple Sign this can be done through your profile settings.
Further, you have a right to request deletion of personal data, and to restrict or object to our processing of your personal data according to this Privacy Statement or other service specific terms.
Finally, you also have a right to file a complaint with the data protection authorities with regards to our processing of your personal data.
Please go to: //esign.simplesign.io/gdpr/21/5b057d94e62b8
for all requests as mentioned in this section.
How we protect and store personal data
How we keep your personal data secure
Simple Sign takes the trust you and our Customers place in us very seriously. Simple Sign is committed to preventing unauthorized access, disclosure or other deviant processing of personal data.
Simple Sign shall ensure the confidentiality of personal data we process, maintain the personal data integrity and secure its availability according to applicable privacy legislation.
As part of our commitments, we utilize reasonable and appropriate organizational, technical and physical procedures and measures to safeguard the information we collect and process, taking into account the type of personal data and risk posed to you and our Customers upon breach.
Since root causes for privacy breaches are most likely to be found internally, we believe that building a strong corporate culture where respect for and awareness around privacy among our employees are fundamental to ensure lawful processing and protection of your data The following measures are of particular importance in this regard:
- Our CEO & CTO have been working together in order to structure internal processes so that no employee gain access to non-relevant personal data.
- Been to seminars about GDPR to learn from others
- eLearning privacy courses that are mandatory for all employees
- Mandatory procedures for keeping records of processing activities and assessing risks for data subjects applies to all in Simple Sign.
- Data processing agreements with subcontractors that process data on behalf of Simple Sign.
- Classification of personal data to ensure implementation of security measures equivalent to risk assessment
- Assess the use of encryption and pseudonymisation as risk mitigating factors.
- Limiting access to personal data to those that need access to fulfil obligations according to law or service agreement etc.
- Working on systems that detects, restores, prevents and reports privacy incidents.
- Use security self-assessments to analyze whether current technical and organisational measures are sufficient to protect personal data, taking into account the requirements outlined in applicable privacy legislation.
- Premises protected by access control and video surveillance systems
How long we store your personal data
Simple Sign will only retain your personal data for as long as necessary for the stated purpose, while also taking into account our need to answer queries or resolve problems and to comply with legal requirements under applicable laws.
This means that Simple Sign may retain your personal data for a reasonable period after you and our Customer’s last interaction with us. When the personal data that we collected is no longer required we erase it. We may process data for statistical purposes, but in such cases, data will be pseudonymised or anonymised.
How we protect and store personal data as data processor?
Simple Sign provides different services to our Customers. Most of our services involves processing of the Customers’ data, hereunder their personal data. The purposes of processing is determined by our Customers not by Simple Sign.
Making the Customer the data controller. Simple Sign do in such cases act as data processor and process the data on behalf of and according to instructions given by the Customer. The relation between the Customer as data controller and Simple Sign as data processor shall be regulated by a data processing agreement.
Customer and Simple Sign obligations
When the Customer act as data controller the Customer shall, according to applicable privacy legislation, ensure the legal grounds for processing the personal data. Further, the Customer shall assess and establish ownership to the risks posed to data subjects by processing their personal data.
Another important aspect of the Customer’s duty as data controller is to comply with the information duty towards data subjects.
Simple Sign is a natural part of the Customers duties as data controller, in the sense that Simple Sign’s services constitutes parts of the processing of personal data that the Customer must ensure are compliant with applicable privacy legislation. Thus, when Simple Sign processes personal data on behalf of its Customers, we must do so in accordance with privacy legislation applicable for data processors.
In short, the Customer and Simple Sign are obligated to cooperate to ensure privacy for data subjects. Simple Sign shall provide the information necessary for the Customer to be compliant with applicable privacy legislation.
Simple Sign uses subcontractors to process personal data and may export your or our Customers data outside the EU in this regard. These subcontractors are typically vendors of cloud services or other IT hosting services.
When using subcontractors, Simple Sign will enter into a data processing agreement (DPA) with subcontractors in order to safeguard your privacy rights and to fulfil our obligations towards our Customers.
When subcontractors are located outside the EU, Simple Sign ensures legal grounds for such international transfers on behalf of you or our Customers, hereunder by relying on Privacy Shield (US) or using the EU Model Clauses.
Simple Sign relies on some strategic external third parties to support our business processes and to provide our cloud services. These third parties include but are not limited to:
-Intercom (US), provider of Intercom, as our marketing automation and support tool
-Google (US), provider of our email, office automation and file storage solution
In any case, you are always welcome to request an overview and more detailed information on Simple Sign’s subcontractors, hereunder documentation of legal grounds for international transfers mentioned above.
If we make significant changes to our Statement that materially alter our privacy practices, we will notify you such as sending an email or posting a notice on our website and/or social media pages prior to the changes taking effect.
The last update of this Privacy Statement was May 23th, 2018.
We value your opinion. If you have any comments or questions about our Privacy Statement, any unresolved privacy or data use concerns that we have not addressed satisfactorily, or concerning a possible breach of your privacy, please send them to firstname.lastname@example.org.
If you want to make a request you can easiest do that via our DSR request tool: //esign.simplesign.io/gdpr/21/5b057d94e62b8
We will handle your requests or complaints confidentially. Our representative will contact you to address your concerns and outline the options regarding how these may be resolved. We aim to ensure that complaints are resolved in a timely and appropriate manner.