Privacy Policy – NiTiAB
Effective from 28/09/2025
Last updated: 28/09/2025
Table of Contents
Introduction
What are personal data and what does processing mean?
Scope of the Policy
What this policy covers
Data Controller
NiTiAB as data controller
Legal basis for processing personal data
What personal data we process and why
Consent and consequences of withdrawal
Data portability
Retention periods
Data protection measures
Sharing of personal data
Embedded content and handling of third-party data
Your rights
Profiling and direct marketing
Cookies
Security disclaimer
Changes to this policy
Contact and complaints officer
1. Introduction
By accessing or using any of NiTiAB’s services, websites, or digital platforms, you consent to the collection, use, and disclosure of your information as described in this privacy policy. If you do not agree with the policy, please do not use our services.
We comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws. This policy describes how we handle your personal data and your rights in relation to them.
2. What are personal data and what does processing mean?
2.1 Personal data is any information that can identify a living individual, directly or indirectly. Examples include:
Name
Personal identification number
Email address
IP address
Photographs, videos, and device identifiers
2.2 Processing includes any operations such as:
Collection
Use
Storage
Alteration
Transfer
Erasure
3. Scope of the Policy
This policy applies to all data subjects whose personal data we collect, including:
Customers
Website visitors
Persons contacting us through any channel
4. What this policy covers
This policy governs all processing of personal data by NiTiAB in relation to our services, marketing, communication, and digital infrastructure.
5. Data Controller
A data controller determines how and why personal data are processed.
6. NiTiAB as data controller
NiTiAB Org.nr 556986-5271 is the data controller for all processing of your personal data.
7. Legal basis for processing personal data
We process personal data under the following legal bases:
Consent
Contractual necessity
Legal obligation
Legitimate interest (e.g., marketing, fraud prevention, analytics)
Multiple legal bases may apply to a single processing activity.
8. What personal data we process and why
8.1 Communication and customer service
We may process your name, contact details, and any information you voluntarily provide.
Purpose: To answer inquiries, provide support, and improve our service.
Legal basis: Legitimate interest.
Retention: Up to 12 months after the matter is closed.
8.2 Website usage and Wi-Fi access
We process data such as IP address, MAC address, browser type, and interaction data.
Purpose: To deliver services, maintain security, and improve performance.
Legal basis: Contract (Wi-Fi), Legitimate interest (website and analytics).
Retention: Website: 3 months; Wi-Fi: 6 months.
9. Consent and consequences of withdrawal
You can withdraw your consent at any time. However, if you do not provide necessary information or withdraw consent to its processing, you may lose access to some or all services. This includes services that rely on user identification or communication.
10. Data portability
You have the right to request that your personal data be transferred to another data controller in a commonly used, machine-readable format, where the processing is based on consent or contractual necessity.
11. Retention periods
We store personal data only as long as necessary for the stated purpose or as required by law. Certain data may be stored longer for legal, accounting, or security reasons.
12. Data protection measures
Technical safeguards: encryption, firewall protection, and secure networks
Organizational safeguards: role-based access, staff training in GDPR
Incident protocols: incidents are assessed, mitigated, and reported in accordance with legal requirements
13. Sharing of personal data
We may share your data with:
Service providers and subcontractors under data processing agreements
Authorities, if legally required or to protect legal rights
We never sell your data.
14. Embedded content and handling of third-party data
Our website may include embedded content (e.g., videos, articles). Such content behaves as if you visited the third-party website, which may collect data, use cookies, or track your interaction. NiTiAB is not responsible for the privacy practices of external websites.
15. Your rights
You have the right to:
Access your personal data
Rectify incorrect data
Erase data under certain conditions
Restrict or object to processing
Withdraw consent
Request data portability
Lodge a complaint with the Swedish Authority for Privacy Protection (IMY)
16. Profiling and direct marketing
You have the right to object to:
Direct marketing
Automated decision-making or profiling related to marketing activities
You can opt out through any marketing communication or by contacting us directly.
17. Cookies
We use cookies for functionality, analytics, and personalization. You can manage cookie settings through your browser. Details can be found in our [Cookie Policy]([insert link]).
18. Security disclaimer
We use appropriate safeguards to protect your data, but no system is completely secure. You use our services and provide personal data at your own risk.
19. Changes to this policy
We may update this policy without prior notice. Changes take effect 180 days after publication unless otherwise stated. Continued use of services implies acceptance of the updated terms.
20. Contact and complaints officer
NiTiAB
Odenvägen 40B, 181 32 Lidingö
nicklas@niti.se
Inquiries must be submitted in writing and include identification. Responses will be sent to your address as registered in the Swedish population register.


