Forento AB ("Forento" or "we"/"us") process personal data in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, General Data Protection Regulation ("GDPR"), and any other Swedish laws and regulations applicable in the field of data protection. This Privacy Policy explains how we use the personal data that we collect from you when you use our Services as stated in our Terms of Use. It also describes your rights toward us and how you can exercise your rights. Capitalized terms used herein without definition shall have the meanings assigned to them in the Terms of Use.
Please note that Forento may also process personal data of our customer's ("Customer") own users, end-users, in connection with our provision of Services to Customers, in which case Forento is the processor of personal data for purposes of GDPR. If Forento is the processor of your personal data, i.e., not the controller, for purposes of GDPR, please contact the controller of your personal data in the first instance to address your rights with respect to such data, i.e. the Customer providing the course or other services in connection with which you provided your personal data. For the avoidance of doubt, this Privacy Policy is based on the requirements in article 28 in GDPR whenever processing is to be carried out on behalf of a data controller.
"Personal data" means any information relating to an identified or identifiable natural person that, directly or indirectly in combination with other information, can be linked to a living, natural person. Personal data is a very broad term, and it includes the name, contact details and IP addresses of such person.
"Processing" of personal data means, including but not limited to, collecting, registering, organizing, structuring, and storing. Processing also means alteration, production, reading, listing, using, and disclosing personal data by transfer, disseminating, changing, removing as well as deletion of the personal data.
"Data subject" means an identified or identifiable person to whom personal data relates.
Forento will only process personal data to the extent necessary to fulfil the Services under the Terms of Use and for purposes which are compatible with providing the Services. Such purposes and processing may include, inter alia:
Forento will only process personal data if we have a lawful basis for doing so. Lawful bases for processing include, inter alia, consent, contractual necessity and our "legitimate interests" or the legitimate interest of others. Forento may process personal data based on the following legal grounds in GDPR:
When you visit one of our digital channels (for example our website, social media and video sharing sites, our mobile applications, online events, digital meetings, webinars, online training etc.), as well as when you contact us via e-mail or our website's chat function, we may collect information about you, such as your name, address, postal address, e-mail address, phone number, identification data and information regarding your use of Forento's products and services. In some cases, we may process your personal identity number. Forento may also collect your personal data from other public sources and external partners from other countries. Personal data that may be collected and processed by Forento could include:
Please note that when you enter your personal data in connection with using the services of our payment providers, your personal data will be processed by us through our third-party service provider, whereupon your personal data will be processed in accordance with the payment provider's privacy policy (as applicable from time to time), which can be found here: stripe.com/privacy.
In relation to some features offered by us, we use third-party service providers. Such third-party service providers may process your personal data in the capacity as data processors. Below, you can find links to information on how our current third-party service providers processes personal data. When you subscribe for any of the services as set forth below, we will (through the third-party service provider) process personal data in accordance with such information.
The Customer has through this Privacy Policy been informed about the fact that personal data will be stored in a database for the purposes described above. If Forento engages co-operation partners, Forento shall ensure that any personal data is afforded equivalent protection as prescribed in this Privacy Policy and in accordance with the GDPR. Forento may also transfer personal data to others within Forento's business operation, coordinators, co-operation partners and providers, as well as third parties, including but not limited to suppliers, cloud service providers, consultants, and authorities. Forento shall, however, only transfer personal data if Forento has a legal ground under the GDPR to do so.
Forento may also transfer personal data to a third country, i.e. a country outside the EU/EEA, or to international organizations according to applicable laws and data regulations. Forento and third parties may be based anywhere in the world, which could include countries that may not offer the same legal protections for personal data as the EU/EEA. Forento will comply with local data protection requirements and its internal global privacy standards and Forento will apply the necessary safeguards under the applicable law of the country transferring the data for such transfers.
The personal data will be, dependent on the purpose for which it is collected, archived, confidentially erased, or anonymized in accordance with applicable rules, which, in short terms, will be when it is no longer necessary. Personal data will be stored during the time it is necessary for Forento to fulfil its obligations and for the purposes set out above. Forento will bring necessary measures to provide the personal data with protection against unauthorized access and loss thereof.
Data subjects have the right to object to Forento's processing of the personal data such as, for example, when processed in connection with direct marketing. Data subjects also have the right to request deletion, restriction, and rectification of the personal data. If consent is withdrawn, or if the stored personal data is incorrect or irrelevant, Forento must delete, restrict, or correct such personal data.
Data subjects have the right to request information about Forento's processing of personal data. If a request is made electronically, Forento shall provide the information in an electronically readable form which is structured and commonly used. Any request from data subjects shall be answered within a reasonable period by Forento.
Forento shall, upon request, provide information about the purpose of the processing, what personal data is being processed, recipients of the personal data and, if possible, for how long the personal data will be stored. Upon request, Forento shall also provide information about the possibility to request deletion, rectification, or alteration of the personal data, as well as how to lodge a complaint to Forento or the competent supervisory authority. Furthermore, Forento shall upon request provide information about the origin of the personal data, the existence of profiling and automatic decision-making, and any transfers to third countries. If requested, Forento shall also provide the data subjects with a copy of the processed personal data.
Data subjects have the right to transfer the personal data to another data controller (data portability), as well as to lodge a complaint regarding Forento's processing of personal data. Complaints shall be submitted to Forento and/or the competent supervisory authority according to the contact details in clause 5 below.
This Privacy Policy may be updated at any time and the latest updated version may always be found on Forento's website: forento.io.
Forento's contact details are as follows: Forento AB, with e-mail: contact@forento.io.
The contact details of the competent supervisory authority in Sweden are as follows: The Swedish Authority for Privacy Protection (Sw. "Integritetsskyddsmyndigheten"), org.no. 202100-0050, with address Box 8114, SE-104 20 Stockholm, Sweden. The Swedish Authority for Privacy Protection can also be contacted by telephone, +46 (0)8-657 61 00, or by e-mail, imy@imy.se. For more information about the Swedish Authority for Privacy Protection, please visit: imy.se.