Introduction and purpose
The purpose of this policy is to ensure that Fibersystem handles personal data in accordance with the European Data Protection Regulation (GDPR). The policy covers all treatments where personal data are handled and comprises both structured and unstructured data. This policy is rooted with all Fibersystem employees.
Application and revision
Fibersystem’s Board is responsible for the processing of personal data in accordance with this policy. The policy shall be determined by the Board at least once a year and updated if necessary. Fibersystem’s Security Manager is responsible for handling the process with annual update of the policy as a result of new and changed regulations. This policy applies to the company board members, CEO, employees and contractors affected by Fibersystem’s business.
Organization and responsibility
The CEO has overall responsibility for the content of this policy and that it is implemented and enforced by the business. The CEO has delegated the responsibility of this policy to the Security Manager. All employees are responsible for acting in accordance with this policy and what it wants to ensure.
Concepts
Meanings
Personal Data
A personal data is any information that can be directly or indirectly attributed to a physical person who is in life.
Registered
The person to which a personal data refers, that is, the natural person who can be identified directly or indirectly through the personal data in a register.
Personal Data Processing
An action or combination of personal data actions – regardless of whether they are automated or not – such as collection, registration, organization and structuring.
Privacy policy
Each personal data processing should be done according to the following principles:
- Legality
- Purpose limitation
- Data Minimization
- Correctness
- Storage minimization
- Integrity and confidentiality
- Our data treatments are documented on a regular basis in the Treatment Registry Follow-up and evaluation of our handling of personal data shall be done at least annually
- Any incidents relating to personal data we process should be reported to the Security Manager without delay. The Security Manager shall report the incident to the Data Inspection Agency without undue delay and no later than 72 hours, and take the necessary measures as a result of the incident.
Our requirements for personal data management under GDPR should always be ensured in procurement and development of IT solutions and services, and shall be part of the requirements specification and any agreements.
Cookies and logs
This website sets no cookies. There is no analytics platform, no tag manager and no third-party scripts on any page. Nothing follows you between visits, and there is nothing to consent to — which is why you are not asked to.
What is processed is the ordinary web server log: the IP address the request came from, the time, the page requested, the response code and the browser’s user agent string. An IP address is personal data. The logs exist to operate and secure the service — to find faults and to detect abuse — on the legal basis of legitimate interest, and they are retained for 90 days.
If a measurement tool is introduced later it will be self-hosted, with IP addresses anonymised and without cross-site identifiers, and this section will be updated before it goes live.
Processors
We use the following processors for personal data:
- Hosting provider — operates the web servers and the logs described above. Servers are located within the EU.
- whistleb.com (WhistleB, Whistleblowing Centre) — operates the reporting channel linked from our whistleblowing page. Reports can be submitted anonymously; read that service’s own information before you use it.
- Business system — stores enquiries submitted through the forms on this site, on servers within the EU.
Data processing agreements are in place with each of them. A current list is available on request from dataskydd@fibersystem.com.
Your rights
You may request a copy of the personal data we hold about you, ask for it to be corrected or deleted, and object to processing based on legitimate interest. Write to dataskydd@fibersystem.com. If you are not satisfied with our handling, you may complain to the Swedish Authority for Privacy Protection (IMY).