Your trust is important to us. Read about how we handle your data in a secure and transparent way to keep your information safe.
This policy describes the personal data we collect and what we do with it, as set out in Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/ EC) (GDPR). The policy also describes your rights and how you can enforce them.
1. General
1.1. This privacy policy applies when Betalo AB (publ) org.nr 559245-2931, e-mail: info@betalo.se, (“Betalo”) provides payment services via app under the Betalo brand name (the “Service”). Betalo is the data controller for the processing of the personal data that you register or that are created when you use the Service.
1.2. In connection with you as a customer creating an account and/or using the Service, Betalo processes your personal data by collecting and providing information on your mobile phone, tablet or other equipment.
2. Terminology and definitions
2.1. For the purposes of this Policy, the following terms are used with the following meaning:
2.2. Personal data refers to any information directly or indirectly attributable to a natural person who is alive, e.g. name, social security number, address, etc. Encrypted data and various kinds of electronic identities (e.g. IP numbers) are personal data if they can be linked to natural persons.
2.3. The processing of personal data refers to everything that occurs with the personal data. Any action taken with personal data constitutes processing, regardless of whether it is carried out automatically or not. Examples of common treatments are collection, registration, organization, structuring, storage, processing or modification, transfer, and deletion.
3. Data we collect
3.1. Information you provide to us
3.1.1. Registration — when opening an account with Betalo, you must provide details such as your social security number through BankID, your email address and mobile phone number. We supplement your registration with the name and address of the State Person and Address Register (SPAR), see section 3.2.
3.1.2. Saved cards — to use the service and make payments, you need to add a Visa, Mastercard or American Express card. Betalo does not save your card details, this is handled by Nets Branch Sweden (Nets) and Worldline — Devcode Payment AB, but we save the type of card you use in order to provide you with the correct service fee.
3.1.3. Enhanced customer knowledge — in order to comply with the rules imposed on us as a payment institution, we will from time to time request additional information about you, such as your country of birth, country of citizenship, from where your
main income comes from as well as if you, someone in your family or a known associate of yours has or has had a politically exposed position.
3.1.4. The processing of this data is a prerequisite for you to be able to use the Service and is carried out in order for us to be able to fulfill our contract with you and for us to be able to fulfill the legal obligations imposed on us.
3.2. Information from others Betalo AB (publ) is a payment institution pursuant to the Act (2010:751) on payment services and is subject to the supervision of the Financial Supervisory Authority
Orgnr: 559245-2931 | E-mail: info@betalo.se | www.betalo.com
Copyright © 2021 Betalo
3.2.1. In addition to the data you provide to us, we may also collect personal data from others (so-called third parties). Betalo, for example, collects address data from public registers, such as SPAR, to ensure that we have the correct address information for you.
3.2.2. The processing of this data is a prerequisite for you to be able to use the Service and is carried out in order for us to be able to fulfill our contract with you and for us to be able to comply with the legal obligations imposed on us.
3.3. Use of the Service
3.3.1. Payments — information you provide to us to record a payment such as payee, payment reference, amount and payment date.
3.3.2. We log usage data when you visit or use our Services, including our mobile app, website and platform technology (such as off-site extensions), such as when you visit or click on content, install or update our mobile app. We use logins, cookies, device information and IP addresses to identify you and log your usage.
3.3.3. Apart from the use of cookies, the processing of this data is a prerequisite for you to be able to use the Service and is carried out in order for us to be able to fulfill our contract with you and to comply with the legal obligations imposed on us. Read more about the conditions for the use of cookies in section 3.4 below.
3.4. Cookies, web beacons and similar technologies
3.4.1. The services on the Betalo website use cookies and other technologies to function properly. Cookies are used to enable Betalo to keep visitor statistics and to be able to improve the experience for you as a user. The data we collect consists of IP address, operating system, browser and extensions, device and screen size, date and time of use, visit pages and reference page. The use of cookies is made only if you consent to this in connection with your visit to the Betalo website. If you do not accept the use of cookies, you can configure your browser not to accept cookies.
3.5. Your device and location
3.5.1. When you visit or use our Services, we receive information about any referring page. We also receive information about your IP address, proxy server, operating system, browser and extensions, date and time, and/or internet service provider or mobile operator. The processing of cookies is based on consent in accordance with section 3.4 above. The processing of other data is a prerequisite for you to be able to use the Service and is carried out in order for Betalo to be able to fulfill the agreement with you to provide the Service.
3.5.2. When you download the Betalo app on your mobile phone, tablet or other device, Betalo needs to store and retrieve certain technical information from the equipment in order for Betalo to provide and update the Service. By downloading the app, you agree that Betalo stores and retrieves certain technical information from the equipment. The processing of this data is a prerequisite for you to be able to use the Service and the information is stored in order for Betalo to be able to fulfill the contract with you to provide the Service. If you no longer wish Betalo to store and retrieve the technical information, you must uninstall the app.
3.6. Other
3.6.1. Our services are dynamic and we continuously introduce new features that sometimes require us to collect new information. If we collect personal information that is materially different from information already collected or if we materially change the way we use
2 (6) your personal data will be communicated to you before such further processing begins. If necessary, the content of this Privacy Policy may also be amended.
4. How we use your information
4.1. As stated above, Betalo processes your personal data for several different purposes based on different legal grounds. Mainly Betalo processes personal data for the purpose of providing, administering, developing and customizing the Service and its functionalities, in order to fulfill the contract with you. In addition, the personal data is processed to ensure customer knowledge, to administer the customer relationship with you, as well as to comply with security and other regulatory requirements, to fulfill legal obligations of Betalo. The personal data set out in sections 3.1 to 3.5 above may also be used as a basis for market and customer analyses, market research, statistics, business monitoring and business and methodological development, based on either a consent obtained by Betalo from you in connection with your registration to create an account with Betalo or by Betalo's legitimate interest in promoting itself and its services and developing and offering customers an improved service offering.
4.2. Betalo further processes your personal data in order to provide better and more personalized offers and services. Personal data and positioning data may, for example, be processed, aggregated, segmented and analyzed in order to provide, through targeted marketing, information, offers or recommendations about our own or partners' goods and services, which are tailored to the user's preferences, behaviors, needs or lifestyle. This is done on the basis of either the consent that Betalo obtains from you in connection with your registration to create an account with Betalo or by Betalo's legitimate interest in promoting itself and its services and being able to offer customers an improved service offering.
4.3. Furthermore, personal data may be processed in order to safeguard Betalo's legal interests or to detect, prevent or draw attention to fraud and other security or technical problems that constitute legitimate interests for Betalo to carry out the processing.
4.4. If you do not want Betalo to process your personal data for direct marketing purposes, you can notify Betalo in writing using the contact details in section 10.
5. How we share your personal data
5.1. Personal data may be disclosed if it is necessary to comply with applicable legal requirements or government requirements, this is done in order for Betalo to fulfill legal obligations.
5.2. Furthermore, Betalo may share your data with other parties in order to process your order and make Payments, facilitate future Payments, enable updating of your payment status and for sending offers from Betalo and Betalo's partners, via SMS, e-mail and other direct mail. This processing takes place in order to be able to fulfill the contract you have entered into with Betalo and, in the case of marketing, based on consent or legitimate interest.
5.3. In order to provide the Service, Betalo will disclose your personal data to partners, such as Nets, for the processing of card data and card data.
5.4. In cases where it is necessary for Betalo to be able to offer you the Service, we share your personal data with companies that are so-called personal data processors for Betalo. A personal data processor is a company that processes the information on behalf of Betalo and according to Betalo's instructions. Betalo has personal data processors who assist Betalo with IT and actors that Betalo engages for Betalo's marketing activities. However, Betalo is always responsible for ensuring that your personal data is processed correctly. When your personal data is shared with data processors, it is only for purposes that are 3 (6) consistent with the purposes for which Betalo has collected the information (e.g. to be able to fulfill Betalo's obligations under the contract with you as a customer). Betalo controls all data processors to ensure that they can provide adequate guarantees regarding the security and confidentiality of personal data. Betalo has written agreements with all data processors (data processor agreements) by which they guarantee the security of the personal data processed and undertake to comply with Betalo's security requirements and requirements regarding the international transfer of personal data.
5.5. Betalo also shares your data with certain companies that are independent data controllers. The fact that the company is an independent controller of personal data means that Betalo does not control how the information provided to the company is processed. Independent personal data controllers with whom Betalo shares your personal data are, for example, financial and legal consultants and accountants. When your personal data is shared with a company that is an independent data controller, the company's privacy policy and principles for personal data management apply.
6. Where is your personal data processed
6.1. Your personal data will only be processed within the EU/EEA.
7. Storage Information
7.1. Data Retention
7.1.1. Your personal data is normally retained only for as long as there is a need to retain it to fulfil the purposes for which the personal data was collected. When you close your Betalo account, Betalo will delete or de-identify the information that Betalo has retained that may be attributed to you, with the exception of such information that Betalo is required by law to retain, normally for 5 years plus the current year after you terminate your Betalo account. The personal data is retained only in order to comply with such legal obligations or to protect Betalo's legal interests, e.g. in the event of a legal proceeding.
7.1.2. Upon termination of an account, we will normally delete information (other than information that Betalo is legally required to retain in accordance with clause 7.1.1 above) stored in the terminated account within 30 days of account termination.
8. Your Choices and Rights
8.1. The right to access and control your personal data
8.1.1. For personal data that we hold about you:
· Delete personal data: you can ask us to delete or delete all or certain personal data (e.g. if it is no longer needed to provide you with Services).
· Change or correct personal data: you may edit some of your personal data through your account. You may also ask us to change, update or correct your personal data in certain cases, in particular if the personal data is incorrect.
· Object to, or restrict or restrict, the use of personal data: you can ask us to stop using all or some of your personal data or restrict our use of it (e.g. if your personal data is inaccurate or stored unlawfully).
· Right to object to certain types of processing: You can object at any time to Betalo's processing of your personal data if the legal basis for the processing is a public interest or a balance of interests pursuant to Article 6 (1) (e) and (f) GDPR and if the processing relates to processing for direct marketing purposes. You also have the right to withdraw your consent at any time regarding a personal data processing based on your consent.
· Right to access and/or retrieve your personal data: You can ask us for information regarding the personal data that Betalo processes about you and ask for a copy of the personal data in machine-readable form. You can also ask to be informed about the purpose of the processing Betalo has done and who has received your personal data. If technically possible and the legal basis for a 4 (6)
The processing of personal data is consent or that the processing is necessary for the performance of a contract, you also have the right to obtain the personal data that you have provided to us in order to transfer them to another controller.
8.2. In the event of unfounded or unreasonable requests (e.g. because they are made repeatedly) Betalo may charge an administrative fee — in which case you will be notified in advance. Betalo will normally respond to your request within one (1) month of receipt, enquiries are made via info@betalo.se.
9. Other important information
9.1. Security
9.1.1. We apply security measures designed to protect your information, such as encrypting your data in all processing. We monitor our systems regularly to detect possible weaknesses and attacks. However, we cannot guarantee the security of any information you provide to us. There is no guarantee that information cannot be accessed, disclosed, altered or destroyed by attacks on our physical, technical or administrative firewalls.
9.2. Management of social security numbers
9.2.1. Betalo will only process your personal identity number when it is clearly justified with regard to the purpose, necessary for secure identification or if there is any other justifiable reason. Betalo always minimizes the use of your social security number as much as possible by, where sufficient, instead using a user ID that does not contain your date of birth.
9.3. Legal basis for processing
9.3.1. We will only collect and process your personal data on lawful grounds. These legal grounds include when you give us your consent (when you have given your consent), contracts (where processing is necessary for the performance of the contract (e.g. to deliver the Betalo Services you have requested)) and legitimate interests, such as protecting you, us or others from security threats or fraud, improving your experience of the Service, and complying with laws that apply to us.
9.3.2. Where we rely on your consent for the processing of your personal data, you have the right to withdraw your consent at any time. Where we rely on legitimate interests, you have the right to object to our processing. If you have any questions about the lawful grounds on which we collect and use your personal data, you can contact us in accordance with section 9 below.
9.4. Betalo has the right to change this policy at any time. Betalo shall notify users who hold an account with Betalo with reasonable notice via email, website or app of future changes to the policy. If you do not accept the amended terms, you have the right to terminate the agreement with Betalo before the amended policy becomes effective. You terminate the contract with Betalo by
to close your Betalo account.
10. Contact information
10.1. Betalo is the data controller and is responsible for ensuring that your personal data is processed in accordance with applicable legislation.
10.2. Do not hesitate to contact Betalo if you have any questions about the processing of your personal data or any complaint. Written or oral questions and complaints are primarily made directly to:
Betalo AB
Engelbrektsagatan 35A
114 32 Stockholm
E-mail: info@betalo.se write “Data protection” in the subject field.
10.4. Betalo has appointed a Data Protection Officer who you can turn to if you are not satisfied with how we have handled your personal data. The Data Protection Officer can be reached at dataskyddsombud@betalo.se.
10.5. If, after contacting us, you are still dissatisfied, you can contact IMY, the supervisory authority for personal data processing, to which you can report your complaint. Privacy Protection Authority (IMY)
Box 8114
104 20 Stockholm
www.imy.se
Phone number: 08-657 61 00
E-mail: imy@imy.se
6 (6)
PDF: Privacy Policy