This policy describes how DB Evidence AB (“Evidence”, “we”) processes personal data when you visit our website, contact us, are a contact person at a customer or supplier, receive our mailings or apply for a job with us.
In short: the website uses no cookies and doesn’t track you. We only process the data we need to reply to you, manage our agreements and, if you want, keep you updated. Your data is never sold.
Data controller
DB Evidence AB, corporate ID no. 559232-3850 c/o Norrsken House, Birger Jarlsgatan 57C, SE-113 56 Stockholm, Sweden servicedesk@evidenceoperations.com
The Evidence platform
When our customers use the Evidence platform, for example for staffing, scheduling and worked time, we process personal data on the customer’s behalf. The customer is then the data controller and Evidence the data processor, under the data processing agreement we have with the customer. If you work for one of our customers and have questions about that processing, please contact your employer first.
What we process and why
| Situation | Data | Legal basis | How long |
|---|---|---|---|
| You visit the website | Technical information such as IP address, browser, time and requested page, in the server logs | Legitimate interest: keeping the website secure and running | At most 30 days |
| Visitor statistics | Anonymous, aggregated statistics: e.g. visits per page, referring website and country. No cookies, no identification of you as a person | Legitimate interest: understanding which content is useful | Only aggregated figures are kept |
| You contact us or book a demo | Name, email, phone, organisation, role and what you write to us | Legitimate interest: replying to you and discussing our services | Up to 24 months after the last contact |
| You are a contact person at a customer, partner or supplier | Name, contact details, organisation, role and our correspondence | Contract and legitimate interest: performing and administering the agreement | For the term of the agreement and then as long as the law requires, e.g. 7 years for accounting records |
| You receive our mailings | Name, email, organisation, and whether mailings are opened and which links are clicked | Consent, or legitimate interest when you are a contact person at a customer | Until you unsubscribe. Every mailing has an unsubscribe link |
| You apply for a job with us | What you send us, e.g. CV, cover letter, education, experience and references | Legitimate interest: carrying out the recruitment. Consent if we’d like to keep your application for future positions | Deleted no later than 6 months after the recruitment ends, unless you have agreed to longer |
| You attend an event or webinar | Name, contact details, organisation and any requests, e.g. dietary | Contract and legitimate interest: running the event | Up to 12 months after the event |
We don’t process sensitive personal data, such as health data, unless you provide it yourself (for example a dietary request for an event), and then only for that purpose.
Cookies
The website uses no cookies and no other tracking technology, neither our own nor third-party. Fonts, images and documents are served from our own server, so no one else learns about your visit. That’s why we don’t show a cookie banner.
Visitor statistics are produced with Plausible Analytics, a European tool that works without cookies, doesn’t store IP addresses and can’t link the statistics to you as a person. The data is stored within the EU.
Who receives the data
We only share personal data with suppliers who help us run our business, and only as far as needed. They may not use the data for their own purposes and are bound by data processing agreements.
- Microsoft: website hosting (Microsoft Azure) and email (Microsoft 365)
- Email mailing provider: for newsletters and other mailings
- Plausible Analytics: visitor statistics, see above; only receives anonymous information
We may also disclose data where the law requires it, for example to a public authority.
We aim to keep all processing within the EU/EEA. If a supplier processes data outside the EU/EEA, we make sure appropriate safeguards under the GDPR are in place, such as the European Commission’s standard contractual clauses or the recipient being certified under the EU–US Data Privacy Framework.
How we protect the data
Information security is governed by a management system in line with ISO 27001. Access to personal data is limited to the staff who need it for their work, and all traffic to the website is encrypted.
Your rights
Under the General Data Protection Regulation (GDPR) you have the right to:
- know what data we hold about you and get a copy of it
- have inaccurate data corrected
- have your data erased
- request that processing be restricted
- object to processing based on legitimate interest, and always to direct marketing
- receive data you have given us in a machine-readable format (data portability)
- withdraw consent at any time
Contact us at servicedesk@evidenceoperations.com and we’ll reply within one month. If you’re not satisfied with how we process your data, you can lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or the data protection authority in your own country.
Changes
We review this policy at least once a year and whenever we change how we process personal data. The latest version is always available here, with the date of the last update.