Privacy Policy

Data controller

We are the data controller for the processing of personal data that we process about our customers and business partners. You can find our contact details below.

Korol Design department at Biomass2Business

Isefjords Alle 13, 4300 Holbæk

CVR no.: 38142399

Our company is not required to have an external DPO, but if you have any questions about the processing of your personal data, please contact us by email.

Processing activities

As a data controller under the GDPR, we carry out the following processing activities.

Visits to our website

When you visit our website, we use cookies to enable the website to function; these are a cookie for language selection and a cookie for cookie acceptance.

Communication with potential customers

If you have any questions about our website or would like to hear more about our services, please contact us via:

  • Contact
  • Conform17apr@korol-design.com

Through this, we will process your personal data so that we can enter into a dialogue with you, e.g. answer questions about our services. We only process the information you provide us with in connection with our communication. We will typically process the following general information: name, email, telephone number.

Our legal basis for processing this personal data is Article 6(1)(f) of the General Data Protection Regulation.

We will delete our communication with you when it is clear whether you want our services or not. In special cases, it may be necessary to store your personal data for a longer period of time.

Custom

We need to communicate with our customers to ensure that the service is provided correctly. In doing so, we may process information about your name, address, services, special agreements, payment information and the like. The legal basis for processing this personal data is Article 6(1)(b) of the General Data Protection Regulation. Once the service has been provided and any outstanding matters have been resolved, we will delete the personal data immediately.

News

If we send out a newsletter, it is voluntary to subscribe to it, and you can unsubscribe at any time. The purpose of the newsletter is to send subscribers emails with new information from the company, which may include new content on the website and advertisements for our services. We will only send you emails if you have given your active consent to this. This requires you to first provide your email address, to which we will then send an email so that you can confirm your subscription. This way, we ensure that you have actually subscribed to the newsletter yourself, i.e. given your active consent. Our legal basis for processing your personal data (i.e. your email address) in connection with the newsletter is Article 6(1)(a) of the General Data Protection Regulation. We will process your personal data for as long as you remain subscribed to the newsletter. When you unsubscribe from the newsletter, we will also stop sending it to you. If we have not sent you a newsletter for 1 year, your consent will lapse as a result of our inactivity. When you unsubscribe from the newsletter, we will store your previous consent for 2 years after it was last used due to the limitation period in accordance with the Consumer Ombudsman’s spam guidelines, section 11.3.

Accounting

We are required to store all accounting documents in accordance with the Accounting Act. This means that we store invoices and similar documents for accounting purposes. These may contain general personal data such as name, address and job description. Our legal basis for processing personal data for accounting purposes is Article 6(1) of the General Data Protection Regulation. We store this information for at least 5 years after the end of the current financial year.

Job applications

We welcome job applications in order to assess whether they match a recruitment need in our company. If you send us your job application, our legal basis for processing your personal data is Article 6(1)(f) of the General Data Protection Regulation. We do not accept unsolicited applications. If you have applied for an advertised job, we will dispose of your application if you are not hired and immediately after the right candidate has been found for the job. If you enter into a recruitment process and/or are hired for the job, we will provide you with separate information about how we process your personal data in this context.

Data processors

Few can do everything themselves, and the same applies to us. We therefore have partners and use suppliers, some of whom may be data processors.

External suppliers may, for example, provide systems for organising our work, services, consulting, IT hosting or marketing.

  • Simply, Inshi Digital

It is our responsibility to ensure that your personal data is processed properly. We therefore place high demands on our partners, and our partners must guarantee that your personal data is protected. We therefore enter into agreements with companies (data processors) that handle personal data on our behalf in order to enhance the security of your personal data.

Disclosure of personal data

We do not disclose your personal data to third parties.

Profiling and automated decisions

We do not engage in profiling or automated decisions.

Third country transfers

As a rule, we use data processors in the EU/EEA or who store data in the EU/EEA. In some cases, this is not possible, and in such cases, data processors outside the EU/EEA may be used if they can provide adequate protection for your personal data.

Security of processing

We keep the processing of personal data secure by implementing appropriate technical and organisational measures. We have carried out risk assessments of our processing of personal data and have subsequently implemented appropriate technical and organisational measures to increase the security of the processing. One of our most important measures is to keep our employees up to date on the GDPR as necessary through training, GDPR courses and by reviewing our GDPR procedures with employees.

The rights of data subjects

Under the Data Protection Regulation, you have a number of rights in relation to our processing of information about you. If you wish to exercise your rights, please contact us so that we can assist you.

Right to access information (right of access)

You have the right to access the information we process about you, as well as a range of additional information.

Right to rectification (correction)

You have the right to have inaccurate information about yourself corrected.

Right to erasure

In certain cases, you have the right to have information about you erased before the time of our regular general erasure.

Right to restriction of processing

In certain cases, you have the right to have the processing of your personal data restricted. If you have the right to restrict processing, we may only process the information in future – except for storage – with your consent, or for the purpose of establishing, enforcing or defending legal claims, or to protect a person or important societal interests.

Right to object

In certain cases, you have the right to object to our otherwise lawful processing of your personal data. You may also object to the processing of your data for direct marketing purposes.

Right to transfer data (data portability)

In certain cases, you have the right to receive your personal data in a structured, commonly used and machine-readable format and to have this personal data transferred from one data controller to another without hindrance. You can read more about your rights in the Danish Data Protection Agency’s guide to the rights of data subjects, which you can find at www.datatilsynet.dk.

Withdrawal of consent

When our processing of your personal data is based on your consent, you have the right to withdraw your consent.

Complaint to the Data Protection Authority

You have the right to lodge a complaint with the Data Protection Authority if you are dissatisfied with the way we process your personal data. You can find the Data Protection Authority’s contact details at www.datatilsynet.dk.

We generally encourage you to read more about the GDPR so that you are up to date with the rules.