1. General
1.1. Modular Finance (we, us, our, ours) is a SaaS-company selling digital tools for the financial market and listed companies in the Nordic region. We have two main business areas; Banking & Finance and Listed Companies.
1.2. At Modular Finance, we are fully committed to your personal integrity and take measures to ensure that your personal data is safe when processed by us. Modular Finance processes personal data in accordance with the General Data Protection Regulation (“GDPR”) and other applicable laws and rules on data protection and personal data processing. In this privacy policy we explain how Modular Finance collects and uses your personal data. The policy also explains the rights you have as a data subject.
2. Personal Data Controller
2.1. Modular Finance AB (org. nr. 556920-1998), Döbelnsgatan 24, 113 52, Stockholm, Sweden, is the personal data controller for the personal data processing covered in this policy.
3. Sources of Personal Data
Other than the data you provide for us, or that we collect through meetings, mail exchange, telephone calls, e-mail or other forms of communication between you and us, we may also collect personal data from others, so called third parties. The personal data collected from such third parties are:
your personal address and similar contact information gathered from public records for maintaining correct and updated information of you;
Information from different data providers.
4. Sharing your personal data
4.1. When processing personal data according to any of the purposes described below in section 5: ”How your personal data is used”, we may share some of your personal data to:
‒ public authorities;
‒ our partners. Such partners are for example companies offering IT-solutions, including electronic platforms and business systems or our bank when processing payments of financial compensation.
4.2. The general rule for all processing of personal data is that it shall be carried out within the EU/EEA. Personal data can however as an exception be transferred to other countries (including countries outside the EU/EEA). We may transfer your personal data to countries outside the EU/EEA when:
‒ the transfer involves a country with an adequate level of data protection according to the European Commission, or
‒ you have consented to the transfer.
4.3. If we transfer your personal data to a country outside the EU/EEA under other circumstances
(for example when we are required by law) we will ensure that the data remains adequately
protected.
5. How your personal data is used
5.1 Purpose
To deliver, evaluate, develop, and improve our services and systems for our clients.
Processing
Collection of contact information, ownership data, insider ownership- and transactions, financial information etc.
Publication in Modular Finance’s services.
Analysis and evaluation of Modular Finance’s services.
Adaptation of services to improve the customer experience.
Categories of personal data
Name.
Contact information.
Corporate governance data.
Ownership data.
Insider data.
Other financial data.
Personal identity numbers.
Technical data.
Legal basis
Legitimate interest. The processing of personal data is required for accommodating our legitimate interest of delivering, developing, and improving our services, products and systems for our clients.
Storage time
Throughout the delivery of our service toward our clients, personal data will be processed for the duration of our client contract and as long as the data is required for the delivery of our services. Thereafter, personal data will be stored for a period of 12 months.
5.2 Purpose
Managing orders and purchases of our services, ongoing client correspondence, customer support issues.
Processing
Collecting contact information.
Processing of payments.
Sending confirmations.
Email contact
Categories of personal data
Name.
Personal identity number.
Contact information (address, e-mail address and telephone number).
Legal basis
Legitimate interest. The processing is needed to accommodate our legitimate interest of communicating with our clients.
Storage time
Throughout the delivery of our service toward our clients, personal data will be processed for the duration of our client contract and as long as the data is required for the delivery of our services. Thereafter, personal data will be stored for a period of 12 months.
5.3 Purpose
Fulfilling our legal obligations.
Processing
Managing legal obligations according to applicable laws and decisions from government authorities.
Categories of personal data
Name.
Personal identity number
Contact information (address, email address, telephone number).
Legal basis
Legal obligation. The collection and processing of personal data is demanded by law.
Storage time
36 months.
5.4 Purpose
Managing job application when recruiting new staff.
Processing
Collection of CV, personal letter, and other documentation regarding the recruitment process. The documentation is sent to us by the candidates.
Communication throughout the process.
Categories of personal data
Name.
Contact information (address, e-mail address and telephone number).
Other personal data that may be included in CV and personal letter.
Legal basis
Consent, legitimate interest
Storage time
24 months after consent has been given. Some personal data may be stored for longer.
6. Cookies
6.1. Cookies are text files sent from our web server and which are saved in your web browser or unit. We use cookies and other similar technology to give you the best possible customer experience and to improve our services. We do not connect stored cookies to personally identify you and we never collect them for individually customized marketing. You may allow
or block most cookies on your unit or in your web browser. All the tracking data will not necessarily be stopped and some functions on our website may be restricted. The collected information helps us, among other things, to better understand the functions of our website.
6.2. The cookies we use normally improve our offered services. Some of our services require cookies to function, while others improve the services for you. We use cookies for general analytical information regarding your usage of our services and to save functional settings such as language and other information.
6.3. You can control the use of cookies. Your web browser or unit gives you the option to change the settings for cookies. Go to the settings for your web browser or unit to learn more about how to adjust the settings for cookies.
7. Google Services
7.1. Our website, www.modularfinance.com / www.modularfinance.se, uses Google-services such as Google Analytics. Google uses the collected personal data to track and analyse the use of www.modularfinance.com, in order to produce reports on activity so that we can improve the utility of the website. Google may use the collected personal data according to Google’s privacy policy.
8. Protecting your personal data
In order to protect your personal data and to maintain effective protection, we have implemented a number of measures:
Training of relevant staff to ensure they are aware of our responsibility when processing your personal data.
Administrative and technical control functions to limit the access to personal data.
Technical security measures, including passwords, firewalls, encryption, and antivirus software.
Physical security measures, such as entrance cards and codes to enter our office.
9. Your rights
9.1. As a data subject, you have a number of rights according to the Data Protection Regulation with regards to your personal data and those who process them. These rights are presented and explained below.
The right of access
9.2. You have the right to access your personal data. Observe that we may ask for additional information to ensure an effective processing of your request.
The right to rectification
9.3. If your personal data is incorrect, you can request to have them rectified. You may also have the right to add information which is incomplete.
The right to erasure
9.4. You may request deletion of the personal data on you that we process if:
the data no longer is necessary for the purposes for which they have been collected or processed;
you object to our legitimate interest of processing your personal data and the reason to your objection overrides our legitimate interest;
you object to personal data processing used for purposes of direct marketing;
the personal data is processed unlawfully; or
the personal data must be deleted to fulfil a legal obligation.
9.5. We may be restricted to delete certain personal data if these are necessary for our business operations or because of legal obligations.
The right to restriction of processing
9.6. In some situations, you have the right to request that we limit the processing of your personal data. If the processing is restricted, we may only store your personal data as well as use them to manage legal claims.
The right to object
9.7. You have the right to avoid direct marketing activities and to object to the processing of personal data that is based on legitimate interest. In order to process your personal data after such an objection, we need to be able to present a legitimate reason for the personal data processing that outweighs your interests, rights, and freedoms. In other cases, we may only process the data to manage legal claims.
The right to data portability
9.8. If the processing of your personal data is based on your consent or a contractual obligation with you, you have the right to request that the personal data that you have transferred to us are transferred to another personal data controller. This requires that the transfer is technically possible and can be automated.
10. Questions or exercising your rights
If you have questions or want to exercise your rights, you may contact our DPO through rikard.romlin@modularfinance.com.
Last updated: Stockholm, 8 December, 2024.