Last updated: 8th of July 2021
The purpose of this document is for Us, as data controllers, to explain how Your data is collected, processed, stored and used. This is done in accordance with, for example, the General Data Protection Regulation 2016/679 (GDPR) which is a legislation of the European Union.
Company: One.com Group AB
Country of registration: Sweden
One.com Group AB (the processor) is acting as a data processor for personal information. For details on how the processor handles Your personal data, see https://www.one.com/static/info/data-processing-agreement-en.pdf
One.com also collects personal data which is only available to them. They track visitor activity using Varnish logs and keep access logs. They discribe this processing as such: "Unaggregated web hist with IPs, URLs, query strings, user agent, country. We need this data for debugging/troubleshooting. Retention is 30 days. It is not an optional feature as we rely on the data to offer an optimal solution. It is therefore not possible to disable it. The saved data is not used for any marketing purposes, and not shared with any third party."
We collect information from You as You use our Website, for example, when creating an account or progressing in our course material. The information We collect may include Your name, e-mail address, how difficult You claim to find course components and information about which pages, and other sources, You have accessed and when.
If You submit hand-ins, ask public questions or contact Us in any other way, any additional personal information included will also be collected and stored. Any information not communicated through our Website while logged in is considered not to be “associated with your account”. Specifically, e-mail conversations are not “associated with your account”. Neither is any anonymized data.
We use Your information to allow for automized adaption of the course material to You. This includes progress tracking as well as processing and analysis of Your progress though our course material to assess how well You know each course component. These activities are carried out on the legal basis of consent. Consent is given by registering an account and is required to gain access to Our services.
We may use personal information to contact You in relation to account creation, deletion or modification. Furthermore, it may be used for communications relating to hand-ins, in response to User petitions or when legally required. We will NOT use Your personal information for third-party advertisement or newsletters. The legal basis for these activities is consent. Consent is given by registering an account and is required to gain access to Our services. We may also ask for Your permission to contact you with direct marketing. In such case, this is based on a separate consent.
Apart from above listed uses, any and all data collected may be processed and used to improve Our services. For example, it may be used for identifying course components that are in need improvements. The data processed is, in this case, anonymized and does therefore not constitute personal data. In order to allow for proper anonymization of data, You are instructed not to include any personal information in Your communications unless specifically asked to do so.
All data is stored within the European Union. In order to ensure a high data security, all communication with Our databases is encrypted. We work actively and continuously to improve Our data security. Your information is stored as long as You have an account on the Site. We do however reserve the right to delete any information.
The data We store may be affected when You exercise Your rights as described below.
Cookies are small files of data sent from a website to Your browser for local storage on Your hard drive. These cookies are typically sent back to the website upon re-visit.
Despite Our best efforts to make the Site as secure as possible, no system, protocol or encryption algorithm is 100% secure. Accessing the Site is therefore associated with a risk.
Users under the age of 16 years are only allowed to use Our services to the extent that it is authorized by the holder of the parental responsibility. Any violation of this rule shall be reported, using the contact details below, and will lead to account deletion.
You have the right to invoke any of Your rights below. If You make a request, We have a month to respond You. Should You have any problem when attempting to exercise Your rights as described below or have reason to believe that Your request has not been properly received or processed, please contact Us using the contact details below.
You have the right to request copies of Your personal data that We have stored. This is associated with a fee. To exercise this right, contact Us through the contact details below.
You have the right to request that We rectify any incorrect information We may have about You. You also have the right to request that We complete any information that You believe to be incomplete. Some account information can be changed from the page “my account”. If You are unable to rectify or complete the information there, You are welcome to contact Us through the contact details below.
You have the right to request that We delete Your personal information, to the extent that We are not legally required to store the information in question or it is to be considered to be in Our legitime interest to keep the information. To delete any information “associated with Your account”, please delete Your account. Note that some anonymized data may remain. To request the deletion of e-mail conversations, please contact Us using the contact details below.
In accordance with GDPR, You have the right to restrict the processing of Your data under certain circumstances. Should You wish to exercise this right, this can be done on the page “My account”, under the heading “Account details”. The data processing will be restricted during a limited amount of time and You will be informed prior to restrictions being lifted. When data processing is restricted, the data will only be processed with Your consent or under specific circumstances as detailed in the GDPR. If You attempt to visit a page with Your login details, We consider it consent to process Your personal data as necessary to display said page. When making hand-ins, asking public questions or contacting Us in any other way, We consider it consent to process the data necessary to give feedback on the hand-in or otherwise respond to Your communications.
You have the right to object to data being processed, for example with the purpose of marketing. On the page “My account”, under the heading “Account details” You may object to any direct marketing. You also have the right to object to processing on the basis of legitime interest, public interest or in exercise of official authority. Though We don’t normally process data on these legal basis, You are welcome to contact Us using the contact details below to object to such processing.
According to the GDPR, You have the right to portability of any personal information concerning You, which You have provided. That is, unprocessed or “raw” data. This right does however have some limitations as it must not adversely affect the rights of others. Most of the personal data We store is either processed or relates to other individuals, such as teachers. The data which We store, for which this right applies, can be found on the page “My account”. On the page “Handins” You can download any handed in material. You also have the right to request that We send the information directly to another data controller, if technically feasible. To exercise this right, please contact Us using the contact details below.
We request that you contact us directly with any complaints so that we may resolve them. This can be done through the contact details below. Should you feel that We have not addressed your concerns and wish to report a complaint, you may do so to the Swedish Authority for Privacy Protection (IMY). Their contact details can be found here: https://www.imy.se/kontakta-oss/
If you have any questions regarding the Policy, please contact Us through e-mail at firstname.lastname@example.org