Privacy policy
eSmart Systems AS is committed to protecting the privacy of its users. This privacy policy is designed to help you understand what information we gather, how we use it, and what we do to protect it. The privacy policy applies to our websites and other digital services such as blog, email subscription and registration of information through forms. While using our site, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you. We process personal information in accordance with the current legislation, including without limitation national laws based the General Data Protection Regulation (EU) 2016/679 ("GDPR") which will be directly applicable as national legislation on 25 May 2018 (EU) and 1 July 2018 or later (EEA) and any national legislation implemented under the GDPR.
eSmart Systems AS is a Norwegian entity, and act as the data controller for the personal data as described in this document. Please find our contact information below in this document.
Why do we process personal information and what information we process
We collect and use your personal information for different purposes, depending on who you are and how we encounter you. We use the information we collect only in compliance with this Privacy Policy and applicable law. We collect the following personal information for the purposes stated here:
- Sign up for our services, such as subscription to our blog or newsletter, download eBooks, or fill out a contact form on our website: email, name, company, phone number and other contact information you fill out based on information you provide to us. We process this information because it is necessary to provide a service directly to you (GDPR article 6 (1) b), or because it is necessary for our interest in providing the services you have ordered on behalf of yourself or a third party (GDPR article 6 (f) b).
- Recruitment to new positions at eSmart Systems: CV, application, attestations and references. Processing of personal data is based on our legitimate interest of processing your application and request to us (GDPR article 6 (1) f), unless explicit consent is obtained by you.
- To obtain information about the use of our website, we use cookies. Use of cookies is based on your consent in accordance with the Norwegian ecommerce act, you may read more about how we use cookies and how you may choose to deactivate cookies and manage your consent here. Cookies help us determine which parts of our digital channels are most popular, including what pages users visit and how long. The information is used for example for performance, development and analysis of services and targeting of ads on the internet. However, we take care of your privacy by using only the statistics information. We process any personal data about you based on a balance of interest between your privacy and our legitimate interest in marketing and improving our services. Our use of cookies is always based on your consent, and all processing of personal data through cookies will cease upon withdrawal of your consent.
- We have profiles / pages in social media. When you visit these pages, such as our company page on Facebook, they will process your personal information and use cookies. More information about how the social media processes personal information and how they use cookies can be found in the respective social media, such as Facebook's Privacy and Cookies pages. In some cases, we can use this information through the social media to show you targeted ads.
- We use both anonymous data and personal data for marketing purposes. This data includes: email, name, position, company. We only do this if you have a customer relationship with us or if you have actively consented thereto. These activities include:
- create target groups for marketing purposes
- customized marketing, for example by providing recommendations or targeted content in our digital channels
- conduct analysis against social channels to be able to communicate with you on these channels.
- We are processing personal data when required by applicable laws, for instance accounting and providing of information when required by authorities (GDPR article 6 (1) c). You may always opt out of our marketing activities by sending us an email to info@esmartsystems.com and we will cease the processing of personal data for that purpose.
You are not required to provide personal information to us, but if you choose not to, you may find a reduced number of our services available to you.
Our digital channels are not intended for, or targeted at, children under 13 years of age. We do not store information about children under 13 years of age. If you think we have stored information about a child under 13 years of age, please contact us in writing so we can delete the information.
Who we share your data with
eSmart Systems AS will not pass on your personal information to others unless you have given us your consent, or if there is a legal basis for such disclosure.
We can share your data:
- In statutory cases, for example by order from the courts, the police or other public authorities, according to strict predefined processes.
- In connection with business transfer, eg. as part of a merger, acquisition, sale of our assets or transfer of services to another company. In this case, you will be notified by email and / or see a notice in our digital channels about any changes in ownership, use of your personal information and choices you may have regarding your personal information.
- For marketing purposes. We use both anonymous and personal data, but only if you have a customer relationship with us or if you have actively consented thereto.
- Other parties with your consent.
eSmart Systems AS uses data processors to collect, store or otherwise process personal information on our behalf. In such cases, we have entered into agreements to ensure information security at all stages of the treatment. We use the following data processors as of today:
How long do we store your information?
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including the purposes of satisfying any legal, accounting or reporting requirements.
To determine the appropriate retention period for your personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data. We consider the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
Personal information is stored as long as you have an active relationship with us or our digital channels, or until you ask us to delete stored information about you. We define a relationship with us or our digital channels such as (i) being a customer of us, (ii) agreeing to receive marketing information from us, or (iii) actively requesting contact with us through social media, electronic messages or online forms.
For example, if you send us your CV and apply for a job, but do not recieve the job, we will delete the information within 30 days, unless you consent to us archiving the CV. If you provide your consent, we will delete the personal data no later than 3 years unless you grant us a new consent.
Retention of anonymous information is not subject to such limitations or requirements. In addition, we try to ensure that personal information and other customer information is updated and correct and that we do not store any information that is unnecessary in relation to the purposes of processing personal information.
How to access and control your personal data?
You have the following rights regarding your personal data:
- Know what personal data we have stored on you and request access to a copy of it
- Require wrong, unnecessary, or outdated personal information to be corrected or removed
- Object to processing of your personal data, typically where we are relying on a legitimate interest (or those of a third party) or you may object or opt out from receiving marketing
- Request restriction or deletion of processing of your personal data
- Request the transfer of your personal data to you or to a third party
- Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdrew your consent.
If you have given us personal information, you can contact us at info@esmartsystems.com or send us a written notification:
eSmart Systems AS
Håkon Melbergs vei 16
1783 Halden
NORWAY
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
We note that you have the right to make a complaint to the Norwegian Data Protection Authority. However, we appreciate that you direct any requests or complaints to us first.
Changes in privacy policy
eSmart Systems AS reserves the right to amend or update the privacy policy. All changes will take effect immediately when being posted here. We will do our best to notify you in the event of significant changes to the privacy policy by email or similar.