This policy has been drafted as simply as possible but in case you are unfamiliar with terms such as data controller or special categories of personal data, you can start by reading more about these and other terms under Key terms.
Personal data: Personal data is any information that can be directly or indirectly attributed to a natural person who is alive, such as name, social security number, quotation number and IP number, if they can be linked to natural persons.
Data controller: The data controller is the actor who alone or jointly with others determines the purposes and means of the processing of personal data.
European Economic Area (EEA): EU Member States plus Norway, Iceland and Liechtenstein.
Online advertising: Marketing messages that you can see on the internet.
Special categories of personal data: These are categories of personal data that reveal racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, the processing of genetic data, biometric data to unambiguously identify a natural person, data concerning health or data concerning the sexual life or sexual orientation of a natural person.
When you sign up for our newsletter
In order for us to provide you with the newsletter, we collect the following personal data:
When you search our website
In order to improve your user experience and provide you with customised services, we may collect the following personal data:
When you contact us or when we contact you or when you participate in promotions, competitions, surveys or other questionnaires about our services
In order for us to be able to get in touch with you, respond to requests from you and manage competitions, campaigns, etc., we process the following personal data:
In addition to what has already been stated under the heading What Personal Data We Collect and for What Purpose, we use your personal data for the purposes described below.
Please note that failure to provide us with certain personal data may prevent us from providing you with the products and services you desire or prevent us from entering into agreements with you regarding such products or services.
To provide products and services at your request
We need to process your personal data in order to manage your quote, provide you with the products or services you wish to purchase and assist you with other orders or repurchases that you request.
To manage and improve our products, services and day-to-day operations
We use personal data to manage and improve our products, websites and other services. We monitor how our services are used, in order to protect your personal data and prevent crimes and misuse of services. This helps us ensure that you can safely use our services. We may use personal data to conduct market research, internal research and development as well as to develop and improve our product range, services, stores, IT systems, security, know-how and the way we communicate with you.
For your safety and to combat crime
We only use surveillance cameras for the case and for the areas in which we are allowed to do this. In the event that we are permitted to do so, we may use CCTV images from these in order to maintain the safety of everyone present in our premises or other buildings, and for the prevention, detection and prosecution of criminal acts. We may also rely on these images to establish, exercise or defend our legal rights.
To connect and interact with you
We always want to improve our service towards you. When you contact us, for example via email, letter and telephone or via social media, we may therefore use personal data to help you with clarifications or assistance. We need to process your personal data in order to be able to manage promotions and competitions you choose to participate in, including those conducted with our suppliers and retail partners, for example in case you win a prize. We may invite you to participate in customer surveys, questionnaires and other market research activities organized by Steven&Friends or by other partners on our behalf.
In order to provide you with marketing and customised marketing
We use your personal data in order to provide marketing and offers and, based on the personal data you provide, to adapt marketing through profiling in order for you to receive offers that are relevant to you. You can read more about how we use your data for marketing and your rights below in the Marketing Communications section.
We want to ensure that all marketing communications related to our products and services within our company and from our suppliers and retail partners, including online advertising, are relevant to your interests.
To do this, we may use your personal data by analysing your previous purchases, browsing habits and search settings when using our website. We thus use profiling to find out which products, services and information you may be most interested in. This gives us the opportunity to tailor our communication to make it more relevant and interesting for you. In order to better understand you as a customer, and to provide services and marketing communications (including online ads relevant to your interests), we may also combine personal data we collect when you make purchases from our suppliers with personal data collected from our websites, mobile apps and other sources. We would like to send you relevant offers and news about our products and services. We may therefore contact you with commercial communications via e-mail, SMS, push notifications, mailbox advertising and telephone. We may also direct marketing to you on the internet and social media.
We may also send you information about products and services of our partners that we believe may be of interest to you. We do this only on condition that you have previously agreed to receive such marketing communications.
If you do not wish to receive marketing from us, you may at any time reject such by following the instructions given in the e-mail you received in connection with the marketing, by using the unsubscribe link contained in all offers we send to you by e-mail.
Of course, the choice is yours, but in case you state that you do not want to receive marketing information from us, it prevents you from receiving great offers and promotions that may be of interest to you.
You may still receive service-related information related to your trip from us, even when you are on-site at the destination, for example if we need to provide important information related to the use of our products and services. We may also contact you via SMS when you are on site at your destination to inform you of relevant offers and excursions on your trip.
In order to improve our products and services, we would like your feedback. We may therefore contact you for market research purposes. You always have the option to choose whether or not to participate, or continue to participate, in our market research.
We may consider your responses to market research regarding products and services that we offer, in order to offer you products and services that better meet your needs as a customer.
Where applicable, in order to provide the products and services you have purchased, we may need to share your personal data with our subcontractors and partners. These include airlines, hotels, transport companies and IT providers. We only share personal data with subcontractors and partners to the extent necessary for our suppliers and partners to provide their services to you and us and they only have access to the personal data that is necessary.
In the event that we transfer personal data to a supplier who is our personal data processor, we always enter into the necessary agreements to ensure that we retain control of the personal data and that these are handled lawfully and with the greatest security by our personal data processor.
In order to develop our business and provide you with better targeted information, services and offers, we may use the services of partners who work with the compilation of information, market analyses, market research and marketing. In order to do this, we share certain personal data with these partners.
In order to manage our operations, we use various IT services and systems. In some of these, personal data is stored and processed. For the systems installed locally by us, the data is handled only by our staff. For those services that are installed with our provider, or that consist of a cloud service, we transfer personal data to them.
We do not sell your personal data to third parties.
If we are required by law or if permitted by law, we may share personal data with the state and authorities to the extent necessary.
We understand the importance of protecting and managing your personal data. We take appropriate security measures to protect your personal data against loss or unauthorized access, use, alteration or disclosure. We work continuously with built-in data protection and data protection as standard.
We would also like to remind you that the security of your personal data may also depend on you. For example, when we have given you the choice, or when you have chosen a password to access certain services, it is your responsibility to keep this password secret.
We train our staff on data protection issues on an ongoing basis and our employees also have strict instructions to handle all personal data in accordance with applicable data protection legislation. We have a data protection officer who has the overall responsibility for personal data management. If you want to get in touch with our Data Protection Officer, you can contact them at firstname.lastname@example.org.
The personal data we collect from you may be transferred to or stored at a destination outside the European Economic Area (EEA). They may also be processed by organisations working outside the EEA that work with us or for one of our suppliers.
If this happens, we ensure that your personal data is adequately protected and processed in accordance with this policy. The protection includes, but is not limited to, appropriate contractual clauses such as standard contractual clauses approved by the European Commission and other appropriate safeguards. We may also carry out impact assessments to ensure that safety has been carefully investigated.
We store your personal data only for as long as is necessary for the purposes set out in this policy and we also follow industry best practices and recommendations and guidelines. The personal data will only be used for the purposes stated in this personal data policy and/or to fulfil legal and administrative obligations. We will then securely delete your personal data. However, the same personal data can be stored in several different places for different purposes. This means that we may delete a data from a system when it is no longer needed there, while the data may continue to be stored in another system if the purpose of that particular system remains. If data is needed after this period for analytical, historical or other legitimate commercial purposes, we will take appropriate steps to anonymise this data so that it no longer constitutes personal data.
If you are a former customer of ours, we will store the personal data we need to continue to contact you with marketing communications as long as you have an active customer relationship with us. You can unsubscribe from receiving marketing communications from us at any time. If you have signed up to receive our newsletter, we will process the data needed to administer this as long as you do not unsubscribe from the newsletter or notify us that you no longer wish to receive it. You can unsubscribe from receiving the newsletter at any time.
In order to defend ourselves against legal claims, for example in the event of disputes, certain data may be retained in accordance with the applicable limitation period. When we are required by law to store data, the data is stored in accordance with the time stipulated by applicable law.
Our websites or mobile apps may contain features linked to social media such as Facebook, Twitter, LinkedIn, Google+ and Pinterest that have their own privacy policies.
Please make sure to carefully read their terms and privacy policies before submitting personal data as we do not assume any liability for these features.
Right to withdraw consent
In cases where the processing is based on your consent, you have the right to revoke this at any time by contacting us.
Right of access
In addition to having online access to the personal data related to your quote, you have the right to receive a copy of the personal data we hold about you. You can write to us and ask for a copy of other personal data we have about you. Please include information that can help us identify and locate your personal data. Access to your data will be provided free of charge. However, if you require additional copies, we may charge a reasonable administrative fee.
Right to rectification, erasure, restriction and right to object to processing
We want to ensure that the personal data we hold about you is accurate and up to date. If any information we have is incorrect, we kindly ask you to inform us about this. You can request to have your personal data rectified at any time. You have the right to have your personal data deleted, inter alia, if they are no longer needed for the purpose, or if the processing is based on your consent and you withdraw this. You also have the right, under certain conditions, to request restriction of the processing of your personal data and to object at any time to the processing of your personal data if the legal basis for the processing is a public interest or a balance of interests and when your personal data is processed to send direct marketing to you. We will update and delete your data, except if we have the right to continue processing it for legitimate purposes.
Right to data portability
If it is technically possible and the legal basis for the processing of your personal data is consent or that the processing has been necessary for the performance of a contract, you have the right under certain conditions to obtain this personal data and the right to transfer it to another controller. This right is only valid after 25 May 2018.
Contact and complaints
You can also contact us if you have a complaint about how we collect, store and use your personal data. We will endeavour to resolve any complaints but if you are dissatisfied with our response, you can contact the local supervisory authority with your complaints: http://www.datainspektionen.se/. Please submit your claims or complaints in writing to our legal department or to the Data Protection Officer:
Please note that we may ask you to confirm your identity before handling your claims or complaints. We may also ask you for more information to ensure that you are authorised to make claims or complaints when you contact us on behalf of someone else.
We will only collect and use your personal data if at least one of the following criteria is met:
Example: To provide products or services that you desire
We need to process your personal data in order to process quotes, provide you with products or services that you wish to purchase or assist you with orders.
Example: To better tailor our offerings to you
We may use your personal information in order to better understand your interests and try to anticipate which other products, services and information you may be most interested in. This gives us the opportunity to tailor our communication to make it more relevant and interesting for you.
This policy supersedes any previous versions. We may change the policy at any time, and we therefore ask you to regularly check our website (s) for updates. In the event of extensive changes, we will clearly inform you about this on our website (s) including, if we deem it appropriate, with an electronic notice to you of the changes to the personal data policy.
Steven&Friends offers 30 minutes of free personal telephone advice when you book through us.
Take the opportunity to get expert help with your questions and valuable knowledge before the trip. It creates security and helps you get the most out of your experience!