Personal data processing

Information on How We Process Your Personal Data

It is important to us that your personal data and your personal privacy are protected in a correct manner. With this text, we want to explain how we handle your personal data. This information applies to you as a member and/or elected representative of OK Norrbotten.

Who is responsible for my personal data?

When you apply for membership, the OK association you become a member of is the data controller responsible for administering your membership. If you are unsure which OK association you are (or will become) a member of, you can contact customer service—see contact details below.

Where does my personal data come from?

The primary source of personal data about you is you yourself, i.e. information you provide when you become a member or otherwise submit to us, such as name, date of birth, personal identity number, billing and delivery address, email address, and mobile phone number.

In addition to the information you provide, we may also obtain personal data about you from the following sources:

Personal data is generated through interactions between you and us. For example, we may store case histories or otherwise document your communication with us. We also receive information about your purchases of goods and services from other companies within OK and OKQ8 Scandinavia.

We continuously retrieve personal data from publicly available sources such as public registers, e.g. the population register.

If you do not provide the requested personal data, we may not be able to offer you the service or product you want or take other actions you request. In some cases, providing personal data is required by law. We will clearly indicate when it is mandatory to provide certain information in order to use or access a specific product or service.

Who your personal data may be shared with

For the purposes described below, your personal data may be shared with other entities within OK and OKQ8 Scandinavia. Such processing is regulated by agreements designed to protect your rights as a data subject. Contact customer service if you want more information about data sharing within OK and OKQ8 Scandinavia.

Personal data may also be disclosed outside OK and OKQ8 Scandinavia. Such recipients fall into one of the following categories: suppliers of goods and services, partners, or authorities.

All disclosure of your personal data will take place in accordance with the law, and we will ensure that the disclosed data is only processed for the purposes for which it was shared.

Purpose and legal basis for processing

Your personal data as a member of an OK association is processed for the purposes listed below and based on the stated legal grounds. We want you to always know how your personal data is used, so this list will be continuously updated as new processing activities are introduced. You will be informed of such changes in an appropriate way, for example via email.

Purpose Legal basis
Administration related to membership applications and new members To take steps at the request of the data subject prior to entering into a contract
Membership administration:
Maintain membership register
Administration of association activities
Interaction with members
Administration of share capital and savings accounts
To comply with a legal obligation
To perform a contract to which you are a party
Administration of membership cards and member benefits To perform a contract to which you are a party
Calculation and payment of interest and patronage refunds To perform a contract to which you are a party
Marketing (see supplementary information below) Legitimate interest, where our legitimate interest is to market our services
Business and activity analysis for the purpose of:
Improving and adapting operations/services
Producing decision-making material
Producing statistics
Legitimate interest, where our legitimate interest is to operate cost-effective and relevant business activities
Ensuring access to unified and updated address information To comply with a legal obligation, including maintaining accurate records

Legitimate interest, where our legitimate interest is to maintain accurate, relevant, and consistent records

Financial management, accounting, and reporting To comply with legal obligations

Legitimate interest, where our legitimate interest is to operate cost-effective and relevant business activities

Customer service case handling To perform a contract to which you are a party
To comply with a legal obligation
Legitimate interest, where our legitimate interest is to provide effective support and case management
Elected representatives (see supplementary information below) Legitimate interest
Performance of contract

It may occur that we need to obtain your explicit consent for processing personal data not covered above.

Special information about processing your personal data for marketing purposes

When you make purchases at an OKQ8 station and use your membership card (or pay with your OKQ8 VISA/debit card), information about your purchases is stored, among other things, to enable us to offer relevant promotions and marketing to you as a member. Based on your purchases, you will receive relevant offers from us. This information may also be used for analysis and follow-up to measure changes in our customer base and to evaluate marketing effectiveness.

As a member, you will also receive monthly newsletters or information about member benefits. Such communication may be general (sent to all members) or targeted (sent based on membership category). We store records of what communication you receive and how you respond. This information is not combined with other sources or disclosed to third parties without your consent.

Certain types of automated decisions with legal or similarly significant effects are subject to special rules under the law. OK and OKQ8 Scandinavia will not use your data for such decisions without providing additional information and, where necessary, obtaining your consent.

Processing of personal data outside the EU/EEA

Your personal data may be transferred to suppliers and/or IT solutions outside the EU/EEA. In such cases, we will take appropriate safeguards, such as using EU-approved standard contractual clauses, to ensure that the transfer and processing comply with applicable laws.

Special information on processing personal data of elected representatives

In connection with nominations for elected positions, your name and contact details such as phone number and address are processed. If you are appointed to a position, we will also require your personal identity number and bank account number. These details are needed to administer and carry out nominations and elections, as well as to manage the contractual relationship and communication between OK and elected representatives.

The legal basis is legitimate interest until the election is completed, and thereafter performance of contract.

Why does OK need the personal data?

OK uses the data to administer your assignment, pay remuneration, report to the Swedish Tax Agency, distribute instructions, and communicate information related to your role. Your name, address, and phone number will also be available to other elected representatives.

Disclosure and deletion of elected representatives’ data

OK will not disclose personal data to third parties except for publishing names on its website and other member channels, or when legally required. Data is retained only as long as necessary, up to two (2) years after the end of the mandate period.

Storage and deletion of your personal data

Your personal data is stored for as long as permitted by applicable law. Where no legal obligation specifies a retention period, data is stored only as long as necessary for the processing purpose.

We may retain data after membership ends if required to fulfill legal obligations or establish, exercise, or defend legal claims, or for a limited period to re-recruit former members.

Your rights

Under EU data protection law, you have the following rights:

  • Right to object to direct marketing
  • Right of access
  • Right to rectification, erasure, or restriction
  • Right to withdraw consent
  • Right to object based on legitimate interest
  • Right to data portability
  • Right to lodge a complaint with a supervisory authority

Contact

To exercise your rights, please send a written and signed request to customer service at:

OKQ8 Customer Service
Box 502
774 27 Avesta

You can always contact customer service if you have questions regarding the processing of your personal data.

More information for those who are also OKQ8 customers

More information about how we handle personal data and specific information for OKQ8 Bank customers is available at OKQ8.se.
Click here to read more.

Website Privacy Policy

We want you to feel safe about how we process your personal data under the GDPR. The regulation came into force in the EU on 25 May 2018 and replaced the Swedish Personal Data Act (PuL). Through external services, we collect data on how you browse our website to improve and analyze our services.

What personal data we collect and why

Media

If you upload images, avoid images with embedded GPS EXIF data. Visitors can download and extract location data from images.

Contact forms

Forms collect data to provide requested services. Submitted data, time, and IP address are stored so we can contact you. You may request deletion at any time.

Cookies

This website uses cookies only for short-term, non-personal data storage. Cookies disappear when the browser is closed. Google Analytics and Facebook Pixel are exceptions and are used for analytics.

Embedded content

Articles may include embedded content from other websites, which may collect data and track interaction.

Analytics

We use Google Analytics and Facebook Pixel to analyze website usage and improve services.

Who we share your data with

We do not sell or share your data but use third-party providers for hosting and backup.

How long we retain your data

Registered users’ data is stored in their profiles. Users and administrators can view and edit data.

Your rights over your data

You may request deletion of your personal data, except where retention is required for legal or security reasons.

How we protect your information

We use backups and advanced antivirus protection and regularly update the website.

Data breach procedures

In case of a data breach, affected users will be notified. Serious breaches will be reported to authorities.