Information on How We Process Your Personal Data
It is important to us that your personal data and your personal privacy are protected in a correct manner. With this text, we want to explain how we handle your personal data. This information applies to you as a member and/or elected representative of OK Norrbotten.
Who is responsible for my personal data?
When you apply for membership, the OK association you become a member of is the data controller responsible for administering your membership. If you are unsure which OK association you are (or will become) a member of, you can contact customer service—see contact details below.
Where does my personal data come from?
The primary source of personal data about you is you yourself, i.e. information you provide when you become a member or otherwise submit to us, such as name, date of birth, personal identity number, billing and delivery address, email address, and mobile phone number.
In addition to the information you provide, we may also obtain personal data about you from the following sources:
Personal data is generated through interactions between you and us. For example, we may store case histories or otherwise document your communication with us. We also receive information about your purchases of goods and services from other companies within OK and OKQ8 Scandinavia.
We continuously retrieve personal data from publicly available sources such as public registers, e.g. the population register.
If you do not provide the requested personal data, we may not be able to offer you the service or product you want or take other actions you request. In some cases, providing personal data is required by law. We will clearly indicate when it is mandatory to provide certain information in order to use or access a specific product or service.
Who your personal data may be shared with
For the purposes described below, your personal data may be shared with other entities within OK and OKQ8 Scandinavia. Such processing is regulated by agreements designed to protect your rights as a data subject. Contact customer service if you want more information about data sharing within OK and OKQ8 Scandinavia.
Personal data may also be disclosed outside OK and OKQ8 Scandinavia. Such recipients fall into one of the following categories: suppliers of goods and services, partners, or authorities.
All disclosure of your personal data will take place in accordance with the law, and we will ensure that the disclosed data is only processed for the purposes for which it was shared.
Purpose and legal basis for processing
Your personal data as a member of an OK association is processed for the purposes listed below and based on the stated legal grounds. We want you to always know how your personal data is used, so this list will be continuously updated as new processing activities are introduced. You will be informed of such changes in an appropriate way, for example via email.
| Purpose | Legal basis |
| Administration related to membership applications and new members | To take steps at the request of the data subject prior to entering into a contract |
| Membership administration: Maintain membership register Administration of association activities Interaction with members Administration of share capital and savings accounts |
To comply with a legal obligation To perform a contract to which you are a party |
| Administration of membership cards and member benefits | To perform a contract to which you are a party |
| Calculation and payment of interest and patronage refunds | To perform a contract to which you are a party |
| Marketing (see supplementary information below) | Legitimate interest, where our legitimate interest is to market our services |
| Business and activity analysis for the purpose of: Improving and adapting operations/services Producing decision-making material Producing statistics |
Legitimate interest, where our legitimate interest is to operate cost-effective and relevant business activities |
| Ensuring access to unified and updated address information | To comply with a legal obligation, including maintaining accurate records
Legitimate interest, where our legitimate interest is to maintain accurate, relevant, and consistent records |
| Financial management, accounting, and reporting | To comply with legal obligations
Legitimate interest, where our legitimate interest is to operate cost-effective and relevant business activities |
| Customer service case handling | To perform a contract to which you are a party To comply with a legal obligation Legitimate interest, where our legitimate interest is to provide effective support and case management |
| Elected representatives (see supplementary information below) | Legitimate interest Performance of contract |
It may occur that we need to obtain your explicit consent for processing personal data not covered above.
Special information about processing your personal data for marketing purposes
When you make purchases at an OKQ8 station and use your membership card (or pay with your OKQ8 VISA/debit card), information about your purchases is stored, among other things, to enable us to offer relevant promotions and marketing to you as a member. Based on your purchases, you will receive relevant offers from us. This information may also be used for analysis and follow-up to measure changes in our customer base and to evaluate marketing effectiveness.
As a member, you will also receive monthly newsletters or information about member benefits. Such communication may be general (sent to all members) or targeted (sent based on membership category). We store records of what communication you receive and how you respond. This information is not combined with other sources or disclosed to third parties without your consent.
Certain types of automated decisions with legal or similarly significant effects are subject to special rules under the law. OK and OKQ8 Scandinavia will not use your data for such decisions without providing additional information and, where necessary, obtaining your consent.
Processing of personal data outside the EU/EEA
Your personal data may be transferred to suppliers and/or IT solutions outside the EU/EEA. In such cases, we will take appropriate safeguards, such as using EU-approved standard contractual clauses, to ensure that the transfer and processing comply with applicable laws.
Special information on processing personal data of elected representatives
In connection with nominations for elected positions, your name and contact details such as phone number and address are processed. If you are appointed to a position, we will also require your personal identity number and bank account number. These details are needed to administer and carry out nominations and elections, as well as to manage the contractual relationship and communication between OK and elected representatives.
The legal basis is legitimate interest until the election is completed, and thereafter performance of contract.
Why does OK need the personal data?
OK uses the data to administer your assignment, pay remuneration, report to the Swedish Tax Agency, distribute instructions, and communicate information related to your role. Your name, address, and phone number will also be available to other elected representatives.
Disclosure and deletion of elected representatives’ data
OK will not disclose personal data to third parties except for publishing names on its website and other member channels, or when legally required. Data is retained only as long as necessary, up to two (2) years after the end of the mandate period.
Storage and deletion of your personal data
Your personal data is stored for as long as permitted by applicable law. Where no legal obligation specifies a retention period, data is stored only as long as necessary for the processing purpose.
We may retain data after membership ends if required to fulfill legal obligations or establish, exercise, or defend legal claims, or for a limited period to re-recruit former members.
Your rights
Under EU data protection law, you have the following rights:
- Right to object to direct marketing
- Right of access
- Right to rectification, erasure, or restriction
- Right to withdraw consent
- Right to object based on legitimate interest
- Right to data portability
- Right to lodge a complaint with a supervisory authority
Contact
To exercise your rights, please send a written and signed request to customer service at:
OKQ8 Customer Service
Box 502
774 27 Avesta
You can always contact customer service if you have questions regarding the processing of your personal data.
More information for those who are also OKQ8 customers
More information about how we handle personal data and specific information for OKQ8 Bank customers is available at OKQ8.se.
Click here to read more.
Website Privacy Policy
We want you to feel safe about how we process your personal data under the GDPR. The regulation came into force in the EU on 25 May 2018 and replaced the Swedish Personal Data Act (PuL). Through external services, we collect data on how you browse our website to improve and analyze our services.
What personal data we collect and why
Media
If you upload images, avoid images with embedded GPS EXIF data. Visitors can download and extract location data from images.
Contact forms
Forms collect data to provide requested services. Submitted data, time, and IP address are stored so we can contact you. You may request deletion at any time.
Cookies
This website uses cookies only for short-term, non-personal data storage. Cookies disappear when the browser is closed. Google Analytics and Facebook Pixel are exceptions and are used for analytics.
Embedded content
Articles may include embedded content from other websites, which may collect data and track interaction.
Analytics
We use Google Analytics and Facebook Pixel to analyze website usage and improve services.
Who we share your data with
We do not sell or share your data but use third-party providers for hosting and backup.
How long we retain your data
Registered users’ data is stored in their profiles. Users and administrators can view and edit data.
Your rights over your data
You may request deletion of your personal data, except where retention is required for legal or security reasons.
How we protect your information
We use backups and advanced antivirus protection and regularly update the website.
Data breach procedures
In case of a data breach, affected users will be notified. Serious breaches will be reported to authorities.
