Privacy Policy

Personal Data means any information that can be used to personally identify you or contact you online or elsewhere.

We always try to collect as little Personal Data as possible or no Personal Data at all. When we collect any Personal Data, we do it with the sole purpose of providing a good service to you.

We take your right to privacy very seriously when you use our websites, our mobile applications, our pages on social networks, online forms and whenever else you communicate electronically with us (our "Digital Services"). That’s why we’ve developed this Privacy Policy to explain how we collect, store, use and process the Personal Data you share with us through our Digital Services.

Please read this Privacy Policy carefully as it contains important information on who we are and how and why we collect, store, use and share your Personal Data. It also explains your rights in relation to your Personal Data and how to contact us or the relevant supervisory authorities in the event you have a complaint. If you do not agree to this Privacy Policy, please do not use our Digital Services.

"We", "us" and "our" refer to the company Allergomat AB.

We are the data controller when processing your Personal Data on the conditions described in this Privacy Policy, which includes any Personal Data you submit to us.

What Personal Data do we gather about you and how do we collect it?

During your interactions with our services, we may collect and use the following Personal Data:

• email address

• billing information, transaction and payment card information

• information about how you use our services

• responses to surveys, competitions and promotions

The types and amount of information collected for the above-mentioned features and services may be updated and vary depending on the activities of Allergomat AB. We collect all personal data directly from you and we do not use any external data sources, cookies or other tracking technologies.

For what purpose do we use your Personal Data and based on which legal grounds?

Under data protection law, we can only use your Personal Data if we have a proper reason for doing so, e.g.:

• To comply with any legal and regulatory obligations

• Respond to your request of service or for the performance of a contract

• Send you transactional or administrative communications

• Because it is also our legitimate interest to better serve you

• To respond to an inquiry or comment from you

What happens if you do not wish to provide your Personal Data?

If you choose not to submit any Personal Data when requested, you may not be able to participate in certain activities and personalized features, or the Digital Services and special offered to you may be limited. For example, if you refuse to share your email address, you will not be able to receive our newsletters or otherwise register on our Digital Services. However, to simply browse our Digital Services and learn more about us and our products, you do not need to give us any Personal Data. In any event, we will always inform you of the Personal Data that is necessary in order to benefit from a service.

Who do we disclose your Personal Data to and why?

We do not share your Personal Data with anyone outside of Allergomat AB.

How long do we keep your Personal Data?

We will store the Personal Data that you sent us via our Digital Services in our databases as long as your account is active, for the duration of the contract with you or as needed to provide you the services you requested or to answer queries or resolve problems, provide improved and new services. We may also retain your Personal Data in accordance with our internal retention procedure as necessary to comply with our legal and regulatory obligations, resolve disputes and enforce our agreements.

We may thus retain your Personal Data after you stop using our services or our Digital Services according to the statute of limitations.

How do we keep your Personal Data secure?

We take all necessary technical and organizational measures to protect the confidentiality and security of your Personal Data collected from this website and/or our applications, including sensitive Personal Data. These efforts include but are not necessarily limited to: (i) storing your Personal Data in secure operating environments that are not available to the public and that are only accessible to authorized employees.

In the case of suspected data security breach, we will notify you.

What are your rights regarding your Personal Data?

• If your Personal Data has been processed on the basis of your consent, you can withdraw your consent at any time, without impact on lawfulness of processing based on consent before its withdrawal.

• You can request to access your Personal Data.

• You can request to rectify your Personal Data if it is inaccurate, incomplete or out of date.

• You can request the erasure of your Personal Data (i) if your Personal Data is no longer necessary for the purpose of the data processing, (ii) you have withdrawn your consent on the data processing based exclusively on such consent, (iii) you objected to the data processing, (iv) the Personal Data processing is unlawful, (v) the Personal Data must be erased to comply with applicable legal obligations.

• You can request the restriction of the processing (i) in the event the accuracy of your Personal Data is contested to allow us to check such accuracy, (ii) if you wish to restrict your Personal Data rather than deleting it despite the fact that the processing is unlawful, (iii) if you wish us to keep your Personal Data because you need it for your defense in the context of legal claims (iv) if you have objected to the processing but we conduct verification to check whether it has legitimate grounds for such processing which may override your own rights (v) if the data processing is based our legitimate interest.

• You can request the portability of the Personal Data you provided to us, in particular if the Personal Data processing is based on your consent or the performance of a contract.

• You always have the option not to share any of your Personal Data with us. If you choose this option, you may be limited in the activities and features we can provide you.

• You have the right to object to the processing of your Personal Data by us.

• You have also the right to give general or specific instructions on how your personal data processed under this Privacy Policy may be used after your death.

How do we treat children's information?

Our Digital Services are not intended for children under the age of majority (“Minor”), so we do not knowingly collect Personal Data from Minors. In the case minors use our services, the Personal Data is treated with the same care as the other users as described in this policy.

How can you contact us or the relevant Supervisory Authority?

If you have any questions, complaints, or comments regarding this Privacy Policy or our information collection practices, please contact us by filling in the contact form below.

We hope that we can resolve any query or concern you may raise about our use of your information. You also have the right to complain to the Supervisory Authority in the European Union where you work, normally live or where any alleged infringement of data protection laws occurred.