PRIVACY POLICY
Data Controller
We are the data controller for the personal data we process about our customers and partners. You can find our contact information below.
ApodanNordic PharmaPackaging A/S
Kigkurren 8C, 1. tv, 2300 København S
CVR no.: 30541553
It is not required for our company to have an external DPO, but if you have questions about the processing of your personal data, you can contact us at packaging@apodanpharma.dk.
Processing activities
As a data controller under the GDPR, we carry out the following processing activities.
Visiting the website
When you visit our website, we use cookies to ensure that the website functions, which you can read more about in the
Cookies section below.
Communication with potential customers
When you have questions about our site or want to hear more about our services, you can contact us at:
We process your personal data in order to communicate with you, for example to answer questions about our services. We only process the information that you provide us in connection with our communication.
We will typically process the following general information: name, e-mail, telephone number.
Our legal basis for processing this personal data is Article 6(1)(f) of the General Data Protection Regulation.
We will delete our communication once it is clear whether you wish to use our services or not.
In special cases, your personal data may be stored for a longer period.
Customers
We need to communicate with our customers so that we can ensure that the service is delivered correctly. This may include information such as name, address, services, special agreements, payment information, and similar data.
The basis for processing this personal data is Article 6(1)(b) of the General Data Protection Regulation.
Once the service has been provided and any outstanding issues have been resolved, we will immediately delete the personal data.
Accounting
We are required to store all accounting documents in accordance with the Danish Accounting Act. This means that we store invoices and similar documents for accounting purposes. These may include general personal data such as name, address, service description.
Our basis for processing personal data for accounting purposes is Article 6(1)(b) of the General Data Protection Regulation.
We store this information for a minimum of 5 years after the end of the current financial year.
Job applications
We welcome job applications to assess whether they match a recruitment need.
If you send us your job application, our basis for processing your personal data is Article 6(1)(f) of the General Data Protection Regulation.
If you have sent an unsolicited application, we will immediately assess whether your application is relevant. We store your application for up to 6 months, after which your information will be deleted if there is no match.
If you have applied for an advertised position, we will delete your application once the recruitment process has concluded and another candidate has been selected.
If you are part of a recruitment process and/or hired for the job, we will provide you with separate information about how we process your personal data in this case.
Data processers
Like most companies, we use external partners and suppliers, some of whom act as data processors.
External suppliers can, for example, provide systems to organize our work, services, consulting, IT hosting or marketing.
It is our responsibility to ensure that your personal data are processed properly. Therefore, we place high demands on our partners, and our partners must guarantee that your personal data are protected.
We enter into data processing agreements with all companies that process personal data on our behalf in order to increase the security of your personal data.
Disclosure of personal data
We do not disclose your personal data to third parties.
Profiling and automated decisions
We do not carry out profiling or automated decisions.
Third-country transfers
We generally use data processors in the EU/EEA, or who store data in the EU/EEA.
In some cases, this is not possible, and data processors outside the EU/EEA may be used if they can ensure adequate protection of your personal data.
Security of processing
We keep personal data secure by implementing appropriate technical and organizational measures.
We have conducted risk assessments of our processing of personal data and have subsequently implemented appropriate technical and organizational measures to increase the security of processing.
Rights of the data subjects
According to the General Data Protection Regulation, you have a number of rights in relation to our processing of your data.
If you want to exercise your rights, please contact us so that we can help you with this.
Right to see information (right of access)
You have the right to gain access to the information that we process about you, as well as a number of additional information.
Right to rectification (correction)
You have the right to have incorrect information about yourself corrected.
Right to erasure
In special cases, you have the right to have information about you deleted, before the time of our general erasure occurs.
Right to restriction of processing
In certain cases, you have the right to have the processing of your personal data restricted. If you have the right to have the processing restricted, we may in the future only process the information – with the exception of storage – with your consent, or for the purpose of establishing, exercising or defending legal claims, or to protect a person or important public interests.
Right to object
In certain cases, you have the right to object to our otherwise lawful processing of your personal data. You can also object to the processing of your information for direct marketing.
Right to transmit information (data portability)
In certain cases, you have the right to receive your personal data in a structured, commonly used and machine-readable format and to have this personal data transferred from one data controller to another without hindrance.
You can read more about your rights in the Danish Data Protection Agency's guidance on the rights of data subjects, which you can find at
www.datatilsynet.dk.
Withdrawal of consent
When our processing of your personal data is based on your consent, you have the right to withdraw your consent.
Complaint to the Danish Data Protection Agency
You have the right to lodge a complaint with the Danish Data Protection Agency if you are dissatisfied with our processing of your personal data. You can find the Danish Data Protection Agency's contact information at
www.datatilsynet.dk.
We encourage you to read more about GDPR to stay informed about your rights and obligations.