At Stockholm Blockchain Group (“Stockholm Blockchain Group", "we", "us"), we process personal data about our customers and visitors on our websites ("you"). We make efforts to handle your personal data with care, keep it secure and comply with data protection laws.
Stockholm Blockchain Group is engaged in blockchain and cryptocurrency services including consulting,education, marketing and lead generation with headquarters in Sweden.
How this Policy Works
The purpose of this Policy is to explain when, why and how we process information which may relate to you ("personal data"). It also provides important information on your statutory rights. This Policy is not intended to override the terms of any contract you have with us, nor rights you might have under data protection laws.
ContentsWHO IS RESPONSIBLE FOR LOOKING AFTER YOUR PERSONAL DATA?
WHAT PERSONAL DATA DO WE PROCESS?
WHAT DO WE USE YOUR PERSONAL DATA FOR AND WHEN DO WE PROCESS YOUR PERSONAL DATA?
WHO DO WE SHARE YOUR PERSONAL DATA WITH?
HOW LONG DO WE KEEP YOUR PERSONAL DATA?
WHAT ARE YOUR RIGHTS?
1. Who is responsible for looking after your personal data?
Stockholm Blockchain Group AB having its registered address BOX 13034 103 01 Stockholm, Sweden, is principally responsible for looking after your personal data (your Data Controller). Data Controller means the company that determines the means and purposes of processing of personal data.
You should be aware that although we are principally responsible for looking after your personal data, information may be held in databases which can be accessed by other companies. When accessing your personal data, all companies will comply with the standards set out in this Policy.
2. What personal data do we process?
We may process the following personal data about you:
- Data of birth
- Email address
- IP address
- Location data
- Website usage
- Content you submit, such as, posts, comments, personal preferences, opinions, complaints, chats
- If you submit a complaint, the account name or username and email registered with the exchange against which the complaint is directed
- Other information. You may choose to provide other information directly to us or we might require other information from you. For example, we may collect other information when we handle a complaint submitted by you.
3. What do we use your personal data for and when do we process your personal data?
Stockholm Blockchain Group will collect information directly from you when you use our services or visit our websites.
We use your personal data to:
- create and manage your account with us
- communicate with you and respond to your inquiries, for example via email.
- send out promotional emails relating to products and services. See also the section below on Direct marketing.
- analyze information in our systems and databases to improve the way we run our business and websites according to user preferences in order to provide a better service and user experience.
- improve and target advertisements that you receive from us.
- If you make available, handle/route a complaint you have submitted via our Complaints Service in order to deliver you a fair, honest and independent complaints resolution service
- meet or exercise any of our legal obligations or rights
We will only process your personal data for the purposes set out in this Section 3 and where we are satisfied that:
- you have provided your consent to us using the data in that way, or
- our use of your personal data is necessary to support 'legitimate interests' that we have as a business (for example, to improve our products, to carry out analytics across our datasets or to deliver a fair, honest and independent complaints resolution service between investors and exchanges), in a way that is proportionate and respects your privacy.
4. Who do we share your personal data with?
We work with many third parties, to help manage our business and deliver services. These third parties may from time to time need to have access to your personal data:
-Our email provider Mailchimp (The Rocket Science Group LLC), a company headquartered in the State of Georgia in the United States, who is Privacy Shield certified as you may see here (https://mailchimp.com/legal/privacy/)
-Our hosting provider DigitalOcean (DigitalOcean, LLC), based in the USA who is Privacy Shield certified as you can see here (https://www.digitalocean.com/legal/privacy-shield/).
-In the event you have submitted a complaint via our Exchange Complaints Service, the exchange or exchange operator against which you submitted a complaint.
-If we are under a duty to disclose to comply with a legal obligation or protect our interests or security.
-In the event we sell, buy or re-organise any business or assets, or if our assets are acquired by a third party, including prospective sellers or buyers.
5. International Transfers
International Transfers mean that personal data is transferred to a country outside the European Union.
As set out in Section 4 above, we may allow access to your personal data to third parties who may be located outside the European Union.
We may also disclose your personal data if we receive a legal or regulatory request from a foreign law enforcement body outside the European Union.
We will always take steps to ensure that any international transfer of information is managed to protect your rights and interests. Any requests for information that we receive from law enforcement or regulators will be carefully checked before personal data is disclosed.
You have the right to ask us for more information about the safeguards we have put in place as mentioned above. Contact us if you wish further information.
6. Direct Marketing
We will use your personal data to send you direct marketing communications in the form of email regarding products and services that we and our partners offer regarding cryptocurrency, blockchain and trading.
In some cases our processing of your personal data for marketing purposes will be based on our legitimate interests. When required by law it will be based on your consent.
You always have a right to say no to further direct marketing, at any time. You can use the opt-out link that you find in all direct marketing communications, or by contacting us.
We take steps to limit direct marketing to a reasonable and proportionate level, and to send you communications that we believe may be of interest or relevance to you, based on the information we have about you.
7. How long do we keep your personal data?
We will retain your personal data for as long as reasonably necessary for the purposes listed in Section 3 of this Policy.
In some circumstances we keep your personal data during a certain period to meet for example legal, tax or accounting requirements.
We maintain a data retention policy for personal data in our care. Where your personal data is no longer required we will ensure it is either securely deleted or made anonymous.
8. What are your rights?
You have a number of rights in relation to your personal data. More information about each of these rights can be found by referring to the table set out further below.
To exercise your rights you may contact us as by sending an email to firstname.lastname@example.org or in writing to Stockholm Blockchain Group at the address set out in Section 1 above.
Please note the following if you wish to exercise your rights:
You can ask us to:
- confirm whether we are processing your personal data;
- give you a copy of that data;
- provide you with other information about your personal data, for example what data we have, what we use it for, who we disclose it to, whether we transfer it outside the EU and how we protect it, how long we keep it for, what rights you have, how you can make a complaint, where we got your data from and whether we have carried out any Automated Decision Making or Profiling, to the extent that information has not already been provided to you in this Policy.
You can ask us to rectify inaccurate personal data. We may seek to verify the accuracy of the data before rectifying it.
You can ask us to erase your personal data, but only where:
- it is no longer needed for the purposes for which it was collected; or
- you have withdrawn your consent (where processing was based on consent); or
- following a successful right to object (see 'Objection' below); or
- it has been processed unlawfully; or
- to comply with a legal obligation.
We are not required to comply with your request to erase your personal data if the processing of your personal data is necessary:
- for compliance with a legal obligation; or
- for the establishment, exercise or defence of legal claims;
There are certain other circumstances in which we are not required to comply with your erasure request, although these two are the most likely circumstances in which we would deny that request
You can ask us to restrict (i.e. keep but not use) your personal data, but only where:
- its accuracy is contested (see Rectification), to allow us to verify its accuracy; or
- the processing is unlawful, but you do not want it erased; or
- it is no longer needed for the purposes for which it was collected, but we still need it to establish, exercise or defend legal claims; or
- you have exercised the right to object, and verification of overriding grounds is pending.
We can continue to use your personal data following a request for restriction, where:
- we have your consent; or
- to establish, exercise or defend legal claims; or
- to protect the rights of another natural or legal person.
You can ask us to provide your personal data to you in a structured, commonly used, machine-readable format, or you can ask to have it 'ported' directly to another Data Controller, but in each case only where:
- the processing is based on your consent or on the performance of a contract with you; and
- the processing is carried out by automated means.
You can object to any processing of your personal data which has our 'legitimate interests' as its legal basis, if you believe your fundamental rights and freedoms outweigh our legitimate interests.
We have an opportunity to demonstrate that we have compelling legitimate interests which override your rights and freedoms.
You can ask to obtain a copy of, or reference to, the safeguards under which your personal data is transferred outside of the European Economic Area.
We may redact data transfer agreements or related documents (i.e. obscure certain information contained within these documents) for reasons of commercial sensitivity.
You have a right to lodge a complaint with the responsible local supervisory authority about our processing of your personal data.
We ask that you please attempt to resolve any issues with us first, although you have a right to contact your supervisory authority at any time.
Latest update: 15 May 2019