1. Categories of personal data and processing purposes
You may use our website or app without providing any personal data about you. In this case, Essity will collect only the following metadata that result from your usage:
Referral page, data and time of access, data volume transmitted, status of transmission, type of web browser, IP-address, operating system and interface, language and version of browser software.
Your IP-address will be used to enable your access to our website or app. Once the IP-address is no longer necessary for this purpose, we will shorten your IP-address by removing the last octet of your IP-address. The metadata, including the shortened IP-address will be used to improve the quality and services of our website or app by analysing the usage behaviour of our users.
If you create an account on/in our website or app, you may be asked to provide personal data about you, for example: Name, postal address, email address, selected password, telephone number, bank account details, credit card details, invoicing and delivery address, interests in certain products/services (voluntary), request to receive marketing emails (voluntary). Essity processes such personal data for purposes of providing our services to you, to provide you with marketing materials to the extent permitted by applicable law, and to analyse your interests for marketing purposes.
If you order a product via our website or app, Essity collects and processes the following personal data about you: Your account data, type and amount of product, purchase price, order date, order status, product returns, customer care requests. Essity processes such personal data for purposes of carrying out the contractual relationship and the product order, providing customer care services, compliance with legal obligations, defending, establishing and exercising legal claims, and tailored marketing.
If you participate in a sweepstake, Essity collects and processes the following personal data about you: Name, postal address, email address, date of entry, selection as winner, prize, answer to quiz. Essity processes such personal data for purposes of carrying out the sweepstake, informing the winner, delivering the price to the winner, carrying out the event, and marketing.
If you order some products, Essity may collect and process also information about your health conditions as implied by product order. Health data are sensitive data within the meaning of the GDPR and Essity is taking all necessary steps to protect such sensitive data as legally required. Subject to your consent, Essity collects and processes your health data solely for the purposes of carrying out the contractual relationship and the product order, providing customer care services, compliance with legal obligations, defending, establishing and exercising legal claims, and tailored marketing.
2. Third Parties
Essity may engage external service providers, who act as a data processor of Essity, to provide certain services to Essity, such as website service providers, marketing service providers or IT support service providers. When providing such services, the external service providers may have access to and/or may process your personal data.
We request those external service providers to implement and apply security safeguards to ensure the privacy and security of your personal data.
Essity may transfer – in compliance with applicable data protection law – personal data to law enforcement agencies, governmental authorities, legal counsel, external consultants, or business partners. In case of a corporate merger or acquisition, personal data may be transferred to the third parties being involve in the merger or acquisition.
The Personal Data that we collect or receive about you may be transferred to and processed by recipients which are located inside or outside the European Economic Area ("EEA"). The countries include those listed at http://ec.europa.eu/justice/data-protection/international-transfers/adequacy/index_en.htm which provide an adequate level of data protection from a European data protection law perspective. The recipients in the USA are partially certified under the EU-US Privacy Shield and thereby recognised as providing an adequate level of data protection from a European data protection law perspective. Other recipients might be located in other countries which do not adduce an adequate level of protection from a European data protection law perspective. Essity will take all necessary measures to ensure that transfers out of the EEA are adequately protected as required by applicable data protection law. With respect to transfers to countries not providing an adequate level of data protection, we base the transfer on appropriate safeguards, such as standard data protection clauses adopted by the European Commission or by a supervisory authority, approved code of conducts together with binding and enforceable commitments of the recipient, or approved certification mechanisms together with binding and enforceable commitments of the recipient. You can ask for a copy of the such appropriate safeguards by contacting us as set out in Sec. 7 (Contact us) below.
3. Legal basis for the processing
- You have given your consent to the processing of your data for one or more specific purposes;
- The processing is necessary for the performance of a contract to which you are a party or to take steps at your request prior to entering a contract;
- The processing is necessary for compliance with a legal obligation to which we are subject to;
- The processing is necessary to protect your vital interests of you or of another natural person;
- The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us;
- The processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of you which require protection of personal data, in particular if you are a child;
- Other applicable legal basis for data processing, especially provisions set out by member state law;
- You have given your explicit consent to the processing of your sensitive personal data for one or more specific purposes;
- The processing is necessary for the purposes of carrying out the obligations and exercising specific rights of Essity or of the data subject in the field of employment and social security and social protection law;
- The processing relates to personal data which are manifestly made public by the data subject;
- The processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity;