Privacy Policy | PRIDO

Processing of personal data

Purpose

We care about your privacy. You should feel secure when entrusting us with your personal data. Therefore, we have established this policy. It is based on applicable data protection legislation and clarifies how we work to protect your rights and your privacy.

The purpose of this policy is for you to know how we process your personal data, what we use it for, who can access it and under what conditions, and how you can exercise your rights.

Background

We process your personal data primarily to fulfill our obligations to you. Our principle is to not process more personal data than necessary for the purpose, and we always strive to use the least privacy-sensitive data.

We need your personal data to comply with laws and our warranty obligations. We also need your personal data to conduct a credit check in connection with a purchase and to provide you with good service in the form of information and follow-up.

You are not obligated to provide your data to us, but if you choose not to, it is possible that we cannot offer you all our services and products.

Guidelines What personal data do we process?

We only process personal data when we have a legal basis or an agreement. We do not process personal data in other cases than when necessary to fulfill obligations under contract and law. Here are examples of the personal data we process:

Name Address Email address Telephone number Social security number Photographs Data you have registered voluntarily and provided

No personal data is processed based on automated decision-making or through profiling.

How do we access your personal data?

We strive to only process personal data when there is a legal basis. We will process your personal data as long as necessary to fulfill our obligations under contract or law.

We access your personal data in the following ways:

Data you provide us directly in connection with a purchase or employment Data recorded when you visit our website Data we obtain from public registers Data we receive when you subscribe to newsletters and other mailings Data we receive when you respond to surveys and studies Data we receive when you contact us, apply for a job with us, visit us, or otherwise make contact with us Is your personal data processed in a secure manner?

We have established procedures and working methods to ensure that your personal data is handled securely. The principle is that only employees and other persons within the organization who need the personal data to perform their work tasks should have access to it.

Regarding sensitive personal data, we have established special authorization controls, which means higher protection for your personal data.

Our security systems are developed with your privacy in focus and protect to a great extent against intrusion, destruction, and other changes that could pose a risk to your privacy.

We have an IT security policy to ensure that your personal data is processed securely.

We do not transfer personal data in other cases than those explicitly stated in this policy.

When do we disclose your personal data?

Our principle is not to disclose your personal data to third parties unless you have consented to it or if it is necessary to fulfill our obligations under contract or law. In cases where we disclose personal data to third parties, we establish confidentiality agreements and ensure that the personal data is processed securely.

Right to be erased

You have the right to contact us to request that your personal data be erased:

If the data is no longer necessary for the purposes for which it was collected If the processing is based solely on your consent and you withdraw that consent If the processing is for direct marketing and you object to the data being processed If you object to personal data processing that occurs after a balance of interests and there are no legitimate reasons that outweigh your interests If the processing of your data has not followed applicable law If erasure is required to fulfill a legal obligation In some cases, we may not be able to comply with a request for erasure, e.g., if we are legally obliged to retain the data. If erasure occurs, we will notify those to whom we have disclosed your data that erasure has taken place. We will also inform you upon request about whom information about the erasure has been disclosed The data controller decides on the right to erasure.

Requirement for registry

Prido AB does not consider itself covered by the requirement for a registry since our data processing:

Is not regular Does not pose a threat to people’s rights and freedoms Does not involve sensitive data or criminal records Requirement for a data protection officer

Prido AB does not consider itself covered by the requirement for a data protection officer since:

We are not an authority or an elected assembly, i.e., a public body We do not have as a core activity to regularly, systematically and extensively monitor individuals We do not have as a core activity to process sensitive personal data or data about criminal actions on a large scale Responsibility

Prido AB is the data controller, which means we are responsible for how your personal data is processed and that your rights are safeguarded.

If you have questions or wish to exercise your rights, contact Prido at telephone +46512-29590.

Prido does not take responsibility for or guarantee the quality of the product, its functionality, or availability on our website or its content. We reserve the right to make changes to our offerings or any inaccuracies that may have occurred in the texts on our website. Colors and materials may differ from their real appearance.

Regarding references to external websites, we do not take responsibility for the content or material on these websites’ home pages.

About Cookies

A cookie, also known as a web cookie, is a small file stored on your device containing information to improve your web browsing experience. Personal information is not collected via cookies. If you prefer not to accept cookies, this can be adjusted in your browser settings.

Enhance your experience

At prido.com, we use cookies to improve the functionality of our website for our visitors. By saving your settings or choices in a cookie, you do not need to redo these selections upon revisiting. The cookie tells the website that you have visited us before and what choices you have made, saving time and making your visit smoother. With new choices, the cookie is automatically updated on your device to reflect the latest selections.

Legislation around cookies

According to the Electronic Communications Act (SFS 2003:389), we are obligated to inform visitors that our website uses cookies and for what purpose they are used.

Types of Cookies

At prido.com, two types of cookies are used. The first type is temporary and disappears when you close your browser. It is used, for example, during visits to prido.com. The second type of cookie is stored as a file on your device for a longer period and is for recurring visits. This type is used, for example, to remember your settings. We do not store personal information via cookies, and the information cannot be used to track individual visitors.

How to avoid cookies

If you do not wish to accept cookies, you can adjust this in your browser settings. This may result in some parts of the website becoming inaccessible. You can set your browser to either automatically reject cookies or to ask you each time a website wants to store a cookie on your device. It is also possible to delete previously stored cookies through the browser settings. For more information, see the browser’s help pages.

Marketing Google Ads (conversion tracking) and Remarketing

We use Google Ads Conversion Tracking and Remarketing on this website, operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ads is an online advertising system that enables us to promote and optimize our services and products.

Through Google Ads Conversion Tracking and Remarketing, we can track specific user actions that occur after clicking on our Google Ads ad. This tool allows us to measure the effectiveness of our advertising campaigns, evaluate the success of different advertising actions, and improve our website along with our advertising activities.

Ads are displayed based on search queries on websites in Google’s ad network. In addition, we use Ads Remarketing Lists for search ads. This allows us to customize search ad campaigns for users who have previously visited our website. Through these services, we can combine our ads with certain search terms or show ads to previous visitors, such as advertising services that visitors have viewed on our website. Therefore, we can display interest-based advertising on other websites within Google’s ad network (such as “Google ads” in Google’s search or on other websites).

Every visit to our website where a Google Ads component is integrated, information about the actions you take is collected and transferred to Google to assess the relevance and effectiveness of our ads. If you are logged into Google at the same time, this information is directly linked to your Google account.

For conversion tracking, cookies are stored on your device, which expire after 30 days. You have the option to object to data storage through conversion tracking by disabling the use of cookies in your browser settings.

The use of Google Ads Conversion Tracking and Remarketing occurs only with your express consent in accordance with Art. 6 Para. 1 lit. a GDPR. For more information on privacy at Google, please visit: https://policies.google.com/privacy?hl=en.

DoubleClick

This website contains components from DoubleClick by Google. DoubleClick is a brand from Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland), under which specific online marketing solutions are marketed to advertising agencies and publishers.

DoubleClick by Google transfers data to the DoubleClick server with each impression, as well as with clicks or other activities. Each of these data transfers triggers a cookie request to your browser. If the browser accepts this request, DoubleClick places a cookie on your IT system. The purpose of the cookie is to optimize and display advertisements. The cookie is used, among other things, to serve and display user-relevant advertising and to create reports on advertising campaigns or to improve them. Additionally, the cookie is used to avoid showing the same ad multiple times.

DoubleClick uses a cookie ID, which is necessary for processing the technical procedure. The cookie ID is needed, for example, to display an ad in a browser. DoubleClick can also use the cookie ID to record which ads have already been shown in a browser to avoid duplicate placements. In addition, the cookie ID allows DoubleClick to record conversions.

A DoubleClick cookie contains no personal data. However, a DoubleClick cookie may contain additional campaign identifiers. A campaign identifier is used to identify the campaigns you have already been in contact with.

Each time you open one of the individual pages on this website operated by us and on which a DoubleClick component has been integrated, the browser on your IT system is prompted by the respective DoubleClick component to transfer data to Google for online advertising and settlement of commissions. As part of this technical process, Google acquires knowledge of data that Google also uses to generate commissions. Google can, for example, track that you clicked on certain links on our website.

You can prevent DoubleClick and our website from setting cookies at any time by adjusting your browser settings accordingly. In addition, cookies that have already been placed can be deleted at any time via the browser or other software programs.

These processing operations are performed only if explicit consent is given in accordance with Art. 6 (1) lit. a GDPR.

The privacy policy for DoubleClick by Google can be read at https://policies.google.com/?hl=en.

Microsoft Ads (formerly Bing Ads)

We have integrated Microsoft Advertising components on this website. Microsoft Advertising is operated by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521.

Microsoft Advertising is an online advertising system that enables us to market and optimize our services and products. Through Microsoft Advertising, especially the conversion and tracking tool, we can track certain user actions that occur after you have clicked on our Microsoft Bing ad.

Each call to one of the individual pages on this website, operated by us and where a Microsoft Advertising component has been integrated, collects information about the actions you perform and transfers it to Microsoft to assess the relevance and effectiveness of our ads. Microsoft and we can identify that someone clicked on an ad, was redirected to our online offer, and reached a predetermined target page (so-called conversion page).

With the help of remarketing lists created based on visitors’ activities on our website, we can also segment audiences and then optimize our Bing ad campaigns based on these segments.

These processes are performed only if you have given your express consent in accordance with Art. 6 (1) lit. a GDPR.

If you do not want to participate in the tracking process for Bing Ads, you can disable the necessary setting of a cookie in your browser settings or use Microsoft’s opt-out page: choice.microsoft.com/en-GB/opt-out.

For further information on data protection and the cookies used by Microsoft Bing Ads, you can find Microsoft’s privacy policy at: https://privacy.microsoft.com/en-gb/privacystatement.

Microsoft stores the data for a period of up to 180 days.

Google Analytics

On our websites, we use Google Analytics, a web analytics service provided by Google Ireland Limited (https://www.google.de/intl/en/about/), Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). In this context, pseudonymized user profiles are created, and cookies (see “Cookies” section) are used. The information generated by the cookie about your use of this website, such as

type/version of browser, the operating system used, referrer URL (the previously visited page), hostname of the accessing computer (IP address), and time of the server request,

is transferred to a Google server in the USA and stored there. The information is used to evaluate the use of the website, to compile reports on website activity, and to provide other services related to website use and internet usage for market research purposes and to tailor these internet pages to user needs. This information may also be transferred to third parties if required by law or if third parties process this data on our behalf. Under no circumstances will your IP address be merged with other Google data. IP addresses are anonymized so that an assignment is not possible (IP masking).

You can refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website.

These processing will only be performed if you have given your express consent in accordance with Art. 6.1 a GDPR.

Furthermore, you can prevent the collection of the data generated by the cookie and related to your use of the website (including your IP address) as well as the processing of this data by Google by downloading and installing a browser add-on (https://tools.google.com/dlpage/gaoptout?hl=en).

As an alternative to the browser add-on, especially for browsers on mobile devices, you can also prevent the collection by Google Analytics by clicking on this link: Disable Google Analytics. An opt-out cookie will be set that prevents the future collection of your data when visiting this website. The opt-out cookie is valid only in this browser and only for our website and is stored on your device. If you delete the cookies in this browser, you must set the opt-out cookie again.

You can read Google Analytics privacy policy at the following address: https://support.google.com/analytics/answer/6004245?hl=en.

Google Tag Manager

We use the service Google Tag Manager from Google. “Google” is a corporate group consisting of Google Ireland Ltd (service provider), Gordon House, Barrow Street, Dublin 4, Ireland, as well as Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and other subsidiaries of Google LLC.

We have entered into an order processing agreement with Google. Google Tag Manager is an auxiliary service and itself processes personal data only for technically necessary purposes. Google Tag Manager takes care of the loading of other components which in turn may collect data. Google Tag Manager does not have access to this data.

These processing operations are performed exclusively when explicit consent has been given in accordance with Art. 6 Par. 1 lit. a GDPR.

Further information about Google Tag Manager and Google’s privacy policy can be found at the following address: https://www.google.com/intl/en/policies/privacy/.

Website Analysis Microsoft Clarity

We have integrated Microsoft Clarity components on this website. The operating company is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. Microsoft Clarity is a web analytics tool that processes data, including data transfer to the USA, where an adequate level of data protection does not exist. Microsoft uses standard contractual clauses to ensure compliance with European data protection standards.

Each time a page on our website with Microsoft Clarity components is opened, data processing by Microsoft is initiated. Microsoft can receive, process, and use information about the use of our website for analysis of user behavior. This may include information such as clicking behavior, scrolling behavior, and other interactions between visitors on our website. More information about data processing by Microsoft Clarity can be found in Microsoft’s privacy policy available here.

Processing is performed only with your express consent according to Art. 6 (1) lit. a GDPR. More information about Microsoft’s standard contractual clauses can be found here. The use of Microsoft Clarity involves risks due to data transfer to countries without an adequate EU level of data protection, but Microsoft commits to following European data protection standards.

Microsoft stores the collected data for a period of 30 days. After this period, the data is automatically deleted.