PRIVACY POLICY - ODEX

1. INTRODUCTION

At Odex ApS, Vassingerødvej 147, 3540 Lynge and CVR no. 42181692 ("Odex"), we understand the importance of processing personal data securely and confidentially. This privacy policy is addressed to our customers, suppliers, business associates, website visitors and other persons with whom we interact. Odex is obliged to observe the requirements and obligations in connection with the processing of personal data according to applicable law, including the General Data Protection Regulation ("GDPR"). We have therefore implemented appropriate procedures to ensure the protection of your personal data.

Odex is the data controller for the processing of your personal data. This privacy policy ("Privacy Policy") contains an overview of Odex's processing activities, including the purposes of the processing and the legal basis for the processing.

If you have questions about this Privacy Policy or if you wish to exercise your rights according to Chapter III of the GDPR and in accordance with section 5 of this Privacy Policy, you can contact Odex at tan@odex.dk.

2. PROCESSING ACTIVITIES

2.1 Website visitors

2.1.1 What personal data do we process and for what purposes

When you visit Odex's website, www.odex.dk ("Website"), Odex processes personal data about you, such as cookies, browser information, IP address and time spent on the website. The purpose of using cookies is i.a. to improve the user experience on our Website, functionality on the website, preparation of statistics, targeting of advertisements to your needs and being able to remember your preferences. You can read more about how we use cookies in our Cookie Policy.

2.1.2 Legal basis

The basis for the processing of your personal data is Odex's legitimate interests and it is Odex's assessment that your interests or fundamental rights and freedoms do not precede this, cf. GDPR article 6, subsection 1, letter f. The legitimate interests pursued by Odex are to be able to provide a website that works optimally, a good user experience on the website and marketing activities. In certain cases, the legal basis is your consent, which we will ask you to give when you visit the Website, cf. GDPR article 6, subsection 1, letter a.

2.1.3 Disclosure of personal data

In certain cases, Odex will pass on your personal data to intra-group companies, business connections or other business partners for business purposes. Such third parties include e.g. social media providers, as described in more detail in section 4 below.

In addition, certain third parties, such as the provider of the technical solution behind our website, process your personal data on behalf of Odex and in accordance with Odex's instructions and the obligations set out in a the data processing agreement entered into with Odex. These data processors may not process your personal data for their own purposes.

2.1.4 Storage of personal data

Personal information collected via cookies through visits to our Website is stored for different periods of time depending on the type of cookie and the purpose of the cookie. Read more in our Cookie Policy.

Personal information collected in connection with the use of social media will be deleted as soon as the content in question is deleted or when you remove your reaction to our content (like, share, etc.). Read more in section 4 below.

2.2 Recipients of newsletters

2.2.1 What personal data do we process and for what purposes

If you wish to receive a newsletter, we process information about your e-mail address. The purpose of the processing is to be able to adapt the content of and send our newsletters.

2.2.2 Legal basis

The legal basis for our processing of your personal data is our legitimate interests in marketing our products and services, cf. GDPR article 6, subsection 1, letter f. You can withdraw your consent to receive our newsletter at any time. To unsubscribe from our newsletters, you can use the link included in each newsletter or you can contact Thor Andersen at tan@odex.dk.

2.2.3 Disclosure of personal data

Certain third parties, such as the supplier of the technical solution that assists with the delivery and management of newsletters, process your personal data on behalf of Odex and in accordance with Odex's instructions and the obligations set out in a data processing agreement entered into with Odex. These data processors may not process your personal data for their own purposes.

2.2.4 Storage of personal data

Personal information associated with your newsletter profile is stored until you withdraw your consent and no longer wish to receive newsletters from us.

2.3 Customers

2.3.1 What personal data do we process and for what purposes

When you place an order with Odex, Odex processes your personal data, such as name and surname, telephone number, postal code, bank and payment information, information about your purchase, delivery and, if relevant, information about the return of the purchased goods. The purpose of the processing is to process your order and any returns.

Bank and payment information

All payment transactions made on the website are processed by a third party payment provider, Nets. Odex does not store your payment information, but has access to parts of the information, such as payment card type, partially anonymized card number and expiry date, in order to prevent fraud.

The legal basis for the processing is GDPR article 6, paragraph 1, letter b. It is either because processing is necessary for the fulfillment of a contract to which you are a party, or for the implementation of measures taken at your request prior to entering into a contract.

In certain cases, the processing of your personal data is necessary to comply with a legal obligation imposed on Odex, e.g. in connection with the storage of accounting material in accordance with the Accounting Act. In such cases, the legal basis is GDPR article 6, paragraph 1, letter c.

2.3.3 Disclosure of personal data

In certain cases, Odex will pass on your personal data to intra-group companies, business connections or other business partners for business purposes. Such third parties include e.g. social media providers, as described in more detail in section 4 below.

In certain specific cases, e.g. in connection with disputes, including if disclosure is necessary for Odex's legal claims to be established, asserted or defended, Odex may disclose your personal information to advisers or other relevant third parties, if it is deemed legal and necessary.

2.3.4 Storage of personal data

Personal information about our customers is stored for as long as deemed necessary, including while we are processing your order. The personal data will be stored for 3 years after your order has been completed for documentation purposes. As far as your personal data is included in Odex's accounting material, e.g. in connection with invoicing, your personal data is stored for 5 years from the end of the accounting year to which the accounting material relates. The purpose of this is compliance with our legal obligations according to the Bookkeeping Act.

2.4 Contact persons at customers, suppliers and other business relationships

2.4.1 What personal data do we process and for what purposes

As a contact person with our customers, suppliers or other business partners, Odex processes personal information about you when you communicate with Odex, e.g. via e-mails in connection with Odex's contractual relationship with the company at which you are employed or in connection with the conclusion or termination of a contract. Odex processes general personal data about you, including your first and last name, e-mail address, telephone number, position, etc.

2.4.2 Legal basis

The legal basis for the processing of your personal data is Odex's legitimate interests, and it is Odex's assessment that your interests or fundamental rights and freedoms do not precede this, cf. GDPR article 6, subsection 1, letter f. The legitimate interests pursued by Odex are the fulfillment of our contractual obligations, maintaining and strengthening our customer relationships, invoicing the services that the company you are employed by provides to Odex and vice versa and of with regard to documentation, if an agreement is concluded via e-mail.

In certain cases, the processing of your personal data is necessary to comply with a legal obligation imposed on Odex, e.g. in connection with the storage of accounting material in accordance with the Accounting Act. In such cases, the legal basis is GDPR article 6, paragraph 1, letter c.

2.4.3 Disclosure of personal data

In certain cases, Odex will pass on your personal data to intra-group companies, business connections or other business partners for business purposes. Such third parties include e.g. social media providers, as described in more detail in section 4 below.

In certain specific cases, e.g. in connection with disputes, including if disclosure is necessary for Odex's legal claims to be established, asserted or defended, Odex may disclose your personal information to advisers or other relevant third parties, if it is deemed legal and necessary.

2.4.4 Storage of personal data

If you are a contact person with one of Odex's customers, suppliers or other business partner, Odex will process personal data about you as long as Odex communicates with you because you are Odex's contact person and for 3 years after termination of the contractual relationship. If it is necessary for legal claims to be established, asserted or defended, your personal data may be stored for a longer period of time.

If your personal data is included in Odex's accounting material, e.g. in connection with invoicing, your personal data is stored for 5 years from the end of the financial year to which the accounting material relates. The purpose of this is compliance with our legal obligations according to the Bookkeeping Act.

2.5 Customer service and inquiries

2.5.1 What personal data do we process and for what purposes

When you contact our customer service at info@odex.dk or employees, we process the personal information you give us in order to handle your inquiry. This will typically be your name, telephone number, e-mail address and the content of your inquiry.

Odex will not process special categories of personal data (sensitive personal data) about you, e.g. health information, unless you have provided such information yourself. Odex must ask you not to send sensitive personal data to us.

2.5.2 Legal basis

The legal basis for the processing of your personal data is Odex's legitimate interests in providing customer service and developing our business, and it is Odex's assessment that your interests or fundamental rights and freedoms do not precede this, cf. GDPR article 6, PCS. 1, letter f.

2.5.3 Disclosure of personal data

In certain specific cases, e.g. in connection with disputes, including if disclosure is necessary so that Odex's legal claims can be established, asserted or defended, Odex may disclose your personal information to advisers or other relevant third parties, if it is deemed legal and necessary.

2.5.4 Storage of personal data

Inquiries from potential customers are deleted 12 months after the inquiry has been resolved, unless it is necessary to store the personal data for documentation reasons, e.g. due to a dispute, including so that legal claims can be established, asserted or defended.

Inquiries from existing customers are deleted 3 years after termination of the contractual relationship, unless it is necessary to store the personal data for documentation reasons, e.g. due to a dispute, including so that legal claims can be established, asserted or defended.

3. TRANSFER OF PERSONAL INFORMATION TO THIRD COUNTRIES (COUNTRIES OUTSIDE EU/EEA)

    In certain cases, your personal data may be transferred to countries outside the EU/EEA. Odex ensures that the transfer takes place in accordance with applicable data protection legislation. This means that a recipient of your personal data who is not resident in the EU/EEA will ensure a sufficient level of protection, e.g. by entering into an agreement with Odex on the use of the EU Commission's standard contract provisions. Odex ensures the implementation of additional protective measures if deemed necessary in the individual case.

    You can request to receive a copy of the legal basis for the transfer by contacting Thor Andersen at tan@odex.dk.

    4. SOCIAL MEDIA

      Our website has integrated plug-ins from the social media Facebook, Instagram and YouTube. When you visit our pages on social media or when you visit our website where plug-ins are integrated, the providers of the social media collect and process personal data using cookies, provided you have given consent to this. The collection and processing of your personal data takes place regardless of whether you have a profile on social media.

      If you access our Website, which has integrated plug-ins from social media, your browser contacts the server of the social media, loads the visual presentation of the plug-in and presents the content to you. While this is happening, the provider of the social media receives information about your use of the Website, as well as additional personal data, such as your IP address. Odex receives anonymous demographic and geographic statistics from the provider of the social regarding visitors to our Website and our social media pages.

      Odex is the joint data controller with the providers of the social media for the processing of personal data in connection with visits to our pages on the social media and our Website. This means, among other things, that you can contact both Odex and the provider of the social media if you wish to exercise your rights according to the GDPR. Facebook, Instagram and YouTube have the primary responsibility for ensuring compliance with the GDPR and for responding to requests for the exercise of data subjects' rights. If you have a profile on the social media, you can exercise your rights via the account settings.

      We have no influence on the amount of personal data that the social media provider collects via the active plug-ins. You can read more about this in the relevant privacy policy:

      5. YOUR RIGHTS

        We have implemented a number of measures to protect your personal data and secure your rights. Because your personal data is processed, you can make use of the rights described below. Some of however, the rights only apply under certain circumstances. The Danish Data Protection Authority has prepared a guide regarding the rights of data subjects, which is available here.

        • You have the right to request insight into, including provision of a copy of, the personal data that we process about you and, in this connection, also the right to receive a range of additional information.
        • You have the right to request that incorrect personal data about yourself be corrected as well as the right to request that incomplete personal data be completed.
        • You have to request to have personal data about you deleted under certain circumstances, for example if the processing is based on your express consent and you withdraw the consent.
        • You have the right to request restriction of the processing of your personal data, for example in connection with the accuracy of the personal data being contested.
        • When our processing is carried out automatically and is based on your consent or fulfillment of an agreement with you, you have the right to request to receive the personal data that you yourself have submitted to us in a structured, commonly used and machine-readable format, as well as the right to request that this personal data be transmitted to another data controller, if this is technically possible.
        • You have the right to object to the processing of your personal data by us, including in particular in relation to direct marketing.
        • You have the right to request not to be subject to a decision based solely on automatic processing, including profiling, which has legal effect or similarly significantly affects you.
        • If you have consented to the processing of your personal data, you have the right to withdraw your consent at any time. If you revoke your consent, this will not affect the processing of your personal data that took place prior to the revocation.

        If you wish to exercise any of the above rights, or if you wish to withdraw a previously given consent, you are welcome to contact Thor Andersen at tan@odex.dk.

        6. QUESTIONS AND COMPLAINTS

          If you have questions regarding this Privacy Policy, wish to exercise one of the above rights, or disagree with the way in which we process your personal data, you can contact Thor Andersen at tan@odex.dk.

          If you disagree with the way in which Odex processes your personal data, you have the right to lodge a complaint about this with the Danish Data Protection Authority. The Danish Data Protection Authority's contact information can be found here. However, we hope that you will initially contact us using the above contact information, so that we can try to reach an agreement.

          7. CHANGES TO THE PRIVACY POLICY

            This privacy policy will be updated and amended periodically, as well as when necessary as a result of changes in data protection law and practice. We therefore recommend that you keep yourself informed.

            Date of last change: December 2023