Privacy policy
How we collect, use and protect personal data.
What we collect
This policy applies to customers, potential customers and visitors to our website. It is written to meet articles 12 and 13 of the EU General Data Protection Regulation (2016/679). If anything here is unclear, write to us and we will explain it in plain language.
Data controller
Who we collect information from
We collect information about our customers, our potential customers and visitors to our website.
What we collect and how we use it
Some of it you give us directly, for example when you fill in a form, use the website or open an email from us. Some of it comes from conversations, including notes and call recordings. We also collect information that is publicly available elsewhere online, such as your company website or a social network profile.
Why we are allowed to process it
Legitimate interest
We process personal data where we have a legitimate interest in doing so and have assessed that it does not override your interests and rights. On that basis we may contact you with marketing offers. We also use it to run customer support and manage the client relationships we already have. You can tell us to stop at any time.
Consent
In some cases we ask for your consent first, and we tell you at that point what the consent covers. This is usually when you complete a form on our website or a landing page. You can withdraw consent whenever you like. Withdrawing it does not undo processing that has already happened, and we will stop processing your data unless we have another lawful basis for keeping it.
How long we keep it
Where there is an agreement, we retain data for as long as that agreement sets out. Where you have given us your details without consent, for example through a form, we keep them while you are still active, meaning you open our emails or visit our website. After a year of no activity we remove your personal data from our records. You can unsubscribe or ask us to delete your data before that.
How we protect it
We use technical safeguards and internal procedures to protect personal data against loss, theft, unauthorised access and disclosure. We do not process more than we need, we anonymise where we can, we review who has access on a regular basis, and we train our staff on data security.
Who has access
Inside Brightvision, access is limited to people who need it, which means sales, marketing and IT administration. Outside Brightvision, we use suppliers to deliver our services. We do not sell your data and we do not share it with third parties beyond that.
Suppliers we work with regularly
We prioritise suppliers inside the EU and EEA. Where a supplier sits outside it, Standard Contractual Clauses apply.
Your rights
Data protection law gives you control over your own data, and you can ask us at any time how we are processing it. To exercise any of the rights below, email hello@brightvision.com.
Request a registry extract
You are entitled to know what personal data we hold about you. Ask us and we will send you an extract.
Correct or complete your information
If what we hold is wrong or incomplete, you can ask us to amend it or fill in what is missing.
Have your information removed
You can ask us to delete some or all of your personal data. This is sometimes called the right to be forgotten. In a few cases we cannot delete everything, because a contract or the law requires us to keep it.
Restrict how we process it
In some situations you can ask us to pause processing for a period, for example while we check information you believe is inaccurate, or while we assess an objection you have raised against processing based on legitimate interest.
Object to our processing
Where we rely on legitimate interest, you can object. We then have to show compelling legitimate grounds that override your interests and rights, or stop.
Move your data elsewhere
Where we process your data under a contract or your consent, you can ask for a copy of what you gave us and, where it is technically possible, have it transferred to another supplier. This is called data portability.
Complain to the supervisory authority
If you are unhappy with how we handle your personal data, you can raise it with the supervisory authority. In Sweden that is the Swedish Authority for Privacy Protection (IMY).
If you do not want marketing from us
You can ask us to stop sending marketing offers. Just tell us your preference, and the quickest way is an email to hello@brightvision.com.
Cookies
Under the law on electronic communication, anyone visiting a website that uses cookies must be told that the site uses them, how they are used, how they can be avoided, and must be able to agree to their use.
A cookie is a small piece of information a website stores in your browser and reads again later. We use cookies to recognise you when you return, remember preferences such as language or region, and see which pages are of particular interest. They also let us count visitors and understand how people move around the site, which is how we work out what to improve. Third parties may set cookies on our site as well, usually analytics or targeting cookies, and those are outside our control.
If you want to avoid cookies
You do not have to accept them. Your browser settings let you refuse all or some cookies, and you can delete cookies already stored at any time. Your browser's support pages explain how.
Changes to this policy
Any changes are published on this page. If we want to make a material change to how we use your personal data, we will ask for your consent before we do.
Ask us anything
about your data
If you want to know what we hold, have it corrected, or have it deleted, just ask.