Expertly automate your insider list management
Streamline your liability registration
Offer secure, anonymous online whistleblowing
Our services are mainly provided on a contractual basis to corporate subscribers, therefore as an individual user, you will be entitled to use the services on the basis we have agreed with the relevant corporate subscriber. We also collect personal data from non-users when you sign for a demo.
InsiderLog is a global company, offering a global service to its users and customers. This policy is drafted with reference to the EU General Data Protection Regulation (from 25th May 2018) (together the “Data Protection Legislation”). InsiderLog believes that compliance with the data protection principles outlined in the Data Protection Legislation creates a strong framework to ensure that individuals’ personal data is secured, protected and used appropriately.
This policy addresses how InsiderLog uses, transfers and stores the personal data we collect about individuals (“Users”) when they access our website or any instance of our online applications (the “Portal”), or use any of our services or products (collectively, the “InsiderLog Products”), or otherwise have their personal data submitted to us in accordance with this policy.
By using any of the InsiderLog Products and/or you or a corporate subscriber you work for agreeing to our terms and conditions, Users are accepting the practices and guidelines set out in this document (the “Policy”), so please take a few minutes to read it over carefully.
When we refer to InsiderLog, “we” or “us” in this Policy, we are referring to InsiderLog and its affiliates together with, as applicable, the InsiderLog Products.
Full name of legal entity: InsiderLog AB (a company registered in Sweden with company number 559141-7083 whose registered office address is Biblioteksgatan 29, 114 35, Stockholm, Sweden.
Name and title of our Data Protection Officer: email@example.com
Email address: firstname.lastname@example.org
Postal address: 14 place des reflets – CS 30064 – 92054 Paris la Défense Cedex
You have the right to make a complaint at any time to Datainspektionen], the supervisory authority for data protection issues in Sweden (email@example.com). We would, however, appreciate the chance to deal with your concerns before you approach Datainspektionen, so please contact us here: firstname.lastname@example.org – in the first instance.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). For the full definition of personal data, please see paragraph 10.
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
We may also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data may be derived from your personal data, but is not considered personal data in law, as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of Users accessing a specific Portal feature.
We may also anonymise data (Anonymised Data) that we collect, use and share for the purposes of providing support to you, a corporate subscriber and other Users of InsiderLog Products. Like Aggregated Data, this data does not directly or indirectly reveal your identity.
However, if we combine or connect Aggregated Data or Anonymised Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.
We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.
Where we need to collect personal data by law, or under the terms of a contract we have with the corporate subscriber authorising your access to our Portal and you fail to provide that data when requested, we may not be able to allow you access to InsiderLog Products. In this case, we will let you know if access to InsiderLog Products is denied.
3.1.1 Direct interactions. You, or a third party authorised by your employer will or will arrange to provide your Identity, Contact, Employment and Profile Data when registering an account with us or requesting access to InsiderLog Products. You may also provide us with this information when corresponding with us by telephone, phone, email, social media or otherwise.
3.1.2 Automated technologies or interactions. As you interact with any InsiderLog Products, we may automatically collect Technical Data and Usage Data. We collect this personal data by using cookies, server logs, web beacons/pixels and other similar technologies.
3.1.3 Third parties. We may receive personal data about you from various third parties, e.g. your employer or a corporate subscriber, as set out below:
18.104.22.168 Identity, Contact and Corporate Subscriber Data from the corporate subscriber authorising your access to any InsiderLog Products to whom we are providing services.
22.214.171.124 Identity, Contact and Corporate Subscriber Data from or on behalf of your employer who has authorised your access to any InsiderLog Products or provided us with your personal data as a result of your employer providing services to a corporate subscriber.
126.96.36.199 Identity, Contact, Corporate Subscriber, Technical, Profile and/or Usage Data from the provision of support service provided (as detailed in paragraph 10.6).
188.8.131.52 Identity, Contact and Corporate Subscriber Data from a third party who has been expressly permissioned by you, your employer or a corporate subscriber
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
4.1.1 Where we need to allow you to access any InsiderLog Product and to provide support services.
4.1.2 Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests. For example, our legitimate interests may include the administration and management of our business and the provision of our services to the corporate subscriber authorising your access to any InsiderLog Product.
4.1.3 Where we need to comply with a legal or regulatory obligation.
Please see paragraph 10.2 to find out more about the types of lawful basis that we will rely on to process your personal data.
Generally, where applicable, we obtain, collect and process your personal data on the basis of consent for some specific marketing purposes (i.e. proposal of products & services, invitation to events…).
We use your personal data in the following ways:
4.2.1 personal data that you provide to us is used to:
184.108.40.206 provide you with access to the information and services that the corporate subscriber authorising your access to our Portal requests from us
220.127.116.11 provide services to your employer or the corporate subscriber authorising your access to our Portal
18.104.22.168 provide support services to you
22.214.171.124 manage and administer our business
126.96.36.199 review and improve our services
188.8.131.52 To provide you with promotional communications, such as email, to the extent that you have provided consent to receive such communications under applicable law, to notify you about changes to the InsiderLog Products.
184.108.40.206 To provide you with an SMS service that provides you a security token that allows you to access the Portal.
4.2.2 personal data that we receive from third parties may be combined with the personal data that you provide to us and used for the purposes described above.
4.2.3 personal data about your use of any InsiderLog Product is used to:
220.127.116.11 administer the InsiderLog Product and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes
18.104.22.168 provision of support services to you
22.214.171.124 improve the Portal to ensure that content is presented in the most effective manner for you and for your computer or mobile device
126.96.36.199 improve other websites we operate
188.8.131.52 refine the provision of the services offered on the Portal and to assist in the development of new services
184.108.40.206 allow you to participate in interactive features of the Portal, when you choose to do so
220.127.116.11 as part of our efforts to keep the Portal safe and secure
18.104.22.168 provide services to your employer or a corporate subscriber
22.214.171.124 provide services to a third-party that has been expressly authorised to access InsiderLog Products by you, your employer or a corporate subscriber
List of third party Cookies
4.4 Change of purpose
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us at email@example.com.
If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
5.1 We may disclose your personal data to other companies of the Euronext NV’s Group from which InsiderLog AB is a subsidiary.
5.2 We may also disclose your personal data to third parties in relation with the purposes for which personal data are processed including:
5.3 We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
We store and process your personal data on servers located within the European Economic Area (the “EEA”). We only transfer your personal data outside the EEA where the European Commission has decided that the third country in question ensures an adequate level of protection in line with EEA data protection standards or where there are appropriate safeguards in place to protect your personal data.
We have put in place appropriate security measures (commensurate with the sensitivity of the personal data we process) to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
InsiderLog employs encryption technology to protect certain transmissions of data to/from the Services, but e-mail and other communications are not encrypted. You should not send any personal or identifying information, such as bank or credit card details via email. By employing e-mail or other insecure electronic communication means you acknowledge that you have no expectation of privacy with respect to the information delivered thereby and that InsiderLog will not be responsible for any loss or damage that could result from interception by third parties of any information so sent.
How long will you use my personal data for?
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, reporting, regulatory or contractual requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
In some circumstances you can ask us to delete your data: please see paragraph 9 below for further information.
Please be aware that we keep personal data for Users of InsiderLog Products (including Identity Data, and Usage Data) for audit purposes whilst the relevant corporate subscriber is contracted to us and as required by any regulatory requirements applicable to the relevant corporate subscriber.
We may be subject to contractual requirements that specify how long we can keep your personal data for (for example, in our contract for the supply of services to the corporate subscriber authorising your access to any InsiderLog Products).
The table below sets out the rights which you have to address any concerns or queries with us about our processing of your personal data. Please note that these rights are not absolute and are subject to certain exemptions under applicable data protection law.
You can exercise any of these rights by:
By sending an email to the following address:
You have the right to make a complaint at any time to Datainspektionen the Swedish supervisory authority for data protection issues (firstname.lastname@example.org). We would, however, appreciate the chance to deal with your concerns before you approach Datainspektionen, so please contact us here: email@example.com – in the first instance.
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive.
We may need to request specific information from you to help us to confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or if you have made a number of requests. In this case, we will notify you and keep you updated.
Means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
A cookie is an online identifier.
Data Protection Authority (DPA)
An official or body that ensures compliance with Data protection laws and investigates alleged Breaches of the laws’ provisions.
An identified or identifiable natural person.
Legitimate Interest means conducting and managing our business in our interests, or the interests of a third party. Our interests could include, for example, our internal administrative purposes or ensuring network and information security. Whether a particular legitimate interest may exist can also depend on the relationship we have with you.
We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests or the interests of a third party. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us.
Performance of Contract means processing your data where it is necessary for the performance of a contract. Such contract may exist with you, your employer or corporate subscriber with whom you or your employer have a business relationship. Alternatively, it may be necessary to take steps at your request before entering into such a contract.
Comply with a legal or regulatory obligation means processing your personal data where it is necessary for compliance with a legal or regulatory obligation that we or a corporate subscriber may be subject to.
Consent means your clear, unambiguous consent for a specific purpose, for example, for marketing and promotional materials.
Means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller.