Privacy policy & cookies
You should always feel safe when you provide your personal information to Leader Västra Småland. On this page, you can read more about how we handle the information we collect.
This privacy policy describes how the association Leader Västra Småland processes collected personal data. The purpose is to ensure that personal data is handled in accordance with the EU's General Data Protection Regulation (GDPR).
Visitors to the website leadervastrasmaland.se
We use cookies on our website. A cookie is a small data file that is saved on the visitor's computer, tablet, or mobile phone when connecting to a website. The content of the cookie is also sent back to the website. The law states that we can store cookies on your device if they are absolutely necessary for using this website. For all other purposes, your consent is required. You can disable cookies in your browser, but then it may not be certain that the website functions correctly.
We store the following cookies:
XX
- XX cookies are generated by XX to secure the operation and security of the website.
XX-based cookies
- XX cookies are used by XX on websites that need to use cookies to function and/or be functionally adapted for visitors. These cookies do not send any user information to external sources or third parties.
We also count the number of users and analyze traffic. We do this to develop and improve our website. We use Google Analytics (_gat, _gid, _ga, r/collect) which collects statistics on the number of visits over time on our website, how long the visit lasts, which pages you visit, and how you access our website.
Recipients of our newsletters
If you sign up for our newsletter, we store your email address in order to send emails to you. We store your email address in our newsletter system MailChimp. We do this as long as you are a subscriber to our newsletter. You can unsubscribe at any time, and then we will no longer store your email address. You unsubscribe by following the unsubscribe link in the newsletters that come to your email address. You can also unsubscribe by emailing us at info@leadervastrasmaland.se
Data controller
The board of the association Leader Västra Småland is the data controller. For the IT systems at the Swedish Board of Agriculture that Leader Västra Småland works in, the Swedish Board of Agriculture has taken on the role of data controller.
Application and revision
The board is responsible for ensuring that the processing of personal data follows this policy.
The data controller is responsible for managing the process of annual updates of the policy due to new and changed regulations. The policy is anchored in the board and is included in the workplace introduction for new employees. This policy applies to the board, employees, and contractors affected by our operations.
What information do we store and for what purpose?
The association Leader Västra Småland processes the personal data that is provided to us. This may include information such as name, email address, phone number, personal identification number, organization number, postal address, bank account number, bank giro number, plus giro number, name of organization, company or association, photos, and other information that is necessary for us, the association Leader Västra Småland, to fulfill our commitments. The association processes personal data to fulfill our mission in accordance with the agreement made with the Swedish Board of Agriculture and solely for the purpose of maintaining a register of personal data when there is a factual basis and it is necessary to:
- conduct daily operations through employed staff and compensated board members,
- convey information and invitations as well as provide support and guidance to project applicants and external stakeholders,
- administer and carry out the processing of projects and project applications,
- assess whether project support should be granted and disburse approved funds,
- compile statistics,
- inform about ongoing and completed projects on the association's website and social media channels,
- store documentation related to projects according to the regulations of the Swedish Board of Agriculture.
Press releases
In connection with new projects and sub-projects being approved, the association may send a press release to local newspapers and other media in the area with brief information about the project and contact details for the project manager, in order to inform the public about our activities.
The website
On the association Leader Västra Småland's website, we collect personal data for those who are employed by the association, members of the board and nomination committee, or contact persons. The personal data consists of images, names, and contact details. The contact details have been submitted to us in connection with employment/assignment/application to the association. We also publish information about projects that have been granted support from us, including the name and email address of the project manager. Contact us at info@leadervastrasmaland.se to change or remove personal data that is published on our website.
Images and film
When events are intended to be documented with photos and film, all participants should be informed that photography and filming may occur and the purpose of this. They should also be informed that the images will not be sold further and who to contact if they do not wish to be photographed.
The information can, for example, be provided in writing in the invitation, during registration, on a sign at the entrance, or verbally during the event.
We save and publish images and film related to projects and the activities that take place in our area of operations. If individuals are present in photo or film material, verbal or written consent is considered to allow these to be published, in order to promote locally led development, legal basis. In our mission as a leader area, there is an obligation to inform about the initiatives that EU support contributes to, and in our opinion, information about these initiatives is of general interest.
Social media
When publishing on social media, the association is responsible for ensuring that personal data is processed in a manner that is not offensive according to the data protection regulation. The responsibility applies to publications made on behalf of the association, but in many social media platforms (such as Facebook, YouTube, Instagram, LinkedIn, and blogs), the responsibility also extends to user publications, such as user comments.
The responsibility means that the association:
- must not publish offensive personal data,
- shall regularly monitor publications to detect offensive personal data,
- shall promptly remove offensive personal data.
Handling of e-mail
The association communicates via e-mail to guide, manage, and process projects. E-mails that contain personal data or sensitive information shall be deleted as soon as the matter has been handled appropriately.
IT – and information security
Information storage occurs in Office 365 and Microsoft Teams where access is protected by passwords, and is done with caution. Information storage also takes place in the online-based program Lime Go.
Originals and paper copies
The association strives to minimize the handling of paper for environmental reasons, but certain originals and paper copies containing personal data exist in the organization and must be handled carefully. This primarily concerns accounting, changes to decisions, applications, and agreements, as well as employment contracts for employees and notes from employee conversations. All these data need to be retained for accounting and documentation purposes. These documents are stored in binders and under supervision. Originals related to employment should be disposed of from unnecessary documentation at the end of an employment.
How long are the data retained?
The information is stored during the association's operational period, as well as the upcoming operational period in order to, for example, inform about previous projects. Data and documents covered by the requirements of the Swedish Board of Agriculture will be archived and stored for a maximum of ten years after the end of the operational period. Documents that have historical value may be archived in the association's archive to preserve our shared memory. The members' information is stored as long as the membership continues.
Legal basis, consent, and information of general interest
The association requests consent in connection with the collection of personal data. There is an opportunity to request the data that is registered with the association as well as to withdraw consent. The data specified in application documents cannot be deleted from registers or archives as the association is obligated to keep these for 10 years after the end of operations according to the regulations of the Swedish Board of Agriculture.
Procedure for requests for deletion, modification, and limitation
If a request for deletion is received, all information will be deleted except for data that must remain due to legal requirements, such as the regulations of the Swedish Board of Agriculture.
Handling of incidents
If the association is subjected to a data breach or in any other way loses control over the data being processed, a so-called personal data incident, the data controller will be notified without unnecessary delay. The data controller must then act promptly.
Reporting of incidents
If it is likely that a personal data incident will pose a risk to the registered individuals, the incident must be reported to the Swedish Authority for Privacy Protection. The report must be made within 72 hours from the time the discovery was made. However, no report needs to be made if it is unlikely that the incident will lead to any risks for individuals' freedoms and rights. The risks considered are whether the individual loses control over their data or that their rights are restricted, that they are subjected to discrimination, identity theft or fraud, financial loss, harmful rumor spreading, or violations of confidentiality or secrecy obligations. If it is not possible to provide all information within 72 hours, data can be supplemented within four weeks. If the report cannot be made at all within 72 hours, the Swedish Authority for Privacy Protection should still be informed and the reasons for the delay should be stated. Information content in the report The information in the report should be:
- What type of incident it concerns
- Which categories of individuals may be affected
- How many individuals it concerns
- What consequences the incident may have
- What measures have been taken to counteract any negative consequences.
Who should make the report?
The association's board is responsible for preparing the report.
Follow-up and improvement work
Handling of any personal data incidents, deficiencies in compliance with routines, or the need for additional routines is managed in the risk analysis and quality report that is prepared annually.
Contact
Do you have any questions? Do you want to delete or update information? Contact the association at info@leadervastrasmaland.se
Guiding principles for personal data processing
Legality – Personal data shall be processed lawfully, fairly, and transparently in relation to the data subject.
Purpose limitation – Personal data shall only be collected and otherwise processed for specific, explicitly stated, and legitimate purposes, and shall not be further processed in a manner that is incompatible with those purposes.
Data minimization – Personal data that is processed shall be adequate, relevant, and not excessive in relation to the purposes.
Accuracy – Personal data that is processed shall be accurate and, where necessary, kept up to date.
Storage limitation – Personal data shall not be kept for longer than necessary in relation to the purposes of the processing.
Integrity and confidentiality – Personal data shall always be processed in a manner that ensures appropriate security using technical or organizational measures. All information about individuals' personal circumstances shall always be treated confidentially.