Data Protection Policy

For clients, users and others whose address is connected to key systems in private households or who have contacted BEKEY directly via the website or otherwise.

1. PERSONAL DATA PROTECTION

BEKEY A/S (hereinafter named BEKEY) has a responsible approach to your personal data. We ensure that data processing is fair and transparent in accordance with the applicable regulations regarding personal data processing.

We process personal data and have adopted this data protection policy to inform you how we process data concerning you, when e.g. you use www.bekey.dk and our SaaS (Software as a Service) solution – whether you access these via mobile applications or a desktop browser.

Our data protection policy covers three groups:

– Customers (usually private individuals) who use NETKEY Lite

– Users who have received a key via NETKEY Lite as part of a BEKEY solution

– Potential customers and clients who have contacted us via our website or otherwise.

BEKEY is the Data Controller for all three groups. We ensure that your personal data are processed in accordance with data legislation.

We offer key systems to private customers and business clients. This data protection policy explains how we process personal data concerning private customers whose address is connected to the key system, users who, by dint of connection to our customer’s key system, have a digital key, and all potential and former customers whose data is recorded in our customer registry.

BEKEY is also the Data Controller for commercial clients. See section 6.2.

2. DATA RESPONSIBILITY AND CONTACT DETAILS

BEKEY is the Data Controller responsible for processing the personal data we receive concerning you. Our contact details are as follows: 

BEKEY A/S

VAT No. DK27507980

Gladsaxe Møllevej 28

DK-2860 Søborg

E-mail: drift@bekey.dk

Website: www.bekey.dk

Phone: +45 43 43 99 90

If you have questions about how we process your personal data, please do not hesitate to contact us.

3. OBJECTIVES AND LEGAL BASIS FOR DATA PROCESSING

3.1 Objectives

We process your personal data for the following purposes:

– To facilitate effective and successful use of our system as part of an active customer relationship

– To facilitate effective and successful use of our system for the user

– To facilitate communication in response to your enquiry

– To offer relevant services associated with the above

– To provide advice and guidance regarding the BEKEY solution

3.2 Legal basis

We process your personal data for the following purposes:

– To facilitate effective and successful use of our system as part of an active customer relationship

– To facilitate effective and successful use of our system for the user

– To facilitate communication in response to your enquiry

– To offer relevant services associated with the above

– To provide advice and guidance regarding the BEKEY solution

4. WE PROCESS THE FOLLOWING INFORMATION CONCERNING YOU

We process data concerning you in order to optimise our services and ensure that we provide good quality products and services, and communicate effectively with you.

The personal data we process concerning our private customers who are connected to the key system:

– Ordinary customer contact details

– Information about purchase(s)

– Customer enquiries

– Address

– Names of door units

The personal data we process concerning users who, because they are connected to our customer’s key system, have a digital key:

– User name

– Person’s name

– Phone no.

– IP address

– Address and times, at which the digital key is used

– User-related correspondence

We must record the above data in order to fulfil our contractual obligations with regard to the customer regarding the supply of a key system at the address including an option to connect multiple users. We receive user data from the customer.

The personal data we process concerning potential customers who, via our website or otherwise, have contacted BEKEY:

– Person’s name

– Phone no.

– E-mail address

– Correspondence in connection to the enquiry

We collect, process and store only the data we need

We collect, process and store only the personal data we need i.e. relevant and adequate data in order to resolve our objectives. Furthermore, we may be obliged to meet legal requirements regarding data collection and storage in connection with our business operations. The type and scope of the personal data we process may also be necessary in order to meet contractual or other legal obligations.

Access to check and update your personal data

To ensure that data recorded is neither incorrect nor misleading, it is important that you can ensure that the data you have entered are correct. As a private customer and user, you have access to edit/rectify the personal data you entered – with exception of your phone number. If you wish to edit incorrect telephone data, you must contact BEKEY.

As our services rely on the user having provided correct and updated personal data, we request that you regularly check and, if necessary, update personal data entries.

We collect anonymised data based on recorded personal data

BEKEY consistently collects data in an anonymised or pseudonymised (i.e. rendered non-identifiable) format – i.e. data based on the personal data recorded and data collected by the system. For example, we might record that a customer has seen an advertisement within a given period. It is not possible to identify the customer in question as the data is anonymous. This means that there is no sensitive personal data associated with this record.

We ask for your consent before we process your personal data

We ask for your consent before we process your personal data for the purposes listed above, unless we have a legal basis for collecting them. We will inform you if we have a legal basis and why we have a legitimate interest in processing your personal data.

You give us your consent voluntarily and can withdraw your consent at any time. You can withdraw your consent online via the contact form at www.bekey.dk.

If we wish to use your personal data for purposes other than those foreseen, we will inform you of the new purpose and request your consent before we begin to process the data. If we have a new legal basis for the new process, we will inform you of it.

The BEKEY solution does not allow BEKEY to identify the age of a user. As our products and services require users to have a telephone and user profile and to have received a key from an administrator who has a BEKEY door unit fitted, it is reasonable to assume that a child’s guardian has consented to the use of our solution. We do not therefore believe that we are obliged to obtain parental consent. 

We will not disclose your personal data without your consent

If we wish to disclose your personal data to partners and other players, e.g. for marketing purposes, we will request your consent and inform you how your data will be used. You may at any time object to this type of disclosure. You can withdraw your consent online.

We will obtain your consent before we disclose your personal data to a partner in a third country. If we disclose your personal data to a partner in a third country, we will ensure that the level of personal data protection offered by that partner meets the applicable legal requirements stipulated by this policy. Our requirements include data processing, data security and securing your rights, e.g. to object to profiling and to complain to Datatilsynet (The Danish Data Protection Authority).

We do not request your consent if we are legally obliged to disclose personal data, e.g. as part of a mandatory report to a public authority.

Consent – and associated functions

In effect, you give consent to a series of measures that are adapted to individual services provided by BEKEY.

When you consent to our terms and conditions, you essentially accept the terms of BEKEY’s data protection policy and concomitantly agree to allow BEKEY to send so-called “transactional e-mails” to your email address. These are:

– Mails confirming the agreement

– Mains confirming payments in accordance with the agreement

– Mails regarding a change of password

– Other mails that are necessary for the contract to continue.

You cannot unsubscribe to these mails – unless the agreement is terminated.

When you use BEKEY’s services, you can choose which functions to use, e.g. “Freshdesk” and “contact form”. These choices will also result in mails to the e-mail address you gave us. If you do not wish to receive mails associated with these functions, you should desist from using the functions in question. Service functions presuppose that it is possible to communicate by e-mail.

BEKEY also allows you to opt to receive e-mail newsletters, in which BEKEY provides information about new products, events, tips, etc. that may be useful to you as our customer and user. As newsletters are not specifically linked to the service for which you have opted to enter an agreement with BEKEY, we must allow customers an option to unsubscribe. They are deactivated by default.

Cookies, objectives and relevance

If we set cookies, you will be informed of their use and the purpose of collecting data via cookies.

We request your consent to use cookies

Before we set cookies on your device, we will request your consent to do so. However, we are permitted to set cookies without consent if they are necessary for functionality and settings purposes.

For further information on how we use cookies or to learn how to delete or block them, visit our website.

5. DATA SECURITY

We protect your personal data and have our own data security policy

Our data security policy contains instructions and measures to protect your personal data from destruction, loss or alteration, unauthorised disclosure, and unauthorised access or knowledge of them.

We have established procedures for assigning access rights to those of our employees who process sensitive personal data and data that discloses information about personal interests and habits. To prevent loss of data, we take consistent back-ups of our data sets. We also safeguard the privacy and authenticity of your data by means of data encryption.  

In the event of a personal data breach that results in a serious risk of discrimination against you, theft of your identity, financial loss, damage to your reputation or causes any other significant inconvenience to you, we will inform you of the data breach without undue delay, as indeed we are obliged to do in accordance with Article 34 of the GDPR.

In order to protect unauthorised access to your personal data, we deploy technical measures that automatically ensure that the data are accessible only to relevant employees.  

6. PARTNERS

Disclosure

We will disclose your data to partners only if we have your consent to do so or if the partners are necessary in order to meet our contractual obligations with you.

Please find a list of necessary partners here:

– We do not currently disclose data to any partners at all.

6.1 Data Processors

In order to provide the best possible service, BEKEY uses the following Data Processors:

Suppliers of hosting/back-up services:

– Amazon Web Services EMEA SARL

– Hetzner Online GmbH

– OVH Hosting Ltd.

IT development and support:

– FK Distribution A/S

– Technology Staffing Corporation (Go Interactive)

– Cekura A/S

– Freshdesk (Freshworks) Inc.

– Google Ireland Ltd.

Administration:

– Twilio Inc.

6.2 Data Processing Agreement with BEKEY

Any company including a public enterprise that uses the BEKEY solution must enter a specific Data Processing Agreement (DPA) with BEKEY. The DPA is required under the terms of the GDPR and seeks to ensure that the customer meets requirements with regard to the processing of personal data made necessary by dint of the contract.

7. DATA TRANSFERS TO A THIRD COUNTRY

We will transfer your personal data to recipients outside the EU/EEA.

We will transfer to the USA and Ukraine. Neither country is considered to provide an adequate level of personal data protection.

Data transfer to the USA will be achieved via a Data Processor, Freshworks Inc. The basis for this transfer is the EU-US Privacy Shield. Contact us if you wish to have a Privacy Shield list. See also section 2 above.

Data transfer to Ukraine takes place via a Data Processor, Technology Staffing Corporation (Go Interactive). Here the basis for data transfer is a Standard Contract Clause. To receive a copy, contact us. See also section 2 above.

8. ERASURE

We store your data for as long as we need to in order to meet our obligations vis-à-vis the customer and for a period of up to five years after expiry of the contract and/or to ensure compliance with the applicable legal obligations, including in particular the provisions of the Danish Bookkeeping Act regarding the storage of accounting records for a period of five years after the end of the financial year.

We delete personal data when we no longer need the data for the objectives for which your data were originally collected, processed or stored. The following general regulations apply to erasure:

  • The one-year rule: If a user ceases to use the NETKEY Lite solution and no longer manages a door unit, we will erase his/her personal data within 12 months.
  • If you are an administrator who manages a door unit, BEKEY will not erase your profile, as this would constitute a data breach because it would then be possible to link the door unit to another user without your consent. To avoid this situation, you can dismount the unit. This means that you will no longer be registered as the administrator and we will be able to erase your data in accordance with item 1 above.
  • Your right to be forgotten: This function allows you to initiate an erasure process in which BEKEY erases any personal data that are not covered by the aforementioned rules. If you have reached no agreements with BEKEY (i.e. you have never used the BEKEY solution), the erasure process allows us to delete all the data we have recorded concerning you.
  • The erasure process itself can take up to 30 days.
  • BEKEY does not erase personal data that is in an anonymised or pseudonymised (non-identifiable) format.

9. YOUR RIGHTS

9.1 Contact details in the event that you wish to exercise your rights

If you wish to exercise any of the following rights, you must contact us. See contact details listed at the top of the data protection policy.

We will process and respond to your request as soon as possible and within one month of receipt unless the scope and complexity of your request make it impossible for us to respond with a month. In this case, we are obliged to respond within three months in all (see Article 12 of the GDPR).

9.2 You have a right to know which personal data we process concerning you

You are entitled at any time to be informed which data we process concerning you, the origin of the data and to what purpose we use them. You have a right to know for how long we store your personal data, who receives data concerning you and to what extent we disclose the data to third parties in Denmark and abroad. This is described in our data protection policy.

9.3 You have a right to have inaccurate personal data rectified or erased.

If you believe that the personal data we process concerning you are inaccurate, you have a right to have them rectified. See Articles 16 and 17 of the GDPR.

If you believe that your data are no longer required for the purpose for which we recorded them, you may ask to have them erased. You can do this online. You may also contact us if you believe that your personal data are not processed in compliance with the legislation and other legal obligations.

However, BEKEY will not erase or rectify data if BEKEY is legally obliged to store all or some of your personal data or if the data are necessary in order to establish or defend legal claims. In this case, BEKEY will store only the data that BEKEY is legally obliged or entitled to store – and erase any other personal data concerning you.

9.4 You have a right to object to how we process your personal data.

Under the following circumstances, you have a right to restrict to how BEKEY processes your personal data (see Article 18 of the GDPR):

  • While BEKEY investigates in response to your having contested the accuracy of the personal data. Restrictions will not be lifted until BEKEY has completed processing your objection.
  • If BEKEY‘s processing is unlawful and you oppose erasure of your personal data and request restrictions to their use instead.

You may activate this measure at your discretion. You can request either deactivation or erasure. 

9.5 Right to data portability

As our processing of your personal data is based on your consent or a contractual agreement and our data processes are automatic, you have a right to data portability.

The right to data portability means that you are entitled to have the personal data you submitted to us sent to you in a structured, commonly used and machine-readable format and have the right to transmit those data to another Data Controller. See Article 20 of the GDPR.

If you wish to exercise the right to data portability, visit www.BEKEY.dk. You can ask us to send you your personal data records in a commonly used format.

9.6 Right to object

You have a right to object to how BEKEY processes your personal data if processing is made in accordance with Articles 6(1)(e) and (f) of the GDPR.

Upon receipt of an objection, BEKEY may no longer process personal data unless BEKEY can prove that our processes are necessary on compelling legitimate grounds, which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims. See Article 21 of the GDPR.

You also have a right to object to how BEKEY processes your personal data if we process them for direct marketing purposes, including profiling. See Article 21 of the GDPR. Upon receipt of an objection, BEKEY is no longer entitled to process your personal data for these purposes.

9.7 Right to withdraw consent

As our data processing depends on your consent, you have a right at any time wholly or in part to withdraw your consent to process your personal data. See Article 7 of the GDPR.

If you withdraw consent, BEKEY will cease to process any personal data, for the processing of which you have withdrawn consent, unless BEKEY is legally obliged or entitled to store all or part of that personal data. In this case, BEKEY will store only the data that BEKEY is legally obliged to retain and erase all other personal data concerning you. Withdrawal of your consent has no legal bearing on data processing undertaken by BEKEY until we received notice of withdrawal.

10. RIGHT TO COMPLAIN

If you wish to complain about how BEKEY processes your personal data, you have a right to lodge a complaint at Datatilsynet (The Danish Data Protection Authority). Contact details as follows:

Datatilsynet (The Danish Data Protection Authority)

Address: Borgergade 28, 5, DK-1300 Copenhagen K

Email: dt@datatilsynet.dk

Phone: + 45 33 19 32

Website: www.datatilsynet.dk

This privacy policy was updated in August 2019 and will be updated regularly.