Information about Froda’s processing of customer personal data
1. Introduction
Froda offers businesses to apply for loans and financing through Froda’s digital platform, making the loan process fast and efficient.
This information describes Froda’s processing of personal data relating to customers, including for which purposes we process customer personal data, which legal basis we rely on for the processing, with which recipients we, where necessary, share personal data, and your rights in relation to the processing of your personal data.
If you have any questions in relation to our processing of your personal data as a customer, please feel free to contact us using the contact details outlined in Section 18 below.
The contents of this information
This information about our processing of customer personal data is divided into different sections to make it easier for you to find the information that you are looking for.
You can use the following list of sections as a guide:
- Processing of personal data
- Who is covered by this information
- Controllership for the processing of customer personal data
- Sources from which we collect personal data
- Our processing of customer personal data
- Business customers
- Savings account
- All customers
- Where we process your personal data
- Protection of your personal data
- Your rights
- How you exercise your rights
- Use of cookies and similar technologies
- Use of AI systems and tools
- Updates to this information
- Categories of personal data in this information
- If you have questions
2. Processing of personal data
Personal data means any information that, directly or indirectly, relates to an identified or identifiable individual. Examples of personal data include your name, email address, or the IP address that your device uses.
This means that information about a business that is a limited liability company does not constitute personal data. However, if your business is a sole trader, the information relating to the business constitutes personal data about you.
Processing means any action taken in relation to personal data, for example collection, storage and transmission for one or more specific purposes.
3. Who is covered by this information
This information covers you:
- who is a representative of a business that applies for a loan or financing from us or a business that has a loan or financing from us, either directly or through one of our business partners, and
- who applies for a savings account or has a savings account with us.
In this information, both categories of individuals are referred to as customers.
Moreover, this information also covers, in relevant parts, processing of personal data relating to guarantors, beneficial owners and board members of the business in connection with the application process for a business loan or financing and to provide the business loan or financing and related services.
4. Controllership for the processing of customer personal data
Froda is the controller of your personal data
Froda AB, company registration number 556999-3388 (“Froda”, “we”, “us”), is the controller for the collection and processing of your personal data as described in this information, unless otherwise is stated. Contact details to us can be found in Section 18 below.
Froda is a joint controller when we provide financing together with certain business partners
Froda cooperates with business partners to provide business loans and financing to businesses.
When our business partners use our embedded funding solution, which they integrate into their own platform in order to provide business loans and financing to businesses, Froda and the business partner are joint controllers for the processing of personal data to provide the business loan and financing to your business.
As such, if you have applied for a business loan or financing through one of our partners that use our embedded funding solution, for example Treyd, the business partner and Froda are jointly responsible for the processing of your personal data for this purpose.
Moreover, when business partners provide information to us, for example transaction information, which is necessary to provide the business loan or financing to your business, the business partner is a joint controller together with us for the sharing of the information to make it possible for us to provide the business loan or financing. You receive information about our partnership with the business partner when you sign up for the business loan or financing.
We have entered into a mutual arrangement according to Article 26 of the GDPR with our business partners that we are joint controllers with, to allocate the responsibility between us and the business partner to ensure the protection of your personal data. You have the right to receive information on the essence of this arrangement. Please contact us on the contact details outlined in Section 18 below in such case. The contents of this information also reflect the arrangement.
5. Sources from which we collect personal data
We collect personal data about you from various sources as outlined below.
Yourself
We collect personal data directly from you when you interact with us, for example when you, on behalf of a business, apply for a business loan or financing from us, when you apply to open a savings account, when you contact our customer service or when you use My Pages.
Representatives of the customer
If you are an official representative of the business, such as a board member, are or will be a guarantor for a business loan on behalf of a customer, or a beneficial owner of the business, we will, where relevant, collect personal data about you from the individual who represents the business, unless you provide the necessary information yourself or if we collect the information from publicly available sources.
Moreover, if different individuals interact with us on behalf of the customer, we will, where applicable for the purposes outlined in this information, collect information about you from a representative of a customer when the representative interacts with us. By way of example, it can be necessary to collect information about you to manage a customer matter when another representative of the same business reaches out to customer service.
Credit information companies
In connection with the application process and to carry out know your customer (KYC) checks, we will collect information about the business that you represent from credit information companies, for example Creditsafe, that we use.
Publicly available information
In connection with the application process and to carry out know your customer (KYC) checks, we will also collect publicly available information, such as information on board members of the business, for example from public records and databases through information service companies, such as Svensk Faktakontroll.
Business partners
Froda cooperates with business partners to provide business loans and financing to businesses within our embedded financing solutions that our business partners can integrate into their own platforms.
As such, when you apply for a business loan or financing via one of our business partners, we will collect personal data from the business partner to manage the application and to provide the business loan or financing and related services. We also collect know your customer (KYC) information from our business partners to fulfil our legal obligations.
In addition, for certain types of loans and financing, we also collect additional information from the business partner during the customer relationship, for example transaction information, to provide the business loan or financing.
Information on business partners that use our embedded financing solutions is available on a page on our website.
Moreover, Froda cooperates with business partners that refer customers to us and, for example, to carry out events and other activities. We collect the personal data that these business partners share with us.
Banks
In connection with the application process, we collect, with your consent, transaction information relating to the company that applies for a business loan or financing from the company’s bank accounts in other banks.
Moreover, for certain types of loans and financing, we collect transaction information with your consent from your bank to provide the business loan or financing, including to manage payments of the loan.
Brokers
We collect information that brokers, for example Lendo, share with us to provide a preliminary offer for a business loan or financing.
Public authorities
We collect personal data that public authorities share with us, for example in connection with legal requests or in case of a dispute.
6. Our processing of customer personal data
Below we describe for which purposes we process personal data about you as a representative of a business that interacts with us or if you are an individual that has applied for or has a savings account with us.
Moreover, where the business you represent is a sole trader, the information relating to the company is also personal data, which we process for the purposes outlined below.
Below we also describe:
- which categories of personal data are being processed for each purpose
- which legal basis we rely on for the processing
- for how long the personal data is stored for each purpose
External recipients in the descriptions below means such recipient with which we, where necessary for the specific purpose, share your personal data and which process the personal data received as a separate controller. As such, external recipient does not include service providers which we have engaged and that process personal data on our behalf as processors.
7. Business customers
You are a business customer if you represent a company or organisation that applies for a business loan or financing with Froda, either directly from us or via our business partners.
The information below also covers:
- individuals that have expressed an interest in our products and services or which we believe may be interested in our products and services (prospects)
- guarantors for a loan with us, beneficial owners and board members of the business (in relevant parts)
Manage the application for a business loan or financing
We process personal data about you as a representative for the company or organisation that applies for a business loan from Froda to manage the application for the business loan, for example to:
- collect information about you to be able to contact you in relation to the application
- manage the signature process of the application
- verify that you have the right to apply for a loan on behalf of the business
Moreover, if the company that you represent is a sole trader, the information that we collect about the company is also personal data which we process for the same purpose, for example to evaluate whether we can approve the application for a business loan.
In connection with the application process, we will analyse the information collected in order to evaluate whether the business has financial possibilities to repay the loan. Where the business is a sole trader, the decision to approve or reject the application constitutes automated decision making. For more information on this, please see Section 12 below.
Additionally, in connection with the application process, we need to verify your identity, please see Verify your identity when interacting with us below. As a part of the application process, we also carry out certain checks, please see the purposes Carry out know your customer (KYC) and anti money laundering checks, and Prevent fraud and misuse of our products and services below.
With your consent, we collect bank information from your bank to manage your application.
You need to provide the information that we request in connection with the application process. Otherwise, we cannot enter into a customer agreement with you and, accordingly, cannot manage your application.
Categories of personal data:
- Identification information
- Contact information
- Profile information
- Communication
- Activity information
If the business is a sole trader, we also process the following categories of personal data:
- Company information
- Financial information
- Transaction information
- Loan information
- Bank information
- Account information
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest of managing the application for a business loan or financing, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
If the business that you represent is a sole trader, the processing of your personal data is necessary to take steps at your request to enter into a customer agreement (Article 6(1)(b) of the GDPR).
Storage period:
Personal data is stored for this purpose during the application process.
External recipients:
- Business partners
- Brokers
- Credit information companies
- Banks
Provide the business loan or financing and related services
We process personal data about you as a representative for the company or organisation that has a business loan with Froda to provide the business loan or financing and related services, for example to manage payments and to communicate with you regarding the business loan or financing.
Categories of personal data:
- Identification information
- Contact information
- Profile information
- Activity information
- Communication
If the business is a sole trader, we also process the following categories of personal data:
- Company information
- Financial information
- Transaction information
- Loan information
- Bank information
- Account information
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest of fulfilling the customer agreement with the business and providing the business loan or financing and related services, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
If the business that you represent is a sole trader, the processing of your personal data is necessary to fulfil the customer agreement with the business (Article 6(1)(b) of the GDPR).
Storage period:
Personal data is stored for this purpose during the customer relationship and for a period of ten (10) years thereafter to manage, defend and exercise legal claims.
External recipients:
- Banks
- Business partners that we cooperate with to provide business loans and financing
Provide offers for business loans and financing
We process personal data about you to provide offers for business loans and financing if:
- you have expressed an interest for a business loan or financing through us, for example via a business partner such as a broker, or
- you have started an application for a business loan or financing, but did not complete the application.
An offer can be provided via the business partner or directly from us, for example by email.
You can always unsubscribe from our marketing communications by clicking on the unsubscribe link in the email or by contacting us.
Categories of personal data:
- Identification information
- Contact information
- Profile information
- Communication
- Activity information
If the business is a sole trader, we also process the following categories of personal data:
- Company information
- Financial information
- Transaction information
- Loan information
- Bank information
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest of promoting our products and services, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
Where your consent to send digital marketing communications is needed, we only send you digital marketing communications if you have provided your consent. In such a case, we also rely on the consent as a legal basis for the processing of personal data for this purpose (Article 6(1)(a) of the GDPR).
Storage period:
Personal data is stored for this purpose during such period that is necessary to provide you with the offer through a business partner or for a maximum period of twelve (12) months from the date that we collected your personal data, for example in connection with an application for a business loan or financing or, if you interact with us, during a maximum period of twelve (12) months from the date of the last interaction.
The above applies unless you have previously objected to our processing of your personal data for marketing purposes.
External recipients:
- Business partners
Manage broker commissions
We process personal data about you to manage broker commissions, for example to calculate broker commissions and to share relevant personal data with the broker as supporting information for payment of broker commissions.
This processing activity is only relevant for businesses that are sole traders.
Categories of personal data:
- Identification information
- Company information
- Loan information
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest of fulfilling our commission agreements with our business partners, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
Storage period:
Personal data is stored for this purpose during such period that is necessary to manage the broker commission in the specific case. Broker commissions are normally paid on a monthly basis. Moreover, personal data processed for this purpose is further stored for a period of ten (10) years thereafter to manage, defend and exercise legal claims.
External recipients:
- Business partners (brokers that we collaborate with)
Enable business partners to carry out their own follow up and to communicate with you
We share personal data with our business partners, for example brokers and referral partners, to enable our business partners to:
- carry out their own follow up
- communicate with you
for example, to make it possible for the business partner to create statistics of referrals or to reach out to you regarding the business loan with us.
Categories of personal data:
- Identification information
- Contact information
- Profile information
- Activity information
If the business is a sole trader, we also process the following categories of personal data:
- Company information
- Loan information
Legal basis:
When your personal data is further processed for this purpose, the processing of personal data relies on the same legal basis as the purpose for which the personal data was collected, please see for example Manage the application for a business loan or financing above.
Moreover, the processing of your personal data is necessary to satisfy our legitimate interest of fulfilling our agreements with our business partners, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
The business partner also has a legitimate interest of understanding whether any referrals made resulted in an agreement regarding a business loan or financing and to communicate with you regarding this.
Storage period:
Personal data is stored for this purpose during the time it takes to compile the necessary information and share the information with the relevant business partner and for a period of ten (10) years thereafter to manage, defend and exercise legal claims.
External recipients:
- Business partners
8. Savings account
If you have applied for opening a savings account or have a savings account with us, we process your personal data for the following purposes.
Manage the application for a savings account
We process personal data about you if you have applied for opening a savings account with us to manage your application for a savings account, for example to evaluate your application and to communicate with you regarding the application.
Additionally, in connection with the application process, we need to verify your identity, please see Verify your identity when interacting with us below. As a part of the application process, we also carry out certain checks, please see the purposes Carry out know your customer (KYC) and anti money laundering checks, and Prevent fraud and misuse of our products and services above.
With your consent, we collect bank information from your bank to manage your application.
You need to provide the information that we request in connection with the application process. Otherwise, we cannot enter into a customer agreement with you and, accordingly, cannot manage your application.
Categories of personal data:
- Identification information
- Contact information
- Communication
- Bank information
- Account information
Legal basis:
The processing of your personal data is necessary to take steps at your request to enter into a customer agreement (Article 6(1)(b) of the GDPR).
Storage period:
Personal data is stored for this purpose during the application process.
External recipients:
- Business partners
- Banks
Provide the savings account and related services
If you have a savings account with us, we process personal data about you to provide the savings account and related services, for example to manage payments (deposits and withdrawals) and communicate with you for the same purpose.
Categories of personal data:
- Identification information
- Contact information
- Account information
- Bank information
- Activity information
- Communication
Legal basis:
The processing of your personal data is necessary to fulfil the customer agreement with you (Article 6(1)(b) of the GDPR).
Storage period:
Personal data is stored for this purpose during the customer relationship and for a period of ten (10) years thereafter to manage, defend and exercise legal claims.
External recipients:
- Banks
9. All customers
As a representative of a business that has applied for or holds a loan with us or if you applied for or have a savings account with us, we also process your personal data, where necessary, for the following purposes.
Manage and document the customer relationship and customer matters
We process personal data to manage and document the customer relationship and customer matters, for example to:
- register you as a contact person
- communicate with you for the same purpose
- manage changes to your or the business’ engagement with us
We also process your personal data for this purpose when you reach out to one of our business partners together with which we offer business loans and financing or savings accounts.
Categories of personal data:
- Identification information
- Contact information
- Profile information
- Matter information
- Activity information
- Communication
If the business is a sole trader and has a business loan or financing with us, we also process the following categories of personal data:
- Company information
- Financial information
- Transaction information
- Loan information
- Bank information
- Account information
Moreover, if you have a savings account with us, we also process the following categories of personal data:
- Account information
- Bank information
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest of fulfilling the customer agreement with the business, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
If the business that you represent is a sole trader or if you have a savings account with us, the processing of your personal data is necessary to fulfil the customer agreement (Article 6(1)(b) of the GDPR).
Storage period:
Personal data is stored for this purpose during the customer relationship and for a period of ten (10) years thereafter to manage, defend and exercise legal claims.
External recipients:
- Business partners (through which you have applied for a business loan or financing or a savings account)
Provide and document customer support
When you contact our customer service, we process personal data about you to provide customer support or to respond to your question.
We also process your personal data for this purpose when you reach out to one of our business partners together with which we offer business loans and financing, and they need our assistance to respond to your question.
Categories of personal data:
- Identification information
- Contact information
- Profile information
- Matter information
- Activity information
- Communication
If the business is a sole trader and has a business loan or financing with us, we also process the following categories of personal data:
- Company information
- Financial information
- Transaction information
- Loan information
- Bank information
- Account information
Moreover, if you have a savings account with us, we also process the following categories of personal data:
- Account information
- Bank information
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest of providing and documenting customer support, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
Storage period:
Personal data is stored for this purpose during the customer relationship and for ten (10) years thereafter to manage, defend and exercise legal claims.
External recipients:
- Business partners (when you reach out to the business partner for this purpose)
Verify your identity when interacting with us
When you interact with us, for example apply for a business loan on behalf of a business or apply for a savings account, when you contact customer service or when you log in to your account on the website (My Pages), we need to verify your identity. As such, we process your personal data to verify your identity, for example when using an electronic identity verification service such as BankID.
Categories of personal data:
- Identification information
- Technical information
- Activity information
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest of ensuring that we do not disclose personal data or information to an unauthorized recipient, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
Where the verification is carried out in order to fulfil our legal obligation to know your customer under the Act on Measures Against Money Laundering and Terrorist Financing Act (2017:630), the processing is necessary to fulfil this legal obligation (Article 6(1)(c) of the GDPR).
Storage period:
Personal data is processed for this purpose during the verification process.
External recipients:
- Banks (which have issued your digital ID)
- Electronic identity verification service providers
Provide access to My Pages
We process your personal data to provide you with secure access to My Pages on our website and to ensure that My Pages functions properly.
Moreover, when you log in to My Pages, we also verify your identity, please see the purpose Verify your identity when interacting with us above.
Categories of personal data:
- Identification information
- Technical information
- Activity information
If the business is a sole trader and has a business loan or financing with us, we also process the following categories of personal data:
- Transaction information
- Loan information
- Account information
Moreover, if you have a savings account with us, we also process the following categories of personal data:
- Account information
- Transaction information
Legal basis:
The processing is necessary to fulfil the terms and conditions for My Pages (Article 6(1)(b) of the GDPR).
We use strictly necessary cookies and similar technologies for this purpose, which do not require your consent.
Storage period:
Personal data is stored for this purpose for a period of twelve (12) months from the time of collection.
For information on how long cookies and similar tracking technologies are stored for this purpose, please see our Cookie Policy.
External recipients:
- No external recipients
Follow up and evaluate the digital application process and the use of My Pages
We process your personal data to follow up and evaluate the digital application process and the use of My Pages on our website to better understand how the application process and My Pages are experienced and used, for example to:
- collect and compile usage statistics
- visualise anonymised user interactions on our website
This also enables us to develop and improve our digital application process and My Pages to provide you with a better user experience.
For this purpose, we use cookies and similar technologies that enable us to analyse visitor and usage statistics.
Categories of personal data:
- Identification information
- Technical information
- Activity information
Legal basis:
The processing is necessary to satisfy our legitimate interest of better understanding how our application process and My Pages are used, to enable us to develop and improve the user experience, which we consider outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
To the extent personal data for this purpose is collected using cookies and similar technologies, the processing is carried out with the consent that you provided by accepting our use of cookies on the website for analytics purposes (Article 6(1)(a) of the GDPR).
Storage period:
Personal data is stored for this purpose for a period of twelve (12) months from the time of collection.
For information on how long cookies and similar tracking technologies are stored for this purpose, please see our Cookie Policy.
External recipients:
- No external recipients
Follow up and evaluate customer relationships
We process your personal data to follow up and evaluate customer relationships, for example to compile statistics and reports to understand customer engagement, financial risks etc.
This processing activity is only relevant for businesses that are sole traders or if you have a savings account with us.
Categories of personal data:
- Identification information
- Profile information
- Matter information
- Activity information
If the business is a sole trader and has a business loan or financing with us, we also process the following categories of personal data:
- Company information
- Financial information
- Transaction information
- Loan information
- Bank information
- Account information
Moreover, if you have a savings account with us, we also process the following categories of personal data:
- Account information
- Bank information
Legal basis:
Since your personal data is further processed for this purpose, the processing of personal data relies on the same legal basis as the purpose for which the personal data was collected, please see for example Manage the application for a business loan or financing above.
Storage period:
The personal data further processed for this purpose is stored during a period of twelve (12) months to carry out the analysis and to facilitate future analyses. Results on an aggregated level which do not include any personal data are stored until further notice or until deleted.
External recipients:
- No external recipients
Follow up and evaluate our business
We process your personal data to follow up and evaluate our business, for example to compile statistics and reports on how the business performs, business risks etc.
This processing activity is only relevant for businesses that are sole traders or if you have a savings account with us.
Categories of personal data:
- Identification information
- Profile information
- Company information
- Loan information
- Account information
- Matter information
- Activity information
- Transaction information
Legal basis:
Since your personal data is further processed for this purpose, the processing of personal data relies on the same legal basis as the purpose for which the personal data was collected, please see for example Manage the application for a business loan or financing above.
Storage period:
The personal data further processed for this purpose is stored during a period of twelve (12) months to carry out the analysis and to facilitate future analyses. Results on an aggregated level which do not include any personal data are stored until further notice or until deleted.
External recipients:
- No external recipients
Develop and improve our business, our offerings, products and services and our business strategies, practices and methods
We process your personal data to develop and improve our business, our offerings, products and services and our business strategies, practices and methods.
It is important to us that our offerings, products and services fulfil your expectations and requirements. The processing of your personal data for this purpose makes it possible for us to, for example:
- develop and improve our internal procedures and processes by carrying out analysis of our business strategies, practices and methods
- develop and improve the tools and services that we use to provide our products and services
- make our products and services easier to use
- improve our customer service
- develop new products and services
We do not carry out profiling as a part of the processing of personal data for this purpose, since we are not interested in your specific behaviour or interests.
Moreover, if it is possible to achieve the purpose of the processing with anonymised personal data, we first make sure to anonymise your personal data.
Categories of personal data:
- Identification information
- Profile information
- Matter information
- Activity information
- Audio and image information
If the business is a sole trader and has a business loan or financing with us, we also process the following categories of personal data:
- Company information
- Financial information
- Transaction information
- Loan information
- Bank information
- Account information
Moreover, if you have a savings account with us, we also process the following categories of personal data:
- Account information
- Bank information
Legal basis:
Since your personal data is further processed for this purpose, the processing of personal data relies on the same legal basis as the purpose for which the personal data was collected, please see for example Manage the application for a business loan or financing above.
Storage period:
The personal data further processed for this purpose is stored during a period of twelve (12) months to carry out the analysis and to facilitate future analyses. Results on an aggregated level which do not include any personal data are stored until further notice or until deleted.
External recipients:
- No external recipients
Record and transcribe calls for educational and quality purposes, for security and to document interactions
When you call us, we will record and transcribe the call if you receive information about this when you call us. The purpose for recording and transcribing your calls is to:
- ensure that we provide excellent customer service
- ensure security, for example to prevent fraud
- document our interactions with you
Categories of personal data:
- Identification information
- Profile information
- Matter information
- Activity information
- Communication
If the business is a sole trader and has a business loan or financing with us, we also process the following categories of personal data:
- Company information
- Financial information
- Transaction information
- Loan information
- Bank information
- Account information
Moreover, if you have a savings account with us, we also process the following categories of personal data:
- Account information
- Bank information
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest of ensuring that we fulfil customer expectations, to protect our staff and assets and to create a record of our interaction with you, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
If you wish to object against the call being recorded or transcribed, you can do this when you call us.
Storage period:
Recorded calls are stored for a period of three (3) months. Transcribed calls are stored for the same period as is outlined in Provide and document customer support above.
External recipients:
- No external recipients
Communicate about us, our business and our products and services
We process your personal data to communicate with you about our business and our products and services, for example to:
- provide you with updates on our products and services offerings
- inform you about things that happen in our business in different channels, such as via email or on social media platforms
You can always unsubscribe from our marketing communications by clicking on the unsubscribe link in the email or by contacting us.
Categories of personal data:
- Identification information
- Contact information
- Profile information
- Activity information
- Communication
If the business is a sole trader and has a business loan or financing with us, we also process the following categories of personal data:
- Company information
- Loan information
Moreover, if you have a savings account with us, we also process the following categories of personal data:
- Account information
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest of communicating with you about our business and products and services to create interest for our business and products and services, and to build our brand, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
Where your consent to send digital marketing communications is needed, we only send you digital marketing communications if you have provided your consent. In such a case, we also rely on the consent as a legal basis for the processing of personal data for this purpose (Article 6(1)(a) of the GDPR).
Storage period:
Personal data is stored for this purpose for as long as there is an active customer relationship and for a period of twelve (12) months thereafter.
The above applies unless you have previously objected to our processing of your personal data for marketing purposes.
External recipients:
- No external recipients
Communicate and interact with you in our digital channels
We process your personal data to communicate and interact with you in our digital channels, for example if you:
- comment on our posts
- write on our pages
- otherwise mention us on social media
Categories of personal data:
- Identification information
- Contact information
- Profile information
- Activity information
- Communication
- Image and audio material
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest in communicating and interacting with you in our digital channels, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
Storage period:
Personal data is stored for this purpose until further notice or until deleted on the relevant social media platform.
External recipients:
- Social media platforms
Follow up and evaluate our communication
We process your personal data to better understand how you interact with our communications. This is done through tracking techniques that enable us to analyse open and click statistics for our communications.
Categories of personal data:
- Identification information
- Technical information
- Activity information
Legal basis:
The processing of your personal data collected from your device relies on the consent you provide when you sign up for our communications (Article 6(1)(a) of the GDPR).
Storage period:
Personal data is stored for this purpose for a period of twelve (12) months from the time of collection.
External recipients:
- No external recipients
Follow up and evaluate marketing campaigns in digital channels
We process your personal data to follow up and evaluate campaigns that you have interacted with in our digital channels, for example if you have clicked on a marketing message or an advertisement on an external website or in social media.
Categories of personal data:
- Identification information
- Technical information
- Activity information
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest in following up and evaluating marketing campaigns that we carry out, so that we can better understand how our marketing campaigns are performing, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
Storage period:
Personal data is stored for this purpose for the duration of the campaign and for a period of three (3) months thereafter in order to compile reports. Thereafter your personal data will be deleted or anonymized.
External recipients:
- No external recipients
Carry out meetings, events, and similar activities
We process your personal data to carry out meetings, events and similar activities, both digital and physical meetings and events, for example to:
- register your participation
- carry out the activity
- communicate with you about the activity
Categories of personal data:
- Identification information
- Contact information
- Profile information
- Communication
- Image and audio material (for example in connection with digital meetings)
- Special categories of personal data, for example health data
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest in carrying out meetings, events and similar activities (Article 6(1)(f) of the GDPR).
Special categories of personal data:
We only process information about any food allergies on the basis of your explicit consent that you provide separately, for example in connection with registration (Article 9(2)(a) of the GDPR).
Storage period:
Personal data is stored for this purpose during the time that the meeting, event or activity is carried out.
If the activity is recorded to document the meeting for traceability, the recording is stored, as a starting point, until further notice.
If the recording is published in our digital channels to communicate about us and our business, the recording will also be stored, as a starting point, until further notice.
External recipients:
- Business partners (that we arrange the relevant activity together with)
Follow up and evaluate activities carried out
If you have participated in an activity that we have carried out, we process your personal data to follow up and evaluate the activity, for example to:
- compile statistics on the number of participants in the activity
- plan future activities
Categories of personal data:
- Identification information
- Contact information
- Profile information
- Activity information
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest in following up and evaluating completed activities, to better understand how we can improve future activities, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
Storage period:
Personal data is stored for this purpose for a period of twelve (12) months from the time of the relevant activity.
External recipients:
- No external recipients
Carry out customer surveys
We process your personal data to carry out customer surveys, for example:
- to decide which target group should receive the survey
- to decide what questions should be included in the survey
- to send out surveys
- to collect and analyse the results of a survey
Your opinions about our business and products and services are important and necessary for us to enable us to develop and improve our business, products and services.
Where necessary to conduct the specific survey, we also further process personal data that we have previously collected for this purpose, please see for example the purpose Provide the business loan or financing and related services above.
Categories of personal data:
- Identification information
- Contact information
- Profile information
- Communication
- Activity information
If the business is a sole trader and has a business loan or financing with us, we also process the following categories of personal data:
- Company information
- Loan information
Moreover, if you have a savings account with us, we also process the following categories of personal data:
- Account information
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest in conducting surveys. This enables us to develop and improve our business, products and services, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
Storage period:
Personal data is stored for this purpose for the duration of the survey and for a period of three (3) months thereafter in order to compile the responses in a report. Thereafter your personal data will be deleted or de-identified. Final reports which do not include your personal data are stored until further notice or until deleted.
External recipients:
- No external recipients
Communicate in the course of the business
We process personal data that you and others share with us in connection with internal and external communication in the course of the business, for example when our employees communicate with each other and external persons via email to perform their working duties.
Categories of personal data:
- Identification information
- Contact information
- Profile information
- Communication
- Matter information
- Activity information
- Image and audio material
If the business is a sole trader and has a business loan or financing with us, we also process the following categories of personal data:
- Company information
- Financial information
- Transaction information
- Loan information
- Bank information
- Account information
Moreover, if you have a savings account with us, we also process the following categories of personal data:
- Account information
- Bank information
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest in our employees communicating internally and externally in their work in order to perform their duties, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
Storage period:
Personal data is stored for this purpose for a period of two (2) years from the date of the last communication in the same conversation or correspondence.
If the communication is for some other purpose outlined in this information, for example to Manage and document the customer relationship, the communication is stored for the storage period specified for the relevant purpose.
External recipients:
- Representatives of customers, suppliers, and business partners
- External persons that we interact with
Document and record decisions and supporting information in the course of the business for traceability
We process your personal data when it is necessary to document decisions, including supporting information for decisions, in the course of the business, for example in connection with internal and external meetings or otherwise when employees perform their working duties. This is to ensure that there is traceability for decisions made in the business.
Categories of personal data:
- Identification information
- Contact information
- Profile information
- Matter information
- Activity information
- Communication
- Image and audio material
If the business is a sole trader and has a business loan or financing with us, we also process the following categories of personal data:
- Company information
- Financial information
- Transaction information
- Loan information
- Bank information
- Account information
Moreover, if you have a savings account with us, we also process the following categories of personal data:
- Account information
- Bank information
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest in ensuring traceability in the business with regard to the decisions made in the business, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
Storage period:
Personal data is stored for this purpose until further notice.
External recipients:
- No external recipients
Manage the sale and restructuring of all or parts of the business
In the event that all or part of our business is sold, or otherwise transferred or restructured, we process your personal data when it is necessary for this purpose.
Should the business be transferred to a buyer, your personal data would also be transferred or disclosed to the buyer. In such a case, the buyer would be responsible (controller) for its subsequent processing of your personal data and that the processing takes place for the same purposes as stated in this information, unless you receive other information in connection with the transfer.
Categories of personal data:
Categories of personal data concerned that are strictly necessary to manage the sale or restructuring of all or part of the business in the individual case are processed for this purpose.
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest in managing a sale or restructuring of, where applicable, all or part of the business, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
Storage period:
Personal data is stored for this purpose for the time necessary to manage the sale or restructuring in the individual case.
External recipients:
- Buyer
- Potential buyers
- External advisors
- Public authorities
Manage, defend and exercise legal claims
We process your personal data when it is necessary to manage, defend and exercise legal claims in an individual case, for example in connection with a dispute or a court process.
Categories of personal data:
Categories of personal data concerned that are necessary to manage and respond to the legal requirement in the individual case are processed for this purpose.
Normally, the following categories of personal data are processed:
- Identification information
- Contact information
- Profile information
- Matter information
- Activity information
- Communication
- Image and audio material
If the business is a sole trader and has a business loan or financing with us, we also process the following categories of personal data:
- Company information
- Financial information
- Transaction information
- Loan information
- Bank information
- Account information
Moreover, if you have a savings account with us, we also process the following categories of personal data:
- Account information
- Bank information
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest in managing, defending and exercising legal claims in an individual case, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
Storage period:
Personal data is stored for this purpose for the period necessary to manage, defend or exercise the legal claim in the individual case.
External recipients:
- Counterparties
- External advisors
- Public authorities
- Courts
- Debt collection agencies
- Arbitration tribunals
- Insurance companies
Carry out know your customer (KYC) and anti money laundering checks
We process your personal data when it is necessary to carry out know your customer (KYC) and anti money laundering checks, for example in connection with an application for a business loan or financing or during the customer relationship.
Categories of personal data:
- Identification information
- Contact information
- Profile information
- Communication
- Activity information
If the business is a sole trader, we also process the following categories of personal data:
- Company information
- Financial information
- Transaction information
- Loan information
- Bank information
- Account information
Moreover, if you have a savings account with us, we also process the following categories of personal data:
- Account information
- Bank information
Legal basis:
The processing of your personal data is necessary to fulfil our legal obligations under the Act (2014:307) on Measures against Money Laundering and Terrorist Financing (Article 6(1)(c) of the GDPR).
Storage period:
Personal data is stored for this purpose during the check and for a period of five (5) years thereafter in accordance with the Act (2014:307) on Measures against Money Laundering and Terrorist Financing.
External recipients:
- Business partners
- Credit information companies
- Information service companies
Prevent fraud and misuse of our products and services
We process your personal data when it is necessary to prevent fraud and misuse of our products and services, for example to carry out risk assessments for this purpose and take measures to avoid entering into agreements with persons that reasonably could abuse our products and services.
Categories of personal data:
Categories of personal data concerned that are necessary to fulfil the purpose to prevent fraud and misuse of our products and services in the individual case are processed for this purpose.
Normally, the following categories of personal data are processed:
- Identification information
- Contact information
- Profile information
- Activity information
- Communication
- Technical information
If the business is a sole trader and has a business loan or financing with us, we also process the following categories of personal data:
- Company information
- Financial information
- Transaction information
- Loan information
- Bank information
- Account information
Moreover, if you have a savings account with us, we also process the following categories of personal data:
- Account information
- Bank information
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest of protecting our business against fraud and misuse of our products and services, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
Storage period:
Personal data is stored for this purpose during a period of ten (10) years from the date of the last interaction or the date of collection of personal data.
External recipients:
- No external recipients
Fulfil legal obligations
We process your personal data when it is necessary for us to comply with our legal obligations, such as accounting requirements and obligations under the GDPR.
Categories of personal data:
Categories of personal data concerned that are necessary to fulfil the legal obligation in the individual case are processed for this purpose.
Normally, the following categories of personal data are processed:
- Identification information
- Contact information
- Profile information
- Matter information
- Activity information
- Communication
- Image and audio material
If the business is a sole trader and has a business loan or financing with us, we also process the following categories of personal data:
- Company information
- Financial information
- Transaction information
- Loan information
- Bank information
- Account information
Moreover, if you have a savings account with us, we also process the following categories of personal data:
- Account information
- Bank information
Legal basis:
The processing of your personal data is necessary to fulfil our legal obligations (Article 6(1)(c) of the GDPR).
Storage period:
Personal data is stored for this purpose for the time necessary for us to comply with the respective legal obligation to which Froda is subject.
By way of example, personal data is stored in accounting material for seven (7) years calculated from the end of the calendar year in which the relevant financial year ended in accordance with the Accounting Act (1999:1048).
External recipients:
- Public authorities
- Law enforcement authorities
Respond to legal requests
We process your personal data when it is necessary to respond to legal requests from public authorities, such as law enforcement authorities, tax authorities and other regulatory authorities, such as the Financial Supervisory Authority.
Categories of personal data:
The categories of personal data necessary to respond to and evaluate the request in the individual case are processed for this purpose.
Normally, the following categories of personal data are processed:
- Identification information
- Contact information
- Profile information
- Matter information
- Activity information
- Communication
- Image and audio material
If the business is a sole trader and has a business loan or financing with us, we also process the following categories of personal data:
- Company information
- Financial information
- Transaction information
- Loan information
- Bank information
- Account information
Moreover, if you have a savings account with us, we also process the following categories of personal data:
- Account information
- Bank information
Legal basis:
When there is a legal obligation for Froda under law or regulation to respond to the legal request, the processing is carried out to fulfil the legal obligation in the specific case (Article 6(1)(c) of the GDPR).
If there is no explicit legal obligation for us to respond to the legal request or if we need support in order to properly respond to the legal request from external advisors, the processing is carried out in order to satisfy our legitimate interest of responding to the legal request if we assess that this legitimate interest under a balancing test outweighs your interests or the potential impact on your fundamental rights and freedoms in the individual case (Article 6(1)(f) of the GDPR).
Storage period:
Personal data is stored for this purpose for the time necessary to respond to the legal request, and for a period of ten (10) years thereafter in order to document and be able to show that the request has been answered.
External recipients:
- Public authorities
- Law enforcement authorities
- External advisors
Protect and ensure the safety of our staff and assets
We process your personal data when it is necessary to manage, investigate and document incidents involving our employees, other persons and our assets, for example to:
- file a police report
- report an incident to the relevant public authority, including law enforcement authorities
Categories of personal data:
All categories of personal data that are necessary to protect and ensure the safety of our employees and the protection of our assets in the individual case are processed for this purpose.
Normally, the following categories of personal data are processed:
- Image and audio material
- Identification information
- Communication
- Contact information
- Profile information
- Matter information
- Activity information
Legal basis:
The processing of your personal data is necessary to satisfy our legitimate interest of protecting and ensuring the safety of our employees and protection of our assets, which we consider under a balancing test outweighs your interest and the potential impact on your fundamental rights and freedoms (Article 6(1)(f) of the GDPR).
Storage period:
Personal data is stored for this purpose for such time that is necessary to investigate the incident and take necessary measures in relation to the incident, such as filing a police report or filing a report with another relevant public authority.
Personal data included in recorded decisions or the supporting information for decisions made for this purpose is stored until further notice for traceability.
External recipients:
- External advisors
- Public authorities
- Law enforcement authority
- Courts
- Insurance company
10. Where we process your personal data
We store your personal data on servers within the EU/EEA.
In certain cases, we transfer your personal data to recipients in third countries outside the EU/EEA, for example to service providers that we engage in such third countries.
In order to ensure an essentially equivalent level of protection for your personal data when transferred (or otherwise made available) to recipients in third countries outside of the EU/EEA, which do not provide an adequate level of protection, we normally use the EU Commission’s adopted standard contractual clauses for international transfers according to decision 2021/914 and implement – in light of the law and practices of the third country – necessary supplementary measures to ensure an essentially equivalent level of protection of the personal data transferred. This to ensure that your personal data is protected regardless of where it is processed.
We also rely on so-called adequacy decisions issued by the European Commission where personal data is transferred to countries and recipients covered by such decision. As an example, we rely on the EU-U.S. Data Privacy Framework for transfers to service providers in the United States that are certified under the framework.
For more information on the safeguards that we have taken to protect your personal data, please contact us, please see contact details in Section 18 below.
11. Protection of your personal data
Froda implements appropriate technical and organisational measures to protect the confidentiality, availability and integrity of your personal data. As such, we take measures to protect your personal data against unlawful or unauthorised access, alteration, loss and destruction.
Your personal data is processed, when necessary, for this purpose. Personal data is stored for this purpose for such period that is outlined in relation to each purpose outlined in this information.
The legal basis for the processing of your personal data to protect your personal data in our IT systems and tools is that the processing is necessary in order for us to fulfil our legal obligation under Article 32 of the GDPR to implement appropriate technical and organisational measures to protect and safeguard your personal data (see Article 6(1)(c) of the GDPR).
Personal data in logs for troubleshooting and error and incident management is stored for a period of up to 24 months from the time of the log event.
12. Your rights
You have certain rights in relation to the processing of your personal data under the GDPR.
You have the right to:
- Access and obtain a copy of your personal data together with additional information about our processing of your personal data (please see Article 15 of the GDPR).
- Rectification of or request that we supplement your personal data if you consider that your personal data is incorrect, incomplete, or misleading (please see Article 16 of the GDPR).
- Erasure of your personal data (please see Article 17 of the GDPR).
You also have the right to:
- Object to our processing of your personal data, for example our processing of your personal data for direct marketing purposes or when we rely on a legitimate interest as the legal basis for the processing (please see Article 21 of the GDPR).
- Request restriction of our processing of personal data, which means that you can, at least for a certain period, prevent us from processing your personal data (other than storing your personal data) (please see Article 18 of the GDPR).
- Data portability, that is to receive a copy of the personal data that you have provided to us in a structured and commonly used format and, where it is technically feasible, request that the personal data is transferred directly to an external recipient (please see Article 20 of the GDPR).
- Withdraw your consent to the processing of personal data based on your consent (please see Article 7 of the GDPR).
- Lodge a complaint with your supervisory authority. In Sweden, we are under the supervision of the Swedish Authority for Privacy Protection (IMY).
Please note that certain rights only apply in certain situations, and that there are several exceptions to certain rights. For more information about your rights under the GDPR, please see the information available on IMY’s website.
Automated individual decision making in the application process
Our goal is to make business financing on fair terms accessible, fast and efficient for our customers. In order to achieve this, we have digitalised the loan process through the provision of our platform.
This also means that if your business is a sole trader, we will within the application process for a business loan or financing analyse whether there is any risk of fraud or money laundering and evaluate your business’ financial possibilities to repay a loan. The processing of personal data for these purposes involves profiling of your personal data and qualifies as automated individual decision making under Article 22 of the GDPR. The legal basis for the automated individual decision making is that the processing is necessary for entering into the customer agreement regarding the business loan or financing with you.
In case of an automatic rejection of your application, you always have the right to reach out to us to obtain a manual re-assessment of your application by an individual. Please contact us on the contact details outlined in Section 18 below in such case.
13. How you exercise your rights
Contact us
If you wish to exercise your rights, please see the contact information in Section 18 below.
If possible, please use the email address that you may have registered with us or used when you have been in contact with us. This makes it easier to handle your request.
We respond to your request as soon as possible and normally within one month
We will respond to your request as soon as possible and normally within one (1) month of receiving your request. However, if your request is complex or if you have made multiple requests, we may need additional time to manage your request. In such a case, we will inform you of this and the reason for the extension no later than one (1) month from the date we received your request.
If for any reason we are unable to comply with your request, in whole or in part, we will inform you of this and the reason why we are unable to comply with your request. You will receive such information within one (1) month from the time we received your request. If you have submitted your request electronically, for example by contacting us by email, we will respond to the request electronically, unless you specifically request otherwise.
We will verify your identity before responding to your request
When you make a request to exercise your rights, we need to confirm your identity to ensure that you are no other person than who you claim to be. This is to avoid, for example, us disclosing personal data to someone unauthorised or wrongly deleting personal data.
If we do not have sufficient information to confirm your identity, we may request that you provide additional information about yourself to confirm your identity. We may also ask you to confirm your identity using a digital identity verification service, for example BankID. We only request the information that is reasonable and necessary to confirm your identity. The time to respond to your request will begin once we have confirmed your identity.
14. Use of cookies and similar technologies
We use cookies and similar technologies on our website. This is to, among other things, collect statistics in order to better understand how the website is used. This enables us to develop and improve the website in order to create a better user experience.
In our Cookie Policy, you can find more information about which cookies we use on the website, and for what purposes.
15. Use of AI systems and tools
We use, where relevant, AI systems and tools to process personal data for the purposes outlined in this information. This is to:
- streamline and automate working tasks and processes that we otherwise would perform manually
- create better supporting information for decisions
- improve and ensure the quality of our operations
We also, when necessary, further process your personal data to train AI systems and tools that we use in the business, please see the purpose Develop and improve our business, our offerings, products and services and our business strategies, practices and methods above.
If you have questions regarding our use of AI systems and tools, please contact us by using the contact information in Section 18 below.
16. Updates to this information
If our processing of personal data changes, for example if we collect and process personal data for new purposes, collect additional categories of personal data or share your personal data with additional recipients than those outlined in this information, we will update the information.
At the top of this information, you can see when the information was last updated.
Version history
Version 1.0
The first version of this privacy notice. The version that you are currently reading is the latest version.
17. Categories of personal data in this information
Below we describe the categories of personal data that are referenced in this information, together with examples.
Account information
Information about your account with us.
Examples: account number, type of account, account balance.
Activity information
Information about your activity and interactions on our website, in our digital channels, when you contact us or otherwise interact with us, for example participate in a meeting or an event.
Examples: clicks, visits and behaviour on the website and in our digital channels, settings and preferences when using functionality on the website and in our digital channels, date and time for your contact or interaction with us, participating in an event or a meeting.
Bank information
Information collected from your bank.
Examples: name of the bank, bank account number.
Communication
Information included in communications, for example in emails.
Examples: content of emails or other correspondence, published posts and comments in digital channels.
Company information
Information about your company.
Examples: company registration number, date of registration, type of company, tax registrations, sector within which the company operates.
Contact information
Information that can be used to contact you or your business.
Examples: address, email, telephone number.
Financial information
Information about your or your company’s financial status.
Examples: income, debts, records of non payment, annual turnover, financial result.
Identification information
Information that can be used to identify you.
Examples: name, personal identification number or social security number, customer identification number.
Image and audio material
Image and audio material in which you appear.
Examples: video, photographs, audio recordings, streaming video and audio (for example in digital meetings).
Loan information
Information about your loan with us.
Examples: loan number, type of loan, loan conditions, loan amount.
Matter information
Information relating to a customer matter that you have with us.
Examples: matter number, type of matter, matter event, and date and time for the event.
Profile information
Information about your profile.
Examples: title, role, username or social media account, the company or organization you represent or work for, gender, age, PEP status, sanctions status, marital status, level of authorization, beneficial owner, guarantor, board member, ownership in relevant company, tax residency, engagements in other businesses.
Special categories of personal data
Special categories of personal data according to Article 9 of the GDPR.
Examples: information relating to your health and health status.
Technical information
Information relating to your device or software on your device.
Examples: type of device, IP address, browser type and version, operating system.
Transaction information
Information about transactions made collected from your bank or in connection with the provision of our products and services.
Examples: amount, date of transaction, type of transaction (withdrawal or deposit), transaction message.
18. If you have questions
Contact us if you have any questions about this information, how we handle your personal data or if you want to exercise your rights, please see below for contact information.
Froda AB
(reg. no.: 556999-3388)
Katarinavägen 9, 116 45
Stockholm, Sweden
Email: info@froda.se
Moreover, Froda has designated a data protection officer (DPO). The DPO is responsible, among other things, for monitoring and reviewing that Froda’s processing of personal data complies with applicable laws and regulations.
You can contact the DPO by email at dpo@froda.se or by sending a letter to the address above with attention to “DPO”.