Privacy Policy
Last updated:
1. Who we are
TRNPK Sweden AB, operating under the names Turnpike and Turnpike Group, is responsible for the personal-data processing described in this Privacy Policy where we act as a data controller.
Organisation number: 559069-4369Contact address: Eriksbergsgatan 8A, 114 30 Stockholm, Sweden
Privacy contact:info@turnpikegroup.com
Data Protection Officer: Martin Henrysson — martin@turnpikegroup.com.
In this policy, “Turnpike”, “we”, “us” and “our” refer to TRNPK Sweden AB.
We handle personal data in accordance with the General Data Protection Regulation, Regulation (EU) 2016/679 (“GDPR”), and applicable Swedish data-protection legislation.
This policy explains how personal data is handled. It is not a request for consent, and visiting our website does not mean that you consent to all processing described here.
2. When this policy applies
This policy covers personal data associated with visiting our public website, contacting us, requesting demonstrations, communicating about our products and services, maintaining business relationships, subscribing to updates and applying for opportunities at Turnpike.
It also explains our general role when our business customers use Turnpike’s software, wearable applications, dashboards and connected services.
For website visitors and business contacts: Turnpike is the controller where we decide why and how your personal data is processed for our own activities.
For people using Turnpike through their employer or another organisation: that organisation will ordinarily be the controller for the workplace or operational processing it determines. Turnpike acts as a processor where we handle the relevant data on its instructions.
Your organisation’s privacy information explains its purposes, legal bases, deployment settings, access permissions and retention arrangements. This policy supplements, but does not replace, that information.
Separate notices may apply to particular applications, deployments or employment-related activities. These will identify the processing they cover.
3. What personal data we collect and where it comes from
The information we process depends on your relationship with us.
Contact and professional information can include your name, work email address, telephone number, employer, job title and business contact details.
Enquiry and relationship information can include messages, meeting arrangements, demonstration requests, requirements you share, proposals, support correspondence and records of business communications.
Contract and payment information can include authorised representatives’ details, signatures, billing contacts, invoice information and transaction records.
Technical information can include IP addresses, browser and device information, access times, requested pages, error records and security logs. Optional tracking can additionally involve cookie identifiers, website interactions and advertising-related information, subject to the choices explained below.
Recruitment information can include your application, CV, qualifications, professional experience, portfolio, interview information and relevant references.
We receive information directly from you, from your interactions with our systems and, where relevant, from your organisation or an authorised business contact. Business contact information may also come from professional introductions, company websites or other relevant public professional sources.
When we obtain information indirectly, we will explain the relevant source and provide the required privacy information within the applicable GDPR deadlines.
Please do not send health information, personal identity numbers, passwords, payment-card details or unnecessary confidential information through general website forms.
4. Why we process personal data and our legal bases
The following applies to processing for which Turnpike acts as a controller. Customer-controlled platform processing is addressed in section 5.
| Activity | Information used and purpose | Legal basis |
|---|---|---|
| Responding to enquiries and arranging demonstrations | Contact details, messages and meeting information, used to answer questions, understand requirements and arrange requested discussions. | Our legitimate interest in responding to requests and developing relevant business relationships: Article 6(1)(f) GDPR. |
| Managing customer, supplier and partner relationships | Professional contacts, correspondence and agreement information, used to negotiate, administer and support business relationships. | Our legitimate interest in managing relationships with organisations and their representatives: Article 6(1)(f). Where you personally are a contracting party, necessary contractual processing may instead rely on Article 6(1)(b). |
| Providing requested assistance | Contact information, issue descriptions and relevant correspondence, used to investigate and respond to business-support requests. | Our legitimate interest in assisting our customers and contacts: Article 6(1)(f). Technical processing performed on a customer’s instructions remains subject to section 5. |
| Accounting and legal compliance | Relevant billing, transaction and agreement records, used to meet accounting, tax and other applicable legal obligations. | Compliance with a legal obligation: Article 6(1)(c). |
| Optional email subscriptions | Contact details and subscription preferences, used to send the updates you request. | Your consent: Article 6(1)(a). |
| Website operation and security | Necessary technical and security records, used to deliver the website, investigate faults, prevent abuse and protect information. | Our legitimate interest in operating secure and reliable systems: Article 6(1)(f). This does not authorise optional tracking without required consent. |
| Optional website analytics and advertising | Relevant identifiers and interaction information, used to understand website use, measure campaigns or support advertising, as described in our cookie information. | Your consent: Article 6(1)(a), together with consent required under applicable cookie rules. |
| Recruitment | Application and relevant assessment information, used to evaluate candidates and communicate about a specific opportunity. | Our legitimate interest in recruiting suitable people: Article 6(1)(f). |
| Rights requests, complaints and legal claims | Information necessary to respond to requests, record our response and establish, exercise or defend legal claims. | Compliance with GDPR obligations under Article 6(1)(c), and our legitimate interest in handling and defending claims under Article 6(1)(f), as applicable. |
Where we rely on legitimate interests, we assess whether the processing is necessary and whether your interests, rights and freedoms override those interests. You may object as explained in section 13.
A contract with your employer does not automatically make contractual necessity the legal basis for processing your personal data. Article 6(1)(b) applies where the relevant contract is with you personally, or the processing is necessary for steps you request before entering that contract.
For identifiable promotional photographs, recordings or testimonials, we obtain the relevant permission and provide information about the intended publication. We do not treat participation in an ordinary meeting as permission to record, transcribe or publish it.
5. Personal data processed through customer deployments
Turnpike’s solutions support staff communication, task coordination, notifications and operational workflows.
Depending on the enabled functions and the customer’s configuration, processing can involve user or device identifiers, organisational roles, teams, work locations, shift information, assigned tasks, requests, notifications, acknowledgements, timestamps and related operational records.
The precise data involved, including information received through integrations, must be identified in the relevant deployment information and data-processing arrangements.
Where Turnpike acts as a processor, we process personal data on the customer’s documented instructions and under a data-processing agreement meeting Article 28 GDPR. That agreement addresses matters such as confidentiality, security, subprocessors, assistance with individuals’ rights, incident handling and deletion or return of data.
The customer is responsible for the purposes and settings it determines, including providing appropriate information to employees and other affected people. Turnpike remains responsible for the obligations that apply to its own role.
Using a Turnpike device or application does not, by itself, constitute employee consent to monitoring. Workplace processing requires an appropriate legal basis, a proportionate purpose and suitable safeguards.
Where Turnpike separately determines a purpose for particular platform-related information, that controller activity must be identified in the applicable privacy information. We do not treat all customer operational data as information available for our unrestricted use.
6. Marketing, cookies and similar technologies
Email communications
We distinguish between responding to a request and sending optional marketing.
Submitting an enquiry or requesting a demonstration does not automatically subscribe you to a newsletter. Where you subscribe to email updates, we use your details for the subscription you select.
You may withdraw your subscription consent or object to direct marketing at any time, using the unsubscribe instructions or by contacting us.
We may retain a limited suppression record, such as your email address and opt-out status, to ensure that your preference continues to be respected. This record is not used to send marketing.
Necessary communications about an existing service, security issue or contract are separate from optional marketing.
Cookies and website tracking
Our website uses cookies or similar technologies for the purposes identified in our Cookie Policy and cookie settings.
Strictly necessary technologies may operate without consent where the law permits. Optional analytics, advertising and other technologies requiring consent are activated only after you make the relevant choice.
You can accept or reject optional technologies and change or withdraw your consent through Cookie settings. Continuing to browse does not constitute consent.
Our cookie information identifies the technologies and providers used, their purposes, the information involved and their duration. It also explains relevant third-party processing.
7. Automation, profiling and artificial intelligence
Some Turnpike functions involve automation, such as filtering notifications or routing requests. Automation does not necessarily mean that a decision with legal or similarly significant effects is being made about an individual.
Where a customer deployment involves profiling or automated decisions, the relevant privacy information must explain the actual processing. Where Article 22 GDPR applies, this includes meaningful information about the logic involved, the significance and expected consequences, and applicable safeguards and rights.
This policy does not authorise Turnpike to reuse customer personal data to train general-purpose AI models or for unrelated purposes. Any proposed additional use requires a separately established lawful basis, appropriate transparency and compliance with the relevant customer arrangements.
8. Who receives personal data
Access and disclosure are limited to what is relevant to the purposes described in this policy.
Authorised personnel may access information where needed for their responsibilities, subject to confidentiality and access controls.
Service providers may process information to supply services such as website hosting, email, meeting booking, business-contact management, support, document storage, accounting and IT security.
Analytics and advertising providers may receive information where the relevant technologies are enabled with the required consent. Their identities, purposes and roles are described in the associated cookie and provider information.
Professional advisers and authorities may receive relevant information where necessary for accounting, audits, legal advice, insurance matters, legal claims or compliance with lawful requirements.
Where a provider processes information on our behalf, we put appropriate processing terms in place. Some recipients, such as authorities or certain professional advisers, act as independent controllers for their own processing.
The appearance of a partner’s name or logo on our website does not mean that we share your personal data with that organisation.
9. Where personal data is processed
Processing locations depend on the systems, suppliers and services involved. Hosting, support access and onward processing must all be considered.
Where personal data is made available to a recipient outside the European Economic Area, we use an applicable GDPR transfer mechanism. Depending on the destination and recipient, this may be an applicable European Commission adequacy decision or appropriate safeguards such as Standard Contractual Clauses.
Where required, we assess the effectiveness of the safeguards and apply supplementary measures. Acceptance of this policy is not consent to an international transfer.
You may contact us for information about the safeguards relevant to your data and how to obtain a copy.
10. How long we retain personal data
We retain personal data for defined purposes and delete or appropriately anonymise it when it is no longer required, unless continued retention is justified by a legal obligation or a specific legal claim.
Different categories have different retention periods.
| Information | Retention period or criterion |
|---|---|
| Enquiries and demonstration requests that do not become a business relationship | 30 days after the final substantive interaction, unless an agreed follow-up remains ongoing. |
| Active customer, supplier and partner contacts | While the person remains a relevant contact for the relationship. Outdated contact details are removed or updated, except where they form part of records that must be retained. |
| Contracts and material business correspondence | During the agreement and for 30 days to address outstanding obligations and relevant claims. |
| Accounting records | Until the end of the seventh year following the end of the calendar year in which the relevant financial year ended, where the Swedish Accounting Act requires this. |
| Email subscription information | Until consent is withdrawn, the subscription is discontinued or the information is otherwise no longer needed for the stated subscription. |
| Opt-out and consent records | Limited information for 30 days, to respect preferences and demonstrate compliance. |
| Routine technical and security logs | 30 days after collection. Relevant extracts may be retained longer for an identified incident or legal claim. |
| Recruitment information | Through the recruitment process, followed by 30 days for relevant recruitment-related claims. Retention for future vacancies requires separately explained arrangements. |
| Cookie and analytics information | The periods specified in the Cookie Policy and relevant provider information. Cookie lifetimes and server-side data retention are identified separately where they differ. |
| Customer-controlled platform data | According to the customer’s documented instructions, configuration and applicable data-processing agreement. |
The accounting retention requirement applies to relevant accounting records, not automatically to every email, enquiry or platform record.
Where data is retained specifically for a legal claim, access and use are limited to that purpose.
After deletion from active systems, information may remain in restricted backups for up to 30 days before scheduled deletion or overwrite.
Information is not treated as anonymous merely because names have been removed. Where it can still be linked to an individual, it remains subject to data-protection requirements.
11. Whether you need to provide information
You can generally browse the public website without providing your name or business contact details, although necessary technical information is processed when the website is delivered to your device.
Providing information through an enquiry or demonstration form is voluntary. However, without sufficient contact information or details about your request, we may be unable to respond or arrange the requested meeting.
Certain information may be necessary to enter into an agreement, provide a requested service or meet a legal obligation. We explain relevant requirements when collecting that information.
Optional marketing consent is not a condition of submitting an enquiry.
For customer-operated applications, your organisation explains which information is necessary for the deployment and the consequences of not providing it.
12. How we protect personal data
We apply technical and organisational measures appropriate to the nature of the information and the risks associated with its processing.
These include limiting access to authorised people, managing access permissions, maintaining appropriate confidentiality arrangements and applying safeguards to the systems and providers involved.
Security measures are reviewed as systems, processing activities and risks change. No system can be guaranteed to be completely secure, but that does not reduce our responsibility to apply appropriate protection.
Where a personal-data breach occurs, we assess it and make the notifications required by applicable law. For processing carried out on a customer’s behalf, we also follow our obligations to notify and assist the relevant customer.
13. Your rights
Depending on the circumstances and the applicable legal conditions, you have rights concerning your personal data.
Access and correction. You may ask whether we process information about you, request access to it and ask us to correct inaccurate or incomplete information.
Erasure and restriction. You may request deletion or restriction of processing where the relevant conditions are met. These rights are not absolute; for example, some information may need to be retained to meet a legal obligation or address a legal claim.
Objection. You may object, for reasons relating to your particular situation, to processing based on legitimate interests. We will stop that processing unless we establish an applicable overriding justification or need the information for legal claims.
Direct marketing. You may object to processing for direct marketing at any time, including associated profiling. We will stop using your personal data for that purpose.
Data portability. Where processing is automated and based on consent or a contract with you, you may request eligible personal data in a structured, commonly used, machine-readable format and, where technically feasible, its transfer to another controller.
Withdrawal of consent. Where processing relies on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Automated decisions. You have the protections and rights applicable to decisions based solely on automated processing that have legal or similarly significant effects, including applicable rights to human intervention and to challenge a decision.
14. Exercising your rights and making a complaint
For requests relating to processing for which Turnpike is the controller, contact info@turnpikegroup.com.
Please provide enough information for us to understand your request. Where there are reasonable doubts about your identity, we may request proportionate additional information to avoid disclosing personal data to the wrong person.
We respond without undue delay and normally within one month. Where GDPR permits an extension because of the complexity or number of requests, the period may be extended by up to two further months. We will explain the extension within the initial month. Requests are normally handled free of charge.
Where your request concerns information processed on a customer’s behalf, we will assist in directing it to the relevant controller and support that controller as required.
You may complain to Integritetsskyddsmyndigheten (IMY), the Swedish Authority for Privacy Protection, or another competent supervisory authority, particularly in the country where you habitually live or work or where you believe an infringement occurred.
You do not have to contact Turnpike before making a complaint.
15. Third-party services and children
When you follow a link to an independently operated website or use an external service, that provider’s privacy information may also apply.
This does not remove Turnpike’s responsibility for its own processing, its selection and use of providers, or any applicable shared responsibilities.
Our public website and commercial enquiries are directed at businesses and professional users, rather than children.
This does not mean that a customer deployment can disregard information relating to younger workers or other children. Where such processing occurs, the responsible organisation must address it in the relevant deployment assessment and privacy information.
16. Changes to this policy
We may update this policy when our processing activities, services or applicable requirements change.
The current version is published on this page with its revision date. Where a material change requires additional information, we will provide it in an appropriate way.
Before using personal data for a new purpose, we will provide the required information and establish the necessary legal basis.
Publishing an updated policy does not create consent or extend consent that you previously provided.