Vasaloppet’s data policy for personal information
CONTENTS

1. INTRODUCTION
2. PERSONAL DATA
3. WHAT PERSONAL DATA WE PROCESS AND WHY
3.1 If you have an account on My pages
3.2 When registering for a race
3.3 When you are a sponsor or partner of Vasaloppet
3.4 When you are a functionary in a Vasaloppet event
3.5 When you communicate with us
3.6 When participating in marketing activities or customer surveys
3.7 When using Vasaloppet’s website and apps
3.8 When you receive salary or other compensation from Vasaloppet
3.9 When we have a legal obligation
4. FOR HOW LONG WE STORE YOUR PERSONAL DATA
5. WHO WE GIVE ACCESS TO YOUR PERSONAL DATA
6. HOW WE PROTECT YOUR PERSONAL DATA
7. ABOUT COOKIES
8. YOUR RIGHTS
9. HOW TO OBJECT TO ELECTRONIC DIRECT MARKETING
10. CONTACT INFORMATION
11. UPDATES TO THE INFORMATIONAL TEXT

1. INTRODUCTION

This informational text explains how Vasaloppet, through Vasaloppsföreningen Sälen-Mora (884401-5886) and Vasaloppets Marknads AB (556299-8392), hereafter referred to jointly as “Vasaloppet”, handles your personal data, and what rights you have in regards to this. This information is directed at those who

  • participate in any of our races
  • are partners or sponsors
  • are functionaries
  • visit our website or our social media platforms and/or use our apps
  • participate in our marketing activities or customer surveys
  • communicate with us in any other way, for example via our customer service.

Your privacy is important to us. It is therefore in our interest that personal data gathered about you is stored and processed in a safe and secure way, and in accordance with data protection legislation.

We encourage you to read this information carefully. If you have any questions about how your personal data will be handled you are welcome to contact us. Our contact information can be found at the end of this informational text.

2. PERSONAL DATA

Personal data constitutes all information that can be connected to you directly or indirectly (that is, together with other information), such as your name, address, image, personal identity number or IP address.

3. WHAT PERSONAL DATA WE PROCESS AND WHY

3.1 If you have an account on My pages

In order to register for one of our races you need an account on My pages. When you create an account on My pages we process the following information, submitted to us by you:

  • Information about your account, such as username and password.
  • Your name, gender, nationality and contact information.
  • Your personal identity number.

As a registered account owner you are assigned a unique customer number (Vasa-ID).

We process your personal data in order to

  • identify you as an account owner, for example in customer service
  • determine who needs to fill in a Swedish personal identity number
  • administer different competition classes and races according to gender.

Legal basis for handling: The account owner gives Vasaloppet consent during the registration process.

Storage time: We save data about you and your account until you withdraw your consent. Among other things we use this information as a basis for race statistics and to count races (for active or upcoming veterans).

3.2 When registering for a race

When you register for a race Vasaloppet processes the following information, submitted to us by you:

  • Your name, gender, nationality, address and contact information.
  • Your personal identity number.
  • Information specific to the race, such as any club membership.
  • Information about payment and payment history.

As a registered participant you are assigned a unique customer number (Vasa-ID) and, later, a start number.

Vasaloppet processes your personal data in order to

  • identify you as an participant, for example in customer service and for timekeeping
  • determine who needs to fill in a Swedish personal identity number, and to keep statistics of the number of participating countries
  • administer different competition classes and races
  • charge the fee for your participation and any additional services
  • handle and deliver what you have paid for in accordance with our terms of registration, for example, providing you with trip or product you have bought
  • contact you (via My pages, app, SMS, email or similar electronic communication) before, during and after the race
  • offer personal service, such as photography, results and insurance
  • market our services and products, for example via email and SMS
  • keep statistics of our races and seasons
  • develop statistics concerning registrations with the goal of improving our range of products.

If you choose to pay for registration via invoice we also process personal data about you together with our payment delivery provider.

Legal basis for handling: The participant gives Vasaloppet consent during the registration process. Supported by a balance of interests, Vasaloppet uses participant information for statistics, personal service, and to market our races as well as secure payment.

Storage time: We save data about you and your participation until you withdraw your consent. Among other things we use this information as a basis for race statistics and to count races (for active or upcoming veterans).

3.3 When you are a sponsor or partner of Vasaloppet

For sponsors and partners GDPR will, among other things, mean that personal data assistant agreements will be made if data is exported to you from our participant database, or if any other personal data is shared. This will also mean that you are required to give consent when registering for activities, sponsor meet-ups, and more.

When you are a sponsor or partner of Vasaloppet we process the following data, submitted to us by you:

  • Name, professional role, employer and address information.

Vasaloppet processes your personal data in order to

  • make invitations to activities arranged by Vasaloppet
  • send out information concerning our events.

Legal basis for handling: Data processed by Vasaloppet about people from company sponsors or partners is determined during the contract process.

Storage time: We save data about you and the company you represent until you withdraw your consent.

3.4 When you are a functionary in a Vasaloppet event

When you are a functionary in any Vasaloppet event we process the following data, submitted to us by you:

  • Name, address, email, phone number, personal identity number, image, clothing size and company or organization connections.
  • Functionary roles in previous years.

Vasaloppet processes your personal data in order to

  • coordinate and manage functionary work in and around our events/races
  • send out information from Vasaloppet in preparation for events/races
  • send out Vasaloppet-related information and offers from our partners
  • send out information in preparation for Vasaloppet’s internal activities and meetings.

Legal basis for handling: The functionary gives consent to processing of personal data in connection with the signing of a functionary agreement, either with the individual functionary or functionary organization.

Storage time: We save data about you and the club you represent until you withdraw your consent.

3.5 When you communicate with us

You can choose to communicate with Vasaloppet in different ways, such as via social media or phone and email with our customer service.

When you communicate with us we process data about you, submitted by you, such as:

  • Name and contact information.
  • Information about your opinion, question or message.

We handle your personal information in order to

  • answer questions related to your matter, such as solving issues, handling complaints and questions about your race
  • deliver ordered information, services or products
  • improve our services and the information we provide and publish on our website
  • analyze conversations in order to improve our service.

Legal basis for handling: We process your personal data because of our, and your, justified interest in handling your matter (balance of interests).

Storage time: We save your personal information up to 24 months after the matter is resolved, in order to ensure traceability in your communication with us.

3.6 When participating in marketing activities or customer surveys

In connection to marketing activities (lectures, competitions, campaigns) or in connection to customer surveys (polls via phone, email or panels) we process the information submitted to us by you, including name and contact information.

We handle your personal information in order to

  • administer the marketing activity or customer survey, including making it possible to provide you with the results
  • inform about and offer new marketing activities and customer surveys
  • develop statistics from marketing activities and customer surveys, in order to improve our services.

Legal basis for handling: We process your personal data because of our, and your, justified interest as described above (balance of interests) and supported by agreements made when administering competitions. If our processing requires your consent, we will acquire your consent before the processing begins.

Storage time: As a base we store your personal information for one month after the activity is completed.

3.7 When using Vasaloppet’s website and apps

When you visit our website we process

  • information on how you interact with and use our website, through Google Analytics
  • information about your visit to our websites, through so-called cookies.

More information on how we use cookies

When using our apps you can choose to send logs to us if you’ve experienced technical issues. We then process information about your use of the app.

We process your personal data in order to

  • provide digital tools and services
  • give support when you are experiencing technical issues
  • maintain, test and improve our digital tools and services
  • discover and prevent security risks, such as virus attacks.

Legal basis for handling: We process your personal data supported by a balance of interests based on our justified interest in maintaining, testing and improving our digital tools and services.

Storage time: We save your personal information for one month after you have used our digital channels.

3.8 When you receive salary or other compensation from Vasaloppet

When you receive a salary or other compensation from Vasaloppet we process the following data, among other things, submitted to us by you:

  • Name, address, email, phone number, personal identity number.
  • Salary and tax information, bank account, emergency contacts.
  • Work duties, work times, absences, evaluations.
  • Other personal data necessary and relevant for Vasaloppet to administer the employment.

Vasaloppet processes your personal data in order to make employment contracts, pay salaries, and to report to agencies such as the Swedish Tax Agency, the Swedish Social Insurance Agency, and for any unemployment benefits.

Personal information will also be included in documents such as driving logs, budgets, time sheets, work schedules, contact information through phone support and potentially the website, lists of emergency contacts, participant lists for activities, and more.

Nordea is the bank Vasaloppet hires to pay salaries and compensations. For more on Nordea’s data protection policy see nordea.se.

Legal basis for handling: Personal data is stored partly to fulfil employment contracts and collective agreements, to follow legal requirements, or with a legal basis in a balance of interests.

Storage time: We store your personal data for as long as it is necessary for Vasaloppet to fulfil its obligations according to employment contracts and collective agreements, and to meet all its legal obligations, including any claims relating to labour legislation. Any personal data that is no longer needed will be discarded.

You have the right to know how your personal data is being processed. This means that you can request access to certain information regarding our data processing. You also have the right to request that incorrect data be rectified, that redundant processing is limited, that unfounded data processing be deleted, and to request to have your personal data moved from our system to a third party, though so-called data portability.

To find out more, contact Åsa Persson, Salary and Staff Administrator, asa.persson@vasaloppet.se or Karin Svärd, Administrative Manager, karin.svard@vasaloppet.se.

3.9 When we have a legal obligation

In addition to what is described above in some cases we also handle your personal data when required to do so by law, for example because of our accounting obligations, obligations related to traffic law, or when requested to do so by a government authority.

Legal basis: When processing your personal information because of a legal obligation, our actions are legally supported by that obligation.

4. FOR HOW LONG WE STORE YOUR PERSONAL DATA

Your personal data is stored for as long as is needed to fulfil the purpose of the handling, or as long as we are required to do so by law. Thereafter your data is deleted or made anonymous in a safe way, so it can no longer be connected to you. Read more about how long we save your data above under each section of chapter 3.

5. WHO WE GIVE ACCESS TO YOUR PERSONAL DATA

Vasaloppet may disclose your personal data to the following categories of recipients:

  • Suppliers (within the EU/EEA) that help Vasaloppet provide IT services for account management, race registration, and payment solutions.
  • External service providers who help Vasaloppet with communication solutions such as newsletters, participant surveys and scientific research.
  • Partners or sponsors who may offer you services and offers.
  • Your bank when identifying yourself via Bank-ID, paying via card or with Swish.
  • Other recipients when required to do so by law, other legal reasons, or decisions by government authorities.

Recipients who process personal data on Vasaloppet’s behalf shall always make a personal data assistant agreement with us in order for us to be able to ensure that your personal data is handled in a correct and secure way. If we use suppliers who handle your personal data on our behalf outside the EU/EEA we will take special security precautions, such as signing a deal that includes the standardized contract clauses for data transfer that have been approved by the European Commission and which are available on the European Commission website.

When your personal data is shared with a recipient that has an independent personal information responsibility, such as a government authority or a bank, the recipient’s privacy policy and information about personal data handling applies.

6. HOW WE PROTECT YOUR PERSONAL DATA

Your privacy is important to us, so safety is a major focus. We take precautions to protect your personal data in accordance with the data protection regulation as well as established guidelines for data security. This means that we have routines and rules in place surrounding data protection, for example transmitting your data in a safe way and ensuring that staff only have access to the data they need to perform their work. We also log events in our IT system and archive data without searchability when your personal information must be stored for a longer period of time (for example because of accounting laws).

7. ABOUT COOKIES

When you visit our website we may also collect information and data about you by the use of so-called “cookies”.

More information on how we use cookies

8. YOUR RIGHTS

You have certain rights in accordance with the data protection regulation:

  • Access to your personal data – you have the right to receive a confirmation of whether we are handling your personal data, and an account of what data we are handling.
  • Demand rectification – you have the right to have incorrect data corrected.
  • Demand deletion – you have the right to, under certain circumstances, have your data deleted.
  • Object to handling that supports itself on our justified interest, and to handling for direct marketing – you have the right to object to the handling of your personal data or to have the handling limited.
  • Right to data portability – you have the right to demand that your personal data is moved from us to another company, government authority or organization. This right is limited to the information that you yourself have submitted to us.

If you want to exercise any of these rights you can contact us via the contact information below.

If you want to know more about the data protection legislation and your rights you can read more on EUR-Lex.

eur-lex.europa.eu

If you should consider that our handling of your personal data is not in accordance with the data protection legislation then we ask you to contact us; see the section on contact information below. You also have the right to complain to the Swedish Data Protection Authority, an authority tasked with protecting individual privacy.

9. HOW TO OBJECT TO ELECTRONIC DIRECT MARKETING

Vasaloppet, or some of Vasaloppet’s sponsors or partners, may come to use your email or phone number for direct marketing. If you do not want us to use your email or phone number for direct marketing you are welcome to get in touch, and we will implement an advertising barrier on your data.

10. CONTACT INFORMATION

Vasaloppsföreningen Sälen-Mora (884401-5886) and Vasaloppets Marknads AB (556299-8392) are the organizations responsible for the processing of your personal data.

If you want additional information on how your personal data is processed, contact us through a written and personally signed request sent to:

Vasaloppets Hus
792 32 Mora

In the letter we wish you to designate your name, address, email, phone number and personal identity number, in addition to your message. Also attach a copy of your identification.

If you simply want to unsubscribe to our newsletter or no longer receive our magazine “Vasalöparen” at your home address you can contact us through +46 (0)250 – 392 00 or via info@vasaloppet.se.

11. UPDATES TO THE INFORMATIONAL TEXT

This informational text was last updated on May 20, 2018, and it is subject to change. If we make significant changes to this text there will be a new version published on our website.