Get answers to common questions about our privacy practices, data protection, and your rights in our Privacy FAQ.

1. WHO IS CONSIDERED DATA CONTROLLER OF THE INFORMATION COLLECTED THROUGH ATTENSI’S SYSTEMS?

It is Attensi’s customers who are data controllers for the information collected through the use of Attensi’s platform. Attensi’s customers use the platform for the purpose of performing internal training of own employees or customers, suppliers or other relevant third parties. Thus, the customer determines the purpose and means of the processing – which is the definition of data controller.

Attensi is a data processor. Attensi will, in order to run the platform, have access to end users’ personal data. Attensi will only process the end users’ information on behalf of the customer and in compliance with its lawful instructions and the processing agreement entered into with the customer.

2. INFORMATION ATTENSI COLLECT FROM END USERS

What information Attensi collects from end users will vary based on customer needs and the relevant platform. In general, the Attensi platform will require the following information:

  • Information about the end user: may include name, title/position, email, phone number, employers name, etc. depending on the specific requirements for use of the platform from case to case.
  • Information about the end user’s use of the platform: in particular performance data resulting from training sessions and competence development performed in connection with the platform or as preparation for use of the platform. This may also include information submitted in relation to enquiries related to the platform, terms of use etc.
  • IP addresses and other information about the end users’ computers: as a visitor on our website/platform, the end user will as a main rule remain anonymous. The data Attensi stores and analyzes is used for statistical purposes only, for instance to ensure the continuous improvement of the services provided. The collected data comprises the name of the internet service provider, the website from which the end user visited the Attensi website, which Attensi website the end user has viewed, the end user’s IP address and the date and duration of the visit. Attensi does not link the IP address to a specific person. Please refer to the cookie-section below for more information.
  • Cookies; we use cookies and other methods to enhance the user experience and optimize the Service. Please refer to our Cookie Policy, which is available here: [link] or provided as a separate document.

3. WILL ATTENSI PROCESS SENSITIVE INFORMATION?

Attensi will not process sensitive personal data.

4. WILL PERSONAL DATA BE ENCRYPTED

Yes, all personal data is encrypted both in transit (using HTTPS and SSL/TLS) and at rest (using AES-256).

Purpose Legal basis

To enable use of the platform

  1. Consent
  2. In order to fulfill the agreement with the end user

To respond to questions or inquiries

  1. Consent

To improve the platform, the content of the platform and the user experience

  1. Consent
  2. Legitimate interest, e.g. to change technical settings based on user feedback or patterns of use, in order to improve the user experience, provided that the processing is not overridden by the end user’s interests.
  3. By use of anonymized data

To notify end users of changes to the platform, the applicable terms of use or privacy policy

  1. Consent
  2. In order to fulfill an agreement with the end user

To identify and provide content that is relevant to any particular user or group of users (if requested by the customer)

  1. Consent
  2. In order to fulfill an agreement with the end user

To send email, push or SMS notices that the end user has signed up for (if requested by the customer)

  1. Consent

To enable investigations, prevention and protection against violations of rules related to the use of the platform, fraud or other potential threats to the customer or third parties´ rights

  1. Legitimate interest, e.g. to prevent loss or damages to the customer, end users or any other third parties, to prevent any actions that may compromise the customer or a third party’s property or the personal data of the other users of the platform, or to pursue or defend a legal interest.
  2. Legal obligations

To comply with all applicable rules and regulations

  1. Legal obligations

For any other purposes, permitted by consent or as permitted or required by law, rule, regulation or any other legal process

  1. Consent
  2. Legal obligations

8. THE USERS RIGHT TO ACCESS INFORMATION STORED ABOUT THEM

The end users have the right to information about what personal data that is registered in the platform, to change or update the stored data, correct any errors in that data and to request that unnecessary data is erased. All requests related to registered information about the end user, shall be directed to the customer who shall forward such requests to Attensi.

9. OTHER RIGHTS FOR THE DATA SUBJECTS

The end user is also entitled to:

  1. request information about the end user’s right to restrict processing or object to processing under certain circumstances; or
  2. request information about the end user’s right to data portability, i.e. the right to obtain, reuse and transfer personal data provided to Attensi to another IT environment.

All such requests shall be directed to the customer, who shall provide the requested information to the end user, and – if necessary – forward any request of restriction of processing or data portability to Attensi.

10. WHO HAS ACCESS TO THE INFORMATION IN THE PLATFORM?

Employees and data processors engaged by Attensi may have access to the personal data processed in relation to the platform, depending on their roles and tasks.

Attensi has established internal access routines, ensuring that employees only access personal data on a need to know-basis, meaning that only employees that who require access in order to perform their duties shall have access to end user’s personal data.

Attensi enters into data processing agreements with their data processor, limiting their use and access to personal data to the purpose of fulfilling their obligations towards Attensi. Attensi’s current data processor(s) only provide hosting services and should not access and use personal data stored in the platform.

11. WHAT SORT OF REPORTS WILL ATTENSI AND/OR THE CUSTOMER BE ABLE TO OBTAIN FROM THE SYSTEM?

Which information that will be included in the reports provided by the platform, will depend on the purpose of the relevant platform and the customers’s choice. In general, the Attensi platform provides reports containing playthrough data for the individual end user resulting from training sessions on the platform. The customer will receive reports on an aggregate level, e.g. confirming which end users that have completed which tests, the associated scoring, achievements, feedback etc. The customer will decide which individuals in the organisation that will receive reports and what level of information the reports shall contain.

12. WHAT ARE ATTENSI’S ROUTINES FOR REPORTING OF BREACHES IN THE SYSTEM?

Attensi, as data processor, shall notify the controller without undue delay after becoming aware of a personal data breach.

Attensi has internal routines for frequent review of security systems, virus protection etc. that allows Attensi to detect any unauthorised access, disclosure, modification etc. to the personal data stored in relation to the platform.

13. HOW LONG WILL THE INFORMATION BE STORED BY ATTENSI?

Attensi will retain the end user’s personal data for as long as it is necessary to fulfil the purposes for processing as defined above, and will as a main rule, delete all personal data upon an end user’s request for cancellation or withdrawal of consent, or upon the customer’s termination of the service agreement.

Continued storage will only occur in case legal obligations requires such storage, e.g. statutory rules related to storage for accounting purposes. Continued storage may also occur where such storage is necessary for the purposes of legitimate interests pursued by the customer, Attensi or third parties, including, but not limited to the establishment, exercise or defence of legal claims.

Attensi has routines for deletion, and will frequently delete personal data that are no longer necessary to fulfil the above purposes, or for end users who has cancelled the registration on the platform.

14. HOW WILL THE INFORMATION BE STORED?

Attensi currently uses Amazon Web Services for hosting services. The data from the platform are stored at redundant databases at Amazon’s servers placed in Frankfurt.

15. DOES ATTENSI USE ANY DATA PROCESSORS?

Yes, Attensi uses data processors. List of approved sub-processors can be found here.

16. WILL ATTENSI STORE OR TRANSFER INFORMATION OUTSIDE THE EU/EEA?

Attensi does currently not store or transfer personal data outside the EU/EEA. Attensi uses Amazon Web Services and Microsoft Azure as sub-processors. Under the current agreements, Amazon and Microsoft are not entitled to store or transfer any personal data outside EU/EEA. If transfer or storage outside the EU/EEA becomes necessary, Attensi will take all reasonable precautions to ensure an adequate level of protection for the personal data.

17. HAS ATTENSI IMPLEMENTED TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE AN APPROPRIATE LEVEL OF SECURITY FOR THE USER’S PERSONAL DATA?

Attensi has taken reasonable and proportionate steps to protect the user’s privacy, including physical, technical and organisational measures, to prevent loss, alterations, theft and unauthorized access to information stored and otherwise processed in relation to the platform.

Please refer to the separate document (“Security attachment”) containing a general description of technical and organisational measures implemented by Attensi to ensure an appropriate level of security.

18. QUESTIONS – CONTACT – MORE INFORMATION

Any questions to this FAQ-document can be directed to Attensi’s dedicated privacy email: dataprivacyofficer@attensi.com

For more information about how personal data will be processed in relation to the Attensi platform, please refer to Attensi’s privacy policy: here.


Last updated: 2018-11-23
© 2012-2024