Privacy Policy

1. Introduction and purpose

You should always feel safe when providing your personal data to ERIKS. For example, when you make a donation, contact us, or apply for a position, we process your personal data in accordance with the General Data Protection Regulation (GDPR). We only collect personal data necessary for our purposes, protect it appropriately, and delete it when it is no longer required. You may request access to your personal data, withdraw your consent, or request erasure of your data at any time.

This privacy policy concerns how we process personal data; other aspects of privacy, such as safety and how individuals are treated in our operations, are regulated in separate policy documents.

2. Data controllers and contact details

ERIKS consists of two separate entities:

  • ERIKS Development Partner (In Swedish: Insamlingsstiftelsen Farbror Eriks barn- och hjälpverksamhet) with org. no. 827500-4789
  • ERIKS Second Hand Association (In Swedish: Föreningen Erikshjälpen Second Hand) with org. no. 827501-1131

Each entity acts as an independent data controller for personal data processed within its own operations. In this policy, “ERIKS” refers collectively to both entities.

ERIKS Second Hand Association operates several stores under its organisation number. There are also partner stores with their own organisation numbers, operating in collaboration with Erikshjälpen Second Hand.

 

Contact details for data protection matters

If you have questions about what data we process about you, want to decline information or communication from us or exercise any of your other rights, you are welcome to contact us:

Personal data
Erikshjälpen
Datorgatan 4
561 33 Huskvarna
Email address: personuppgifter@erikshjalpen.se
Phone number: +46 383-46 74 50

Below you can read about what data we process about you, for what purpose we process your data and what legal basis we have for processing it.

3 Processing of personal data by ERIKS

The following processing activities are handled within both of ERIKS´ entities.

3.1 Application for a job, internship, volunteer position or youth fundraising ambassador

We process data about you when you apply to engage with us.

Data we process:

  • Name, personal identity number, postal address, email address, phone number
  • Information in your application such as CV, cover letter, education, work experience and references (if applicable)
  • Details of any interviews or conversations with you
  • Data that comes from an external party, e.g. The Swedish Public Employment Service, the probation service or other partners for internships (if applicable)
  • Information about the desired location, store or assignment (if applicable)

Purpose and legal basis:

  • Managing applications and evaluating candidates: Legitimate interests
  • Administration of the recruitment process: Legitimate interests
  • Collaborate with external actors (e.g. the Swedish Public Employment Service or the Probation Service) regarding internships: Legitimate interests

Justification of legitimate interests:

Based on a legitimate interests assessment, we process data in order to be able to handle applications in an efficient and correct manner.

Data retention period:

  • For applications for employment, the data is stored for a maximum of 24 months after the end of the recruitment process.
  • For applications for internships, volunteer positions or youth fundraising ambassador roles that do not result in a placement or assignment, the data is stored for a maximum of 12 months after the end of the process.

 

3.2 Newsletters and other direct mailings

We process personal data about you if you have registered that you wish to receive newsletters or other direct mailings from us.

This category only applies to mailings that you have actively chosen to receive.

If, on the other hand, you have a different engagement with us, for example as a donor, or have interacted with us in different ways, you may receive other types of mailings that are processed according to the respective category in this policy.

Data we process:

  • Name, postal address (for physical mailing), email address (for digital mailing)

Purpose and legal basis:

  • Distribution, newsletters or other mailings: Consent

Data retention period:

  • Data are stored until you notify us that you no longer want to receive the newsletter or mailing.

 

3.3 Complaints and whistleblowing

We process data about you if you submit a complaint or whistleblower alarm to us and you choose not to be anonymous.

Data we process:

  • Name, email address, phone number
  • Notification or report, in written or other format
  • Any attached documents or evidence
  • Communication history in the case
  • Information about persons or situations involved in the case

Purpose and legal basis:

  • Receiving, handling and following up on complaints and taking the necessary steps to improve our business: Legitimate interests
  • Receiving, handling and investigating whistleblower cases in accordance with applicable whistleblower legislation, including documentation and follow-up: Legal obligation

Justification of legitimate interests:

Based on a legitimate interests assessment, we process data in order to be able to receive, investigate and handle complaints and whistleblower cases in a correct manner to ensure the quality of our operations and protect both whistleblowers and interested parties.

Any unnecessary personal data provided in the notification will be deleted immediately.

Data retention period:

  • Data is stored up to 24 months after the case is closed.
  • In the event of serious reports that have led to disciplinary action or legal proceedings, the data may be stored for longer in accordance with applicable legislation.

 

3.4 Social media

We are active on social media platforms such as Facebook, Instagram, LinkedIn and TikTok to communicate about our work, create engagement and reach more people with our message.

Data we process:

  • Names, profile pictures, and usernames of people who interact with us
  • Content of comments, messages, and posts where we’re mentioned or tagged
  • Interaction data (likes, shares, comments)
  • Information you share with us via direct messages

Purpose and legal basis:

  • Communication and dialogue with followers and stakeholders, including answering questions, managing issues via direct messages, and moderating comments: Legitimate interests
  • Targeted communications and reach analysis: Legitimate interests

Justification of legitimate interests:

We have a legitimate interest in reaching out with information about our work, communicating with users and engaging more people to support our mission. We also analyze the reach and statistics of our posts, to ensure that we create relevant information and reach the right recipients.

Data retention period:

  • We continuously delete direct message conversations. In many cases, you can delete posts that you’ve created, liked or shared yourself.
  • Other data is stored in accordance with the terms and conditions of each platform.

We act as the data controller for the content on our social media accounts, while users are responsible for the content they post. We reserve the right to remove comments that we deem inappropriate.

 

3.5 Contact persons at organisations

We process information about you if you are a contact person at an organisation that is a donor, supplier or partner of ERIKS.

Data we process:

  • Name, email address, phone number, role or job title

Purpose and legal basis:

  • Administration of the relationship between our organisations: Legitimate interests

Justification of legitimate interests:

Based on a legitimate interests assessment, we process data for the purpose of being able to administer the gift or relationship between your organisation and ERIKS.

Data retention period:

  • Data is stored for the duration of the collaboration and for up to 12 months afterwards, or until a new contact person is appointed.
  • If your company or organisation has made a donation to ERIKS, we will save the data for 36 months after the last donation.

4 Processing of personal data by ERIKS Development Partner

4.1 Donors

We collect personal data when you make a donation in the form of money, buy a gift certificate, launch your own fundraising campaign or contact our donor services.

Data we process:

  • Name, personal identity number, postal address, email address, phone number
  • Donation amount, payment history, payment method, bank account number (in case of direct debit)
  • Donor ID, communication history, free-text comments

Purpose and legal basis:

  • Handling of contractual donations: Performance of a contract
  • Handling of one-time donations: Legitimate interests
  • Accounting and reporting: Legal obligation
  • Donor services, follow-up and analysis: Legitimate interests
  • Information, communication and invitations: Legitimate interests

Justification of legitimate interests:

Based on a legitimate interests assessment, we process data to streamline administration, reducing costs and being able to provide information about our work in a relevant and transparent manner. This means that we can strengthen and help more children and families.

Data retention period:

  • Name, donation amount, date and any OCR number or message are stored for 7 years according to The Swedish Accounting Act.
  • Other information is stored for as long as you are a donor and for 36 months after your last donation.

 

4.2 Potential donor – existing contact

We may process your personal data if you have interacted with us and we assess that you might be interested in supporting our work. The data may come from yourself, from events we organize, quizzes you have completed, products you have purchased from us or any other contact with us.

Data we process:

  • Name, personal identity number, postal address, email address, phone number

Purpose and legal basis:

  • Contact to inform you about our work and to ask whether you would like to make one-time or recurring donations: Legitimate interests

Justification of legitimate interests:

Based on a legitimate interests assessment, we process data for the purpose of identifying and contacting people who might be interested in supporting our work based on previous interactions with us.

Data retention period:

  • Up to 12 months after last contact

 

4.3 Potential donor – new contact

We are actively looking for new people who might be interested in supporting our work by learning more about our organisation and our purpose. In order to identify and reach out to potential new donors, we process personal data that is purchased from external sources (such as SPAR, the Swedish State Personal Address Register) or retrieved from public news sources, where we assess that people may be interested in our work.

Data we process:

  • Name, personal identity number, postal address, email address, phone number

Purpose and legal basis:

  • Contact to inform you about our work and to ask whether you would like to make one-time or recurring donations: Legitimate interests

Justification of legitimate interests:

Based on a legitimate interests assessment, we process data for the purpose of identifying and contacting people who may be interested in supporting our work.

Data retention period:

  • Up to six months for purchased data for a specific activity

 

4.4 Wills

We may process information about you if you have entered or shown interest in entering ERIKS in your will.

Data we process:

  • Name, personal identity number, postal address, email address, phone number

Purpose and legal basis:

  • Monitoring ERIKS´ rights according to wills: Legitimate interests
  • Donor services, follow-up and analysis: Legitimate interests
  • Information, communication and invitations: Legitimate interests

Justification of legitimate interests:

Based on a legitimate interests assessment, we process data for the purpose of monitoring wills that may benefit us. We may also inform about our work to raise more money that allows us to strengthen and help more children and families in vulnerability.

Data retention period:

  • Until the will takes effect or ERIKS ceases to be a beneficiary
  • Up to 12 months after the last contact if you have shown interest in making a will to ERIKS

 

4.5 Recipients of gift certificates

We process information about you if you receive a gift certificate.

Data we process:

  • Name, postal address, email address, phone number

Purpose and legal basis:

  • Prepare and administer gift certificates: Legitimate interests

Justification of legitimate interests:

Based on a legitimate interests assessment, we process data for the purpose of being able to administer the donation and issuing the gift certificate.

Data retention period:

  • 12 months after the gift certificate was created

5 Personal data processing by ERIKS Second Hand Association

5.1 Pick-up and delivery of goods

We process information about you when you order pick-up of donated goods or delivery of purchased goods to/from our second-hand shops.

Data we process:

  • Name, pick-up address, email address, phone number

Purpose and legal basis:

  • Administer and carry out pick-up or delivery of goods: Legitimate interests

Justification of legitimate interests:

Based on a legitimate interests assessment, we process personal data to efficiently and correctly administer and execute the collection and delivery of goods to and from our second-hand stores.

Data retention period:

  • The data is stored for up to 12 months after the collection or delivery has been completed.

 

5.2 Invoice purchases in stores

We process your personal data when you, as a contact person for a company or organisation, purchase goods in our stores and pay via invoice.

Data we process:

  • Name, email address, phone number, personal identity number

Purpose and legal basis:

  • Managing invoice purchase and payment: Performance of a contract
  • Customer service and support: Legitimate interests
  • Bookkeeping and accounting: Legal obligation

Justification of legitimate interests:

Based on a legitimate interests assessment, we process data in order to be able to provide customer service and handle any questions about the purchase.

Data retention period:

  • Personal data are stored for up to 24 months following the most recent purchase, or for the duration of any agreement we have with the company or organisation to purchase on invoice.
  • Personal data may also appear in invoice documentation and order information that is stored for 7 years according to The Swedish Accounting Act.

 

5.3 Camera surveillance in stores

Our stores are monitored by cameras (CCTV) to help prevent crime, ensure safety, and support the investigation of incidents. Surveillance is carried out only in areas where the business need outweighs an individual’s right to privacy. Access to the footage is restricted to authorised personnel.

Data we process:

  • Image and video material in which individuals can be identified
  • Information from notifications or reports of incidents, including communication history

Purpose and legal basis:

  • Prevent, detect and investigate thefts and incidents in stores, and possibly hand over material to the police during criminal investigations: Legitimate interests
  • Maintaining order and safety for customers and staff: Legitimate interests

Justification of legitimate interests:

Our legitimate interests are to protect customers, employees and the business against crime and to create a safe environment in the store. Camera surveillance is a proportionate and effective tool for detecting and investigating incidents and is only used where a balancing of interests shows that the security benefits outweigh the individual’s privacy interest.

Data retention period:

  • Recorded material is normally stored for up to 30 days.
  • In the event of suspicion of a crime or other incident, the material may be stored for longer as long as it is needed to investigate the incident or comply with legal requirements.

6 Updating and completing personal data

We supplement information in our donor database with addresses, personal identity numbers and gender from registers such as the Swedish Tax Agency, SPAR (the Swedish State Personal Address Register) and other reliable external information services. The aim is to always have as up-to-date information as possible in order to be able to target information to existing and potential donors and avoid sending information to the wrong person. This means that we may hold information about your name, personal identity number, address and phone number in our database even if, for example, you have donated via Swish without providing this information. If we notice that several donors live at the same address, we record this to avoid sending multiple mailings to the same household.

We are also actively looking for people who may be interested in supporting our work with a larger donation. In such cases, we may supplement information about you with data such as income, education, occupation, interests, and engagement. This is done to better understand donor behaviour and to tailor our communications in a relevant and appropriate manner. The data is stored for a maximum of 12 months. If you choose to make a larger donation, we may store the data for longer, for as long as it is necessary to administer the donation and maintain our ongoing relationship with you.

7 Who do we disclose the data to?

Your personal data will be processed by ERIKS. In addition, your personal data may be shared with third parties who process personal data on our behalf, so-called data processors. We ensure that a data processing agreement is always in place whenever a third party processes personal data on our behalf. We may provide access to your personal data to IT and system providers, banks, payment service providers, web agencies, printing companies, and telemarketing companies, to the extent necessary to perform the requested services. In certain cases, we may share information such as your name and email address with social media providers in order to target marketing to you and to share information about our work.

8 Is the data stored in countries outside the EU or EEA (third country)?

As a general rule, we and our suppliers and partners only process your personal data within the EU/EEA. In cases where personal data is processed outside the EU/EEA (in a “third country”), there is either a decision from the European Commission that the third country in question ensures an adequate level of protection for the processing of personal data or other appropriate safeguards under the GDPR, for example in the form of standard contractual clauses that ensure that your rights are protected.

9 What are your rights?

In accordance with applicable data protection legislation, you have the right to access information about the personal data we process about you, as well as the right to request correction of your personal data.

Under certain circumstances, you have the right to request erasure of your personal data, restriction of processing, or to object to processing. You also have the right, under certain conditions, to data portability. This means you may receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format, and you have the right to transfer that data to another data controller.

You have the right to withdraw your consent to the processing of your personal data at any time, with effect from the date of withdrawal. You also have the right to object at any time to the processing of your personal data for direct marketing and profiling.

Should you have any complaints regarding our processing of your personal data, you can use our complaint form available on our website, erikshjalpen.se. It is also possible to send an email to complaints@erikshjalpen.se. It is also possible to file a complaint with the Swedish Authority for Privacy Protection (in Swedish: Integritetsskyddsmyndigheten), which monitors the processing of personal data.

10 Safety

10.1 How do we work with IT security?

We and our partners continuously update firewalls and antivirus software to protect your data and prevent unauthorised access. Only staff with authorized accounts and passwords have access to the spaces and systems where the personal data is stored. Our employees are also strictly instructed to handle all personal data in accordance with applicable laws and regulations.

 

10.2 What is a cookie?

ERIKS uses cookies to create the best possible experience on our website erikshjalpen.se. Cookies are small text files that are stored on your computer and contain data from websites that you have visited. The aim is to give visitors access to various functions and facilitate browsing. The next time you visit the same website, it can read your cookie and display the pages according to your settings.

For more information see erikshjalpen.se/cookies.

 

10.3 Are we responsible for external links?

ERIKS´ material may contain links to external websites or services that are not under our control. If you follow a link to an external website, you will be asked to read the privacy principles and cookie information that apply to the page in question.

Publicerad: 09 januari 2026

Betala med Swish genom att skanna QR-koden

QR kod Erikshjälpen
Gör så här:
  1. Öppna Swish-appen.
  2. Tryck på “Skanna” och rikta kameran över QR-koden.
  3. Bekräfta och signera betalningen med mobilt BankID.