In Erikshjälpen's privacy policy, you can read about how we ensure that your personal data is processed in accordance with the General Data Protection Regulation (GDPR). This privacy policy has been decided by Erikshjälpen's board and is valid from November 28, 2025.

1. Introduction and purpose

You should always feel secure when you provide your personal data to Erikshjälpen. When you make a donation, contact us, or apply for a job with us, for example, we process your personal data in accordance with the General Data Protection Regulation (GDPR). We only collect what we need, protect the data, and delete it when we no longer need it. You can always request access to your personal data, withdraw your consent, or ask us to delete your data.

This privacy policy concerns how we process personal data; other aspects of privacy, such as security and treatment in our operations, are regulated in separate policy documents.

2. Data controllers and contact details

There are two different areas of activity under the name Erikshjälpen:

  • The Erikshjälpen Foundation (Fundraising Foundation Uncle Erik's Children's and Aid Work, organization number 827500-4789)
  • The Erikshjälpen Second Hand Association (organization number 827501-1131)

Each branch of activity is independently responsible for the processing of personal data within its own operations. In this policy, the collective name Erikshjälpen is used to describe both of these branches of activity together.

The Erikshjälpen Second Hand association Erikshjälpen Second Hand several stores under its organization number. In addition, there are a number of partner stores with their own organization numbers that operate second-hand stores in collaboration with the Erikshjälpen Second Hand association. The partner stores are independent businesses and are responsible for the personal data processed in their stores.

 

Contact us

If you have any questions about what information we process about you, wish to decline information or communication from us, or wish to exercise any of your other rights, please feel free to contact us:

Personal data
Erikshjälpen
Datorgatan 4
561 33 Huskvarna
Email: personuppgifter@erikshjalpen.se
Phone: 0383-46 74 50

Below you can read about what information we process about you, for what purpose we process your information, and what legal basis we have for processing it.

3. Personal data processing within Erikshjälpen

These treatments are handled within both of Erikshjälpen's areas of operation.

3.1 Application for a job, internship, Volunteer, or recruitment assignment

We process information about you when you apply to work with us.

Data we process:

  • Name, personal identification number, postal address, email address, telephone number
  • Information in your application such as your CV, cover letter, education, work experience, and references (if applicable)
  • Information from any interviews or conversations with you
  • Information provided by an external party, such as the Employment Service, probation service, or other partner involved in the internship placement.
  • Information about desired placement, store, or assignment (if applicable)

Purpose and legal basis:

  • Processing applications and evaluating candidates: Legitimate interest
  • Administration of the recruitment process: Legitimate interest
  • Collaborate with external actors (e.g., the Employment Service or probation service) in relation to work placements: Legitimate interest

Explanation of legitimate interest:

Based on a balancing of interests, we process data for the purpose of handling applications efficiently and correctly.

Storage time:

  • For job applications, the data is stored for a maximum of 24 months after the recruitment process has been completed.
  • For applications for internships, Volunteer or recruitment assignments that do not lead to placement or assignment, the data is stored for a maximum of 12 months after the process is completed.

 

3.2 Newsletters and other mailings

We process personal data about you if you have yourself indicated that you wish to receive newsletters or other mailings from us.

This category only includes mailings that you have actively consented to.

If you have another relationship with us, for example as a donor, or have interacted with us in various ways, you may receive other types of mailings that are handled according to the respective category in this policy.

Data we process:

  • Name, postal address (for physical mailings), email address (for digital mailings)

Purpose and legal basis:

  • Distribution of newsletters or other mailings: Consent

Storage time:

  • Until you notify us that you no longer wish to receive the newsletter or mailing

 

3.3 complaint Whistle blowing

We process information about you if you submit a complaint whistleblower report to us and you choose not to remain anonymous.

Data we process:

  • Name, email address, phone number
  • Notification or report in text or other format
  • Any attached documents or evidence
  • Communication history in the case
  • Information about persons or situations involved in the case

Purpose and legal basis:

  • Receiving, handling, and following up on complaint taking necessary measures to improve our operations: Legitimate interest
  • Receive, handle, and investigate whistleblower cases in accordance with applicable whistleblower legislation, including documentation and Monitoring: Legal obligation

Explanation of legitimate interest:

Based on a balancing of interests, we process data for the purpose of receiving, investigating, and handling complaint whistleblower cases in an appropriate manner to ensure the quality of our operations and protect both the whistleblower and the parties involved.

Any unnecessary personal data provided in the notification will be deleted immediately.

Storage time:

  • Up to 24 months after the case has been closed
  • In the case of serious reports that have led to disciplinary measures or legal proceedings, the information may be stored for longer in accordance with applicable legislation.

 

3.4 Social media

We are active on social media platforms such as Facebook, Instagram, LinkedIn, and TikTok to communicate about our work, generate engagement, and reach more people with our message.

Data we process:

  • Names, profile pictures, and usernames of people who interact with us
  • Content in comments, messages, and posts where we are mentioned or tagged
  • Interaction data (likes, shares, comments)
  • Information you share with us via direct messages

Purpose and legal basis:

  • Communication and dialogue with followers and stakeholders, including responding to questions, handling matters via direct messages, and moderating comments: Legitimate interest
  • Target group-specific communication and analysis of reach: Legitimate interest

Explanation of legitimate interest:

We have a legitimate interest in disseminating information about our work, communicating with users, and engaging more people in our activities. We also analyze the reach and statistics of our posts to ensure that we are creating relevant information and reaching the right audience.

Storage time:

  • We delete ongoing conversations via direct messages. In many cases, you can delete posts that you have created, liked, or shared yourself.
  • Other data is stored in accordance with the terms and conditions of the respective platform.

Erikshjälpen is responsible for the content on our social media accounts, but you as a user are responsible for what you write. We reserve the right to remove comments that we deem inappropriate.

 

3.5 Contact persons at organisations

We process information about you if you are a contact person for an organization that is a donor, supplier, or partner of Erikshjälpen.

Data we process:

  • Name, email address, phone number, role or position

Purpose and legal basis:

  • Administration of the relationship between our organisations: Legitimate interest

Explanation of legitimate interest:

Based on a balancing of interests, we process data for the purpose of administering the donation or managing the relationship between your organization and Erikshjälpen.

Storage time:

  • Data is stored during the collaboration and for up to 12 months afterwards, or until we have a new contact person.
  • If your Corporate organization has made a donation to Erikshjälpen, we will store the information for 36 months after the last donation.

4. Personal data processing within the Erikshjälpen Foundation

4.1 Gift givers

We collect personal information when you make a monetary donation, purchase a gift certificate, start a fundraiser contact our donor services.

Data we process:

  • Name, personal identification number, postal address, email address, telephone number
  • Gift amount, payment history, payment method, bank account number (for autogiro)
  • Donor ID, communication history, free text comments

Purpose and legal basis:

  • Handling of contractual gifts: Agreements
  • Handling of one-time donations: Legitimate interest
  • Accounting and reporting: Legal obligation
  • Donor services, Monitoring analysis: Legitimate interest
  • Information, communication, and invitations: Legitimate interest

Explanation of legitimate interest:

Based on a balancing of interests, we process data for the purpose of streamlining administration, reducing costs, and being able to provide information about our work in a relevant and transparent manner. This enables us to strengthen and help more children and families in vulnerable situations.

Storage time:

  • Names, gift amounts, dates, and any OCR numbers or messages are stored for 7 years in accordance with the Accounting Act.
  • Other information is stored for as long as you are a donor and for 36 months after your last donation.

 

4.2 Potential donor – existing contact

We may process your personal data if you have interacted with us and we believe that you may have an interest in supporting our activities. The data may come from you, from events we organize, quizzes you have completed, products you have purchased from us, or other contact with us.

Data we process:

  • Name, personal identification number, postal address, email address, telephone number

Purpose and legal basis:

  • Contact us to learn more about our activities and ask if you would like to make a one-time or regular donation: Legitimate interest

Explanation of legitimate interest:

Based on a balancing of interests, we process data for the purpose of identifying and contacting individuals who may be interested in supporting our work based on previous interactions with us.

Storage time:

  • Up to 12 months after last contact

 

4.3 Potential donor – new contact

We actively seek out new individuals who may be interested in supporting our activities by learning more about our organization and our purpose. In order to identify and reach out to potential new donors, we process personal data that is, for example, purchased from external sources (such as SPAR) or obtained from public news sources, where we believe individuals may be interested in our work.

Data we process:

  • Name, personal identification number, postal address, email address, telephone number

Purpose and legal basis:

  • Contact us to learn more about our activities and ask if you would like to make a one-time or regular donation: Legitimate interest

Explanation of legitimate interest:

Based on a balancing of interests, we process data for the purpose of identifying and contacting individuals who may be interested in supporting our work.

Storage time:

  • Up to six months for purchased data for a specific activity

 

4.4 Wills

We may process information about you if you have registered or expressed interest in registering Erikshjälpen in your will.

Data we process:

  • Name, personal identification number, postal address, email address, telephone number

Purpose and legal basis:

  • Monitor Erikshjälpen's rights under wills: Legitimate interest
  • Donor services, Monitoring analysis: Legitimate interest
  • Information, communication, and invitations: Legitimate interest

Explanation of legitimate interest:

Based on a balancing of interests, we process data for the purpose of monitoring wills that may be left to us. We may also provide information about our work to raise more money so that we can strengthen and help more children and families in vulnerable situations.

Storage time:

  • Until the will is executed or Erikshjälpen ceases to be the beneficiary of the will.
  • Up to 12 months after your last contact if you have expressed interest in include us in your Will Erikshjälpen

 

4.5 Recipients of gift certificates

We process information about you if you receive a gift certificate.

Data we process:

  • Name, mailing address, email address, telephone number

Purpose and legal basis:

  • Establish and administer gift certificates: Legitimate interest

Explanation of legitimate interest:

Based on a balancing of interests, we process data for the purpose of administering the gift and sending the gift certificate.

Storage time:

  • 12 months after the gift certificate was created

5. Processing of personal data within the Erikshjälpen Second Hand association

5.1 Collection and delivery of goods

We process information about you when you order the collection of donated goods or the delivery of purchased goods to/from our second-hand stores.

Data we process:

  • Name, pickup address, email address, phone number

Purpose and legal basis:

  • Managing and carrying out the collection or delivery of goods: Legitimate interest

Explanation of legitimate interest:

Based on a balancing of interests, we process data for the purpose of administering and carrying out the collection and delivery of goods to/from our second-hand business in an efficient and correct manner.

Storage time:

  • The data is stored for up to 12 months after completion of collection/delivery.

 

5.2 In-store invoice purchases

We process information about you when you, as a contact person for a Corporate organization, shop in our stores and pay by invoice.

Data we process:

  • Name, email address, phone number, social security number

Purpose and legal basis:

  • Manage invoice purchases and payments: Agreements
  • Customer service and support: Legitimate interest
  • Accounting and reporting: Legal obligation

Explanation of legitimate interest:

Based on a balancing of interests, we process data for the purpose of providing customer service and handling any questions regarding the purchase.

Storage time:

  • Personal data is stored for a maximum of 24 months after the last purchase or for as long as we have an agreement with the company/organization to purchase on invoice.
  • Personal data may also be included in invoice documentation and order information, which is stored for seven years in accordance with the Accounting Act.

 

5.3 Camera surveillance in stores

We use CCTV surveillance in our stores to prevent crime, create a safe environment, and enable the investigation of incidents. Surveillance is only used in areas where the business's need for CCTV surveillance outweighs the individual's interest in personal privacy. Only authorized personnel have access to the footage.

Data we process:

  • Image and video material in which individuals can be identified
  • Information from incident reports or notifications, including communication history

Purpose and legal basis:

  • Preventing, detecting, and investigating theft and incidents in stores, and possibly handing over material to the police in criminal investigations: Legitimate interest
  • Maintaining order and safety for customers and staff: Legitimate interest

Explanation of legitimate interest:

Our legitimate interest is to protect customers, employees, and the business against crime and to create a safe environment in the store. Camera surveillance is a proportionate and effective tool for detecting and investigating incidents, and is only used where a balancing of interests shows that the security benefits outweigh the individual's privacy interests.

Storage time:

  • Recorded material is normally stored for up to 30 days.
  • In the event of suspected crime or other incident, the material may be stored for longer as long as necessary to investigate the incident or comply with legal requirements.

6. Completion of information

We supplement the information in our donor database with addresses, personal identification numbers, and gender from registers such as the Swedish Tax Agency, SPAR (the Swedish Personal Address Register), and other reliable external information services. The purpose is to always have the most up-to-date information possible in order to target information to existing and potential donors and avoid sending information to the wrong person. This means that we may have information about your name, personal identification number, address, and telephone number in our database even if, for example, you have donated via Swish without providing this information. If we see that several donors live at the same address, we also note this so that we do not send multiple mailings to the same household.

We are also actively seeking individuals who may be interested in supporting our activities with a larger donation. We may then supplement information about you with, for example, income details, education, occupation, interests, and commitments. This is done in order to better understand donor behavior and to be able to tailor our communication in a relevant and appropriate manner. The information is stored for a maximum of 12 months. If you choose to make a larger donation, we may store the information for longer, as long as it is necessary to administer the donation and our ongoing relationship with you.

7. Who do we disclose the information to?

Your personal data will be processed by Erikshjälpen. In addition, your personal data may be shared with third parties who process personal data on our behalf, known as personal data processors. We ensure that there is always a data processing agreement in place in situations where a third party processes personal data on our behalf. We disclose or allow IT and system suppliers, banks, payment services, web agencies, printing companies, and telemarketing companies to access your personal data that is necessary to perform the tasks requested.

In some cases, we provide name and email address information to social media providers in order to target marketing to you and disseminate information about our business.

8. Is the data stored in countries outside the EU or EEA (third countries)?

As a general rule, we and our suppliers and partners only process your personal data within the EU/EEA. In cases where personal data is processed outside the EU/EEA (in "third countries"), there is either a decision by the European Commission that the third country in question ensures an adequate level of protection for the processing of personal data or other appropriate safeguards under the GDPR, for example in the form of standard contractual clauses that ensure that your rights are protected.

9. What are your rights?

In accordance with the applicable data protection legislation, you have the right to access information about what personal data we process about you and the right to request rectification of your personal data.

Under certain conditions, you also have the right to request erasure of personal data or restriction of processing of your personal data or to object to our processing. You also have the right, under certain conditions, to obtain the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format and have the right to transmit it to another controller.

You have the right to withdraw your consent to the processing of your personal data at any time with effect from the moment of withdrawal. You also have the right to object at any time to the processing of your personal data for direct marketing and profiling purposes.

If you have any complaint our processing of your personal data, you can use our complaint form available on our website, erikshjalpen.se. You can also send an email to complaints@erikshjalpen.se. It is also possible to submit a complaint the Swedish Data Protection Authority, which oversees the processing of personal data.

 

10. Security

10.1 How do we work with IT security?

We and our partners work continuously to keep firewalls and antivirus software up to date to protect and prevent unauthorized access to your data. Only personnel with authorized accounts and passwords have access to the areas and systems where personal data is stored. Our employees also have strict instructions to handle all personal data in accordance with applicable laws and regulations.

 

10.2 What is a cookie?

Erikshjälpen uses cookies to create the best possible experience on our website erikshjalpen.se. Cookies are small text files that are stored on your computer and contain data from websites you have visited. The purpose is to give visitors access to various functions and make browsing easier. The next time you visit the same website, it can read your cookie and display the pages according to your settings.

For more information, see erikshjalpen.se/cookies.

 

10.3 Are we responsible for external links?

Erikshjälpen's information material may sometimes contain links to external websites or services that we do not control. If you follow a link to an external website, you are encouraged to read the principles for personal data processing and information about cookies that apply to the page in question.

1. introduction and purpose

You should always feel safe when providing your personal data to ERIKS. For example, when you make a donation, contact us, or apply for a position, we process your personal data in accordance with the General Data Protection Regulation (GDPR). We only collect personal data necessary for our purposes, protect it appropriately, and delete it when it is no longer required. You may request access to your personal data, withdraw your consent, or request erasure of your data at any time.

This privacy policy concerns how we process personal data; other aspects of privacy, such as safety and how individuals are treated in our operations, are regulated in separate policy documents.

2. Data controllers and contact details

ERIKS consists of two separate entities:

  • ERIKS Development Partner (In Swedish: Insamlingsstiftelsen Farbror Eriks barn- och hjälpverksamhet) with org. no. 827500-4789
  • ERIKS Second Hand Association (In Swedish: Föreningen Erikshjälpen Second Hand) with org. no. 827501-1131

Each entity acts as an independent data controller for personal data processed within its own operations. In this policy, “ERIKS” refers collectively to both entities.

ERIKS Second Hand Association operates several stores under its organization number. There are also partner stores with their own organization numbers, operating in collaboration with Erikshjälpen Second Hand.

 

Contact details for data protection matters

If you have questions about what data we process about you, want to decline information or communication from us, or exercise any of your other rights, you are welcome to contact us:

Personal data
Erikshjälpen
Datorgatan 4
561 33 Huskvarna
Email address: personuppgifter@erikshjalpen.se
Phone number: +46 383-46 74 50

Below you can read about what data we process about you, for what purpose we process your data, and what legal basis we have for processing it.

3 Processing of personal data by ERIKS

The following processing activities are handled within both of ERIKS' entities.

3.1 Application for a job, internship, volunteer position, or youth fundraising ambassador

We process data about you when you apply to engage with us.

Data we process:

  • Name, personal identification number, postal address, email address, phone number
  • Information in your application such as CV, cover letter, education, work experience, and references (if applicable)
  • Details of any interviews or conversations with you
  • Data that comes from an external party, e.g. The Swedish Public Employment Service, the probation service, or other partners for internships (if applicable)
  • Information about the desired location, store, or assignment (if applicable)

Purpose and legal basis:

  • Managing applications and evaluating candidates: Legitimate interests
  • Administration of the recruitment process: Legitimate interests
  • Collaborate with external actors (e.g. the Swedish Public Employment Service or the Probation Service) regarding internships: Legitimate interests

Justification of legitimate interests:

Based on a legitimate interests assessment, we process data in order to be able to handle applications in an efficient and correct manner.

Data retention period:

  • For applications for employment, the data is stored for a maximum of 24 months after the end of the recruitment process.
  • For applications for internships, volunteer positions, or youth fundraising ambassador roles that do not result in a placement or assignment, the data is stored for a maximum of 12 months after the end of the process.

 

3.2 Newsletters and other direct mailings

We process personal data about you if you have registered that you wish to receive newsletters or other direct mailings from us.

This category only applies to mailings that you have actively chosen to receive.

If, on the other hand, you have a different engagement with us, for example as a donor, or have interacted with us in different ways, you may receive other types of mailings that are processed according to the respective category in this policy.

Data we process:

  • Name, mailing address (for physical mail), email address (for digital mail)

Purpose and legal basis:

  • Distribution, newsletters, or other mailings: Consent

Data retention period:

  • Data is stored until you notify us that you no longer wish to receive the newsletter or mailing.

 

3.3 Complaints and whistleblowing

We process data about you if you submit a complaint or whistleblower alarm to us and you choose not to be anonymous.

Data we process:

  • Name, email address, phone number
  • Notification or report, in written or other format
  • Any attached documents or evidence
  • Communication history in the case
  • Information about persons or situations involved in the case

Purpose and legal basis:

  • Receiving, handling, and following up on complaints and taking the necessary steps to improve our business: Legitimate interests
  • Receiving, handling, and investigating whistleblower cases in accordance with applicable whistleblower legislation, including documentation and follow-up: Legal obligation

Justification of legitimate interests:

Based on a legitimate interests assessment, we process data in order to be able to receive, investigate and handle complaints and whistleblower cases in a correct manner to ensure the quality of our operations and protect both whistleblowers and interested parties.

Any unnecessary personal data provided in the notification will be deleted immediately.

Data retention period:

  • Data is stored for up to 24 months after the case is closed.
  • In the event of serious reports that have led to disciplinary action or legal proceedings, the data may be stored for longer in accordance with applicable legislation.

 

3.4 Social media

We are active on social media platforms such as Facebook, Instagram, LinkedIn, and TikTok to communicate about our work, create engagement, and reach more people with our message.

Data we process:

  • Names, profile pictures, and usernames of people who interact with us
  • Content of comments, messages, and posts where we are mentioned or tagged
  • Interaction data (likes, shares, comments)
  • Information you share with us via direct messages

Purpose and legal basis:

  • Communication and dialogue with followers and stakeholders, including answering questions, managing issues via direct messages, and moderating comments: Legitimate interests
  • Targeted communications and reach analysis: Legitimate interests

Justification of legitimate interests:

We have a legitimate interest in reaching out with information about our work, communicating with users, and engaging more people to support our mission. We also analyze the reach and statistics of our posts to ensure that we create relevant information and reach the right recipients.

Data retention period:

  • We continuously delete direct message conversations. In many cases, you can delete posts that you’ve created, liked, or shared yourself.
  • Other data is stored in accordance with the terms and conditions of each platform.

We act as the data controller for the content on our social media accounts, while users are responsible for the content they post. We reserve the right to remove comments that we deem inappropriate.

 

3.5 Contact persons at organizations

We process information about you if you are a contact person at an organization that is a donor, supplier, or partner of ERIKS.

Data we process:

  • Name, email address, phone number, role or job title

Purpose and legal basis:

  • Administration of the relationship between our organizations: Legitimate interests

Justification of legitimate interests:

Based on a legitimate interests assessment, we process data for the purpose of being able to administer the gift or relationship between your organization and ERIKS.

Data retention period:

  • Data is stored for the duration of the collaboration and for up to 12 months afterwards, or until a new contact person is appointed.
  • If your company or organization has made a donation to ERIKS, we will save the data for 36 months after the last donation.

4 Processing of personal data by ERIKS Development Partner

4.1 Donors

We collect personal data when you make a donation in the form of money, buy a gift certificate, launch your own fundraising campaign, or contact our donor services.

Data we process:

  • Name, personal identification number, postal address, email address, phone number
  • Donation amount, payment history, payment method, bank account number (in case of direct debit)
  • Donor ID, communication history, free-text comments

Purpose and legal basis:

  • Handling of contractual donations: Performance of a contract
  • Handling of one-time donations: Legitimate interests
  • Accounting and reporting: Legal obligation
  • Donor services, follow-up, and analysis: Legitimate interests
  • Information, communication, and invitations: Legitimate interests

Justification of legitimate interests:

Based on a legitimate interests assessment, we process data to streamline administration, reduce costs, and be able to provide information about our work in a relevant and transparent manner. This means that we can strengthen and help more children and families.

Data retention period:

  • Name, donation amount, date, and any OCR number or message are stored for 7 years in accordance with the Swedish Accounting Act.
  • Other information is stored for as long as you are a donor and for 36 months after your last donation.

 

4.2 Potential donor – existing contact

We may process your personal data if you have interacted with us and we assess that you might be interested in supporting our work. The data may come from yourself, from events we organize, quizzes you have completed, products you have purchased from us, or any other contact with us.

Data we process:

  • Name, personal identification number, postal address, email address, phone number

Purpose and legal basis:

  • Contact to inform you about our work and to ask whether you would like to make one-time or recurring donations: Legitimate interests

Justification of legitimate interests:

Based on a legitimate interests assessment, we process data for the purpose of identifying and contacting people who might be interested in supporting our work based on previous interactions with us.

Data retention period:

  • Up to 12 months after last contact

 

4.3 Potential donor – new contact

We are actively looking for new people who might be interested in supporting our work by learning more about our organization and our purpose. In order to identify and reach out to potential new donors, we process personal data that is purchased from external sources (such as SPAR, the Swedish State Personal Address Register) or retrieved from public news sources, where we assess that people may be interested in our work.

Data we process:

  • Name, personal identification number, postal address, email address, phone number

Purpose and legal basis:

  • Contact to inform you about our work and to ask whether you would like to make one-time or recurring donations: Legitimate interests

Justification of legitimate interests:

Based on a legitimate interests assessment, we process data for the purpose of identifying and contacting people who may be interested in supporting our work.

Data retention period:

  • Up to six months for purchased data for a specific activity

 

4.4 Wills

We may process information about you if you have included or shown interest in including ERIKS in your will.

Data we process:

  • Name, personal identification number, postal address, email address, phone number

Purpose and legal basis:

  • Monitoring ERIKS' rights according to wills: Legitimate interests
  • Donor services, follow-up, and analysis: Legitimate interests
  • Information, communication, and invitations: Legitimate interests

Justification of legitimate interests:

Based on a legitimate interests assessment, we process data for the purpose of monitoring wills that may benefit us. We may also inform about our work to raise more money that allows us to strengthen and help more children and families in vulnerability.

Data retention period:

  • Until the will takes effect or ERIKS ceases to be a beneficiary
  • Up to 12 months after the last contact if you have shown interest in making a will to ERIKS

 

4.5 Recipients of gift certificates

We process information about you if you receive a gift certificate.

Data we process:

  • Name, mailing address, email address, phone number

Purpose and legal basis:

  • Prepare and administer gift certificates: Legitimate interests

Justification of legitimate interests:

Based on a legitimate interests assessment, we process data for the purpose of being able to administer the donation and issuing the gift certificate.

Data retention period:

  • 12 months after the gift certificate was created

5 Processing of personal data by ERIKS Second Hand Association

5.1 Pick-up and delivery of goods

We process information about you when you order pick-up of donated goods or delivery of purchased goods to/from our second-hand shops.

Data we process:

  • Name, pickup address, email address, phone number

Purpose and legal basis:

  • Manage and handle the pickup or delivery of goods: Legitimate interests

Justification of legitimate interests:

Based on a legitimate interests assessment, we process personal data to efficiently and correctly administer and execute the collection and delivery of goods to and from our second-hand stores.

Data retention period:

  • The data is stored for up to 12 months after the collection or delivery has been completed.

 

5.2 Invoice purchases in stores

We process your personal data when you, as a contact person for a company or organization, purchase goods in our stores and pay via invoice.

Data we process:

  • Name, email address, phone number, personal identification number

Purpose and legal basis:

  • Managing invoice purchase and payment: Performance of a contract
  • Customer service and support: Legitimate interests
  • Bookkeeping and accounting: Legal obligation

Justification of legitimate interests:

Based on a legitimate interests assessment, we process data in order to be able to provide customer service and handle any questions about the purchase.

Data retention period:

  • Personal data is stored for up to 24 months following the most recent purchase, or for the duration of any agreement we have with the company or organization to purchase on invoice.
  • Personal data may also appear in invoice documentation and order information that is stored for 7 years according to The Swedish Accounting Act.

 

5.3 Camera surveillance in stores

Our stores are monitored by cameras (CCTV) to help prevent crime, ensure safety, and support the investigation of incidents. Surveillance is carried out only in areas where the business need outweighs an individual’s right to privacy. Access to the footage is restricted to authorized personnel.

Data we process:

  • Image and video material in which individuals can be identified
  • Information from notifications or reports of incidents, including communication history

Purpose and legal basis:

  • Prevent, detect, and investigate thefts and incidents in stores, and possibly hand over material to the police during criminal investigations: Legitimate interests
  • Maintaining order and safety for customers and staff: Legitimate interests

Justification of legitimate interests:

Our legitimate interests are to protect customers, employees, and the business against crime and to create a safe environment in the store. Camera surveillance is a proportionate and effective tool for detecting and investigating incidents and is only used where a balancing of interests shows that the security benefits outweigh the individual's privacy interest.

Data retention period:

  • Recorded material is normally stored for up to 30 days.
  • In the event of suspicion of a crime or other incident, the material may be stored for longer as long as it is needed to investigate the incident or comply with legal requirements.

6 Updating and completing personal data

We supplement information in our donor database with addresses, personal identity numbers, and gender from registers such as the Swedish Tax Agency, SPAR (the Swedish State Personal Address Register), and other reliable external information services. The aim is to always have as up-to-date information as possible in order to be able to target information to existing and potential donors and avoid sending information to the wrong person. This means that we may hold information about your name, personal identity number, address, and phone number in our database even if, for example, you have donated via Swish without providing this information. If we notice that several donors live at the same address, we record this to avoid sending multiple mailings to the same household.

We are also actively looking for people who may be interested in supporting our work with a larger donation. In such cases, we may supplement information about you with data such as income, education, occupation, interests, and engagement. This is done to better understand donor behavior and to tailor our communications in a relevant and appropriate manner. The data is stored for a maximum of 12 months. If you choose to make a larger donation, we may store the data for longer, for as long as it is necessary to administer the donation and maintain our ongoing relationship with you.

7 Who do we share the data with?

Your personal data will be processed by ERIKS. In addition, your personal data may be shared with third parties who process personal data on our behalf, so-called data processors. We ensure that a data processing agreement is always in place whenever a third party processes personal data on our behalf. We may provide access to your personal data to IT and system providers, banks, payment service providers, web agencies, printing companies, and telemarketing companies, to the extent necessary to perform the requested services. In certain cases, we may share information such as your name and email address with social media providers in order to target marketing to you and to share information about our work.

8 Is the data stored in countries outside the EU or EEA (third country)?

As a general rule, we and our suppliers and partners only process your personal data within the EU/EEA. In cases where personal data is processed outside the EU/EEA (in a “third country”), there is either a decision from the European Commission that the third country in question ensures an adequate level of protection for the processing of personal data or other appropriate safeguards under the GDPR, for example in the form of standard contractual clauses that ensure that your rights are protected.

9 What are your rights?

In accordance with applicable data protection legislation, you have the right to access information about the personal data we process about you, as well as the right to request correction of your personal data.

Under certain circumstances, you have the right to request erasure of your personal data, restriction of processing, or to object to processing. You also have the right, under certain conditions, to data portability. This means you may receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format, and you have the right to transfer that data to another data controller.

You have the right to withdraw your consent to the processing of your personal data at any time, with effect from the date of withdrawal. You also have the right to object at any time to the processing of your personal data for direct marketing and profiling.

If you have any complaints regarding our processing of your personal data, you can use our complaint form available on our website, erikshjalpen.se. You can also send an email to complaints@erikshjalpen.se. It is also possible to file a complaint with the Swedish Authority for Privacy Protection (in Swedish: Integritetsskyddsmyndigheten), which monitors the processing of personal data.

10 Safety

10.1 How do we work with IT security?

We and our partners continuously update firewalls and antivirus software to protect your data and prevent unauthorized access. Only staff with authorized accounts and passwords have access to the spaces and systems where the personal data is stored. Our employees are also strictly instructed to handle all personal data in accordance with applicable laws and regulations.

 

10.2 What is a cookie?

ERIKS uses cookies to create the best possible experience on our website erikshjalpen.se. Cookies are small text files that are stored on your computer and contain data from websites that you have visited. The aim is to give visitors access to various functions and facilitate browsing. The next time you visit the same website, it can read your cookie and display the pages according to your settings.

For more information, see erikshjalpen.se/cookies.

 

10.3 Are we responsible for external links?

ERIKS' material may contain links to external websites or services that are not under our control. If you follow a link to an external website, you will be asked to read the privacy principles and cookie information that apply to the page in question.

Pay with Swish by scanning the QR code

QR code Erikshjälpen
Do this:
  1. Open the Swish app.
  2. Press "Scan" and point the camera over the QR code.
  3. Confirm and sign the payment with mobile BankID.