Privacy Notice on the use of Microsoft 365 in the ASSA ABLOY Group
We, ASSA ABLOY (hereafter "We", "ASSA ABLOY", "Us", or "Our") provide this Privacy Notice on the use of Microsoft 365 in the ASSA ABLOY Group (hereafter “Microsoft 365 Notice”) in order to inform you about Our practices with respect to the collection, storage, use, disclosure or erasure (hereafter jointly “Process or Processing“) of information of any kind (e.g., contact data, authentication data, business information, photos, videos and audio) related to you (hereinafter jointly “Personal Data”) in connection with the use of Microsoft 365 in the ASSA ABLOY Group.
This Microsoft 365 Notice applies to you if you are in a B2B collaboration with Us via Our Microsoft environment as a cooperation partner, or if you are an employee or consultant, (hereafter “Users”, or “You”) and contains specific information on Our data Processing practices related to the use of Microsoft 365.
1. Legal justification for Processing of your Personal Data and Processing Purposes
For the Processing of Personal Data in connection with Microsoft 365, We generally rely on the justification of realizing a legitimate interest. Our legitimate interest is to equip employees and consultants with state of the art software solutions aimed to increase personal and organizational productivity, including the interaction with cooperation partners. For certain user groups and tools, We also rely on the justification of performance of service agreement and/or the employment contract, especially regarding such tools that are necessary to enable cooperation partners and employees to fulfil or which support them in fulfilling their individual duties and responsibilities under their service agreement or employment contract.
In addition to the general information collected and processed about you and to the extent you have access to the tools, We collect and process the following Personal Data about you in connection with the tools for the purposes laid out in the table below.
Processing of special categories of Personal Data in the connection with the use of Microsoft 365 is not anticipated.
| Tool category | Processing Purposes | Personal Data Processed | Source of Personal Data | Legal justification |
|---|---|---|---|---|
| Standard office applications e.g., Word, Excel, PowerPoint, OneNote |
|
|
|
|
| Office applications for special user groups e.g., Access, Publisher, Visio Online, Power Apps, Power Automate |
|
|
|
|
| Tools for efficient collaboration and communication e.g., SharePoint, Teams (incl Webcast), OneDrive, Planner |
|
|
|
|
| E-mail & calendar tools, contact management e.g., Outlook (incl Calendar and Tasks), Exchange, People |
|
|
|
|
| Video & Web presentation tools e.g., Sway, Stream |
|
|
|
|
| Analysis and evaluation tools¹ e.g., Power BI, Delve, Graph, MyAnalytics |
|
|
|
|
| Device and application management e.g., Intune |
|
|
|
|
1) Access to Personal Data processed by Graph, Delve and MyAnalytics is generally limited to you and details regarding the Processing of Personal Data by Delve may be subject to your individual configuration of Delve.
2. Data transfers and recipients and legal justifications for such transfers
Microsoft Corporation acting as a processor, is located in the US, and subject to the EU – U.S. Data Privacy Framework which provides an adequate level of data protection for the Personal Data and that appropriate technical and organizational security measures are in place to protect Personal Data against accidental or unlawful destruction, accidental loss or alteration, unauthorized disclosure or access, and against all other unlawful forms of processing. Any onward transfer (including Our affiliates outside the EU/EEA) is subject to appropriate onward transfer requirements as required by applicable law.
During IT-support the data might be transferred. 1:st and 2:nd line support located in EU, while 3:rd line support is located globally.
3. Retention periods for and deletion of your Personal Data
Communication between co-worker and external person. The personal data is saved for this purpose under a period of twelve (12) month calculated from the time of the last communication in the same conversation and then for a period of ten (10) years to fulfill our legitimate interest to manage and respond to legal requirements.
Participate in training, events and other activities. The personal data is saved for this purpose during the time of the activity and for up to 13 months thereafter, calculated from the time the activity took place. It is kept to fulfill our legitimate interest to follow up the participation and evaluate the activity, as well as for planning of any follow up activities. Photos, videos, or audios collected to satisfy our legitimate interest to document our business is kept until further notice.
Having a digital identity at ASSA ABLOY When one leaves ASSA ABLOY ones digital identity is deactivated. Email is deleted 60 days after the deactivation and OneDrive is deleted 153 days after the deactivation. NOTE: All default retention periods are overruled if there's a litigation hold, E-discovery case, or a retention policy applied to the specific account data.
Secure the technical functionality and safety The personal data is saved under the same period as stated per purpose above. Logs are kept for support and incident handling for twelve (12) months calculated from the time of the logging. The personal data in security copies are saved for twelve (12) months calculated from the time of the copy was taken.
4. Monitoring
We maintain the right to monitor and review Service/System operations to ensure compliance with our directive of acceptable use, as well as to fulfill ASSA ABLOY's responsibilities under the laws and regulations of the jurisdictions in which it operates.
6. Changes of this notice
This Microsoft 365 Notice is subject to change. You will be notified adequately of any such changes.
7. How to contact us
If you wish to exercise your data subject rights or if you have any other questions concerning this Microsoft 365 Notice, please address your request to gc.privacy@assaabloy.com or ASSA ABLOY AB, Att: Group Center Data Protection Manager, Box 70340, 107 23 Stockholm, Sweden.
8. Supervisory Authority
In case of any complaints, you also have the right to lodge a complaint with the competent supervisory authority, in particular in the Member State of your habitual residence or alleged infringement of the GDPR.
List of supervisory authority per country Our Members | European Data Protection Board (europa.eu)