Privacy & Data Protection Notice
This notice explains how ToBeShore AB collects, uses, shares, protects and retains personal data, including how personal data is handled within our international delivery organisation.
Protecting personal data is important to ToBeShore. We apply the principles of data minimisation, privacy by design and secure processing throughout our business and delivery model. Our default approach is to avoid processing, exposing or transferring personal data where it is not necessary for the agreed purpose.
Our standard delivery model is designed so that customer production environments and customer data remain within EU/EEA-based environments, while our development teams work with source code, synthetic or purpose-built test data, documentation and sanitised operational information.
This notice applies to you if you are, for example, a customer or prospective customer contact, supplier or partner contact, consultant, job applicant, website visitor or another person who communicates or interacts with ToBeShore.
If you have questions about this notice, how we process personal data or wish to exercise your rights, please contact us at gdpr@tobeshore.se.
Who we are and when this notice applies
ToBeShore AB is a Swedish technology company providing software development, cloud, managed services, consulting and related technology services.
ToBeShore AB normally acts as the data controller for personal data that it collects and processes for its own purposes, for example in connection with sales, customer relationships, recruitment, supplier relationships, administration and this website.
In customer assignments, ToBeShore may instead process personal data on behalf of a customer. In those situations, the customer will normally act as the data controller and ToBeShore as the data processor. The exact allocation of responsibilities depends on the actual processing activities and the applicable agreements.
This Privacy & Data Protection Notice primarily describes processing for which ToBeShore AB is the data controller. Where ToBeShore acts as a processor, processing is also governed by the relevant customer agreement, data processing agreement and documented customer instructions.
The personal data we collect
ToBeShore only collects personal data that is relevant and necessary for a defined purpose.
Depending on your relationship with us, this may include:
Business and customer contacts
We may process information such as:
- name
- job title and role
- company or organisation
- business email address
- business telephone number
- correspondence and meeting information
- information relating to an enquiry, customer relationship, contract or assignment
Customers, suppliers and contractual relationships
Where necessary for administration and delivery, we may also process:
- contract and assignment information
- billing and payment-related information
- information necessary for customer or supplier administration
- support and service-related correspondence
Job applicants
If you apply for a position with ToBeShore, we may process information you provide to us, such as:
- name and contact details
- CV and employment history
- education and professional qualifications
- application and interview information
- references where applicable
- other information relevant to the recruitment process
We do not intentionally request special categories of personal data unless such processing is necessary, proportionate and permitted by applicable law.
Website and technical information
When you use our website, limited technical information may be processed for security, availability and operation of the website, such as IP address, browser or device information and technical request or security logs.
Optional analytics technologies are activated only with your consent. We do not currently use marketing cookies or equivalent marketing tracking technologies on this website.
Information from other sources
We normally receive personal data directly from you, your employer or the organisation you represent.
In some cases, we may receive business contact information from a customer, partner, supplier, professional network or publicly available business source where we have a legitimate reason to contact you.
Why we process personal data and our legal basis
ToBeShore processes personal data only where we have a defined purpose and a legal basis.
| Purpose | Typical legal basis |
|---|---|
| Managing enquiries, business contacts and prospective customer relationships | Legitimate interests |
| Managing customer and supplier relationships | Performance of a contract and/or legitimate interests |
| Delivering services where ToBeShore acts as data controller | Performance of a contract and/or legitimate interests |
| Contract, financial and business administration | Performance of a contract, legitimate interests and/or legal obligation |
| Accounting, taxation and other statutory record keeping | Legal obligation |
| Recruitment for a current position | Legitimate interests and, where applicable, steps taken prior to entering into a contract |
| Retaining candidate information for separately agreed future opportunities | Consent where required |
| Protecting systems, users and information against security threats or misuse | Legitimate interests and, where applicable, legal obligations |
| Maintaining and developing professional customer relationships | Legitimate interests |
| Direct marketing and business communications | Legitimate interests and, where required by law, consent |
| Optional website analytics | Consent |
Where we rely on legitimate interests, we assess whether our interest in carrying out the processing is proportionate and whether your interests, rights or freedoms outweigh that interest.
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing that was lawful before the consent was withdrawn.
Where ToBeShore acts solely as a data processor on behalf of a customer, the customer determines the purpose and legal basis for the underlying processing.
How long we retain personal data
We do not retain personal data longer than necessary for the purpose for which it was collected.
The retention period depends on the type of information, the purpose of the processing and any legal or contractual requirements.
Customers and active assignments
Personal data required to manage a customer relationship or assignment is normally retained for the duration of the relationship and for a limited period afterwards where necessary for administration, follow-up or the establishment, exercise or defence of legal claims.
Ordinary operational customer and assignment information is normally reviewed and removed when it is no longer necessary and, as a general rule, within twelve months after the relevant customer agreement or assignment has ended unless another legitimate reason requires retention.
Accounting and statutory records
Information that must be retained under accounting, tax or other applicable legislation is retained for the statutory retention period.
Prospective customers and other business contacts
Business contact information may be retained while there is an active or reasonably anticipated professional relationship.
Inactive business contact information is periodically reviewed and removed when there is no longer a legitimate business purpose for retaining it.
You may object at any time to the use of your personal data for direct marketing.
Recruitment
Information relating to an active recruitment process is retained for as long as necessary to complete that process and for a limited period afterwards where necessary to establish, exercise or defend legal claims.
If we would like to retain an unsuccessful applicant's information specifically for future opportunities, we will inform the applicant and obtain consent where required. Such consent may be withdrawn at any time.
Correspondence
General enquiries and correspondence are retained only for as long as reasonably necessary to resolve the matter or maintain the relevant business relationship.
Security and operational logs
Security and operational logs are retained according to documented operational and security requirements and only for as long as necessary for troubleshooting, security monitoring, incident investigation or similar legitimate purposes.
How and with whom we share personal data
ToBeShore does not sell personal data.
We limit disclosure of personal data and only make information available where it is necessary for a legitimate purpose.
Depending on the circumstances, personal data may be made available to:
- companies within the ToBeShore group, including our Sri Lankan subsidiary where necessary and permitted
- authorised cloud, IT, communications and infrastructure providers
- accounting, payroll or other business administration providers
- customers where information is required for an agreed assignment or consulting service
- authorised consultants or service providers
- professional advisers, auditors or legal advisers
- public authorities where disclosure is required by law
- other recipients where you have requested or authorised the disclosure
Access is limited to information necessary for the relevant purpose and is subject to appropriate contractual, organisational and technical safeguards.
Where a supplier processes personal data on behalf of ToBeShore, the relationship is governed by an appropriate data processing agreement where required.
Our role under the GDPR in customer assignments
ToBeShore provides different types of technology and consulting services. Our role under the GDPR therefore depends on the nature of each assignment and the actual processing being performed.
Consulting assignments under customer direction
In some consulting assignments, a consultant works directly within the customer's organisation, under the customer's instructions and using systems, accounts and working environments controlled by the customer.
In such cases, the customer may be the data controller for the relevant processing and ToBeShore may not itself act as a data processor for every activity performed by the individual consultant.
The allocation of roles is assessed based on the actual processing activities, responsibilities and agreements and not solely on where the consultant works or whose equipment is used.
ToBeShore remains the data controller for its own processing of information relating to the consultant, contract, customer relationship, invoicing and business administration.
Where ToBeShore provides necessary consultant contact or professional information to a customer, we process that disclosure on an appropriate legal basis and limit it to information necessary for the assignment.
Development, managed services, support and other assignments
Where ToBeShore processes personal data on documented instructions from a customer in order to provide development, managed services, support, maintenance or another agreed service, the customer will normally act as the data controller and ToBeShore as the data processor.
Such processing is governed by an appropriate data processing agreement.
ToBeShore processes customer personal data only in accordance with documented instructions, the applicable agreement and applicable data protection law.
Sub-processors
Where ToBeShore acts as a data processor and another legal entity processes customer personal data on our behalf, that entity may act as a sub-processor.
This can include our Sri Lankan subsidiary where personnel there are required to process customer personal data as part of an agreed service.
Sub-processors are engaged only in accordance with applicable customer agreements and the requirements of Article 28 GDPR, including the required customer authorisation.
ToBeShore imposes appropriate data protection obligations on authorised sub-processors and remains responsible to the customer for the performance of those obligations as required by the GDPR.
International processing and our Sri Lanka delivery organisation
ToBeShore AB works together with its subsidiary in Sri Lanka as part of our international development and delivery organisation.
EU/EEA-based customer environments
Our standard architecture and delivery model is designed so that customer production environments and ordinary customer data remain hosted within EU/EEA-based cloud environments, primarily in Sweden or within environments controlled by our customers in the EU/EEA.
Customer production data is not routinely transferred to or stored locally in Sri Lanka as part of our standard development process.
Our Sri Lankan development and delivery teams normally work with:
- source code
- synthetic or purpose-built test data
- technical documentation
- development environments
- sanitised operational information
Customer production datasets and customer personal data are not copied into local Sri Lankan development or test environments for development purposes.
Remote access from Sri Lanka
The fact that information remains physically hosted within the EU/EEA does not in itself mean that international data protection requirements can never apply.
In specific support, managed service, operational or troubleshooting situations, authorised personnel in Sri Lanka may need remote access to information held within an EU/EEA-based customer or ToBeShore environment.
Where such information contains personal data, access is treated as controlled international processing and is assessed under the applicable GDPR requirements.
Where remote access constitutes a transfer of personal data to a third country under Chapter V GDPR, an appropriate transfer mechanism and the necessary safeguards must be established before such access is permitted.
Depending on the situation, this may include:
- the relevant customer agreement and data processing agreement
- required sub-processor authorisation
- the European Commission's Standard Contractual Clauses
- an assessment of the relevant international transfer
- appropriate technical and organisational safeguards
- restricted and authorised access
- least-privilege principles
- logging and monitoring
- time-limited access where appropriate
Sri Lanka is outside the EU/EEA and is not currently covered by an adequacy decision from the European Commission.
Our default operating principle is therefore to avoid making personal data available to our Sri Lankan organisation unless such access is genuinely necessary for an agreed service and the appropriate contractual, legal and security safeguards are in place.
You may contact gdpr@tobeshore.se for more information regarding safeguards used for international transfers.
Data minimisation, development, testing and operational logs
Data minimisation and privacy by design are central principles in ToBeShore's development and delivery model.
Development and test environments
Customer production datasets and customer personal data are not copied into or used as test data in ToBeShore development and test environments.
Development and testing are performed using:
- synthetic data
- purpose-built non-production test data
- properly anonymised information where appropriate
Production, development and test activities are separated to reduce unnecessary access to customer information.
Pseudonymised, masked or encrypted information is still treated as personal data where an individual can reasonably be identified using the information itself or additional information available to ToBeShore or another relevant party.
Operational logs and diagnostics
Operational logs, traces, diagnostic information and error reports can sometimes contain personal data or other customer information.
Our default process is therefore to filter, sanitise and redact operational information before it is made available to development personnel in Sri Lanka.
Where technically and operationally appropriate, information not required for the relevant troubleshooting or support activity is removed or masked.
This may include:
- names
- email addresses
- telephone numbers
- personal identifiers
- customer-specific identifiers
- IP addresses where not required
- personal data contained in application payloads
- authentication information
- authorization headers
- session identifiers
- cookies
- access tokens
- passwords
- API keys
- secrets
- user-generated content
- other customer information not required for the technical task
Raw production information
Raw production logs and unrestricted production information are not routinely available to development teams in Sri Lanka.
Direct access from Sri Lanka to raw production information that contains personal data is treated as controlled production access.
Where such access is exceptionally necessary, it must be:
- required for an agreed operational purpose
- permitted under the applicable customer agreement and data processing agreement
- appropriately authorised
- restricted to the minimum information and personnel necessary
- protected through appropriate identity and access controls
- logged and monitored where appropriate
- time-limited where appropriate
- handled in accordance with applicable international-transfer requirements
Information that has been genuinely anonymised so that an individual can no longer reasonably be identified is no longer treated as personal data.
Information that has only been pseudonymised, masked or otherwise transformed but can still be linked to an identifiable individual continues to be treated as personal data.
Information security
ToBeShore applies technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, loss or destruction.
Measures are selected according to the nature, scope, context and risk of the processing and may include:
- identity and access management
- multi-factor authentication
- least-privilege access
- role-based access control
- encryption where appropriate
- secure cloud and infrastructure configurations
- separation of production, development and test environments
- logging, monitoring and access review
- secure development and operational practices
- vulnerability management and system hardening
- backup and recovery controls
- confidentiality obligations
- employee security and data protection training
- documented incident management procedures
- supplier and sub-processor controls
Access to personal data is restricted to personnel who need it for an authorised purpose.
Our architecture and delivery processes are specifically designed to:
- keep customer production environments and ordinary customer data within EU/EEA-based environments
- separate production data from development and testing activities
- prevent production customer data from being used as development or test data
- minimise cross-border access to personal data
- sanitise operational information before normal development use
- restrict exceptional production access according to least-privilege and need-to-know principles
No security measure can eliminate all risk. ToBeShore therefore continuously reviews and adapts safeguards according to the systems, services and risks involved.
Recruitment
ToBeShore processes personal data provided in connection with job applications for the purpose of evaluating candidates and managing recruitment.
We only collect information that is relevant to the recruitment process.
Application information is retained for the duration of the relevant recruitment process and for a limited period thereafter where necessary for legal claims or other legitimate purposes permitted by law.
We do not automatically retain every unsuccessful application for several years for unrelated future vacancies.
If we would like to retain a candidate's information specifically so that we can consider that individual for future opportunities, we will inform the candidate and obtain consent where required.
Consent for future recruitment may be withdrawn at any time by contacting gdpr@tobeshore.se.
Your data protection rights
Depending on the circumstances and legal basis for the processing, you may have the following rights.
- Access
- You may request confirmation of whether ToBeShore processes personal data about you and request access to that information.
- Rectification
- You may request that incorrect or incomplete personal data is corrected.
- Erasure
- You may request deletion of personal data where the conditions for erasure under the GDPR are met. The right to erasure is not absolute. We may need to retain certain information where required by law or necessary for the establishment, exercise or defence of legal claims.
- Restriction
- You may in certain circumstances request that processing of your personal data is restricted.
- Object
- Where processing is based on legitimate interests, you may have the right to object based on your particular circumstances. You always have the right to object to processing of your personal data for direct marketing purposes.
- Data portability
- Where the conditions under the GDPR are met, you may have the right to receive personal data you provided to us in a structured, commonly used and machine-readable format or request that it is transferred to another controller.
- Withdraw consent
- Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the consent was withdrawn.
- Lodge a complaint
- You have the right to lodge a complaint with the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY), if you believe your personal data has been processed in breach of applicable data protection law.
To exercise any of your rights, contact gdpr@tobeshore.se. We may need to verify your identity before responding to a request.
Cookies and similar technologies
This website uses strictly necessary cookies and similar storage technologies required for the website to operate and remember your privacy choices.
Optional analytics technologies are not loaded unless you have given the required consent.
- Strictly necessary
- These technologies are necessary for the website to operate, maintain security or remember your privacy preferences. Where permitted by law, these are active without consent and cannot be disabled through our cookie settings.
- Analytics
- Analytics technologies help us understand how visitors use the website so that we can improve its performance and content. Analytics are disabled by default and are activated only with your consent.
- Marketing
- We do not currently use marketing cookies or equivalent marketing tracking technologies on this website. If we introduce such technologies in the future, we will update this notice and obtain the required consent before activating them.
Your choice
You may accept, reject or change your choices for optional cookies at any time through the Cookie Settings link available on the website. Withdrawing consent is designed to be as easy as giving it.
The current cookie information available through Cookie Settings must identify, where applicable:
- the cookie or technology
- its provider
- its purpose
- whether it is a third-party technology
- what type of information it collects or uses
- how long it remains on your device
You can also block or delete cookies through your browser settings. Doing so may affect how some website functionality behaves.
Changes to this notice
We may update this Privacy & Data Protection Notice when our services, processing activities, legal requirements or working practices change.
The date at the top of this page shows when this notice was last updated.
Material changes affecting how we process personal data will be communicated where required by applicable law.
Contact and complaints
If you have questions about this notice, believe that information ToBeShore holds about you is incorrect, wish to exercise a data protection right or have concerns about how we process personal data, please contact us.
Privacy / GDPR contact at ToBeShore
ToBeShore AB · Registration number 559366-6224 · Sweden
gdpr@tobeshore.seIntegritetsskyddsmyndigheten (IMY)
If you believe ToBeShore processes your personal data in a way that does not comply with the GDPR, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection.