OUR PRIVACY COMMITMENT

Planmeca Group is committed to protecting your privacy.

We respect your rights as a data subject. We keep you informed about our data protection practices and the purpose and legal basis of data processing when we obtain your personal data. We retain your personal data only for as long as necessary.

We share your personal data only with appropriate and authorised third parties who also respect our privacy practices. We always use appropriate transfer mechanisms and safeguards when processing and transferring personal data.

PRIVACY NOTICE OF PLANMECA GROUP’S THIRD-PARTY DUE DILIGENCE PROCEDURES

This privacy notice explains how Planmeca and the companies which belong to the same group (collectively ‘Planmeca’) collect, manage and protect your personal data. This privacy notice is addressed to our prospective, present and former clients, business partners and dealers.

This privacy notice describes how we at Planmeca process personal data when acting as a data controller.

PURPOSES AND LEGAL BASIS OF PROCESSING

In the course of our business, we collect and process personal data of our prospective, present and former clients (including end-user clients), business partners and distributors.

The purposes of collecting and processing personal data depend on the capacity in which you interact with us. The main purposes for collecting and processing personal data at Planmeca are:

- In the screening, qualification and validation of business partners, including any client, supplier or distributor acceptance procedures, personal data is collected in order to estimate risks and evaluate potential obstacles for business caused by sanctions, criminal offenses or reputation or other similar obstacles that pose a significant risk for Planmeca Group.

We only process personal data when we have a legal basis to do so. The legal basis depends on the personal data concerned and the specific context in which we process it.

This means that we collect and process personal data in the following cases:

- When we have a legitimate interest such as a business or commercial reason to process personal data − these reasons might include e.g. risk management purposes, estimating risks for the reputation of Planmeca Group and to ensure the quality of Planmeca Group’s services. When we use legitimate interest as a legal basis, we carefully consider that such processing is compatible with the data subject’s rights and freedoms
- For compliance with our legal or statutory obligations

CATEGORIES OF PERSONAL DATA WE PROCESS

CATEGORIES OF PERSONAL DATA WE PROCESS The data we process depends on the nature of our relationship with you. We typically process personal data categories such as:

- General contact information and other information such as name, phone number, e-mail address, mailing address, and other contact details
- Company information and information on the function and job title of contact persons of our clients
- Passport copies
- Personal identification codes like national identity codes
- Age and other necessary information to verify identity of the person if necessary
- Criminal convictions or offences

This data might be directly provided by you, or it might be collected from our business partners, or other third parties. The data we collect from you comes from a variety of channels, such as when you contact us or purchase our products or services.

RETENTION PERIOD

We will only retain your personal data for as long as necessary to fulfill the purposes described in this Privacy Notice and to comply with mandatory legislation such as accounting requirements. As a general rule, we process relevant personal data for the duration of the business relationship and for a predefined period after the relationship ends.

We aim to make sure that personal data we process is up to date and correct. In some circumstances, we may anonymise personal data for e.g. statistical purposes.

DATA TRANSFERS AND PROCESSING OUTSIDE THE EU/EEA

We are a global company and due to technical and operational requirements we may process personal data outside the European Union and/or the European Economic Area. If we transfer personal data outside the EU/EEA, the transfer will be carried out in accordance with appropriate transfer mechanisms, such as using the standard data protection clauses.

We may share personal data excluding criminal convictions or offences within our group companies and suppliers. In some cases, we may also share personal data with appropriate and authorised third-party recipients when providing services for you. We may also transfer personal data to our subcontractors that process data on our behalf for e.g. IT development, hosting and support. We only share information with government authorities if required to do so to comply with a legal or statutory requirement.

SECURITY OF PROCESSING

We maintain appropriate and adequate organisational, technical and physical safeguards designed to protect against unlawful or unauthorised destruction, loss, alteration, use or disclosure of, or access to, the personal information provided to us. Only authorised persons have access to the personal data we maintain, and the access is on a strict 'need-to-know' basis. We require all employees who have access to any personal data to handle it strictly confidential.

DATA PROTECTION RIGHTS

In accordance with the applicable data protection legislation, you may have the right to

- Request access to the personal data we hold about you
- Request that we rectify any inaccuracies in the personal data we hold about you
- In some circumstances, to request the transfer of your personal data to a third party
- In some circumstances, to request erasure or restriction of processing or to object to processing

You may also have the right to object to the use of personal data for marketing purposes.

If you would like to exercise any of the rights listed above, you can submit your request to us by sending an email to dpo(at)planmeca.com.

You have the right to file a complaint to your local data protection authority if you are not content with our data protection practices.

OUR CONTACT DETAILS

We have appointed a global Data Protection Officer. If you have questions about data protection at Planmeca or if you need any further information, please contact the Data Protection Officer at dpo(at)planmeca.com.

CHANGES TO OUR PRIVACY NOTICE

We may update this privacy notice without prior notice when necessary to reflect changes to our data protection practices. This notice was updated on 29 May 2023.