Privacy Policy for Commercial Business Partners

The Nilfisk group of companies stores (retains) and uses contact information about the contact persons and other relevant employees at our business partners globally, as well as relevant information about our investors.

 

The European Union’s (EU) General Data Protection Regulation 2016/679 (GDPR) governs how Nilfisk uses this information. References to Art. are to GDPR articles. Under the GDPR, information about individuals is called personal data (Art. 4(1)), and covers anything that can be used to identify an individual – a name, a bank account number, a photograph. Collecting, using, retaining and sharing information is data processing (Art. 4(2)).

 

The GDPR applies to any Nilfisk company based in the European Economic Association (EEA)1 and the United Kingdom (UK), by UK law, processing the personal data of persons residing anywhere globally. It also applies to Nilfisk companies located outside the EU if, in the course of doing business in the EU, they process the personal data of persons residing in the EU. The GDPR does not apply when a Nilfisk company outside the EEA processes personal data of persons residing outside the EEA.

 

Individuals, and organizations who provide employees’ personal data to us, are Data Controllers (Art. 4(7)), and depending on how we use that data, Nilfisk is a Co-Controller or Data Processor of that data (Art. 4.8).

 

1 The EEA comprises Norway, Iceland, Lichtenstein and all EU countries: Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxemburg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain and Sweden. Countries where Nilfisk is located are in italics.

What kind of business partner personal data does Nilfisk process and why do we process that data?

 

Customers, consultants, advisors, agents and vendors, including their advisors and other representatives, e.g. attorneys:

  • Types of persons whose data we process (Data Subjects (Art. 4.1)): Employees, board members.
  • Types of personal data Nifisk processes involving their employees:
    • Names,job titles and job functions
    • IP addresses
    • Business address and other contact details, e.g. telephone numbers and e-mail addresses
    • Credit Card information - commercial customer contact persons
    • Passwords and usernames

GDPR processing legal basis – legitimate business interests (Art. 6.1(f)):

Nilfisk processes this personal data to communicate with business partners in order for Nilfisk, as a vendor or customer/client, to:

  • Negotiate and communicate regarding business relationships,
  • Comply with its contractual obligations and exercise its contractual rights;
  • Comply with applicable regulatory requirements, e.g. reporting to tax authorities, Customs, health and safety agencies, environmental authorities, enforcement agencies,
  • Address legal issues arising from its business relationships,
  • Develop and enhance commercial relations with business partners,
  • Obtain advice and services, and;
  • Evaluate goods and services offered by current or prospective vendors.

 

Further, Nilfisk processes this data because of its legitimate interests as a vendor (Art. 6.1(f)) in:

  • maintaining and enhancing its relationships with customers, in order to provide them with its products and services, including repair, service and maintenance;
  • providing current or prospective customers with information about Nilfisk’s products and services, e.g. in newsletters and other marketing information, subject to any required opt-in and opt-out options;
  • enhancing Nilfisk’s website’s functionality and user experience using Cookies,
  • unsolicited commercial contacts and direct marketing communications, e.g., providing information on similar products when someone browses products on our websites or purchases a product, subject to opt-out options,
  • requesting and processing your reviews of our products and services, and;
  • generating statistics and other anonymized information to enhance products and service.

 

Nilfisk retains your data for as long as operationally or legally necessary (Arts. 5.1(e), 6.1(f)), including:

  • Up to ten (10) years after we are in contact about our business relationship;
    • To provide service and maintenance and maintain relevant business related data;
    • In case legal claims, disputes or other legal disagreements between us arise;
  • Until you instruct us to delete your data, which we will do subject to retaining data necessary for relevant business purposes, e.g. accounting, service, legal requirements and legal claims, or;
  • Up to 10 years after an actual or potential legal dispute or claim involving a business partner ends.
  • Longer periods as required by applicable laws and regulations, e.g., health and safety. ​

 

Nilfisk obtains personal data from business partners themselves (Art. 13) and from Nilfisk employees and relevant third parties, including directories other business partners (Art. 14).

 

Business partner due diligence

Prospective vendors seeking to supply Nilfisk are required, in our SAP Ariba system, to complete due diligence questions about their past and current activities as regards legal compliance (anti-corruption, foreign trade controls, competition law and data protection laws) and corporate social responsibility (CSR) matters. The questions ask about, e.g., violations of applicable laws and trade sanctions, or official investigations, as well as about adherence to CSR regulations and standards.

 

In addition, Nilfisk obtains and processes reports from a third party due diligence service provider, due diligence reports on vendors and other relevant business partners, covering legal compliance and CSR risks, e.g. records of prosecutions, media coverage and general public reputation.

 

When a business relationship has begun, Nilfisk monitors its business partner’s compliance with applicable laws, e.g. anti-corruption laws, and the provisions of our agreement.

 

Due diligence monitoring may include the personal data of key individuals associated with business partners.

 

Due diligence and monitoring data processing legal basis (Art. 6.1(f)):

  • Nilfisk has a significant legitimate interest in knowing the background of prospective business partners before agreeing to do business, in order to adequately evaluate legal and reputational risks;
  • Nilfisk likewise has a significant legitimate interest in being aware of legal or reputation risks it may face as a result of a business partner’s violation of laws, behavior standards or contractual duties;
  • Contracts with business partners contain legal compliance and behavior obligations; and
  • Nilfisk must know the legal risks arising from a business partner’s background and ongoing actions in its relationship with Nilfisk in relation to potential or actual legal claims, including from relevant law enforcement and other government agencies, e.g. anti-corruption, trade sanctions, competition laws.
  • The foregoing interests significantly outweigh individuals’ privacy interests. Due diligence obtained from third parties is kept as confidential information available only to employees and third party advisors, e.g. legal advisors, on a need-to-know basis.

Sharing and transfer of your personal data:

Nilfisk shares business partner data, on a need-to-know basis, within the Nilfisk organization, and with third parties providing services involving delivery, invoicing, payment processing, and repairs, service and maintenance of products (sub-processors – Art. 28). Nilfisk does this due to its legitimate interests in selling products and providing services to its customers. (Art. 6.1(f))

 

Customers: Your data will generally be available in the following places within Nilfisk:

  • Your own country
  • Countries where your company deals with Nilfisk or its dealers/distributors;
  • The EEA and UK
  • The United States
  • India

 

Nilfisk will also share your personal data with third party dealers of its products in your local area, in order that they can contact you about potential business. You can opt out of this service.

 

Vendors, other business partners: Your data is accessible to all Nilfisk companies globally, and relevant third party business partners, unless otherwise agreed. The list of countries is in Appendix 1.

 

General: Nilfisk will share relevant data as needed with third parties engaged to support Nilfisk operations, e.g. accounting, logistics, insurance, quality control, enhancing products and services, gauging customer loyalty.

 

Nilfisk transfers and/or makes data accessible outside the EEA and UK under EU adequacy decisions or standard EU data transfer agreements (Standard Contractual Clauses) with the data recipients, on an as needed basis, to global Nilfisk companies, data processors and companies providing communications and other services (Arts. 28, 45 and 46)). The countries outside the EEA where data may be transferred or is accessible through Cloud Systems is in Appendix 1

Investors

In accordance with Danish legislation and the rules imposed by the NASDAQ share exchange, Nilfisk  maintains a shareholder register of all investors, including the name, address, title, contact details and share account number that each individual investor has provided. The data are processed by a third party data processor, and a small number of Nilfisk employees in Finance and Corporate Affairs may access the register. Data is deleted within a few days after a Nilfisk shareholder disposes of his/her shares.

 

Individual investors wishing to attend shareholder meetings provide Nilfisk’s data processor with their names and the names of their guests. These data, and the attendance registration number, are stored by the processor no longer than five years after the meeting, and then deleted. Investors may also join quarterly webinars using their name and e-mail address, and those data are deleted no later than five years after the call. Only Nilfisk employees involved in those events can access the data in both cases. The legal basis for such processing are Nilfisk’s legal obligations and legitimate interests (Arts. 6.1(c) and (f)).

Nilfisk University

Business partners’ data subjects may receive training on Nilfisk products through Nilfisk University (NU) by consenting through the application process to having specific data processed in relation to admission, training, testing and evaluation (Art. 6.1(a), or as a part of their business relationship with Nilfisk regarding knowledge of Nilfisk products and services, or Nilfisk’s compliance and sustainability requirements, due to Nilfisk’s legitimate business interests (Art. 6.1(f).

 

Their data are available to Nilfisk employees involved in the training and accounting and relevant third party data processors in the EU, US and India, and to their own employers, which may be Nilfisk customers. Further data processing details are found on the admission and other NU materials.

Your rights regarding your personal data.

The GDPR, when applicable, grants certain rights regarding Nilfisk’s processing of their data. Contact Nilfisk’s global compliance team at compliance.com@nilfisk.com if you wish to exercise the following rights, if applicable, regarding your data, or if you wish to complain about its processing:

  • Request right of access to the personal data Nilfisk has about you and receive a copy of it, subject to the data privacy rights of others. (Art. 15)
  • Ask Nilfisk to correct or update your data if our information is inaccurate. (Art. 16)
  • Request Nilfisk to stop or limit processing your data to the extent feasible while correcting errors, subject to Nilfisk’s rights to continue processing certain personal data. (Art. 18)
    • Including for customers: stopping unsolicited contacts or direct marketing communications.
  • Under certain circumstances, request data portability, e.g. to provide your personal data in a PDF (machine readable) format to you or transmit such data to another data controller, if technically feasible. (Art. 20)
  • Request erasure of your personal data if specific conditions are met, and subject to Nilfisk’s rights to refuse the request in order to protect its legal rights and interests. (Art. 17)
  • Object to the processing of personal data (Art. 21)

 

Nilfisk will comply with your requests to the extent possible, subject to:

  • its obligations under laws and agreements,
  • its recordkeeping practices, including retaining necessary business documents
  • its legal interests, including those related to possible legal claims,

all of which may limit Nilfisk’s ability to fully comply with your request. You can also contact your national data protection agency with questions or complaints about Nilfisk’s processing of your personal data.

 

If you have questions:

  • The Nilfisk company collecting and processing your data is the Data Controller
    • The list of relevant Nilfisk companies is found in Appendix 2.
  • If you have questions about deleting your personal data at Nilfisk, please click here.
  • If you have other questions about your personal data at Nilfisk, please click here.
  • Denmark’s Data Protection Agency (Datatilsynet) with questions or if you wish to lodge a complaint: https://www.datatilsynet.dk/
    • Or other EU data protection agencies, please click here.
  • With other questions, please contact Nilfisk's global compliance team at: Nilfisk A/S, Marmorvej 8, DK-2100 Copenhagen, Denmark: compliance.com@nilfisk.com

Cookies Policy

Last updated July 2024.

Appendix 1:

COUNTRIES OUTSIDE THE EUROPEAN UNION (EU)2, ICELAND, LICHTENSTIEN AND NORWAY WHERE EMPLOYEE DATA MAY BE TRANSFERRED OR ACCESSIBLE VIA CLOUD SYSTEMS

COUNTRIES WHERE DATA MAY BE PROCESSED AT A NILFISK ENTITY HAS (N) BESIDE IT

COUNTRIES WHERE DATA MAY BE PROCESSED BY A THIRD PARTY HAS (TP) BESIDE IT

Argentina (N)

Australia (N)

Brazil (N)

Canada (N)

Chile (N)

China, including Hong Kong, Macau and Taiwan (N)

India (N) (TP)

Japan (N)

Republic of Korea (South Korea) (N)

Malaysia (N)

Mexico (N)

New Zealand (N)

Peru (N)

Singapore (N)

Switzerland (N)

Thailand (N)

Turkey (N)

United Arab Emirates (Dubai) (N)

United States (N)

Vietnam (N)

 

2 EU countries where Nilfisk processes data: Austria, Belgium, Czech Republic, Denmark, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Netherlands, Poland, Portugal, Romania, Slovakia, Spain, and Sweden.

Appendix 2:

Company Country
Nilfisk S. R.L. Argentina
Nilfisk Pty Ltd Australia
Nilfisk GmbH Austria
Nilfisk NV/SA Belgium
Nilfisk Equipamentos de Limpieza Ltda Brazil
Nilfisk Canada Company Canada
Nilfisk S.p.A. Chile
Nilfisk Cleaning Equipment (Shanghai) Co., Ltd Shanghai, China
Suzhou Nilfisk Research and Development Co.,Ltd. Suzhou, China
Viper Cleaning Equipment (Dongguan) Ltd. Dongguan, China
NILFISK s.r.Ο. Czech Republic
Nilfisk A/S Denmark
Nilfisk Holding A/S Denmark
Nippon Investment Corporation ApS Denmark
Nilfisk OY Finland
Nilfisk SAS France
Nilfisk GmbH Germany
Nilfisk-Advance Eppingen GmbH Germany
Floor Cleaning Machines Ltd Great Britain
Industrial Cleaning Machines Limited Great Britain
Nilfisk Ltd Great Britain
NILFISK HELLAS SINGLE MEMBER SOCIETE ANONYME Greece
Nilfisk Limited Hong Kong
Nilfisk Kereskedelmi Kft.

Szigetszentmiklós-

Lakihegy, Hungary

Nilfisk Production Kft.

Szigetszentmiklós-

Lakihegy, Hungary

Nilfisk India Private Limited India
Nilfisk Ltd. Ireland
Nilfisk S.p.A. a socio unico Italy
Nilfisk Inc. Japan
Nilfisk Korea Co., Ltd. Korea
Nilfisk Limited - Macau Branch Macau
Nilfisk de Mexico Manufacturing S. de R.L. de C.V. Mexico
Nilfisk de Mexico S. de R.L. de C.V. Mexico
NILFISK SDN BHD Malaysia
Nilfisk B.V. Netherlands
Nilfisk AS Norway
Nilfisk Ltd New Zealand
Nilfisk SAC Peru
Nilfisk Polska sp. z o.o. Poland
Nilfisk LDA Portugal
Nilfisk-Advance Romania S.R.L Romania
Nilfisk Pte Ltd Singapore
Nilfisk s.r.o. Slovakia
NILFISK SAU Spain
Nilfisk AB Sweden
Nilfisk AG Switzerland
Nilfisk Co., Ltd. (THA) Thailand
Nilfisk Profesyonel Temizlik Ekipmanları A.Ş. Turkey
Nilfisk Limited Taiwan Branch (H.K.) Taiwan
Nilfisk Trading LLC United Arab Emirates
Hydro Tek Systems, Inc. United States of America
Nilfisk, Inc. United States of America
Nilfisk U.S. Holding, Inc. United States of America
Nilfisk Robotics Inc. United States of America
Nilfisk Pressure-Pro LLC United States of America
Nilfisk Co., Ltd. (VNM) Vietnam

Sign up for news and key industry insights