Privacy Policy

Data Controller

We are the data controller responsible for processing the personal data we collect and process about our customers and business partners. You can find our contact details below.

MasterQMS ApS

Messingvej 40B
8940 Randers SV, Denmark

CVR No.: 39099578

Our company is not required to appoint an external Data Protection Officer (DPO). However, if you have any questions regarding the processing of your personal data, you can contact us at info@masterqms.com.

Processing Activities

As a data controller under the GDPR, we carry out the following processing activities, which we manage through our GDPR software.

Website Visits

When you visit our website, we use cookies to ensure that the website functions properly. You can read more about this in our Cookie Policy.

Communication with Potential Customers

If you have questions about our website or would like to learn more about our services, you can contact us via:

  • Contact Form
  • Email
  • Telephone


Through these channels, we process your personal data in order to communicate with you, for example to answer questions about our services. We only process the information that you provide to us as part of this communication.

We typically process the following general personal data: name, email address, and telephone number.

Our legal basis for processing this personal data is Article 6(1)(f) of the General Data Protection Regulation.

We delete our communication with you once it becomes clear whether or not you wish to use our services.

In certain cases, it may be necessary to retain your personal data for a longer period.

Customers

We need to communicate with our customers to ensure that our services are delivered correctly. In this connection, we may process information such as name, address, services provided, special agreements, payment information, and similar details.

Our legal basis for processing this personal data is Article 6(1)(b) of the General Data Protection Regulation.

Once the service has been delivered and any outstanding matters have been resolved, we will normally delete the personal data shortly thereafter.

Accounting

We are required to retain all accounting records in accordance with the Danish Bookkeeping Act. This means that we retain invoices and similar accounting documents for bookkeeping purposes. These documents may contain general personal data such as name, address, and description of services.

Our legal basis for processing personal data for accounting purposes is Article 6(1) of the General Data Protection Regulation

We retain this information for a minimum of 5 years after the end of the current financial year.

Job Applications

We are happy to receive job applications in order to assess whether they match our company’s recruitment needs.

If you send us a job application, our legal basis for processing your personal data is Article 6(1)(f) of the General Data Protection Regulation.

If you have submitted an unsolicited application, we will assess as soon as possible whether your application is relevant. If there is no match, we will delete your personal data.

If you have applied for an advertised position and are not hired, we will dispose of your application shortly after the successful candidate has been selected.

If you take part in a recruitment process and/or are hired for the position, we will provide you with separate information about how we process your personal data in this connection.

Data Processors

Few companies can manage everything on their own, and the same applies to us. We therefore work with business partners and use suppliers, some of whom may act as data processors.

External suppliers may, for example, provide systems for organizing our work, services, consulting, IT hosting, or marketing.

It is our responsibility to ensure that your personal data is processed properly. We therefore place high demands on our business partners, and they must guarantee that your personal data is protected.

We therefore enter into agreements with companies (data processors) that process personal data on our behalf in order to strengthen the security of your personal data.

Disclosure of Personal Data

We do not disclose your personal data to third parties.

Profiling and Automated Decision-Making

We do not carry out profiling or automated decision-making.

Transfers to Third Countries

As a general rule, we use data processors located in the EU/EEA or that store data within the EU/EEA.

In some cases, this is not possible. In such situations, we may use data processors located outside the EU/EEA, provided that they ensure an adequate level of protection for your personal data.

Security of Processing

We ensure the secure processing of personal data by implementing appropriate technical and organizational measures.

We have carried out risk assessments of our processing of personal data and, on this basis, implemented appropriate technical and organizational measures to strengthen the security of processing.

One of our most important measures is to keep our employees up to date on GDPR through ongoing awareness training, GDPR courses, and regular reviews of our GDPR procedures.

Data Subject Rights

Under the General Data Protection Regulation, you have a number of rights in relation to our processing of your personal data.

If you wish to exercise any of your rights, please contact us so that we can assist you.

Right of Access

You have the right to obtain access to the personal data we process about you, as well as certain additional information.

Right to Rectification

You have the right to have inaccurate personal data about you corrected.

Right to Erasure

In certain cases, you have the right to have personal data about you deleted before the time of our general deletion procedure.

Right to Restriction of Processing

In certain cases, you have the right to restrict the processing of your personal data. If you are entitled to restriction of processing, we may in future only process the data – apart from storage – with your consent, for the establishment, exercise, or defence of legal claims, or for the protection of another person or important public interests.

Right to Object

In certain cases, you have the right to object to our otherwise lawful processing of your personal data. You may also object to the processing of your personal data for direct marketing purposes.

Right to Data Portability

In certain cases, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to have that personal data transmitted from one data controller to another without hindrance.

You can read more about your rights in the Danish Data Protection Agency’s guidance on data subject rights, available at www.datatilsynet.dk.

Withdrawal of Consent

Where our processing of your personal data is based on your consent, you have the right to withdraw that consent at any time.

Complaint to the Danish Data Protection Agency

You have the right to lodge a complaint with the Danish Data Protection Agency if you are dissatisfied with the way we process your personal data. You can find the Danish Data Protection Agency’s contact details at www.datatilsynet.dk.

We generally encourage you to read more about the GDPR so that you remain up to date with the applicable rules.