SDC Privacy Policy

LAST UPDATED: 2026-08-13

This privacy policy explains how we collect and use your personal data, as well as the rights you have and how to exercise them.

1 Introduction

Scandinavian Data Centers AB ("SDC","we", "us", or "our") is a Swedish-owned data center operator providing colocation, power, and connectivity services across a distributed network of facilities in Sweden. We are committed to protecting the personal data of our customers, partners, employees, visitors to ou rfacilities, and website visitors in accordance with applicable privacy legislation.

This Privacy Policy explains how we collect, use, store, and share personal data in connection with our services and business operations. It applies to all personal data processed by SDC in its capacity as a data controller, and where applicable, as a data processor acting on behalf of our customers.

Our processing of personal data is governed primarily by Regulation (EU)2016/679 (the General Data Protection Regulation, "GDPR"), together with the Swedish Data Protection Act (Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning), as well as applicable sector-specific legislation including the Swedish Electronic Communications Act(Lag (2022:482) om elektronisk kommunikation, "LEK") and the Swedish Security Protection Act (Säkerhetsskyddslagen (2018:585)). As a provider of data centre services, SDC is also subject to the Swedish Cybersecurity Act (Cybersäkerhetslagen (2025:1506)), which implements the NIS2 Directive (EU)2022/2555; a number of our customers are separately subject to that frame workin their own right.

This Policy is provided for information and transparency purposes. It does not form part of any contract between you and SDC, and it does not itself constitute a request for your consent. Where we rely on consent as the legal basis for a particular processing activity, we will ask for it separately, andyou may withdraw it at any time.

We may update this Privacy Policy from time to time to reflect changes in our operations, services, or legal obligations. The most current version will always be available on our website and, where required by law, we will notify you of material changes before they take effect.

Scandinavian Data Centers AB ("SDC","we", "us", or "our") is a Swedish-owned data center operator providing colocation, power, and connectivity services across a distributed network of facilities in Sweden. We are committed to protecting the personal data of our customers, partners, employees, visitors to ou rfacilities, and website visitors in accordance with applicable privacy legislation.

This Privacy Policy explains how we collect, use, store, and share personal data in connection with our services and business operations. It applies to all personal data processed by SDC in its capacity as a data controller, and where applicable, as a data processor acting on behalf of our customers.

Our processing of personal data is governed primarily by Regulation (EU)2016/679 (the General Data Protection Regulation, "GDPR"), together with the Swedish Data Protection Act (Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning), as well as applicable sector-specific legislation including the Swedish Electronic Communications Act(Lag (2022:482) om elektronisk kommunikation, "LEK") and the Swedish Security Protection Act (Säkerhetsskyddslagen (2018:585)). As a provider of data centre services, SDC is also subject to the Swedish Cybersecurity Act(Cybersäkerhetslagen (2025:1506)), which implements the NIS2 Directive (EU)2022/2555; a number of our customers are separately subject to that frame workin their own right.

This Policy is provided for information and transparency purposes. It does not form part of any contract between you and SDC, and it does not itself constitute a request for your consent. Where we rely on consent as the legal basis for a particular processing activity, we will ask for it separately, andyou may withdraw it at any time.

We may update this Privacy Policy from time to time to reflect changes in our operations, services, or legal obligations. The most current version will always be available on our website and, where required by law, we will notify you of material changes before they take effect.

2 Definitions

For the purposes of this Privacy Policy, the followingterms shall have the meanings set out below. These definitions align with the GDPR and applicable Swedish legislation.

Personal Data: Any information relating to an identified or identifiable natural person (“Data Subject”). An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, or online identifier.

Processing: Any operation or set of operations performed on Personal Data, whether by automated means or otherwise, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure,dissemination, restriction, erasure, or destruction.

Data Controller: The natural or legal person, public authority, agency, orother body which, alone or jointly with others, determines the purposes andmeans of the processing of Personal Data. SDC acts as a Data Controller withrespect to Personal Data collected in connection with its own businessoperations, including customer and supplier relationships, facility management,and marketing activities.

Data Processor: A natural or legal person, public authority, agency, orother body which processes Personal Data on behalf of the Data Controller. SDCmay act as a Data Processor where it processes Personal Data on behalf of itscolocation customers pursuant to a Data Processing Agreement.

Data Subject: Any identified or identifiable natural person whose Personal Data is processed by SDC or on behalf of SDC.

GDPR: Regulation (EU) 2016/679 of the European Parliament andof the Council of 27 April 2016 on the protection of natural persons withregard to the processing of personal data and on the free movement of such data.

Sensitive Personal Data: Categories of Personal Data afforded heightenedprotection under Article 9 GDPR, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for the purpose of uniquelyidentifying a person, health data, and data concerning a person’s sex life orsexual orientation.

Third Party: Any natural or legal person, public authority, agency, orbody other than the Data Subject, Data Controller, Data Processor, and personswho, under the direct authority of the Data Controller or Processor, are authorised to process Personal Data.

Data Processing Agreement(DPA): A legally binding agreement entered into between SDC and a customer or supplier governing the processing of Personal Data by SDC in its capacity as Data Processor, in accordance with Article 28 GDPR.

Security Protection Act(Säkerhetsskyddslagen): Swedish legislation (SFS 2018:585) governing the protection of classified information and security-sensitive activities. Certain SDC facilities and customer engagements may be subject to obligations under this Act.

NIS2 Directive: Directive (EU) 2022/2555 on measures for a high commonlevel of cyber security across the Union. Certain customers operating critical infrastructure and hosted within SDC facilities may be subject to this Directive’s requirements.

Colocation Services: The service offering whereby SDC provides physical space, power, cooling, and connectivity infrastructure within its data centerfacilities for customers to house their own IT equipment.

Supervisory Authority: The competent national authority responsible formonitoring and enforcing compliance with the GDPR. In Sweden, this is theIntegritetsskyddsmyndigheten (IMY).

3 Responsibility

Scandinavian Data Centers AB, registered in Sweden (org.nr. 559332-4295), with its registered address at Rådmansgatan 22, 114 25 Stockholm, is the Data Controller for Personal Data processed in connection with SDC’s own business operations, including the management of customer and supplier relationships, access control and facility security, employment matters, and marketing communications.

3.1  Data Controller Responsibilities

As Data Controller, SDC is responsible for ensuring that Personal Data is processed lawfully, fairly, and transparently in accordance with the GDPR and applicable Swedish law. This includes:

•      Establishing andmaintaining a lawful basis for each category of processing activity.

•      Ensuring that Personal Datais collected for specified, explicit, and legitimate purposes and not processedin a manner incompatible with those purposes.

•      Implementing appropriate technical and organisational measures to ensure a level of security appropriateto the risk of processing, including measures to prevent unauthorised access, accidental loss, destruction, or damage.

•      Maintaining a Record of Processing Activities (RoPA) in accordance with Article 30 GDPR.

•      Ensuring that Data Subjectscan effectively exercise their rights as set out in this Policy.

•      Notifying the Swedish supervisory authority (IMY) and, where required, affected Data Subjects, of any Personal Data breach in accordance with Articles 33 and 34 GDPR.

3.2  Data Processor Responsibilities

Where SDC processes Personal Data on behalf of its colocation customers acting as Data Controllers, SDC acts as a Data Processor. In this capacity, SDC will:

•      Process Personal Data only on documented instructions from the customer (Data Controller), unless requiredto do so by applicable law.

•      Ensure that personsauthorised to process the Personal Data are subject to appropriateconfidentiality obligations.

•      Implement appropriatetechnical and organisational security measures in accordance with Article 32GDPR.

•      Not engage sub-processorswithout prior written authorisation from the customer, and where suchauthorisation is given, ensure that sub-processors are bound by equivalent dataprotection obligations.

•      Assist the customer infulfilling its obligations with respect to Data Subject rights requests,security measures, data breach notification, and data protection impactassessments.

•      At the customer’s choice,delete or return all Personal Data upon termination of the colocation agreement, unless retention is required by law.

•      Provide the customer with all information necessary to demonstrate compliance and cooperate with auditsand inspections.

The respective rights and obligations of SDC and its customers in their capacity as Data Controllers and Data Processors are further governed by Data Processing Agreements entered into pursuant to Article 28 GDPR.

3.3  Data Protection Contact

SDC has designated a point of contact for data protection matters. Any questions, concerns, or requests relating to the processing ofPersonal Data under this Policy should be directed to:

4 What We Process, Why, and On What Basis

The Personal Data we process depends on yourrelationship with SDC. The table below sets out each category of Data Subject,the Personal Data concerned, the purposes of the processing, and our legalbasis under Article 6 GDPR.

| You are | Personal Data we process | Purposes | Legal basis |
| --- | --- | --- | --- |
| **A customer or prospective customer representative** | Name, job title,employer, business contact details; correspondence, meeting notes, enquiriesand support requests; contract signatory details; order history, serviceconfiguration, invoicing and payment records; portal account identifiers andactivity logs | Providing and administering the Services; support; invoicingand payment; account management; managing the commercial relationship |Performance of a contract (Art. 6(1)(b)); our legitimate interest inadministering a relationship where the contract is with your employer (Art.6(1)(f)) |
| **A supplier or partner representative** | Name, job title, employer,business contact details; correspondence; contract, delivery and invoicingrecords; where site work is involved, the access data described below |Procurement; contract administration; coordinating work at our facilities |Performance of a contract (Art. 6(1)(b)); our legitimate interest in managingour supply chain (Art. 6(1)(f)) |
| **A visitor to one of our facilities** | Name, employer, the party you attendon behalf of, authorised areas, authorising person; access card and credentialidentifiers; entry and exit records by time and location; visitor registerentries; camera surveillance footage | Controlling and recording access;protecting the facility, our customers' equipment, and the safety of people onsite; maintaining an auditable access record; investigating security incidents| Our legitimate interest in physical security and in maintaining accessrecords our customers rely on (Art. 6(1)(f)); compliance with a legal obligationunder the Security Protection Act and the Cybersecurity Act (Art. 6(1)(c)) |
| **A job applicant** | Name, contact details, CV, cover letter, references,employment and education history, assessments and interview notes; where a roleis security-sensitive, information processed in connection with securityclearance | Assessing your application and administering the recruitmentprocess | Steps taken at your request prior to entering a contract (Art.6(1)(b)); our legitimate interest in assessing candidates (Art. 6(1)(f)); legalobligation, for security clearance (Art. 6(1)(c)) |
| **An employee** | Data necessary to administer the employment relationship |Employment administration | Employees receive separate, more detailedinformation through internal channels; this Policy does not replace it |
| **A website visitor** | IP address, device and browser type, operatingsystem, referring page, pages viewed, date and time; details you submit throughforms or subscriptions | Operating and securing the website; responding toenquiries; measuring and improving the site; sending communications you haverequested | Our legitimate interest in operating a secure and functioningwebsite (Art. 6(1)(f)); your consent for non-essential cookies and marketing(Art. 6(1)(a)) |

**Camera surveillance.** Cameras cover entrances, perimeters, delivery areas,and technical and customer areas within our facilities. They protect thefacility, our customers' equipment, and the people working in them, and are notused to monitor the work performance of individual employees or contractors.Signage is displayed at all monitored areas. Detailed information about ourcamera surveillance is set out in our separate Camera Surveillance Informationpage.

**Marketing.** We process the business contact details of customer and prospectrepresentatives to send business communications, newsletters, and eventinvitations, on the basis of our legitimate interest in promoting our servicesto business contacts, or your consent where required by law. You may object atany time, and every marketing message contains an unsubscribe facility.

**Other purposes.** We also process Personal Data to maintain the security,availability, and integrity of our infrastructure, including logging,monitoring, and incident response and reporting; to comply with legal andregulatory obligations, including bookkeeping under the Swedish Bookkeeping Act(Bokföringslagen (1999:1078)) and obligations under the Security Protection Actand the Cybersecurity Act; and to establish, exercise, or defend legalclaims.

**Sources.** We collect Personal Data primarily from you or from theorganisation you represent. We also receive it from our customers and supplierswhen they nominate individuals for site access or as service contacts, frompublicly available sources and business information services in connection withsales and know-your-customer checks, and from our own systems, where it isgenerated by your use of our facilities, portals, or website.

**Sensitive Personal Data.** SDC does not routinely process Sensitive Personal Data. We do not use biometric data to identify individuals; access to ourfacilities is controlled by credentials and personal identification numbers.Sensitive Personal Data may exceptionally be processed where necessary underemployment law, to protect vital interests, or to establish, exercise, ordefend legal claims, on the basis of an applicable exception under Article 9(2)GDPR. Data relating to criminal convictions and offences is processed onlywhere permitted under Article 10 GDPR and Swedish law, in particular inconnection with security clearance under the Security Protection Act.

**Legitimate interests.** Where we rely on legitimate interests, we havecarried out an assessment balancing those interests against the rights andfreedoms of the Data Subjects concerned. You may request further informationabout that assessment using the contact details in section 3.3.

5 Disclosure, Transfers, Retention, and Security

5.1 Disclosure

We do not sell Personal Data. We disclose it only where necessary for the purposes described in section 4, and only to:

- **Service providers acting on our behalf** — providers of IT, hosting,security, communications, accounting, and professional services. They process Personal Data as our Data Processors under written agreements concluded pursuant to Article 28 GDPR and may not use it for their own purposes.
- **Customers** — where an individual attends one of our facilities on their behalf and disclosure of access records is necessary for security, audit, or contractual purposes.
- **Competent authorities** — including the Swedish Post and Telecom Authority(PTS), the Swedish Security Service (Säkerhetspolisen), the Swedish Armed Forces, the Swedish Civil Contingencies Agency (MSB), IMY, law enforcement agencies, and courts, where required by law or necessary to establish,exercise, or defend legal claims.
- **Professional advisers, insurers, and auditors** — where necessary in connection with their services to SDC.
- **Acquirers or prospective acquirers** — in connection with a merger,acquisition, financing, or reorganisation of all or part of our business,subject to appropriate confidentiality protections.

5.2 Transfers Outside the EU/EEA

SDC stores and processes Personal Data within the European Union and theEuropean Economic Area, and selects its suppliers with that requirement inmind. We do not transfer Personal Data outside the EU/EEA in the ordinarycourse of our operations.

Should such a transfer become necessary, it will take place only where an adequate level of protection is ensured — on the basis of a European Commission adequacy decision, Standard Contractual Clauses together with any supplementary measures required following a transfer impact assessment, or another lawful mechanism under Chapter V GDPR. We will update this Policy before any such transfer takes place, and you may request information about the safeguards applied.
5.3 Retention

We retain Personal Data only for as long as necessary for the purposes for which it was collected, or for as long as required by law.

Category | Retention period
| Customer and supplier relationship data | Duration of the relationship, then ten (10) years, corresponding to the general limitation period under the Swedish Limitations Act (Preskriptionslagen (1981:130)) |
| Accounting and invoicing records | Seven (7) years following the end of the calendar year in which the financial year ended, under the Bookkeeping Act |
| Facility access records (entry and exit logs) | Twelve (12) months, or longer where required under the Security Protection Act or necessary to investigate an ongoing security incident |
| Visitor register data | Twelve (12) months |
| Camera surveillance footage | Thirty (30) days, unless the footage documentsan incident under investigation, in which case until the investigation and anyresulting proceedings are concluded |
| Access credentials and authorisation records | Duration of the authorisation,then twelve (12) months |
| Marketing contact data | Until you object or withdraw consent; a minimal suppression record is kept thereafter so that we can honour your objection |
| Job application data | Two (2) years following the conclusion of the recruitment process, corresponding to the limitation period under the Swedish Discrimination Act (Diskrimineringslagen (2008:567)) |
| Security and system logs | Twelve (12) months, unless a longer period isrequired for incident investigation or by law |
| Website and analytics data | As set out in our Cookie Policy |

Where data is processed for several purposes with different periods, the longest applicable period governs. At the end of the period, Personal Data is erased or irreversibly anonymised
5.4 Security

SDC implements appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, in accordance with Article 32 GDPR. These include multi-layered physical security at our facilities, with perimeter protection, controlled access zones, camera surveillance, and continuous monitoring; access management on least-privilege and need-to-know principles,reviewed regularly and revoked promptly when no longer required; encryption ofPersonal Data in transit and, where appropriate, at rest; network segmentation,logging, and monitoring to detect and respond to incidents; confidentiality undertakings and security awareness training for all personnel with access to Personal Data; documented and regularly tested incident response and business continuity procedures; and security requirements imposed on suppliers by written agreement, with assessment before engagement.

In the event of a Personal Data breach, we will notify IMY without undue delay and, where feasible, within 72 hours of becoming aware of it under Article 33 GDPR, and will inform affected Data Subjects where the breach is likely to result in a high risk to their rights and freedoms under Article 34 GDPR. Where we act as a Data Processor, we will notify the relevant customer without undue delay

6 Your Rights

Under the GDPR you have the following rights in relation to Personal Data that SDC processes about you:

- **Access (Article 15)** — to confirmation of whether we process Personal Dataconcerning you, a copy of that data, and information about the processing.
- **Rectification (Article 16)** — to have inaccurate data corrected and incomplete data completed.
- **Erasure (Article 17)** — to have data erased where it is no longer necessary, where you withdraw consent, where you successfully object, or where it has been processed unlawfully.
- **Restriction (Article 18)** — to require that we restrict processing incertain circumstances, including while we verify the accuracy of data you have contested.
- **Data portability (Article 20)** — where processing is based on consent or a contract with you and carried out by automated means, to receive the data you have provided in a structured, commonly used, machine-readable format, and tohave it transmitted to another controller where technically feasible.
- **Objection (Article 21)** — to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests; and an unconditional right to object to direct marketing, which we will act on immediately.
- **Withdrawal of consent (Article 7)** — where processing is based on consent,to withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.

These rights are not absolute. We may be unable to comply in full where datamust be retained to meet a legal obligation — for example under the BookkeepingAct or the Security Protection Act — or where retention is necessary toestablish, exercise, or defend legal claims. Where we decline a request inwhole or in part, we will explain why.

**Automated decision-making.** SDC does not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing, and does not carry out profiling for such purposes.

**Cookies.** Our website uses cookies and similar technologies. Non-essential cookies are set only with your consent, which you may give, decline, or withdraw at any time through the cookie settings on our website. Details are set out in our Cookie Policy.

6.1 How to Exercise Your Rights

Contact us using the details in section 3.3. We will respond without undue delay and in any event within one month of receiving your request. Where a request is complex, or where we have received a number of requests, we may extend that period by up to two further months, and will tell you of the extension and the reason within the first month.

We may need to verify your identity before acting, so that Personal Data is not disclosed to an unauthorised person. Exercising your rights is free of charge,although we may charge a reasonable fee, or decline to act, where a request is manifestly unfounded or excessive.

Where your request concerns Personal Data that SDC processes as a Data Processor on behalf of a customer, we will forward it to that customer, who is the Data Controller, and assist them in responding.

You may lodge a complaint with Integritetsskyddsmyndigheten (IMY) at any time. Contact details are available at imy.se.
 

Scandinavian Data Centers AB

Data Protection Contact

Email: info@scandinaviandc.com

Address: Rådmansgatan 22, 114 85 Stockholm, Sweden

You also have the right to lodgea complaint with the Swedish supervisory authority,Integritetsskyddsmyndigheten (IMY), at imy.se, if you believe that SDC’sprocessing of your Personal Data is not conducted in accordance with applicabledata protection law.

LAST UPDATED: 2026-08-13

This privacy policy explains how we collect and use your personal data, as well as the rights you have and how to exercise them.

1 Introduction

Scandinavian Data Centers AB ("SDC","we", "us", or "our") is a Swedish-owned data center operator providing colocation, power, and connectivity services across a distributed network of facilities in Sweden. We are committed to protecting the personal data of our customers, partners, employees, visitors to ou rfacilities, and website visitors in accordance with applicable privacy legislation.

This Privacy Policy explains how we collect, use, store, and share personal data in connection with our services and business operations. It applies to all personal data processed by SDC in its capacity as a data controller, and where applicable, as a data processor acting on behalf of our customers.

Our processing of personal data is governed primarily by Regulation (EU)2016/679 (the General Data Protection Regulation, "GDPR"), together with the Swedish Data Protection Act (Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning), as well as applicable sector-specific legislation including the Swedish Electronic Communications Act(Lag (2022:482) om elektronisk kommunikation, "LEK") and the Swedish Security Protection Act (Säkerhetsskyddslagen (2018:585)). As a provider of data centre services, SDC is also subject to the Swedish Cybersecurity Act(Cybersäkerhetslagen (2025:1506)), which implements the NIS2 Directive (EU)2022/2555; a number of our customers are separately subject to that frame workin their own right.

This Policy is provided for information and transparency purposes. It does not form part of any contract between you and SDC, and it does not itself constitute a request for your consent. Where we rely on consent as the legal basis for a particular processing activity, we will ask for it separately, andyou may withdraw it at any time.

We may update this Privacy Policy from time to time to reflect changes in our operations, services, or legal obligations. The most current version will always be available on our website and, where required by law, we will notify you of material changes before they take effect.

2 Definitions

For the purposes of this Privacy Policy, the followingterms shall have the meanings set out below. These definitions align with the GDPR and applicable Swedish legislation.

Personal Data: Any information relating to an identified or identifiable natural person (“Data Subject”). An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, or online identifier.

Processing: Any operation or set of operations performed on Personal Data, whether by automated means or otherwise, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure,dissemination, restriction, erasure, or destruction.

Data Controller: The natural or legal person, public authority, agency, orother body which, alone or jointly with others, determines the purposes andmeans of the processing of Personal Data. SDC acts as a Data Controller withrespect to Personal Data collected in connection with its own businessoperations, including customer and supplier relationships, facility management,and marketing activities.

Data Processor: A natural or legal person, public authority, agency, orother body which processes Personal Data on behalf of the Data Controller. SDCmay act as a Data Processor where it processes Personal Data on behalf of itscolocation customers pursuant to a Data Processing Agreement.

Data Subject: Any identified or identifiable natural person whose Personal Data is processed by SDC or on behalf of SDC.

GDPR: Regulation (EU) 2016/679 of the European Parliament andof the Council of 27 April 2016 on the protection of natural persons withregard to the processing of personal data and on the free movement of such data.

Sensitive Personal Data: Categories of Personal Data afforded heightenedprotection under Article 9 GDPR, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for the purpose of uniquelyidentifying a person, health data, and data concerning a person’s sex life orsexual orientation.

Third Party: Any natural or legal person, public authority, agency, orbody other than the Data Subject, Data Controller, Data Processor, and personswho, under the direct authority of the Data Controller or Processor, are authorised to process Personal Data.

Data Processing Agreement(DPA): A legally binding agreement entered into between SDC and a customer or supplier governing the processing of Personal Data by SDC in its capacity as Data Processor, in accordance with Article 28 GDPR.

Security Protection Act(Säkerhetsskyddslagen): Swedish legislation (SFS 2018:585) governing the protection of classified information and security-sensitive activities. Certain SDC facilities and customer engagements may be subject to obligations under this Act.

NIS2 Directive: Directive (EU) 2022/2555 on measures for a high commonlevel of cyber security across the Union. Certain customers operating critical infrastructure and hosted within SDC facilities may be subject to this Directive’s requirements.

Colocation Services: The service offering whereby SDC provides physical space, power, cooling, and connectivity infrastructure within its data centerfacilities for customers to house their own IT equipment.

Supervisory Authority: The competent national authority responsible formonitoring and enforcing compliance with the GDPR. In Sweden, this is theIntegritetsskyddsmyndigheten (IMY).

3 Responsibility

Scandinavian Data Centers AB, registered in Sweden (org.nr. 559332-4295), with its registered address at Rådmansgatan 22, 114 25 Stockholm, is the Data Controller for Personal Data processed in connection with SDC’s own business operations, including the management of customer and supplier relationships, access control and facility security, employment matters, and marketing communications.

3.1  Data Controller Responsibilities

As Data Controller, SDC is responsible for ensuring that Personal Data is processed lawfully, fairly, and transparently in accordance with the GDPR and applicable Swedish law. This includes:

•      Establishing andmaintaining a lawful basis for each category of processing activity.

•      Ensuring that Personal Datais collected for specified, explicit, and legitimate purposes and not processedin a manner incompatible with those purposes.

•      Implementing appropriate technical and organisational measures to ensure a level of security appropriateto the risk of processing, including measures to prevent unauthorised access, accidental loss, destruction, or damage.

•      Maintaining a Record of Processing Activities (RoPA) in accordance with Article 30 GDPR.

•      Ensuring that Data Subjectscan effectively exercise their rights as set out in this Policy.

•      Notifying the Swedish supervisory authority (IMY) and, where required, affected Data Subjects, of any Personal Data breach in accordance with Articles 33 and 34 GDPR.

3.2  Data Processor Responsibilities

Where SDC processes Personal Data on behalf of its colocation customers acting as Data Controllers, SDC acts as a Data Processor. In this capacity, SDC will:

•      Process Personal Data only on documented instructions from the customer (Data Controller), unless requiredto do so by applicable law.

•      Ensure that personsauthorised to process the Personal Data are subject to appropriateconfidentiality obligations.

•      Implement appropriatetechnical and organisational security measures in accordance with Article 32GDPR.

•      Not engage sub-processorswithout prior written authorisation from the customer, and where suchauthorisation is given, ensure that sub-processors are bound by equivalent dataprotection obligations.

•      Assist the customer infulfilling its obligations with respect to Data Subject rights requests,security measures, data breach notification, and data protection impactassessments.

•      At the customer’s choice,delete or return all Personal Data upon termination of the colocation agreement, unless retention is required by law.

•      Provide the customer with all information necessary to demonstrate compliance and cooperate with auditsand inspections.

The respective rights and obligations of SDC and its customers in their capacity as Data Controllers and Data Processors are further governed by Data Processing Agreements entered into pursuant to Article 28 GDPR.

3.3  Data Protection Contact

SDC has designated a point of contact for data protection matters. Any questions, concerns, or requests relating to the processing ofPersonal Data under this Policy should be directed to:

4 What We Process, Why, and On What Basis

The Personal Data we process depends on yourrelationship with SDC. The table below sets out each category of Data Subject,the Personal Data concerned, the purposes of the processing, and our legalbasis under Article 6 GDPR.

| You are | Personal Data we process | Purposes | Legal basis |
| --- | --- | --- | --- |
| **A customer or prospective customer representative** | Name, job title,employer, business contact details; correspondence, meeting notes, enquiriesand support requests; contract signatory details; order history, serviceconfiguration, invoicing and payment records; portal account identifiers andactivity logs | Providing and administering the Services; support; invoicingand payment; account management; managing the commercial relationship |Performance of a contract (Art. 6(1)(b)); our legitimate interest inadministering a relationship where the contract is with your employer (Art.6(1)(f)) |
| **A supplier or partner representative** | Name, job title, employer,business contact details; correspondence; contract, delivery and invoicingrecords; where site work is involved, the access data described below |Procurement; contract administration; coordinating work at our facilities |Performance of a contract (Art. 6(1)(b)); our legitimate interest in managingour supply chain (Art. 6(1)(f)) |
| **A visitor to one of our facilities** | Name, employer, the party you attendon behalf of, authorised areas, authorising person; access card and credentialidentifiers; entry and exit records by time and location; visitor registerentries; camera surveillance footage | Controlling and recording access;protecting the facility, our customers' equipment, and the safety of people onsite; maintaining an auditable access record; investigating security incidents| Our legitimate interest in physical security and in maintaining accessrecords our customers rely on (Art. 6(1)(f)); compliance with a legal obligationunder the Security Protection Act and the Cybersecurity Act (Art. 6(1)(c)) |
| **A job applicant** | Name, contact details, CV, cover letter, references,employment and education history, assessments and interview notes; where a roleis security-sensitive, information processed in connection with securityclearance | Assessing your application and administering the recruitmentprocess | Steps taken at your request prior to entering a contract (Art.6(1)(b)); our legitimate interest in assessing candidates (Art. 6(1)(f)); legalobligation, for security clearance (Art. 6(1)(c)) |
| **An employee** | Data necessary to administer the employment relationship |Employment administration | Employees receive separate, more detailedinformation through internal channels; this Policy does not replace it |
| **A website visitor** | IP address, device and browser type, operatingsystem, referring page, pages viewed, date and time; details you submit throughforms or subscriptions | Operating and securing the website; responding toenquiries; measuring and improving the site; sending communications you haverequested | Our legitimate interest in operating a secure and functioningwebsite (Art. 6(1)(f)); your consent for non-essential cookies and marketing(Art. 6(1)(a)) |

**Camera surveillance.** Cameras cover entrances, perimeters, delivery areas,and technical and customer areas within our facilities. They protect thefacility, our customers' equipment, and the people working in them, and are notused to monitor the work performance of individual employees or contractors.Signage is displayed at all monitored areas. Detailed information about ourcamera surveillance is set out in our separate Camera Surveillance Informationpage.

**Marketing.** We process the business contact details of customer and prospectrepresentatives to send business communications, newsletters, and eventinvitations, on the basis of our legitimate interest in promoting our servicesto business contacts, or your consent where required by law. You may object atany time, and every marketing message contains an unsubscribe facility.

**Other purposes.** We also process Personal Data to maintain the security,availability, and integrity of our infrastructure, including logging,monitoring, and incident response and reporting; to comply with legal andregulatory obligations, including bookkeeping under the Swedish Bookkeeping Act(Bokföringslagen (1999:1078)) and obligations under the Security Protection Actand the Cybersecurity Act; and to establish, exercise, or defend legalclaims.

**Sources.** We collect Personal Data primarily from you or from theorganisation you represent. We also receive it from our customers and supplierswhen they nominate individuals for site access or as service contacts, frompublicly available sources and business information services in connection withsales and know-your-customer checks, and from our own systems, where it isgenerated by your use of our facilities, portals, or website.

**Sensitive Personal Data.** SDC does not routinely process Sensitive Personal Data. We do not use biometric data to identify individuals; access to ourfacilities is controlled by credentials and personal identification numbers.Sensitive Personal Data may exceptionally be processed where necessary underemployment law, to protect vital interests, or to establish, exercise, ordefend legal claims, on the basis of an applicable exception under Article 9(2)GDPR. Data relating to criminal convictions and offences is processed onlywhere permitted under Article 10 GDPR and Swedish law, in particular inconnection with security clearance under the Security Protection Act.

**Legitimate interests.** Where we rely on legitimate interests, we havecarried out an assessment balancing those interests against the rights andfreedoms of the Data Subjects concerned. You may request further informationabout that assessment using the contact details in section 3.3.

5 Disclosure, Transfers, Retention, and Security

5.1 Disclosure

We do not sell Personal Data. We disclose it only where necessary for the purposes described in section 4, and only to:

- **Service providers acting on our behalf** — providers of IT, hosting,security, communications, accounting, and professional services. They process Personal Data as our Data Processors under written agreements concluded pursuant to Article 28 GDPR and may not use it for their own purposes.
- **Customers** — where an individual attends one of our facilities on their behalf and disclosure of access records is necessary for security, audit, or contractual purposes.
- **Competent authorities** — including the Swedish Post and Telecom Authority(PTS), the Swedish Security Service (Säkerhetspolisen), the Swedish Armed Forces, the Swedish Civil Contingencies Agency (MSB), IMY, law enforcement agencies, and courts, where required by law or necessary to establish,exercise, or defend legal claims.
- **Professional advisers, insurers, and auditors** — where necessary in connection with their services to SDC.
- **Acquirers or prospective acquirers** — in connection with a merger,acquisition, financing, or reorganisation of all or part of our business,subject to appropriate confidentiality protections.

5.2 Transfers Outside the EU/EEA

SDC stores and processes Personal Data within the European Union and theEuropean Economic Area, and selects its suppliers with that requirement inmind. We do not transfer Personal Data outside the EU/EEA in the ordinarycourse of our operations.

Should such a transfer become necessary, it will take place only where an adequate level of protection is ensured — on the basis of a European Commission adequacy decision, Standard Contractual Clauses together with any supplementary measures required following a transfer impact assessment, or another lawful mechanism under Chapter V GDPR. We will update this Policy before any such transfer takes place, and you may request information about the safeguards applied.
5.3 Retention

We retain Personal Data only for as long as necessary for the purposes for which it was collected, or for as long as required by law.

Category | Retention period
| Customer and supplier relationship data | Duration of the relationship, then ten (10) years, corresponding to the general limitation period under the Swedish Limitations Act (Preskriptionslagen (1981:130)) |
| Accounting and invoicing records | Seven (7) years following the end of the calendar year in which the financial year ended, under the Bookkeeping Act |
| Facility access records (entry and exit logs) | Twelve (12) months, or longer where required under the Security Protection Act or necessary to investigate an ongoing security incident |
| Visitor register data | Twelve (12) months |
| Camera surveillance footage | Thirty (30) days, unless the footage documentsan incident under investigation, in which case until the investigation and anyresulting proceedings are concluded |
| Access credentials and authorisation records | Duration of the authorisation,then twelve (12) months |
| Marketing contact data | Until you object or withdraw consent; a minimal suppression record is kept thereafter so that we can honour your objection |
| Job application data | Two (2) years following the conclusion of the recruitment process, corresponding to the limitation period under the Swedish Discrimination Act (Diskrimineringslagen (2008:567)) |
| Security and system logs | Twelve (12) months, unless a longer period isrequired for incident investigation or by law |
| Website and analytics data | As set out in our Cookie Policy |

Where data is processed for several purposes with different periods, the longest applicable period governs. At the end of the period, Personal Data is erased or irreversibly anonymised
5.4 Security

SDC implements appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, in accordance with Article 32 GDPR. These include multi-layered physical security at our facilities, with perimeter protection, controlled access zones, camera surveillance, and continuous monitoring; access management on least-privilege and need-to-know principles,reviewed regularly and revoked promptly when no longer required; encryption ofPersonal Data in transit and, where appropriate, at rest; network segmentation,logging, and monitoring to detect and respond to incidents; confidentiality undertakings and security awareness training for all personnel with access to Personal Data; documented and regularly tested incident response and business continuity procedures; and security requirements imposed on suppliers by written agreement, with assessment before engagement.

In the event of a Personal Data breach, we will notify IMY without undue delay and, where feasible, within 72 hours of becoming aware of it under Article 33 GDPR, and will inform affected Data Subjects where the breach is likely to result in a high risk to their rights and freedoms under Article 34 GDPR. Where we act as a Data Processor, we will notify the relevant customer without undue delay

6 Your Rights

Under the GDPR you have the following rights in relation to Personal Data that SDC processes about you:

- **Access (Article 15)** — to confirmation of whether we process Personal Dataconcerning you, a copy of that data, and information about the processing.
- **Rectification (Article 16)** — to have inaccurate data corrected and incomplete data completed.
- **Erasure (Article 17)** — to have data erased where it is no longer necessary, where you withdraw consent, where you successfully object, or where it has been processed unlawfully.
- **Restriction (Article 18)** — to require that we restrict processing incertain circumstances, including while we verify the accuracy of data you have contested.
- **Data portability (Article 20)** — where processing is based on consent or a contract with you and carried out by automated means, to receive the data you have provided in a structured, commonly used, machine-readable format, and tohave it transmitted to another controller where technically feasible.
- **Objection (Article 21)** — to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests; and an unconditional right to object to direct marketing, which we will act on immediately.
- **Withdrawal of consent (Article 7)** — where processing is based on consent,to withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.

These rights are not absolute. We may be unable to comply in full where datamust be retained to meet a legal obligation — for example under the BookkeepingAct or the Security Protection Act — or where retention is necessary toestablish, exercise, or defend legal claims. Where we decline a request inwhole or in part, we will explain why.

**Automated decision-making.** SDC does not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing, and does not carry out profiling for such purposes.

**Cookies.** Our website uses cookies and similar technologies. Non-essential cookies are set only with your consent, which you may give, decline, or withdraw at any time through the cookie settings on our website. Details are set out in our Cookie Policy.

6.1 How to Exercise Your Rights

Contact us using the details in section 3.3. We will respond without undue delay and in any event within one month of receiving your request. Where a request is complex, or where we have received a number of requests, we may extend that period by up to two further months, and will tell you of the extension and the reason within the first month.

We may need to verify your identity before acting, so that Personal Data is not disclosed to an unauthorised person. Exercising your rights is free of charge,although we may charge a reasonable fee, or decline to act, where a request is manifestly unfounded or excessive.

Where your request concerns Personal Data that SDC processes as a Data Processor on behalf of a customer, we will forward it to that customer, who is the Data Controller, and assist them in responding.

You may lodge a complaint with Integritetsskyddsmyndigheten (IMY) at any time. Contact details are available at imy.se.
 

Scandinavian Data Centers AB

Data Protection Contact

Email: info@scandinaviandc.com

Address: Rådmansgatan 22, 114 85 Stockholm, Sweden

You also have the right to lodgea complaint with the Swedish supervisory authority,Integritetsskyddsmyndigheten (IMY), at imy.se, if you believe that SDC’sprocessing of your Personal Data is not conducted in accordance with applicabledata protection law.

SDC Privacy Policy

LAST UPDATED: 2026-08-13

This privacy policy explains how we collect and use your personal data, as well as the rights you have and how to exercise them.

1 Introduction

Scandinavian Data Centers AB ("SDC","we", "us", or "our") is a Swedish-owned data center operator providing colocation, power, and connectivity services across a distributed network of facilities in Sweden. We are committed to protecting the personal data of our customers, partners, employees, visitors to ou rfacilities, and website visitors in accordance with applicable privacy legislation.

This Privacy Policy explains how we collect, use, store, and share personal data in connection with our services and business operations. It applies to all personal data processed by SDC in its capacity as a data controller, and where applicable, as a data processor acting on behalf of our customers.

Our processing of personal data is governed primarily by Regulation (EU)2016/679 (the General Data Protection Regulation, "GDPR"), together with the Swedish Data Protection Act (Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning), as well as applicable sector-specific legislation including the Swedish Electronic Communications Act(Lag (2022:482) om elektronisk kommunikation, "LEK") and the Swedish Security Protection Act (Säkerhetsskyddslagen (2018:585)). As a provider of data centre services, SDC is also subject to the Swedish Cybersecurity Act (Cybersäkerhetslagen (2025:1506)), which implements the NIS2 Directive (EU)2022/2555; a number of our customers are separately subject to that frame workin their own right.

This Policy is provided for information and transparency purposes. It does not form part of any contract between you and SDC, and it does not itself constitute a request for your consent. Where we rely on consent as the legal basis for a particular processing activity, we will ask for it separately, andyou may withdraw it at any time.

We may update this Privacy Policy from time to time to reflect changes in our operations, services, or legal obligations. The most current version will always be available on our website and, where required by law, we will notify you of material changes before they take effect.

Scandinavian Data Centers AB ("SDC","we", "us", or "our") is a Swedish-owned data center operator providing colocation, power, and connectivity services across a distributed network of facilities in Sweden. We are committed to protecting the personal data of our customers, partners, employees, visitors to ou rfacilities, and website visitors in accordance with applicable privacy legislation.

This Privacy Policy explains how we collect, use, store, and share personal data in connection with our services and business operations. It applies to all personal data processed by SDC in its capacity as a data controller, and where applicable, as a data processor acting on behalf of our customers.

Our processing of personal data is governed primarily by Regulation (EU)2016/679 (the General Data Protection Regulation, "GDPR"), together with the Swedish Data Protection Act (Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning), as well as applicable sector-specific legislation including the Swedish Electronic Communications Act(Lag (2022:482) om elektronisk kommunikation, "LEK") and the Swedish Security Protection Act (Säkerhetsskyddslagen (2018:585)). As a provider of data centre services, SDC is also subject to the Swedish Cybersecurity Act(Cybersäkerhetslagen (2025:1506)), which implements the NIS2 Directive (EU)2022/2555; a number of our customers are separately subject to that frame workin their own right.

This Policy is provided for information and transparency purposes. It does not form part of any contract between you and SDC, and it does not itself constitute a request for your consent. Where we rely on consent as the legal basis for a particular processing activity, we will ask for it separately, andyou may withdraw it at any time.

We may update this Privacy Policy from time to time to reflect changes in our operations, services, or legal obligations. The most current version will always be available on our website and, where required by law, we will notify you of material changes before they take effect.

2 Definitions

For the purposes of this Privacy Policy, the followingterms shall have the meanings set out below. These definitions align with the GDPR and applicable Swedish legislation.

Personal Data: Any information relating to an identified or identifiable natural person (“Data Subject”). An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, or online identifier.

Processing: Any operation or set of operations performed on Personal Data, whether by automated means or otherwise, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure,dissemination, restriction, erasure, or destruction.

Data Controller: The natural or legal person, public authority, agency, orother body which, alone or jointly with others, determines the purposes andmeans of the processing of Personal Data. SDC acts as a Data Controller withrespect to Personal Data collected in connection with its own businessoperations, including customer and supplier relationships, facility management,and marketing activities.

Data Processor: A natural or legal person, public authority, agency, orother body which processes Personal Data on behalf of the Data Controller. SDCmay act as a Data Processor where it processes Personal Data on behalf of itscolocation customers pursuant to a Data Processing Agreement.

Data Subject: Any identified or identifiable natural person whose Personal Data is processed by SDC or on behalf of SDC.

GDPR: Regulation (EU) 2016/679 of the European Parliament andof the Council of 27 April 2016 on the protection of natural persons withregard to the processing of personal data and on the free movement of such data.

Sensitive Personal Data: Categories of Personal Data afforded heightenedprotection under Article 9 GDPR, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for the purpose of uniquelyidentifying a person, health data, and data concerning a person’s sex life orsexual orientation.

Third Party: Any natural or legal person, public authority, agency, orbody other than the Data Subject, Data Controller, Data Processor, and personswho, under the direct authority of the Data Controller or Processor, are authorised to process Personal Data.

Data Processing Agreement(DPA): A legally binding agreement entered into between SDC and a customer or supplier governing the processing of Personal Data by SDC in its capacity as Data Processor, in accordance with Article 28 GDPR.

Security Protection Act(Säkerhetsskyddslagen): Swedish legislation (SFS 2018:585) governing the protection of classified information and security-sensitive activities. Certain SDC facilities and customer engagements may be subject to obligations under this Act.

NIS2 Directive: Directive (EU) 2022/2555 on measures for a high commonlevel of cyber security across the Union. Certain customers operating critical infrastructure and hosted within SDC facilities may be subject to this Directive’s requirements.

Colocation Services: The service offering whereby SDC provides physical space, power, cooling, and connectivity infrastructure within its data centerfacilities for customers to house their own IT equipment.

Supervisory Authority: The competent national authority responsible formonitoring and enforcing compliance with the GDPR. In Sweden, this is theIntegritetsskyddsmyndigheten (IMY).

3 Responsibility

Scandinavian Data Centers AB, registered in Sweden (org.nr. 559332-4295), with its registered address at Rådmansgatan 22, 114 25 Stockholm, is the Data Controller for Personal Data processed in connection with SDC’s own business operations, including the management of customer and supplier relationships, access control and facility security, employment matters, and marketing communications.

3.1  Data Controller Responsibilities

As Data Controller, SDC is responsible for ensuring that Personal Data is processed lawfully, fairly, and transparently in accordance with the GDPR and applicable Swedish law. This includes:

•      Establishing andmaintaining a lawful basis for each category of processing activity.

•      Ensuring that Personal Datais collected for specified, explicit, and legitimate purposes and not processedin a manner incompatible with those purposes.

•      Implementing appropriate technical and organisational measures to ensure a level of security appropriateto the risk of processing, including measures to prevent unauthorised access, accidental loss, destruction, or damage.

•      Maintaining a Record of Processing Activities (RoPA) in accordance with Article 30 GDPR.

•      Ensuring that Data Subjectscan effectively exercise their rights as set out in this Policy.

•      Notifying the Swedish supervisory authority (IMY) and, where required, affected Data Subjects, of any Personal Data breach in accordance with Articles 33 and 34 GDPR.

3.2  Data Processor Responsibilities

Where SDC processes Personal Data on behalf of its colocation customers acting as Data Controllers, SDC acts as a Data Processor. In this capacity, SDC will:

•      Process Personal Data only on documented instructions from the customer (Data Controller), unless requiredto do so by applicable law.

•      Ensure that personsauthorised to process the Personal Data are subject to appropriateconfidentiality obligations.

•      Implement appropriatetechnical and organisational security measures in accordance with Article 32GDPR.

•      Not engage sub-processorswithout prior written authorisation from the customer, and where suchauthorisation is given, ensure that sub-processors are bound by equivalent dataprotection obligations.

•      Assist the customer infulfilling its obligations with respect to Data Subject rights requests,security measures, data breach notification, and data protection impactassessments.

•      At the customer’s choice,delete or return all Personal Data upon termination of the colocation agreement, unless retention is required by law.

•      Provide the customer with all information necessary to demonstrate compliance and cooperate with auditsand inspections.

The respective rights and obligations of SDC and its customers in their capacity as Data Controllers and Data Processors are further governed by Data Processing Agreements entered into pursuant to Article 28 GDPR.

3.3  Data Protection Contact

SDC has designated a point of contact for data protection matters. Any questions, concerns, or requests relating to the processing ofPersonal Data under this Policy should be directed to:

4 What We Process, Why, and On What Basis

The Personal Data we process depends on yourrelationship with SDC. The table below sets out each category of Data Subject,the Personal Data concerned, the purposes of the processing, and our legalbasis under Article 6 GDPR.

| You are | Personal Data we process | Purposes | Legal basis |
|
| **A customer or prospective customer representative** | Name, job title,employer, business contact details; correspondence, meeting notes, enquiriesand support requests; contract signatory details; order history, serviceconfiguration, invoicing and payment records; portal account identifiers andactivity logs | Providing and administering the Services; support; invoicingand payment; account management; managing the commercial relationship |Performance of a contract (Art. 6(1)(b)); our legitimate interest inadministering a relationship where the contract is with your employer (Art.6(1)(f)) |
| **A supplier or partner representative** | Name, job title, employer,business contact details; correspondence; contract, delivery and invoicingrecords; where site work is involved, the access data described below |Procurement; contract administration; coordinating work at our facilities |Performance of a contract (Art. 6(1)(b)); our legitimate interest in managingour supply chain (Art. 6(1)(f)) |
| **A visitor to one of our facilities** | Name, employer, the party you attendon behalf of, authorised areas, authorising person; access card and credentialidentifiers; entry and exit records by time and location; visitor registerentries; camera surveillance footage | Controlling and recording access;protecting the facility, our customers' equipment, and the safety of people onsite; maintaining an auditable access record; investigating security incidents| Our legitimate interest in physical security and in maintaining accessrecords our customers rely on (Art. 6(1)(f)); compliance with a legal obligationunder the Security Protection Act and the Cybersecurity Act (Art. 6(1)(c)) |
| **A job applicant** | Name, contact details, CV, cover letter, references,employment and education history, assessments and interview notes; where a roleis security-sensitive, information processed in connection with securityclearance | Assessing your application and administering the recruitmentprocess | Steps taken at your request prior to entering a contract (Art.6(1)(b)); our legitimate interest in assessing candidates (Art. 6(1)(f)); legalobligation, for security clearance (Art. 6(1)(c)) |
| **An employee** | Data necessary to administer the employment relationship |Employment administration | Employees receive separate, more detailedinformation through internal channels; this Policy does not replace it |
| **A website visitor** | IP address, device and browser type, operatingsystem, referring page, pages viewed, date and time; details you submit throughforms or subscriptions | Operating and securing the website; responding toenquiries; measuring and improving the site; sending communications you haverequested | Our legitimate interest in operating a secure and functioningwebsite (Art. 6(1)(f)); your consent for non-essential cookies and marketing(Art. 6(1)(a)) |

**Camera surveillance.** Cameras cover entrances, perimeters, delivery areas,and technical and customer areas within our facilities. They protect thefacility, our customers' equipment, and the people working in them, and are notused to monitor the work performance of individual employees or contractors.Signage is displayed at all monitored areas. Detailed information about ourcamera surveillance is set out in our separate Camera Surveillance Informationpage.

**Marketing.** We process the business contact details of customer and prospectrepresentatives to send business communications, newsletters, and eventinvitations, on the basis of our legitimate interest in promoting our servicesto business contacts, or your consent where required by law. You may object atany time, and every marketing message contains an unsubscribe facility.

**Other purposes.** We also process Personal Data to maintain the security,availability, and integrity of our infrastructure, including logging,monitoring, and incident response and reporting; to comply with legal andregulatory obligations, including bookkeeping under the Swedish Bookkeeping Act(Bokföringslagen (1999:1078)) and obligations under the Security Protection Actand the Cybersecurity Act; and to establish, exercise, or defend legalclaims.

**Sources.** We collect Personal Data primarily from you or from theorganisation you represent. We also receive it from our customers and supplierswhen they nominate individuals for site access or as service contacts, frompublicly available sources and business information services in connection withsales and know-your-customer checks, and from our own systems, where it isgenerated by your use of our facilities, portals, or website.

**Sensitive Personal Data.** SDC does not routinely process Sensitive Personal Data. We do not use biometric data to identify individuals; access to ourfacilities is controlled by credentials and personal identification numbers.Sensitive Personal Data may exceptionally be processed where necessary underemployment law, to protect vital interests, or to establish, exercise, ordefend legal claims, on the basis of an applicable exception under Article 9(2)GDPR. Data relating to criminal convictions and offences is processed onlywhere permitted under Article 10 GDPR and Swedish law, in particular inconnection with security clearance under the Security Protection Act.

**Legitimate interests.** Where we rely on legitimate interests, we havecarried out an assessment balancing those interests against the rights andfreedoms of the Data Subjects concerned. You may request further informationabout that assessment using the contact details in section 3.3.

5 Disclosure, Transfers, Retention, and Security

5.1 Disclosure

We do not sell Personal Data. We disclose it only where necessary for the purposes described in section 4, and only to:

- **Service providers acting on our behalf** — providers of IT, hosting,security, communications, accounting, and professional services. They process Personal Data as our Data Processors under written agreements concluded pursuant to Article 28 GDPR and may not use it for their own purposes.
- **Customers** — where an individual attends one of our facilities on their behalf and disclosure of access records is necessary for security, audit, or contractual purposes.
- **Competent authorities** — including the Swedish Post and Telecom Authority(PTS), the Swedish Security Service (Säkerhetspolisen), the Swedish Armed Forces, the Swedish Civil Contingencies Agency (MSB), IMY, law enforcement agencies, and courts, where required by law or necessary to establish,exercise, or defend legal claims.
- **Professional advisers, insurers, and auditors** — where necessary in connection with their services to SDC.
- **Acquirers or prospective acquirers** — in connection with a merger,acquisition, financing, or reorganisation of all or part of our business,subject to appropriate confidentiality protections.

5.2 Transfers Outside the EU/EEA

Personal Data relating to our customers, suppliers, partners, employees, job applicants, and visitors to our facilities is stored and processed within the European Union and the European Economic Area. We select our suppliers with that requirement in mind, and we do not transfer that data outside the EU/EEA.

The single exception concerns the operation of our website. Our website is built and hosted on Webflow and delivered through Cloudflare, both of which are established in the United States and operate global networks. Technical data generated by your visit — including your IPaddress — may therefore be processed outside the EU/EEA. Both providers act as our processors under agreements concluded pursuant to Article 28 GDPR, and such transfers are made on the basis of Standard Contractual Clauses adopted by the European Commission, together with the supplementary and technical measures those providers apply. Further detail is set out in our Cookie Policy.

Should any further transfer outside the EU/EEA become necessary, it will take place only where an adequate level of protection is ensured — on the basis of a European Commission adequacy decision, Standard Contractual Clauses together with any supplementary measures required following a transfer impact assessment, or another lawful mechanism under Chapter V GDPR. We will update this Policy before any such transfer takes place, and you may request information about the safeguards applied.

6 Your Rights

Under the GDPR you have the following rights in relation to Personal Data that SDC processes about you:

- **Access (Article 15)** — to confirmation of whether we process Personal Dataconcerning you, a copy of that data, and information about the processing.
- **Rectification (Article 16)** — to have inaccurate data corrected and incomplete data completed.
- **Erasure (Article 17)** — to have data erased where it is no longer necessary, where you withdraw consent, where you successfully object, or where it has been processed unlawfully.
- **Restriction (Article 18)** — to require that we restrict processing incertain circumstances, including while we verify the accuracy of data you have contested.
- **Data portability (Article 20)** — where processing is based on consent or a contract with you and carried out by automated means, to receive the data you have provided in a structured, commonly used, machine-readable format, and tohave it transmitted to another controller where technically feasible.
- **Objection (Article 21)** — to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests; and an unconditional right to object to direct marketing, which we will act on immediately.
- **Withdrawal of consent (Article 7)** — where processing is based on consent,to withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.

These rights are not absolute. We may be unable to comply in full where datamust be retained to meet a legal obligation — for example under the BookkeepingAct or the Security Protection Act — or where retention is necessary toestablish, exercise, or defend legal claims. Where we decline a request inwhole or in part, we will explain why.

**Automated decision-making.** SDC does not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing, and does not carry out profiling for such purposes.

**Cookies.** Our website uses cookies and similar technologies. Non-essential cookies are set only with your consent, which you may give, decline, or withdraw at any time through the cookie settings on our website. Details are set out in our Cookie Policy.

6.1 How to Exercise Your Rights

Contact us using the details in section 3.3. We will respond without undue delay and in any event within one month of receiving your request. Where a request is complex, or where we have received a number of requests, we may extend that period by up to two further months, and will tell you of the extension and the reason within the first month.

We may need to verify your identity before acting, so that Personal Data is not disclosed to an unauthorised person. Exercising your rights is free of charge,although we may charge a reasonable fee, or decline to act, where a request is manifestly unfounded or excessive.

Where your request concerns Personal Data that SDC processes as a Data Processor on behalf of a customer, we will forward it to that customer, who is the Data Controller, and assist them in responding.

You may lodge a complaint with Integritetsskyddsmyndigheten (IMY) at any time. Contact details are available at imy.se.
 

Scandinavian Data Centers AB

Data Protection Contact

Email: info@scandinaviandc.com

Address: Rådmansgatan 22, 114 85 Stockholm, Sweden

You also have the right to lodgea complaint with the Swedish supervisory authority,Integritetsskyddsmyndigheten (IMY), at imy.se, if you believe that SDC’sprocessing of your Personal Data is not conducted in accordance with applicabledata protection law.

LAST UPDATED: 2026-08-13

This privacy policy explains how we collect and use your personal data, as well as the rights you have and how to exercise them.

1 Introduction

Scandinavian Data Centers AB ("SDC","we", "us", or "our") is a Swedish-owned data center operator providing colocation, power, and connectivity services across a distributed network of facilities in Sweden. We are committed to protecting the personal data of our customers, partners, employees, visitors to ou rfacilities, and website visitors in accordance with applicable privacy legislation.

This Privacy Policy explains how we collect, use, store, and share personal data in connection with our services and business operations. It applies to all personal data processed by SDC in its capacity as a data controller, and where applicable, as a data processor acting on behalf of our customers.

Our processing of personal data is governed primarily by Regulation (EU)2016/679 (the General Data Protection Regulation, "GDPR"), together with the Swedish Data Protection Act (Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning), as well as applicable sector-specific legislation including the Swedish Electronic Communications Act(Lag (2022:482) om elektronisk kommunikation, "LEK") and the Swedish Security Protection Act (Säkerhetsskyddslagen (2018:585)). As a provider of data centre services, SDC is also subject to the Swedish Cybersecurity Act(Cybersäkerhetslagen (2025:1506)), which implements the NIS2 Directive (EU)2022/2555; a number of our customers are separately subject to that frame workin their own right.

This Policy is provided for information and transparency purposes. It does not form part of any contract between you and SDC, and it does not itself constitute a request for your consent. Where we rely on consent as the legal basis for a particular processing activity, we will ask for it separately, andyou may withdraw it at any time.

We may update this Privacy Policy from time to time to reflect changes in our operations, services, or legal obligations. The most current version will always be available on our website and, where required by law, we will notify you of material changes before they take effect.

2 Definitions

For the purposes of this Privacy Policy, the followingterms shall have the meanings set out below. These definitions align with the GDPR and applicable Swedish legislation.

Personal Data: Any information relating to an identified or identifiable natural person (“Data Subject”). An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, or online identifier.

Processing: Any operation or set of operations performed on Personal Data, whether by automated means or otherwise, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure,dissemination, restriction, erasure, or destruction.

Data Controller: The natural or legal person, public authority, agency, orother body which, alone or jointly with others, determines the purposes andmeans of the processing of Personal Data. SDC acts as a Data Controller withrespect to Personal Data collected in connection with its own businessoperations, including customer and supplier relationships, facility management,and marketing activities.

Data Processor: A natural or legal person, public authority, agency, orother body which processes Personal Data on behalf of the Data Controller. SDCmay act as a Data Processor where it processes Personal Data on behalf of itscolocation customers pursuant to a Data Processing Agreement.

Data Subject: Any identified or identifiable natural person whose Personal Data is processed by SDC or on behalf of SDC.

GDPR: Regulation (EU) 2016/679 of the European Parliament andof the Council of 27 April 2016 on the protection of natural persons withregard to the processing of personal data and on the free movement of such data.

Sensitive Personal Data: Categories of Personal Data afforded heightenedprotection under Article 9 GDPR, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for the purpose of uniquelyidentifying a person, health data, and data concerning a person’s sex life orsexual orientation.

Third Party: Any natural or legal person, public authority, agency, orbody other than the Data Subject, Data Controller, Data Processor, and personswho, under the direct authority of the Data Controller or Processor, are authorised to process Personal Data.

Data Processing Agreement(DPA): A legally binding agreement entered into between SDC and a customer or supplier governing the processing of Personal Data by SDC in its capacity as Data Processor, in accordance with Article 28 GDPR.

Security Protection Act(Säkerhetsskyddslagen): Swedish legislation (SFS 2018:585) governing the protection of classified information and security-sensitive activities. Certain SDC facilities and customer engagements may be subject to obligations under this Act.

NIS2 Directive: Directive (EU) 2022/2555 on measures for a high commonlevel of cyber security across the Union. Certain customers operating critical infrastructure and hosted within SDC facilities may be subject to this Directive’s requirements.

Colocation Services: The service offering whereby SDC provides physical space, power, cooling, and connectivity infrastructure within its data centerfacilities for customers to house their own IT equipment.

Supervisory Authority: The competent national authority responsible formonitoring and enforcing compliance with the GDPR. In Sweden, this is theIntegritetsskyddsmyndigheten (IMY).

3 Responsibility

Scandinavian Data Centers AB, registered in Sweden (org.nr. 559332-4295), with its registered address at Rådmansgatan 22, 114 25 Stockholm, is the Data Controller for Personal Data processed in connection with SDC’s own business operations, including the management of customer and supplier relationships, access control and facility security, employment matters, and marketing communications.

3.1  Data Controller Responsibilities

As Data Controller, SDC is responsible for ensuring that Personal Data is processed lawfully, fairly, and transparently in accordance with the GDPR and applicable Swedish law. This includes:

•      Establishing andmaintaining a lawful basis for each category of processing activity.

•      Ensuring that Personal Datais collected for specified, explicit, and legitimate purposes and not processedin a manner incompatible with those purposes.

•      Implementing appropriate technical and organisational measures to ensure a level of security appropriateto the risk of processing, including measures to prevent unauthorised access, accidental loss, destruction, or damage.

•      Maintaining a Record of Processing Activities (RoPA) in accordance with Article 30 GDPR.

•      Ensuring that Data Subjectscan effectively exercise their rights as set out in this Policy.

•      Notifying the Swedish supervisory authority (IMY) and, where required, affected Data Subjects, of any Personal Data breach in accordance with Articles 33 and 34 GDPR.

3.2  Data Processor Responsibilities

Where SDC processes Personal Data on behalf of its colocation customers acting as Data Controllers, SDC acts as a Data Processor. In this capacity, SDC will:

•      Process Personal Data only on documented instructions from the customer (Data Controller), unless requiredto do so by applicable law.

•      Ensure that personsauthorised to process the Personal Data are subject to appropriateconfidentiality obligations.

•      Implement appropriatetechnical and organisational security measures in accordance with Article 32GDPR.

•      Not engage sub-processorswithout prior written authorisation from the customer, and where suchauthorisation is given, ensure that sub-processors are bound by equivalent dataprotection obligations.

•      Assist the customer infulfilling its obligations with respect to Data Subject rights requests,security measures, data breach notification, and data protection impactassessments.

•      At the customer’s choice,delete or return all Personal Data upon termination of the colocation agreement, unless retention is required by law.

•      Provide the customer with all information necessary to demonstrate compliance and cooperate with auditsand inspections.

The respective rights and obligations of SDC and its customers in their capacity as Data Controllers and Data Processors are further governed by Data Processing Agreements entered into pursuant to Article 28 GDPR.

3.3  Data Protection Contact

SDC has designated a point of contact for data protection matters. Any questions, concerns, or requests relating to the processing ofPersonal Data under this Policy should be directed to:

4 What We Process, Why, and On What Basis

The Personal Data we process depends on yourrelationship with SDC. The table below sets out each category of Data Subject,the Personal Data concerned, the purposes of the processing, and our legalbasis under Article 6 GDPR.

| You are | Personal Data we process | Purposes | Legal basis |
| --- | --- | --- | --- |
| **A customer or prospective customer representative** | Name, job title,employer, business contact details; correspondence, meeting notes, enquiriesand support requests; contract signatory details; order history, serviceconfiguration, invoicing and payment records; portal account identifiers andactivity logs | Providing and administering the Services; support; invoicingand payment; account management; managing the commercial relationship |Performance of a contract (Art. 6(1)(b)); our legitimate interest inadministering a relationship where the contract is with your employer (Art.6(1)(f)) |
| **A supplier or partner representative** | Name, job title, employer,business contact details; correspondence; contract, delivery and invoicingrecords; where site work is involved, the access data described below |Procurement; contract administration; coordinating work at our facilities |Performance of a contract (Art. 6(1)(b)); our legitimate interest in managingour supply chain (Art. 6(1)(f)) |
| **A visitor to one of our facilities** | Name, employer, the party you attendon behalf of, authorised areas, authorising person; access card and credentialidentifiers; entry and exit records by time and location; visitor registerentries; camera surveillance footage | Controlling and recording access;protecting the facility, our customers' equipment, and the safety of people onsite; maintaining an auditable access record; investigating security incidents| Our legitimate interest in physical security and in maintaining accessrecords our customers rely on (Art. 6(1)(f)); compliance with a legal obligationunder the Security Protection Act and the Cybersecurity Act (Art. 6(1)(c)) |
| **A job applicant** | Name, contact details, CV, cover letter, references,employment and education history, assessments and interview notes; where a roleis security-sensitive, information processed in connection with securityclearance | Assessing your application and administering the recruitmentprocess | Steps taken at your request prior to entering a contract (Art.6(1)(b)); our legitimate interest in assessing candidates (Art. 6(1)(f)); legalobligation, for security clearance (Art. 6(1)(c)) |
| **An employee** | Data necessary to administer the employment relationship |Employment administration | Employees receive separate, more detailedinformation through internal channels; this Policy does not replace it |
| **A website visitor** | IP address, device and browser type, operatingsystem, referring page, pages viewed, date and time; details you submit throughforms or subscriptions | Operating and securing the website; responding toenquiries; measuring and improving the site; sending communications you haverequested | Our legitimate interest in operating a secure and functioningwebsite (Art. 6(1)(f)); your consent for non-essential cookies and marketing(Art. 6(1)(a)) |

**Camera surveillance.** Cameras cover entrances, perimeters, delivery areas,and technical and customer areas within our facilities. They protect thefacility, our customers' equipment, and the people working in them, and are notused to monitor the work performance of individual employees or contractors.Signage is displayed at all monitored areas. Detailed information about ourcamera surveillance is set out in our separate Camera Surveillance Informationpage.

**Marketing.** We process the business contact details of customer and prospectrepresentatives to send business communications, newsletters, and eventinvitations, on the basis of our legitimate interest in promoting our servicesto business contacts, or your consent where required by law. You may object atany time, and every marketing message contains an unsubscribe facility.

**Other purposes.** We also process Personal Data to maintain the security,availability, and integrity of our infrastructure, including logging,monitoring, and incident response and reporting; to comply with legal andregulatory obligations, including bookkeeping under the Swedish Bookkeeping Act(Bokföringslagen (1999:1078)) and obligations under the Security Protection Actand the Cybersecurity Act; and to establish, exercise, or defend legalclaims.

**Sources.** We collect Personal Data primarily from you or from theorganisation you represent. We also receive it from our customers and supplierswhen they nominate individuals for site access or as service contacts, frompublicly available sources and business information services in connection withsales and know-your-customer checks, and from our own systems, where it isgenerated by your use of our facilities, portals, or website.

**Sensitive Personal Data.** SDC does not routinely process Sensitive Personal Data. We do not use biometric data to identify individuals; access to ourfacilities is controlled by credentials and personal identification numbers.Sensitive Personal Data may exceptionally be processed where necessary underemployment law, to protect vital interests, or to establish, exercise, ordefend legal claims, on the basis of an applicable exception under Article 9(2)GDPR. Data relating to criminal convictions and offences is processed onlywhere permitted under Article 10 GDPR and Swedish law, in particular inconnection with security clearance under the Security Protection Act.

**Legitimate interests.** Where we rely on legitimate interests, we havecarried out an assessment balancing those interests against the rights andfreedoms of the Data Subjects concerned. You may request further informationabout that assessment using the contact details in section 3.3.

5 Disclosure, Transfers, Retention, and Security

5.1 Disclosure

We do not sell Personal Data. We disclose it only where necessary for the purposes described in section 4, and only to:

- **Service providers acting on our behalf** — providers of IT, hosting,security, communications, accounting, and professional services. They process Personal Data as our Data Processors under written agreements concluded pursuant to Article 28 GDPR and may not use it for their own purposes.
- **Customers** — where an individual attends one of our facilities on their behalf and disclosure of access records is necessary for security, audit, or contractual purposes.
- **Competent authorities** — including the Swedish Post and Telecom Authority(PTS), the Swedish Security Service (Säkerhetspolisen), the Swedish Armed Forces, the Swedish Civil Contingencies Agency (MSB), IMY, law enforcement agencies, and courts, where required by law or necessary to establish,exercise, or defend legal claims.
- **Professional advisers, insurers, and auditors** — where necessary in connection with their services to SDC.
- **Acquirers or prospective acquirers** — in connection with a merger,acquisition, financing, or reorganisation of all or part of our business,subject to appropriate confidentiality protections.

5.2 Transfers Outside the EU/EEA

SDC stores and processes Personal Data within the European Union and theEuropean Economic Area, and selects its suppliers with that requirement inmind. We do not transfer Personal Data outside the EU/EEA in the ordinarycourse of our operations.

Should such a transfer become necessary, it will take place only where an adequate level of protection is ensured — on the basis of a European Commission adequacy decision, Standard Contractual Clauses together with any supplementary measures required following a transfer impact assessment, or another lawful mechanism under Chapter V GDPR. We will update this Policy before any such transfer takes place, and you may request information about the safeguards applied.
5.3 Retention

We retain Personal Data only for as long as necessary for the purposes for which it was collected, or for as long as required by law.

Category | Retention period
| Customer and supplier relationship data | Duration of the relationship, then ten (10) years, corresponding to the general limitation period under the Swedish Limitations Act (Preskriptionslagen (1981:130)) |
| Accounting and invoicing records | Seven (7) years following the end of the calendar year in which the financial year ended, under the Bookkeeping Act |
| Facility access records (entry and exit logs) | Twelve (12) months, or longer where required under the Security Protection Act or necessary to investigate an ongoing security incident |
| Visitor register data | Twelve (12) months |
| Camera surveillance footage | Thirty (30) days, unless the footage documentsan incident under investigation, in which case until the investigation and anyresulting proceedings are concluded |
| Access credentials and authorisation records | Duration of the authorisation,then twelve (12) months |
| Marketing contact data | Until you object or withdraw consent; a minimal suppression record is kept thereafter so that we can honour your objection |
| Job application data | Two (2) years following the conclusion of the recruitment process, corresponding to the limitation period under the Swedish Discrimination Act (Diskrimineringslagen (2008:567)) |
| Security and system logs | Twelve (12) months, unless a longer period isrequired for incident investigation or by law |
| Website and analytics data | As set out in our Cookie Policy |

Where data is processed for several purposes with different periods, the longest applicable period governs. At the end of the period, Personal Data is erased or irreversibly anonymised
5.4 Security

SDC implements appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, in accordance with Article 32 GDPR. These include multi-layered physical security at our facilities, with perimeter protection, controlled access zones, camera surveillance, and continuous monitoring; access management on least-privilege and need-to-know principles,reviewed regularly and revoked promptly when no longer required; encryption ofPersonal Data in transit and, where appropriate, at rest; network segmentation,logging, and monitoring to detect and respond to incidents; confidentiality undertakings and security awareness training for all personnel with access to Personal Data; documented and regularly tested incident response and business continuity procedures; and security requirements imposed on suppliers by written agreement, with assessment before engagement.

In the event of a Personal Data breach, we will notify IMY without undue delay and, where feasible, within 72 hours of becoming aware of it under Article 33 GDPR, and will inform affected Data Subjects where the breach is likely to result in a high risk to their rights and freedoms under Article 34 GDPR. Where we act as a Data Processor, we will notify the relevant customer without undue delay

6 Your Rights

Under the GDPR you have the following rights in relation to Personal Data that SDC processes about you:

- **Access (Article 15)** — to confirmation of whether we process Personal Dataconcerning you, a copy of that data, and information about the processing.
- **Rectification (Article 16)** — to have inaccurate data corrected and incomplete data completed.
- **Erasure (Article 17)** — to have data erased where it is no longer necessary, where you withdraw consent, where you successfully object, or where it has been processed unlawfully.
- **Restriction (Article 18)** — to require that we restrict processing incertain circumstances, including while we verify the accuracy of data you have contested.
- **Data portability (Article 20)** — where processing is based on consent or a contract with you and carried out by automated means, to receive the data you have provided in a structured, commonly used, machine-readable format, and tohave it transmitted to another controller where technically feasible.
- **Objection (Article 21)** — to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests; and an unconditional right to object to direct marketing, which we will act on immediately.
- **Withdrawal of consent (Article 7)** — where processing is based on consent,to withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.

These rights are not absolute. We may be unable to comply in full where datamust be retained to meet a legal obligation — for example under the BookkeepingAct or the Security Protection Act — or where retention is necessary toestablish, exercise, or defend legal claims. Where we decline a request inwhole or in part, we will explain why.

**Automated decision-making.** SDC does not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing, and does not carry out profiling for such purposes.

**Cookies.** Our website uses cookies and similar technologies. Non-essential cookies are set only with your consent, which you may give, decline, or withdraw at any time through the cookie settings on our website. Details are set out in our Cookie Policy.

6.1 How to Exercise Your Rights

Contact us using the details in section 3.3. We will respond without undue delay and in any event within one month of receiving your request. Where a request is complex, or where we have received a number of requests, we may extend that period by up to two further months, and will tell you of the extension and the reason within the first month.

We may need to verify your identity before acting, so that Personal Data is not disclosed to an unauthorised person. Exercising your rights is free of charge,although we may charge a reasonable fee, or decline to act, where a request is manifestly unfounded or excessive.

Where your request concerns Personal Data that SDC processes as a Data Processor on behalf of a customer, we will forward it to that customer, who is the Data Controller, and assist them in responding.

You may lodge a complaint with Integritetsskyddsmyndigheten (IMY) at any time. Contact details are available at imy.se.
 

Scandinavian Data Centers AB

Data Protection Contact

Email: info@scandinaviandc.com

Address: Rådmansgatan 22, 114 85 Stockholm, Sweden

You also have the right to lodgea complaint with the Swedish supervisory authority,Integritetsskyddsmyndigheten (IMY), at imy.se, if you believe that SDC’sprocessing of your Personal Data is not conducted in accordance with applicabledata protection law.