Privacy policy

Fiftytwo is committed to protecting personal data and respecting the privacy of the individuals whose data we process.
We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Danish data protection legislation. This Privacy Policy explains how Fiftytwo processes and protects personal data and describes the rights of individuals in relation to our processing.

Identity and contact details

Fiftytwo A/S
Ejby Industrivej 91
2600 Glostrup, Denmark
CVR: 24784010

Data Protection Manager : compliance@fiftytwo.com

Our Data Protection Manager can answer questions concerning Fiftytwo’s processing of personal data, our data protection practices, and your rights.
Where Fiftytwo processes personal data on behalf of a customer, Fiftytwo acts as a data processor and processes personal data in accordance with the applicable Data Processing Agreement (DPA) and the customer’s documented instructions.

 

Purpose and legal basis

Fiftytwo processes personal data for different purposes depending on our relationship with you.
 
Where Fiftytwo determines the purposes and means of the processing, we act as data controller. We may process personal data for purposes such as customer and business relationship management, communication, responding to enquiries, marketing, website operation, security, administration, and compliance with our data retention and deletion requirements.
 
As part of our data retention and deletion processes, Fiftytwo uses a scanner to identify personal data in emails, attachments, and documents in Outlook and OneDrive. The tool supports employees in reviewing personal data and identifying information that is no longer required.
 
Depending on the processing activity, our legal basis may be performance of a contract (Article 6(1)(b)), compliance with a legal obligation (Article 6(1)(c)), consent (Article 6(1)(a)), or our legitimate interests (Article 6(1)(f)). Our legitimate interests may include managing customer and business relationships, operating and securing our systems, and maintaining appropriate data governance.
 
Where Fiftytwo processes personal data on behalf of a customer, Fiftytwo acts as data processor and processes the personal data in accordance with the customer’s documented instructions and the applicable DPA.
 

Cookies

We use cookies and similar technologies on our website for necessary functionality and, subject to your choices, analytics and other purposes.
You can manage your cookie preferences and read more about the cookies we use here.

 

Retention of data

We retain personal data only for as long as necessary for the purpose for which it is processed or as required by applicable legal or contractual obligations.
 
Personal data is reviewed and deleted in accordance with Fiftytwo’s applicable retention and deletion requirements.
 
Where Fiftytwo processes personal data on behalf of a customer, retention and deletion are carried out in accordance with the customer’s instructions and the applicable DPA.

 

Your rights

Where Fiftytwo acts as data controller, you have certain rights regarding your personal data under applicable data protection law. Depending on the circumstances, these may include the right to:

  • request access to your personal data;
  • request correction or deletion of your personal data;
  • request restriction of processing;
  • object to processing;
  • request data portability; and
  • withdraw your consent where processing is based on consent.

These rights may be subject to conditions or limitations under applicable law.

If Fiftytwo processes your personal data solely on behalf of one of our customers, the customer is the data controller. Requests concerning your rights should therefore normally be directed to that customer. Fiftytwo will assist the customer in responding to such requests in accordance with the applicable DPA.

To exercise your rights in relation to processing for which Fiftytwo is the data controller, please contact compliance@fiftytwo.com.

You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet).

 

Security

Fiftytwo maintains appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage.
 
Access to personal data is managed through appropriate access controls. Fiftytwo also assesses relevant suppliers and service providers used in connection with the processing of personal data.

 

Questions?

If you have any questions about Fiftytwo’s processing of personal data or wish to exercise your rights, please contact:
Data Protection Manager
compliance@fiftytwo.com
 
You may also contact the Danish Data Protection Agency (Datatilsynet) if you wish to lodge a complaint: www.datatilsynet.dk