Last updated December 7, 2020
1) About Pie Systems
2) What are personal data?
3) What types of personal data do we process about you and why?
4) Use of your personal data
5) Legal basis for the processing of your personal data
6) Sharing of personal data
7) Data integrity and data protection
8) Your rights
1. About Pie Systems
Pie Systems is streamlining the process of VAT refunds for travellers, maximizing value and efficiency for both travellers and merchants alike. With Pie Systems’ fully digitized end-to-end solution, merchants can facilitate, and travellers can receive, VAT refunds at the tap of a few buttons on their mobile devices.
Pie Systems IVS
Havnegade 39, 1058 København, Denmark
Danish CVR no. 39877848
Email: [email protected]
2. What are personal data?
Personal data are any information concerning an identified or identifiable natural person. An identifiable natural person means a person who can be identified, directly or indirectly, in particular by reference to an identifier, e.g. a name, an identification number or one or more factors specific to the identity of a given person.
3. What types of personal data do we process about you and why?
The data we process about you will be used for various purposes in connection with your customer relationship and the operation of Pie Systems’ business. The data processed may vary depending on whether you are a customer, supplier or business partner, but will generally be data relating to customer management and supplier management, information used to improve our website and the Pie VAT app, and data relating to Pie Systems’ rights and obligations.
Any failure by you to provide personal data may mean that we at Pie Systems will be unable to fulfil our obligations relating to your customer or supplier relationship.
Pie Systems collects and processes general personal data only in connection with your customer or supplier relationship with Pie Systems.
Pie Systems will typically process the following data (the list is not exhaustive):
Data about our customers: Data that you provide to us when becoming a customer of Pie Systems, including contact details (name, address, email address, phone number and country of residence), your credit card, your picture, your geolocation, your marketing or communication preferences, and data that you provide to us when contacting us to ask a question or to report a problem or generally as part of your customer relationship with Pie Systems.
To facilitate tax free services in accordance to government regulations, there are certain pieces of data and information Pie Systems will obtain including, but not limited to:
- Passport Information
- Address of Residence
- Payment Information
Security of data processing
Any personally identifiable information on the user should be encrypted at rest, and any person that can view or access this data should be limited to reading what they need to complete their task. Personal identifiable information should remain encrypted, and with limited access until the data is no longer required by financial service records. At this time the data can be deleted from the system.
Our services should remain accessible to the best of the ability of the operators, software, and companies that are supporting our business. Transmission and storage of data are secured and encrypted to industry standard.
Finally, no personal information will be logged in any known logs.
Storage period/erasure procedures
Personal data is stored for minimum 7 years after which the personal data is automatically erased. This is in accordance to law requiring 7 years of auditable financial information.
Upon termination of the provision of personal data processing services, the Pie Systems shall either delete or return the personal data.
Data about our suppliers and business partners: Data that you provide to us in connection with the conclusion of a supply or cooperation agreement, including contact details (workplace, job title, first name, middle name(s), last name, address, telephone number and email address), data that you provide to us on your marketing or communication preferences, and data that you provide to us when contacting us to ask a question or to report a problem or generally as part of our cooperative relations.
Data that we collect and process when you visit our website or use our app: Data on the way you navigate to and between our websites and the resources you access, information about your computer, device and browser, including in some instances your IP address, browser type, and other hardware and software information, the time and date of your use and other statistics. If you access our website from a mobile device, we may also collect the unique identification number of your device.
4. Use of your personal data
Pie Systems processes your personal data for the purposes set out below. Please note that not all the specified purposes, categories of data, recipients of data or types of processing of data will in all instances apply to you.
Pie Systems processes your personal data solely to the extent necessary in connection with your customer or supplier relationship (in each case taking any interests into account) or according to current law.
· Customer relationship management: Creation and management of your customer relationship with Pie Systems as part of the operation of the Pie Systems business, including the maintenance of our CRM register containing information about our contact persons for our customers, customer service, invoicing, debt collection, marketing, statistics, etc.
· Statistics and analyses: As a general rule, the statistics and analyses provided by Pie Systems will be prepared in anonymous form and so do not contain data directly attributable to you as a natural person.[SL3] However, in certain cases, e.g. reports to tour groups, the provided data will have to be directly attributable to you as a natural person.
· Supplier relationship and cooperative relations management: Pie Systems processes your personal data as part of the management of supplier relationships and/or cooperative relations where you are a supplier or business partner or a contact person of a supplier or business partner with which Pie Systems has business relations as part of the operation of our business, including the maintenance of our CRM register containing information about our contact persons for our suppliers and business partners.
· Operation and maintenance of our website and app: The provision of our online services at our website and app, including to support the ongoing evaluation and improvement of our website and app.
· Compliance with current laws and regulations: The compliance with laws and regulations to which Pie Systems is subject in connection with the operation of the business or to fulfil various duties of reporting or disclosure under current laws and regulations imposed on Pie Systems.
Pie Systems does not use your personal data to make decisions based solely on automatic processing, including profiling.
Pie Systems endeavours to ensure that all personal data processed by us are accurate and up to date. As a result, we request that you always inform us of any change in your data (e.g. any change of address or payment details) to enable us to ensure that the data are always accurate and up to date.
5. Legal basis for the processing of your personal data
Pie Systems will process your personal data only if we have a legal basis for doing so.
Non-sensitive data about you are generally processed on one of the following bases:
· Consent: You have given your consent to the processing of your personal data for one or more specific purposes. Processing based on consent is in accordance with Article 6(1)(a) of the General Data Protection Regulation (the “GDPR”).
· Contract: The conclusion or performance of your contract with Pie Systems. Processing based on contract is in accordance with Article 6(1)(b) of the GDPR.
· Legal obligation: Compliance with a legal obligation imposed on Pie Systems. Processing based on a legal obligation is in accordance with Article 6(1)(c) of the GDPR. The Danish Acts requiring Pie Systems to process personal data include:
a. The Danish Bookkeeping Act, which requires Pie Systems to retain all bookkeeping records for a minimum of 5 years.
b. The Danish Tax Control Act, which requires Pie Systems to report information to the Danish tax authorities.
· Our legitimate interests: The legitimate interests pursued by Pie Systems, i.e. the purposes described above. Processing based on our legitimate interests is in accordance with Article 6(1)(f) of the GDPR.
· Third-party legitimate interests: There may also be situations in which we process your personal data on the grounds of the legitimate interests pursued by a third party as regards the purposes described above, except where such interests are overridden by your interests. Processing based on the legitimate interests of a third party is in accordance with Article 6(1)(f) of the GDPR.
6. Sharing of personal data
Pie Systems will disclose data only to the extent necessary as part of the operation of our business.
Furthermore, Pie Systems may disclose your personal data and/or make them available to other suppliers and/or service providers in connection with the general operation of our business, e.g. in connection with the external administration of our IT systems, analysis tasks, marketing tasks, debt collection, audit, legal assistance, etc.
Pie Systems endeavours, wherever possible, to restrict the disclosure of personal data in a form enabling them to be attributed to a natural person in order to limit the instances of disclosure of data that could be attributed to you personally.
Pie Systems does not disclose your personal data unless such disclosure is necessary in order to perform our activities or fulfil your needs.
Your personal data may in some cases be transferred to and processed in an unsecure country outside the EU/EEA area (e.g. the US) by our service providers. For the ongoing protection of your personal data, we will take appropriate steps to ensure that transfers of personal data are in accordance with applicable law and carefully managed to protect your privacy rights and interests and that transfers are limited to countries which are recognised as providing an adequate level of legal protection or where we can be satisfied that alternative arrangements are in place to protect your privacy rights (i.e. Privacy Shield Frameworks, EU Commission-approved standard contractual data protection clauses, etc.). Information about the countries to which we will, where appropriate, transfer your personal data and the safeguards implemented can be obtained upon request.
7. Data integrity and data protection
Personal data are retained for no longer than is necessary in relation to the purpose for which they were collected, unless retention is necessary to comply with national statutory requirements, including statutory retention periods relating to EU-subsidy control, bookkeeping, etc.
Pie Systems’ policy is to protect personal data by taking adequate technical and organisational security measures. Once your personal data are no longer needed, we will ensure that they are erased in a secure manner.
8. Your rights
You are entitled at all times to exercise your rights under the data protection legislation in force at any time. However, please note that we will not always be required to fulfil these rights in whole or in part. For example, you are not entitled to erasure of your personal data retained by Pie Systems if the law obliges Pie Systems to store such data.
· Your right of access: You may e.g. request access to the personal data held by us and information about e.g. the purpose(s) for which personal data are used and to whom they are disclosed.
· Your right to object: You may object to the processing of your personal data, including object to automated decisions and profiling or to the use of your personal data for direct marketing.
· Your right to rectification: You may request correction of any incorrect information about yourself.
· Your right to restrict processing and erasure: You may request the restriction or erasure of information about yourself if the relevant conditions are met.
· Your right to data portability: Your right to data portability is applicable to information you have provided to us if the processing is based on your consent or a contract, and such portability is technically possible.
In addition, you have the right to withdraw your consent to processing of your personal data in case our processing is based on your consent.
If you withdraw your consent or request restriction of our processing of your personal data, it may mean that we will no longer be able to manage our agreement with you.
If you wish to exercise one or more of your rights, please contact us at [email protected] Your request will be processed in accordance with the data protection legislation in force at any time.
Any complaint about the processing by Pie Systems of your personal data should be filed with:
The Danish Data Protection Agency
Borgergade 28, 5th floor
DK-1300 Copenhagen K
Email: [email protected]