Skip to content | Go to main menu

Back to legal

Privacy Policy

General Privacy Notice – LOOMIS–PAY

We, at Loomis Digital Solutions AB (”LOOMIS–PAY”) value your privacy. It is important for us that you feel safe and well-informed when you or your company use our products and services. Therefore, this privacy notice outlines how we process your personal data, and you are welcome to reach out to us if you have any questions in this regard.

Who controls your personal data?

LOOMIS–PAY is registered with the Swedish Companies Registration Office under company registration number 556191–0679 with its registered office located at Drottninggatan 82, 111 36 Stockholm. The company processes personal data in its capacity as data controller in accordance with the General Data Protection Regulation (”GDPR”) for the processing of personal data as described in this notice. LOOMIS–PAY have appointed a Data Protection Officer whom you can contact if you have any questions regarding how we process your personal data.

You can contact our data protection officer (“DPO”) by sending an e-mail to lds.dpo@loomispay.com and state ”To the DPO” in the subject line.

Categories of personal data

The personal data that we collect or create is categorized as follows:

· Contact and identification details

Name, date of birth, social security number, title, occupation, gender, billing and shipping addresses, email address, cellphone number, nationality, age, income etc.

· Information regarding products or services

Details regarding the products or services which you have bought or ordered. E.g. type of product or delivery tracking number.

· Payment information

Credit and debit card details (card number, date of expiration and CVV code), bank account number, name of bank, etc.

· Information regarding your use of products or services

The service(s) and different functions within those services you have in use and the choices you have made regarding their usage. This includes information regarding sales, merchandise, and your personal choices related to the product or service.

· Information regarding your contacts with customer service

Recorded phone calls, chat conversations and email correspondence, etc.

· Information from external sanctions lists and PEP lists

Sanctions lists and lists of persons constituting so-called politically exposed persons (“PEP”) includes information such as name, date of birth, place of birth, occupation or position, and the reason as to why the person is on the respective list.

·  Sensitive personal data

Sensitive personal data is data which reveal religious beliefs, political or philosophical opinions, such as PEP-related information, trade union membership, or information concerning health, sex life or sexual orientation, as well as biometric data.

Processing of personal data relating to our customers

LOOMIS–PAY processes personal data necessary for us to be able to offer you and your company our products and services. The type of personal data processed depends on your or your company’s relation to us, the purpose of the processing etc. Your company refers to the organization that has a customer relation to us and which you are employed by or otherwise represent or act on behalf of. In order to clarify which personal data is being processed for which purpose and on what legal basis, we have outlined the following table:

Purpose of the processing

Categories of personal data processed for the purpose

Legal basis for the processing

To provide our products and services, carry out contracts with you and otherwise administer our business relationship with you

- Contact and identification details

- Information regarding products/services

- Payment information

- Information regarding your use of products/services

Performance of contract, or – where the individual is not a contractual party (such as employees of customers) – legitimate interest (Article 6(1)(b) and (f) GDPR. LOOMIS–PAY has a legitimate interest in providing our services as well as managing and administering our business relationships, including communicating with representatives of our customers.

 

To check and verify that you are who you claim to be

- Contact and identification details

Performance of contract and legal obligation
(Article 6(1)(b) and (c) GDPR). Legal obligation according to Sweden’s Payment Services Act (2010:751)

 

Provide support to customers through phone and email

- Contact and identification details

- Information regarding your use of products/services

- Information regarding your contacts with customer service

Performance of contract and legitimate interest

(Article 6(1)(b) and (f) GDPR). LOOMIS–PAY has a legitimate interest in providing customer support and responding to inquiries, including recording phone calls for quality control and educational purposes.

 

Promoting our products and services and conducting customer surveys

- Contact and identification details

- Information regarding your use of products/services

Legitimate interest
(Article 6(1)(f) GDPR).

LOOMIS–PAY has a legitimate interest in improving and growing our business and strengthening customer relationships.

 

To establish, exercise and/or defend ourselves against legal claims

- Contact and identification details

- Information regarding products / services

- Payment information

- Information regarding your use of products services

- Information regarding your contacts with customer service

Legitimate interest
(Article 6(1)(f) GDPR).

LOOMIS–PAY has a legitimate interest in protecting our legal position, rights and interests, including in connection with disputes, claims or legal proceedings.

 

Ensuring a secure IT environment

- Contact and identification details (including IP-address)(including IP-address)

- Information regarding your use of products/services

Legitimate interest
(Article 6(1)(f) GDPR).

LOOMIS–PAY has a legitimate interest in maintaining the security, integrity and resilience of our IT systems, services and data.

 

To improve our services and for general business development

- Information regarding your use of products/services

Legitimate interest(Article 6(1)(f) GDPR).

LOOMIS–PAY has a legitimate interest in developing, improving and maintaining a competitive, efficient and relevant products and services.

 

Complying with regulations aimed to prevent money laundering and financing of terrorism

- Contact and identification details

- Payment information

- Information regarding your use of services

- Information from external sanction lists and PEP lists

- Sensitive personal data

Legal obligation
(Article 6(1)(c) GDPR) according to Sweden’s Anti Money Laundering Act (2017:630)

Preventing other criminal acts and security related incidents

- Contact and identification details

- Information regarding your use of services

Legal obligation and legitimate interest
(Article 6(1)(c) and (f) GDPR)

To meet information requirements based on e.g. the Swedish Payment Services Act (Lag (2010:751) om betaltjänster) or GDPR

- Contact and identification details

- Information regarding your use of products / services

Legal obligation
(Article 6(1)(c) GDPR)

Dealing with requests from public authorities and obligations to report data to public authorities in certain cases

- Contact and identification details
- Other information depending on what the matter entails 

Legal obligation
(Article 6(1)(c) GDPR)

Compiling the accounts and financial statements in accordance with the applicable accounting rules

- Information regarding products / services

- Payment information

-Contact- and identification details 

Legal obligation
(Article 6(1)(c) GDPR) according to the Swedish Bookkeeping Act (1999:1078)

 

Where processing is based on legitimate interest, Loomis has carried out a legitimate interest assessment to ensure that the processing is necessary and that our interests are not overridden by your rights and freedoms. You are welcome to contact our Data Protection Officer for further information about these assessments. 

Processing of personal data relating to our suppliers and partners 

LOOMIS–PAY processes personal data necessary for us to manage our relationship with you and your organisation as a partner or supplier, including procuring products and services and fulfilling our contractual and legal obligations. This information is intended for you as a contact person at a supplier or partner collaborating with LOOMIS–PAY.

To clarify which personal data is processed for which purposes and on what legal basis, we have outlined the following table:

 

 Purpose of the processing Categories of personal data processed for the purpose Legal basis for the processing
 To enter into, perform, and otherwise manage our agreements with the organisation that you represent.  - Contact and identification details Legitimate interest (Article 6(1) (f) GDPR). LOOMIS–PAY has a legitimate interest in entering into and managing agreements with suppliers and partners.
 Compiling the accounts and financial statements in accordance with the applicable accounting rules.  - Contact- and identification details Legal obligation 
(Article 6(1)(b) and (c) GDPR). Legal obligation according to according to the Swedish Bookkeeping Act (1999:1078).

 

Where processing is based on legitimate interest, Loomis has carried out a legitimate interest assessment to ensure that the processing is necessary and that our interests are not overridden by your rights and freedoms. You are welcome to contact our Data Protection Officer for further information about these assessments. 

Processing of personal data relating to prospective customers 

LOOMIS–PAY processes personal data necessary to identify, contact, and follow up with you and your organisation as a prospective customer, including assessing your interest in our products and services and taking steps prior to entering into a potential business relationship.

This information is intended for you as a contact person or representative of an organisation that has shown interest in, or may be interested in, LOOMIS–PAY’s products or services.

To clarify which personal data is processed for which purposes and on what legal basis, we have outlined the following table:

Purpose of the processing
Categories of personal data processed for the purpose
Legal basis for the processing
To create a sales lead regarding a potential customer
- Contact- and identification details
Legitimate interest 
(Article 6(1)(f) GDPR)
To create and send a sales offer to an interested customer
- Contact and identification details
- Information regarding products or services
Legitimate interest 
(Article 6(1)(f) GDPR)
Completing the sales offer by taking measures to comply with regulations aimed to prevent money laundering and financing of terrorism

- Contact and identification details
- Information regarding products or services
- Payment information
- Information from external sanction lists and PEP lists
- Sensitive personal data

Legal obligation (Article 6(1)(c) GDPR)
Promoting our products and services
- Contact and identification details
Legitimate interest 
(Article 6(1)(f) GDPR). LOOMIS–PAY has a legitimate interest in improving and growing our business and strengthening customer relationships.

Where processing is based on legitimate interest, Loomis has carried out a legitimate interest assessment to ensure that the processing is necessary and that our interests are not overridden by your rights and freedoms. You are welcome to contact our Data Protection Officer for further information about these assessments. 

Retention period

LOOMIS–PAY retains your personal data for only as long as is necessary to fulfil the respective purpose of processing. In certain cases, LOOMIS–PAY is subject to legal requirements that require us to store personal data during a specific period of time.

If no contract is concluded between you and us or if the data is not needed to comply with a legal requirement, the data will be kept only for as long as necessary to fulfil the purpose of the processing in question.

Personal data collected and/or used to prevent money laundering and financing of terrorism. We are required to retain transactional and certain other customer-related data for at least five (5) years after the termination of the customer relationship. In some cases, we are required to retain data for ten (10) years. This is according to anti-money laundering and terrorist financing laws and regulations.

Personal data for accounting purposes. We are required to retain accounting information (for example identification information, company information, payment information) for at least seven (7) years, according to bookkeeping regulations (Swedish Bookkeeping Act).

Personal data used to satisfy the contractual relationship between our customers and us. We store personal data connected to our business relations with you for the duration of the contract, and thereafter a period of time necessary to establish, exercise or defend legal claims.

Your rights

The data subject is provided with a number of rights under the GDPR. As Data Controller LOOMIS–PAY ensures that the following rights are met when a request is made to us. Your rights in relation to your personal data are as follows:

 

· Right to information

You have the right to be informed when your personal data is being processed. We provide you with such information through this notice and by responding to questions from you.

· Right of access

You have the right to request a copy of your personal data if you want to know what information we have and process about you.

· Right of rectification

You have the right to have inaccurate personal data corrected. In addition, you have the right to supplement any incomplete personal data considering the purpose for which we process your personal data.

· Right to erasure

You have the right to request to have your personal data erased, which also can be referred to as a “right to be forgotten”.

· Right to restriction of processing

You have the right to request that the processing of personal data be restricted.

· Right to object

You have the right to object to the processing of personal data carried out by us as a pursuant to our legitimate interest. If you object to such processing, we may only continue to process the data if we demonstrate that there are legitimate grounds for us to process the data where our interests outweigh your interests, for example where the processing is for the establishment, exercise or defense of legal claims. An example of where your interests outweigh ours is when you object to marketing.

· Right to data portability

When we process personal data by automated means on the basis of your consent or for the performance of a contract with you, you have the right to obtain your personal data in a structured, commonly used and machine-readable format for the purpose of transferring the data to another data controller.

· Right to lodge a complaint

You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), which is the Swedish supervisory authority for the personal data processing LOOMIS–PAY carries out.

 

For more information regarding each right, please visit IMY's website here

Please contact our data protection officer by sending an email to lds.dpo@loomispay.com if you wish to exercise any of your rights or if you have any further questions regarding the processing of your personal data. State “To the DPO” in the subject line.

Recipients of personal data

LOOMIS–PAY shares personal data with others only when necessary to fulfil the purposes described above.

 

If we share your personal data with a company that processes the data on our behalf, the recipient is a so-called data processor. We ensure that the personal data is processed in accordance with this information and applicable law. Consequently, your data is processed in an appropriate manner and in accordance with an adequate level of protection. LOOMIS–PAY uses data processors who support us with:

• Customer support

• Software and data storage such as email, customer relationship management, and financial systems

• Payment processing 

In connection with certain specific services which LOOMIS–PAY provide, another organization is the data controller and LOOMIS–PAY is the data processor. This applies when Loomis provides services to a controller for which LOOMIS–PAY does not determine how the data is processed or the purpose of the processing. In this case you receive information about personal data processing from the controller.

In some cases, LOOMIS–PAY and the recipient process personal data independently as separate data controllers. This may occur, for example, when we are required to provide information to authorities such as the Police, the Swedish Financial Supervisory Authority, the Tax Agency, or other public authorities.

We may also share personal data with partners who act as separate data controllers in order to offer a broader range of financial products and services. One of our partners is the payment facilitator Fiserv. For more information on how Fiserv processes personal data, please refer to Fiserv’s privacy notice

Transfer outside the EU/EEA

LOOMIS–PAY processes your personal data mainly within the EU/EEA. In some cases, personal data may be processed by recipients in countries outside the EU/EEA. Where this is the case, we ensure that the receiving country has an adequate level of data protection, or that there are appropriate safeguards in accordance with applicable legislation. Such safeguards include, but are not limited to, the use of the European Commission’s standard contractual clauses when concluding contracts between LOOMIS–PAY and recipients outside the EU/EEA. We also assess whether there are laws in the recipient countries that affects the protection of your personal data and, when necessary, we implement specific measures to ensure that the protection of your data is maintained when it is transferred to a country outside the EU/EEA.

If you want more detailed information about third country transfers and the safeguards ensuring an appropriate level of data protection, please do not hesitate to reach out to our data protection officer by sending an email: lds.dpo@loomispay.com.

Updates of this notice

LOOMIS–PAY continuously works to improve our products and services to be able to offer our customers an even better experience. Therefore, we may update this privacy notice. If we make any major changes affecting your personal data, we will provide you with information regarding the changes in accordance with applicable law. Please visit this page regularly to keep up to date with how we process your personal data.

 

The information was last updated on 30 June 2026.

Cookies

Cookies are text files containing information that are inserted and stored on your computer’s hard drive when you visit websites. Cookies can be temporary or persistent. Temporary cookies disappear when you close your browser. Persistent cookies are stored in your browser until they reach their expiration date, you have the option to delete them prematurely in your browser.

You can find more information about the individual cookies we use and the purposes for which we use them. Please click the cookie symbol in the bottom left corner of our website.

Menu