1. PURPOSE & SCOPE This GDPR Compliance & Data Privacy Policy ("Policy") supplements our Privacy Policy and outlines how Kajsa Ingemansson / KAMI Performance Works complies with the General Data Protection Regulation (GDPR) (EU 2016/679) and other applicable Swedish and EU data protection laws. This Policy applies to all personal data we collect, process, or store in relation to:
Visitors to our Website.
Customers of our Services.
Subscribers to our email lists or communities.
2. KEY DEFINITIONS Term Definition
Personal Data Any information relating to an identified or identifiable natural person (e.g., name, email, IP address). Data Subject An identified or identifiable natural person (e.g., you, our Client). Controller Kajsa Ingemansson (determines the purposes and means of processing personal data). Processor Third-party services (e.g., Stripe) that process personal data on our behalf. Processing Any operation performed on personal data (e.g., collection, storage, use, disclosure). Consent Freely given, specific, informed, and unambiguous indication of your wishes (e.g., opt-in checkbox).
3. LEGAL BASIS FOR PROCESSING Under GDPR Article 6, we process your personal data only if at least one of the following applies: Legal Basis When It Applies Example
Consent (Art. 6(1)(a)) You have explicitly consented to Marketing emails, cookies, the processing for one or more sensitive data (e.g., health specific purposes. info for coaching).
Contract Performance Processing is necessary to fulfill Delivering Services, processing (Art. 6(1)(b)) a contract with you or take steps payments, scheduling sessions. at your request. Legal Obligation Processing is required by law. Tax reporting, court orders. (Art. 6(1)(c))
Vital Interests Processing is necessary to protect Rare (e.g., medical emergencies (Art. 6(1)(d)) your life or physical integrity. during retreats).
Public Interest Processing is necessary for a Not applicable to our business. (Art. 6(1)(e)) task carried out in the public interest. Legitimate Interest Processing is necessary for our Improving Services, fraud (Art. 6(1)(f)) legitimate interests and does not prevention, analytics. override your rights.
4. DATA PROTECTION PRINCIPLES We adhere to the GDPR principles for processing personal data: Principle How We Comply
Lawfulness, Fairness, Transparency We process data legally, fairly, and transparently (see Section 3 for legal bases). Purpose Limitation We collect data only for specified, explicit, and legitimate purposes (see Section 5 of Privacy Policy). Data Minimization We collect only the data we need for the intended purpose. Accuracy We keep your data accurate and up to date. You can request corrections. Storage Limitation We retain data no longer than necessary (see Section 8 of Privacy Policy). Integrity & Confidentiality We implement security measures to protect your data (see Section 7 of Privacy Policy). Accountability We document our compliance with GDPR and can demonstrate it upon request.
5. DATA PROTECTION BY DESIGN & DEFAULT We implement technical and organizational measures to ensure GDPR compliance:
5.1 Technical Measures
Pseudonymization: Where possible, we pseudonymize data (e.g., using unique IDs instead of names).
Encryption: All data is encrypted in transit (TLS/SSL) and at rest (AES-256).
Automated Deletion: Data is automatically deleted after the retention period (e.g., 2 years for inactive accounts).
5.2 Organizational Measures
For GDPR-related inquiries, contact Kajsa Ingemansson at: [email protected].
As a sole practitioner, I ensure my own compliance with GDPR through ongoing education.
We conduct Data Protection Impact Assessments (DPIAs) where required by law
We ensure third-party processors (if any) comply with GDPR and require Data Processing Agreements (DPAs)."
6. RECORDS OF PROCESSING ACTIVITIES (ROPA) Under GDPR Article 30, we maintain internal records of our processing activities, including:
Purpose of processing (e.g., deliver coaching, send emails).
Categories of data subjects (e.g., Clients, subscribers).
Categories of personal data (e.g., name, email, payment info).
Recipients of data (e.g., Stripe).
Retention periods (see Section 8 of Privacy Policy).
Technical/organizational measures (see Section 5).
Note: These records are not public but are available to supervisory authorities upon request.
7. DATA SUBJECT RIGHTS (GDPR CHAPTER III) As a data subject, you have the following rights under GDPR. To exercise any of these rights, email us at [email protected]: Right Description Our Response Exceptions Time
Right to Access Request a copy of your30 days We may request proof of (Art. 15) personal data we hold. identity to verify your request.
Right to Rectification Request corrections to 30 days None (Art. 16) inaccurate or incomplete data.
Right to Erasure Request deletion of your 30 days We may retain data for legal compliance ("Right to Be data if it is no longer (e.g., tax records) or exercising legal claims. Forgotten") (Art. 17) necessary or you withdraw consent.
Right to Restrict Request that we limit 30 days None Processing (Art. 18) processing of your data (e.g., for marketing).
Right to Data Request your data in a 30 days Only applies to automated processing Portability (Art. 20)machine-readable format based on consent or contract. (e.g., CSV, JSON).
Right to Object Object to direct marketing 30 days We may continue processing if we (Art. 21) or profiling based on demonstrate compelling legitimate grounds. legitimate interests. Right to Withdraw Withdraw consent for Immediate Does not affect the lawfulness of Consent (Art. 7(3)) marketing or cookiesprocessing before withdrawal. at any time. Right to Lodge a File a complaint with a N/A None Complaint (Art. 77) supervisory authority (e.g., Swedish Data Protection Authority (IMY)).
8. DATA BREACH NOTIFICATION Under GDPR Article 33 & 34, we are required to notify you and the supervisory authority of a data breach if it is likely to result in a high risk to your rights and freedoms. 8.1 Our Procedure
Detection: We monitor for breaches 24/7 using automated tools and manual reviews.
Investigation: We assess the risk within 72 hours of detection.
Notification to Authority: If the breach poses a high risk, we notify the Swedish Data Protection Authority (IMY) within 72 hours.
Notification to You: If the breach poses a high risk to you, we notify you without undue delay via:
Email (to the address on file).
Website banner (for widespread breaches).
Direct mail (if email is compromised).
8.2 What We Include in Notifications
Nature of the breach (e.g., unauthorized access, data leak).
Categories of data affected (e.g., names, emails, payment info).
Likely consequences (e.g., risk of identity theft, fraud).
Measures taken or proposed to address the breach.
Contact information for our DPO.
9. INTERNATIONAL DATA TRANSFERS As a Swedish-based business, we primarily process data within the EU/EEA. However, some of our service providers (e.g., Stripe, Kajabi, ConvertKit) are based in the US or other third countries. 9.1 Safeguards for TransfersWe ensure adequate protection for international transfers using:
Standard Contractual Clauses (SCCs): Approved by the European Commission (Decision 2021/914).
Binding Corporate Rules (BCRs): For multinational processors.
Privacy Shield: For US-based providers (where applicable).
Adequacy Decisions: For countries with equivalent data protection laws (e.g., UK, Canada).
9.2 Your Rights for TransfersYou have the right to:
Request a copy of the safeguards we have in place (e.g., SCCs).
Lodge a complaint with the Swedish Data Protection Authority (IMY) if you believe your rights have been violated.
10. DATA RETENTION & DELETION We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including: Data Type Retention Period Legal Basis Account Data Active account + 2 years Legitimate Interest (Art. 6(1)(f)) Payment Data 7 years Legal Obligation (Art. 6(1)(c)) Program Data Duration of program + 1 year Contract Performance (Art. 6(1)(b)) Marketing Data Until you unsubscribe Consent (Art. 6(1)(a)) Technical Data 26 months (Google Analytics) Legitimate Interest (Art. 6(1)(f)) Deletion Process:
We automatically delete data after the retention period.
You can request deletion at any time (subject to legal obligations).
We verify deletion through audits and logs.
11. AUTOMATED DECISION-MAKING & PROFILING We do not use fully automated decision-making (e.g., AI-driven decisions without human intervention) that has legal or significant effects on you. We do use limited profiling for:
Marketing: To send you targeted emails or ads based on your interests (e.g., performers vs. directors).
Analytics: To improve our Website and Services (e.g., Google Analytics).
Your Rights:
You can opt out of profiling for marketing by:
Clicking "Unsubscribe" in emails.
Adjusting cookie settings in your browser.
You can request human review of any automated decision by contacting us at [email protected].
12. CONTACT INFORMATION For GDPR-related inquiries,contact Kajsa Ingemansson at: Email:[email protected] Address: Flygelvägen 231, 224 72, Sweden Phone: +46 (0)703828961 For general privacy questions, contact us at: Email:[email protected]
13. SUPERVISORY AUTHORITY If you believe we have violated GDPR, you may lodge a complaint with the Swedish Data Protection Authority (Integritetsskyddsmyndigheten, IMY): Website:www.imy.se Email:[email protected]Phone: +46 8 657 61 00 Address: Integritetsskyddsmyndigheten (IMY) Box 8114 104 20 Stockholm Sweden