Privacy Policy

Introduction

When using Payday and interacting with Payday, personal data about you is processed. This Privacy Policy is made to help you understand what personal data is collected, why it is collected and how Payday handles, protects, stores, exports, and deletes your personal data.

Personal data is any information relating to an identified or identifiable natural person, such as an email address, street address, phone number, etc.

In section 2 in this Privacy Policy we describe how Payday processes personal data in the role as a Processor inside in the application Payday. In section 3 we describe how personal data is processed by Payday as a Controller, which also specifies further the processing of personal data inside the application Payday (3.1) and when interacting with Payday in other channels such as our website (3.2).

Payday as a Processor

For the personal data you enter into Payday and that is processed there, your employer (our customer) is the data Controller. Payday does in such cases act as a data Processor and processes the data on behalf of and according to instructions given by your employer (our customer). For more information regarding this, please contact customer support for the service.

If you have any requests regarding deletion of your personal data, correction of the personal data or insight to what personal data that are processed about you, you should contact your employer.

Payday as a Controller

In some cases, Payday will be the data Controller for your personal data. This is when Payday determines the purposes and means of the processing of personal data, for example for improving the application, support, marketing and security purposes.

When Payday is the Controller for your personal data in our application Payday, section 3.1 applies. When Payday is the Controller for your personal data processed when interacting with us through other channels, section 3.2 applies. Your rights are explained in section 3.3 which applies to the processing of personal data both in the application and when interacting through other channels.

3.1 Information about processing of personal data inside the application Payday, where Payday is the Controller

3.1.1 What personal data do we process?

The type of personal data that Payday processes about you may be:

  • Basic personal information such as name, email and demographic information
  • User and web traffic information such as login ID, username, and IP address
  • Statistics that show how the users use our software

3.1.2 How is personal data collected?

In general, Payday collects personal data directly from you or other persons linked to our Customer, your employer. If the Customer purchases Payday products or services via a partner company, we may collect information about you from the partner company.

Payday will also use cookies and other tracking technologies when you use our applications/services, in order to optimise your experience of Payday and our products. For this purpose, Payday uses various third-party services, such as Google Analytics, Gist, Facebook, Wootric, CookieHub, Microsoft.

3.1.3 Why do we process personal data?

This Privacy Policy applies when Payday process your personal data for the following purposes:

Delivery of our services and products

  • To submit estimates and process orders, invoicing, payments for our services and products
  • To provide and maintain the features and functionality of the products and services
  • To deliver services directly to you, such as our webinars, whitepapers, etc.
  • To create users in our products
  • To send you information that you have requested
  • To send you service updates and other administrative communications

Support, improvements and analysis

  • To provide customer support to you
  • To improve and develop the quality, functionalities and user experiences of our products and services
  • To measure and analyze the use of our products and services to improve your experiences

Security

  • To detect, limit and prevent security threats and perform maintenance and troubleshooting
  • To log security incidents in our products and services
  • To send you security notices and updates when appropriate

3.1.4 What is the legal basis for processing your personal data?

Payday has a legitimate interest when we process your data for security, support, marketing, analysing and improvement purposes. Your personal data is processed from a business perspective in a manner that we believe does not conflict with your privacy rights or freedoms.

Read more about how Payday processes your personal data for marketing purposes based on legitimate interest and your rights when we process your personal data for such purposes under section 3.2.8 below.

3.1.5 How is your personal data shared?

Payday is a part of the Visma Group. As Visma consists of many different subsidiaries, it is important for us that we provide the best possible overall experience for you. In order to maintain an overview and insight, Payday may share your personal data across companies in the Visma Group.

Payday may also share your personal data with external third parties in the following contexts:

Business partners
Payday may share your personal information with our partners in the event this is legitimate from a business perspective and according to applicable privacy legislation.

Public authorities
The police and other authorities may request access to personal information from Payday. In these cases, Payday will only provide the data if there is a court order etc. to do so.

3.1.6 Use of processors

When using processors, Payday will enter into a data processing agreement in order to safeguard your privacy rights. If processors are located outside the EU/EEA, Payday ensures legal grounds for such international transfers on your behalf, hereunder by using the EU Model Clauses.

You are always welcome to request an overview and more detailed information on Payday’s processors. For how to contact Payday , please see the last section of this policy.

3.1.7 How long is your data stored?

Payday will only store your personal information for as long as necessary to fulfil the purpose of processing, but in most cases never longer than 3 years since your last registered activity.

Your personal data may be subject to different retention policies based on the type of data and the purpose of collecting it. For further information regarding deletion, feel free to contact Payday (see contact information in the last section of this policy).

3.2 Information about processing of personal data on websites and other channels, where Payday is the controller

3.2.1 What personal data do we process?

The type of personal data that Payday processes about you may be:

  • Basic personal information such as name, address, telephone number, email and demographic information
  • User and web traffic information such as IP address
  • Financial information such as invoice-related information
  • Statistics that show how the users consume content we offer
  • Information provided through job applications

For the purposes mentioned in the section “Why we process personal data”, Payday does not process sensitive personal data about you.

3.2.2 How is personal data collected?

In general, Payday collects personal data directly from you or other persons linked to our Customer, your employer. If the Customer purchases Payday’s products or services via a partner company, we may collect information about you from the partner company.

Payday will also use cookies and other tracking technologies when you visit our website, in order to optimise your experience of Payday. For this purpose, Payday uses various third-party services, such as Microsoft, Google Analytics, Gist, Meta Platforms, Wootric, CookieHub.

In some cases, we may also collect information about you from other sources. These sources may be third-party data aggregators, marketing partners, public sources or third-party social networks.

3.2.3 Why do we process personal data?

This Privacy Policy applies when Payday process your personal data for various purposes when you interact with us, such as:

Buy and deliver

  • Facilitate customer orders, agreements, payments
  • Offer services directly to you, such as e-learning, webinars, reports, etc.
  • Provide requested offers on products and services to Customers
  • Create and facilitate accounts for users of our services

Support and improve

  • Improve and develop the quality, functionality and user experience of our products, services and websites
  • Offer customer support of our products and services

Security

  • Detect, mitigate and prevent security threats and abuse, and perform maintenance and debugging

Marketing

  • Manage and send marketing preferences and content
  • Create interest profiles in order to promote relevant products and services (profiling)

Recruiting

  • Manage recruitment processes and process job applications
  • Evaluate submitted documentation, conduct interviews and call references

3.2.4 What is the legal basis for processing your personal data?

We process data based on several legal grounds.

Agreement with you
We process your personal data on the basis of a legal binding contract with you. This will typically be when you register to use our applications, including, for example, our accounting program or apply for a job in Payday. Processing your personal data such as CV, application and references is necessary for handling jobseekers’ requests before a contract is entered into.

Your consent
Payday might process your personal data based on consent. You will always be able to withdraw your consent, after you have given the consent.

Legitimate interest
Payday has a legitimate interest when we process your data for security, support and improvement purposes, or when you act as customer contact/lead for our existing and potential customers, hereunder in customer support. Your personal data is processed from a business perspective in a manner that we believe does not conflict with your privacy rights or freedoms.

3.2.5 How is your personal data shared?

Within the Visma Group
Payday is a part of the Visma Group. As Visma consists of many different subsidiaries, it is important for us that we provide the best possible overall experience for you. In order to maintain an overview and insight, Payday may share your personal data across companies in the Visma Group.

Outside of the Visma Group
Payday may also share your personal data with external third parties in the following contexts:

User communities
If you make a post, comment or similar on user communities or other forums or sites, such information can be read and used by anyone with access to such forums. Payday is not responsible for any information you submit on such forums or sites.

Business partners
Payday may share your personal information with our partners in the event this is legitimate from a business perspective and according to applicable privacy legislation.

Public authorities
The police and other authorities may request access to personal information from Payday In these cases, Payday will only provide the data if there is a court order etc. to do so.

3.2.6 Use of processors

Payday uses processors to process personal data. These processors are typically vendors of cloud services or other IT hosting services. When using processors, Payday will enter into a data processing agreement in order to safeguard your privacy rights. If processors are located outside the EU/EEA, we ensure legal grounds for such international transfers on your behalf, hereunder by using the EU Model Clauses.

You are always welcome to request an overview and more detailed information on our processors. For how to contact us , please see the last section of this policy.

3.2.7 How long is your data stored?

Payday will only store your personal information as long as required to perform our contractual obligations. When processing your personal data on other legal basis, such as legitimate interest, data is stored as long as necessary to fulfil the purpose of processing.

Hence, your personal data may be subject to different retention policies based on the type of data and the purpose of collecting it. Below are some examples:

When recruiting, Payday will delete your personal information such as CV, application and other documents when the recruitment process is closed, typically maximum 6 months after application deadline, unless otherwise agreed upon with you.

Another example is contact information stored for marketing purposes, including leads or prospects. Such personal data will be deleted no later than 24 months after the last registered activity.

For further information regarding deletion, feel free to contact us (see contact information in the last section of this policy)

3.2.8 Marketing

When you interact with Payday e.g. by visiting our web pages, downloading content, attending webinars, and as part of using our services, Payday will be processing your personal data based on legitimate interest. One of our legitimate interests is the processing of personal data for direct marketing purposes.

Payday uses your personal data to provide relevant content to you through direct marketing on social media platforms and emails, webpages or in a service, based on your preferences. The personal data processed are aggregated details about you such as IP address, interests (where you have clicked, etc.), username and device. This is done through technologies like cookies and is called profiling. Payday will also be able to combine this information with information about the customer relationship we may have with your company.

The purpose of the profiling is to deliver customized marketing to you, improve your user experience with our services / websites and deliver products that our customers are satisfied with. Payday’s services are generally used as tools for work-related purposes, and your behaviour in these tools says little about your personal life. No sensitive data is processed. Your personal data is therefore processed from a business perspective in a way that we believe does not conflict with your freedoms and rights as an individual.

Payday uses email as a tool to communicate marketing, however only if you have consented in accordance with national marketing legislation (if needed). If you have consented, you will always have the possibility to opt out as described below, or when you receive an email containing marketing.

Right to opt-out of marketing communications
You have the right to opt out of receiving marketing communications from Payday and being subject to profiling. You can do this by either:

  • Following the instructions for opt-out in the relevant marketing communication
  • Changing preferences under the relevant edit account section if you have an account with Payday.
  • Contacting us via email at [email protected]

You will also always have the option to opt into/out of cookies on a particular web page, through our cookie banner.

Please note that even if you opt out from receiving marketing communications, you may still receive administrative communications from Payday, such as order confirmations and notifications necessary to manage your account or the services provided to Customers.

3.3 What are your rights?

You can invoke the following rights in relation to our processing of your personal data:

  • Access. You have the right to request a copy of personal data we process about you
  • Rectification. You also have the right to request Payday to rectify inaccurate personal data concerning you. If you have an account with Payday, this can usually be done through the appropriate "your account" or "your profile" sections on the applicable Payday service
  • Deletion. You can request Payday to delete personal data relating to you
  • Restriction. You may ask us to restrict the processing of your personal data
  • Portability. You may ask us to provide you or others with your personal data in a structured, commonly used and machine-readable format
  • Object. On grounds relating to your particular situation, you have the right to object to our processing of your personal data on the basis of legitimate interests or for direct marketing purposes. You also have the right to object to our processing of your personal data for the performance of tasks carried out in the public interests or in the exercise of official authority or based on legitimate interests

Please note that there may be certain exceptions or limitations to the abovementioned rights which could apply depending on the specific circumstances of your situation. In such cases, we will provide you with detailed information about the applicable exception or limitation and help you exercise your rights to the fullest extent possible, in accordance with applicable laws and regulations.

Please use [email protected] to file requests as mentioned in this section.

Finally, you also have a right to file a complaint to the data protection authorities with regards to our processing of your personal data.

Changes to the Privacy Policy

We encourage you to review the Policy regularly. If we make significant changes to our Policy that materially alter our privacy practices, we may also notify you by other means, such as sending an email or posting a notice on our website prior to the changes taking effect.

Last updated: 2024-10-02.

How to contact us

The controller responsible for the processing of your personal data is:

Payday ehf.
Address: Bæjarlind 14-16, 201 Kópavogi, Iceland
Telephone number: +3545515121

We value your opinion. If you have any comments or questions about our Privacy Policy, or any privacy concerns, including regarding a possible breach of your privacy, please send them to [email protected].

We will handle your requests or complaints confidentially. Our representative will contact you to address your concerns and outline the options regarding how these may be resolved. We aim to ensure that complaints are resolved in a timely and appropriate manner.