Privacy Policy

Rev A
Date: 2026-09-07

Combain Mobile AB, Scheelevägen 27, 223 70 Lund, Sweden, is responsible for the processing of personal data described in this policy when Combain acts as data controller. Questions or requests can be sent to support@combain.com.

1. What this policy covers

This policy covers personal data processed by Combain in connection with our website, customer and prospect relationships, accounts, support and our own business administration. When Combain processes personal data solely on behalf of a customer, the customer is normally the controller and Combain acts as processor under the applicable agreement and Data Processing Agreement (DPA).

2. Personal data we may process

  • Business and account data: name, organisation, address where relevant, work email, telephone number, account and service information.
  • Communications and support data: messages, support information and other information you provide when contacting us.
  • Technical and service data: IP address, service or device identifiers, usage and log data and, depending on the service and customer configuration, radio/network and location information.
  • Website and cookie data: browser, device and usage data described in our Cookie Policy.

3. Why we process personal data

Purpose

Examples

Legal basis

Provide and administer services

Account administration, service delivery, billing and contractual communications

Contract where applicable; legitimate interests for B2B administration; legal obligation where required

Support and customer communication

Responding to enquiries and support cases

Contract / pre-contract steps where applicable; otherwise legitimate interests

Security and service operation

Authentication, logging, abuse prevention and troubleshooting

Legitimate interests and, where applicable, legal obligations

Product and service improvement

Analysis of service performance and improvement of products

Legitimate interests where Combain is controller; customer instructions where Combain is processor; anonymous or aggregated data where appropriate

Marketing

News, product updates and offers

Consent where required, or another lawful basis where permitted by applicable law

Non-essential cookies

Analytics, preferences and marketing technologies

Consent

 

4. Location and service data processed for customers

Some Combain services process radio/network observations and location-related information provided by a customer or a customer device. If that information is personal data and Combain processes it only for the customer, Combain acts as processor and processes it according to the customer agreement, DPA and documented instructions. Data that has been irreversibly anonymised so that no individual is identifiable is not personal data under the GDPR.

5. Sharing and service providers

We may use contracted service providers for functions such as hosting and IT operations, communications and support, billing/payment and website technologies. Processors are subject to contractual data-protection obligations. We may also disclose personal data when required by law or a competent authority. The categories and locations of relevant processors are documented in our internal processor and transfer records.

6. International transfers

Where personal data is transferred outside the European Economic Area, Combain uses a transfer mechanism permitted by Chapter V of the GDPR, such as an adequacy decision or the European Commission Standard Contractual Clauses, and applies additional safeguards where required.

7. Retention

  • Customer and business-contact data is kept for the customer relationship and thereafter only as needed for legal obligations, contractual claims or legitimate business records.
  • For Combain-hosted CPS Location API request logs, the current internal ROPA states an ordinary retention of approximately 30 days and a maximum of two months. Customer-specific and on-premise deployments may differ under the applicable agreement.
  • Billing and accounting records are retained for the period required by applicable law.
  • Marketing data is retained until consent is withdrawn, the recipient unsubscribes or the data is no longer needed, subject to records required to respect an opt-out.
  • Backup copies are removed through the normal backup rotation unless longer retention is legally required.

8. Your rights

Depending on the circumstances, you may have the right to:

  • access your personal data;
  • correct inaccurate personal data;
  • request erasure or restriction of processing;
  • object to processing based on legitimate interests or to direct marketing;
  • receive portable data where the right to data portability applies;
  • withdraw consent at any time where processing is based on consent; and
  • lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

We respond to valid rights requests without undue delay and normally within one month. The period may be extended by up to two additional months where the GDPR permits this. If Combain is acting only as processor, we will normally refer the request to the relevant customer/controller and assist that controller as required.

9. Security

Combain applies technical and organisational measures appropriate to the risks of the relevant processing. Control areas include access management, communications security, confidentiality, logging and monitoring, vulnerability and patch management, backup and recovery, incident management and supplier controls. The exact implementation varies by service and processing context.

10. Cookies and changes to this policy

For details about website cookies and consent settings, see our Cookie Policy. We may update this Privacy Policy when our processing or legal requirements change. The current version is published on our website.

Contact: Combain Mobile AB, Scheelevägen 27, 223 70 Lund, Sweden, support@combain.com.