Rev A
Date: 2026-09-07
Combain Mobile AB, Scheelevägen 27, 223 70 Lund, Sweden, is responsible for the processing of personal data described in this policy when Combain acts as data controller. Questions or requests can be sent to support@combain.com.
1. What this policy covers
This policy covers personal data processed by Combain in connection with our website, customer and prospect relationships, accounts, support and our own business administration. When Combain processes personal data solely on behalf of a customer, the customer is normally the controller and Combain acts as processor under the applicable agreement and Data Processing Agreement (DPA).
2. Personal data we may process
- Business and account data: name, organisation, address where relevant, work email, telephone number, account and service information.
- Communications and support data: messages, support information and other information you provide when contacting us.
- Technical and service data: IP address, service or device identifiers, usage and log data and, depending on the service and customer configuration, radio/network and location information.
- Website and cookie data: browser, device and usage data described in our Cookie Policy.
3. Why we process personal data
Purpose | Examples | Legal basis |
Provide and administer services | Account administration, service delivery, billing and contractual communications | Contract where applicable; legitimate interests for B2B administration; legal obligation where required |
Support and customer communication | Responding to enquiries and support cases | Contract / pre-contract steps where applicable; otherwise legitimate interests |
Security and service operation | Authentication, logging, abuse prevention and troubleshooting | Legitimate interests and, where applicable, legal obligations |
Product and service improvement | Analysis of service performance and improvement of products | Legitimate interests where Combain is controller; customer instructions where Combain is processor; anonymous or aggregated data where appropriate |
Marketing | News, product updates and offers | Consent where required, or another lawful basis where permitted by applicable law |
Non-essential cookies | Analytics, preferences and marketing technologies | Consent |
4. Location and service data processed for customers
Some Combain services process radio/network observations and location-related information provided by a customer or a customer device. If that information is personal data and Combain processes it only for the customer, Combain acts as processor and processes it according to the customer agreement, DPA and documented instructions. Data that has been irreversibly anonymised so that no individual is identifiable is not personal data under the GDPR.
5. Sharing and service providers
We may use contracted service providers for functions such as hosting and IT operations, communications and support, billing/payment and website technologies. Processors are subject to contractual data-protection obligations. We may also disclose personal data when required by law or a competent authority. The categories and locations of relevant processors are documented in our internal processor and transfer records.
6. International transfers
Where personal data is transferred outside the European Economic Area, Combain uses a transfer mechanism permitted by Chapter V of the GDPR, such as an adequacy decision or the European Commission Standard Contractual Clauses, and applies additional safeguards where required.
7. Retention
- Customer and business-contact data is kept for the customer relationship and thereafter only as needed for legal obligations, contractual claims or legitimate business records.
- For Combain-hosted CPS Location API request logs, the current internal ROPA states an ordinary retention of approximately 30 days and a maximum of two months. Customer-specific and on-premise deployments may differ under the applicable agreement.
- Billing and accounting records are retained for the period required by applicable law.
- Marketing data is retained until consent is withdrawn, the recipient unsubscribes or the data is no longer needed, subject to records required to respect an opt-out.
- Backup copies are removed through the normal backup rotation unless longer retention is legally required.
8. Your rights
Depending on the circumstances, you may have the right to:
- access your personal data;
- correct inaccurate personal data;
- request erasure or restriction of processing;
- object to processing based on legitimate interests or to direct marketing;
- receive portable data where the right to data portability applies;
- withdraw consent at any time where processing is based on consent; and
- lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
We respond to valid rights requests without undue delay and normally within one month. The period may be extended by up to two additional months where the GDPR permits this. If Combain is acting only as processor, we will normally refer the request to the relevant customer/controller and assist that controller as required.
9. Security
Combain applies technical and organisational measures appropriate to the risks of the relevant processing. Control areas include access management, communications security, confidentiality, logging and monitoring, vulnerability and patch management, backup and recovery, incident management and supplier controls. The exact implementation varies by service and processing context.
10. Cookies and changes to this policy
For details about website cookies and consent settings, see our Cookie Policy. We may update this Privacy Policy when our processing or legal requirements change. The current version is published on our website.
Contact: Combain Mobile AB, Scheelevägen 27, 223 70 Lund, Sweden, support@combain.com.