Privacy policy – Shareholders

General

The General Data Protection Regulation is applicable from 25 May 2018. This Privacy Policy outlines how BioArctic AB (“BioArctic”) as of 25 May 2018 processes personal data relating to you as a shareholder, or as a representative of a shareholder, or as a holder of or representative of a holder of other financial instruments that can be converted to or give the right to buy shares (“shareholders”).

Data controller

As a personal data controller, BioArctic is responsible for ensuring that all personal data is processed properly and in accordance with applicable data protection legislation. However, the Central Securities Depository, Euroclear Sweden AB, is the data controller for data processed in the central securities depository register.

Personal data collected and processed by BioArctic

Personal data relating to you can be provided to BioArctic directly by you or by the organisation that you represent. Also, personal data relating to you contained in the central securities depository register can be provided to us by the Central Securities Depository, Euroclear Sweden AB. BioArctic processes the following categories of personal data:

  • Contact details, including name, address, telephone number, and e-mail address
  • Personal identity number
  • Company registration number (if it can be linked to you)
  • Holding of shares or other financial instruments
  • If applicable, information regarding legal guardianship, pledges and pledgees, and notes in the central securities depository register

Furthermore, any other information that has been provided by you or by the organisation that you represent or that is included in the information obtained by the Central Securities Depository may be processed by BioArctic.

Our processing of your personal data

The purposes of the processing of personal data relating to you and the legal basis for such processing is set forth in the table below.

Purpose

Legal basis

To fulfil BioArctic’s obligations set forth in the articles of association relating to you as a shareholder.

Performance of a contract

The processing is necessary for the performance of BioArctic’s contractual obligations set forth in the articles of association relating to you as a shareholder.

Legitimate interests

The processing is necessary for the purposes of the legitimate interests pursued by BioArctic to fulfil its contractual obligations relating to its shareholders (this only pertains to representatives of shareholders).

To fulfil BioArctic’s duties set forth in the Swedish Companies Act (Sw. Aktiebolagslagen) to its shareholders (e.g. notices of general meetings of shareholders, administration in connection with general meetings of shareholders or other company events).

 

Compliance with legal obligations

The processing is necessary for compliance with BioArctic’s legal obligations set forth in the Swedish Companies Act (Sw. Aktiebolagslagen).

Legitimate interests

The processing is necessary for the purposes of the legitimate interests pursued by BioArctic to fulfil its legal obligations relating to its shareholders (this only pertains to representatives of shareholders).

To distribute information related to shareholders.

Compliance with legal obligations

The processing is necessary for compliance with BioArctic’s legal obligations set forth in the Market Abuse Regulation.

Legitimate interests

The processing is necessary for the purposes of the legitimate interests pursued by BioArctic to provide shareholders and other stakeholders with regulatory information or other information relevant to BioArctic.

How long do we keep your personal data?

Your personal data is kept by BioArctic as long as is required by law or as long as there is a need to keep the data to fulfil the purposes for which the data was collected in accordance with this Privacy Policy.

With whom do we share your personal data?

The minutes from general meetings of shareholders and the voting register for general meetings of shareholders may be disclosed to shareholders present at such general meeting, the Swedish Company Registration Office (Sw. Bolagsverket), auditors, in accordance with law, or at BioArctic’s discretion, if such disclosure is considered to be appropriate.

Information regarding inter alia major shareholders may be disclosed to authorities, advisors, and the public in connection with drafting of prospectuses, information memorandums, and financial reports. A list of BioArctic’s up to maximum 20 shareholders with the largest shareholding is published on BioArctic’s website.

Personal data is also shared with other trusted parties, such as suppliers, professional advisors, and auditors.

Transfer of personal data to third countries

BioArctic will not transfer your personal data to any country outside the EU/EEA, with the exception of what may be stated under the section ”With Whom Do We Share Your Personal Data?” above.

Your rights

You have a right to access your personal data and request that BioArctic corrects, deletes, or limits its processing of your personal data. Furthermore, you have a right to object to BioArctic’s processing of your personal data as set out in the applicable data protection legislation. If the legal basis for BioArctic’s processing of your personal data is based on consent or performance of a contract, you have a right to receive a transcript of your personal data processed by BioArctic in a structured, accessible and machine-readable format and a right to request that such data be transferred to another data controller.

You are entitled to submit a complaint regarding BioArctic’s processing of your personal data with the Swedish Data Protection Authority (Sw. Datainspektionen, which during 2018 will change its name to Dataskyddsmyndigheten), Box 8114, SE-104 20 Stockholm, Sweden.

If personal data is not disclosed to BioArctic

If you chose not to disclose your personal data to BioArctic, BioArctic will not be able to fulfil is legal duties and contractual obligations relating to you as a shareholder. Consequently, you will not be able to exercise your rights as a shareholder, e.g. your right to participate and vote at general meetings of shareholders.

Contact information

Do not hesitate to contact us if you have any questions regarding this Privacy Policy, our processing of your personal data, or if you want to exercise any of your rights under applicable data protection legislation.

BioArctic’s contact information:

Swedish company registration number: 556601-2679
Address: Warfvinges väg 35, SE-112 51 Stockholm, Sweden
Telephone number: +46 8 695 6930
E-mail address (to BioArctic’s data protection officer): dpo@bioarctic.se