About EGGS Design

EGGS Design is an independent group of innovation consultancies, helping clients craft new products, services and business transformations. We work holistically to ensure that personal insights play well together with technology, brand and business.

While we embrace technology, we are not driven by it. We also respect the impact technology can have on individual rights such as privacy and free expression, so we strive to balance these interests in the work we perform for our clients.

1. Accountability and contact details

When processing your personal data for its own purposes and needs, EGGS Design acts as a data controller.

When carrying out user-insight projects, EGGS Design may act as a joint data controller with the client ordering the innovation project or as a data processor. See below section 4 for more information on insight projects.

Our contact information for all privacy-related matters is: privacy@eggsdesign.com

2. What personal data do we process and why?

EGGS Design is required to process personal data to conduct its business activities, answer inquiries and maintain or create new business relationships. In these situations, your personal data is provided to us by you directly.

  • We process personal data such as name, email, role and telephone number about prospective clients, to follow up on leads and establish new business connections. This is done under our legitimate commercial interests and in preparation for entering new contracts.

  • We process personal data about existing customers such as contact details to our contact point within the company, to administer our relationship, perform billing, answer inquiries and provide assistance. This is done under our need to fulfil our contractual and legal obligations, such as those connected to taxes and bookkeeping.

  • We process personal data to obtain insight into specific subjects. These insights are gained by sending questionnaires to a particular target group or interviewing the insight subjects. The personal data and the precise processing activities to be performed is dependent on the scope and subject of the project. We rely on explicit consent from the insight subjects for collecting and processing that data.

  • We process personal data such as CV, professional references and contact information if you’ve applied to a job with us. This is done in our legitimate interest to assess your competence and fulfil our business needs.

3. Personal data that is not collected directly from you

We may receive personal data about you indirectly if:

  • We have contacted your organisation, and your organisation provides us with your contact in its response. This is done under our legitimate interest to obtain information or establish a relationship with your organisation.

  • A company you are a customer, member or employee of provides us with your contact information so that we may contact you within the scope of an insight project we are conducting for them or for a third party they have an agreement or relationship with. Those companies, entities and organisations are themselves responsible for having a valid lawful basis for collecting your personal data and providing us with your contact information.

4. Projects including User-insight

EGGS Design provides its clients with research and insight into certain user-groups or subjects, including the health industry. As a result, personal data provided willingly by an insight interviewee will vary according to the particular project and may include so-called "special categories" of data such as personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, health or sex life history, sexual orientation, trade union membership or criminal history. This specific category data receive additional protection under the law, and EGGS Design has implemented a secure process to ensure its proper handling and deletion.

While a project is ongoing, we secure your personal data by pseudonymising it.This means we use an identifier such as "Interviewee #1" to refer to you rather than a personal trait like your name, age or telephone number. Once we have gathered sufficient insights, we aggregate your responses along with other project participants so that no single person may be identified by delivering our results to our customer.Once the project has been completed and the aggregated results produced, the material gathered from your participation (including any photos, audio recordings or other personal data) is promptly deleted or fully anonymised.

In cases where our customers solely determine the purpose, scope and focus group of a project, EGGS Design acts as a data processor. In these cases, our customer provides us with your contact information and remains responsible for the lawfulness of the purpose and legal basis for processing. For more information on how such a customer processes your data and how you may exercise your data subject rights, please contact the customer directly or, if you prefer, contact us as described below and we will notify them.

In cases where EGGS Design collaborates with a customer to jointly determine the project focus group and/or locates participants itself, we act as a joint data controller with our customer. In these cases, you will find information in this privacy notice about how your personal data is processed and how to exercise your data subject rights.

5. Who do we share your personal data with?

In conducting its business activities, EGGS Design may share your personal data with the following parties:

Other EGGS Subsidiaries within the EGGS Design

  • To maintain an overview of which customers and contacts have relationships with various entities within the EGGS Design

Public Authorities

  • In the event of legal action involving EGGS, EGGS may be required to provide personal information according to a court order or other statutory requirement.

6. Who processes your personal data on behalf of EGGS Design?

To process its data and perform its activities, EGGS Design AS relies on several companies to store and process personal data on our behalf. These companies are referred to as “data processors”, and our relationship with them is defined in a written data processing agreement that states the processors’ obligations and limitations under which they will process personal data. EGGS Design utilises the following data processors to process your personal data under our specific instructions:

Atlassian

  • Purpose: Project management

  • Processing Location: USA

  • Legal Basis for Transfer Outside of EU/EEA: Privacy Shield

Dropbox

  • Purpose: Document storage

  • Processing Location: Western Europe

  • Legal Basis for Transfer Outside of EU/EEA: N/A

Eventbrite

  • Purpose: Event registration

  • Processing Location: USA

  • Legal Basis for Transfer Outside of EU/EEA: Privacy Shield

Google

  • Purpose: Site analytics and performance measurement of eggsdesign.com website

  • Processing Location: Western Europe, USA

  • Legal Basis for Transfer Outside of EU/EEA: Privacy Shield

HootSuite

  • Purpose: User engagement on social media

  • Processing Location: Canada

  • Legal Basis for Transfer Outside of EU/EEA: Adequacy Decision by European Commission in Commission Decision 2002/2/EC

Microsoft

  • Purpose: Office 365

  • Processing Location: Western Europe, USA

  • Legal Basis for Transfer Outside of EU/EEA: Privacy Shield

Slack

  • Purpose: Project collaboration

  • Processing Location: USA

  • Legal Basis for Transfer Outside of EU/EEA: Privacy Shield

Visma

  • Purpose: Customer billing/ERP

  • Processing Location: Norway

  • Legal Basis for Transfer Outside of EU/EEA: N/A

7. Retention periods

To the extent permitted by applicable law, EGGS Design retains your personal information for as long as it is needed to fulfil the purposes for which we obtained it. We may in some cases keep it beyond that time if we process the same data under another lawful basis, stated in this Privacy Policy or at the point of collection, that permits us that.

Contacts of Partners, Vendors and Customers

We retain contact information of employees of our partners, vendors and customers for 2 years after our commercial relationship terminates unless the employee terminates their employment before, and we are informed to update the data, or we are required to retain it longer due to legal action.

Insight Project Data

We anonymise or delete all information regarding an insight project within 30 days of the project’s completion.

Data of Former EGGS Design Employees

EGGS Design retains information on its former employees as necessary to comply with other legal obligations such as applicable accounting and tax law. Certain information kept for accounting and tax reasons such as your salary history will be deleted no later than 5 years following the end of your employment, while limited information pertaining to your identification as a former employee, your role, dates of employment and information linked to your competence and/or responsibilities shall be retained in our systems.

8. Your data protection rights

You have the right to request us to confirm whether we are processing personal data about you. Also, you have the right to ask us to:

  • Access to your personal data

  • Rectify, supplement and update your personal information

  • Delete or restrict the processing of your personal data under certain circumstances

  • Object to processing activities carried out for marketing purposes, as well as to object to certain activities carried out to fulfil our legitimate purposes, under certain circumstances

  • Have personal data that you have provided us directly ported to you or another company in a commonly readable file format

  • Withdraw a consent you have given, at any time

You may exercise your rights by contacting us at privacy@eggsdesign.com. Requests will typically be answered within 30 days. For more information about your data subject rights, visit the Norwegian Datatilsynet’s website.

9. Complaints

If you have queries or concerns, please contact us at privacy@eggsdesign.com, and we'll respond. If you remain dissatisfied, you may file a complaint about the way we process your personal information to the Norwegian Datatilsynet, who is the supervisory authority for the processing of personal data by EGGS Design.

10. Visits to our website

When you visit our website, we process your IP-address, your cookies and user setting information, as well as information about the machine you’re using including device attributes like IP address, operating system software, device type and browser type to generate anonymous site analytics and performance measurement using Google Analytics.

Furthermore, we may collect information about your interaction with our website, including logs, crash reports, date and time, referrer URL of your request, and other information of relevance to uncover malfunction and ensure the security of our website and IT-infrastructure.

We use TLS-certificate (HTTP) to ensure the security of the communication between our websites and our visitors so that no one can read or change the information being exchanged.

These processing activities are performed based on our legitimate interests to improve our website and its usability, improve the quality of the information we provide and measure activity for site analytics and performance management, as well as ensure the security of our website.

We use cookies. For information on the cookies we use, and what data they collect, please check our cookie policy, eggsdesign.com/article/cookies

11. Changes to this notice

We periodically update or change this privacy notice as a consequence of changes to our business activities, our processing activities or changes in the law. We will post a notice on this website when such changes are made, so you may review what is new and inform yourself about our practices.

Oslo, Norway, April 9, 2019.