Legal
01 · General
At ABC Labs AB (“ABC,” “we,” or “us”) we protect the personal integrity of individuals and always strive for a high level of data protection. This privacy policy explains how we collect and use your personal information, both as a customer of ours or as a test subject. It also describes your rights and how you can assert them. It is important that you read and understand this policy and feel safe in our processing of your personal data. You are always welcome to contact us if you have any questions.
This privacy policy applies to you who:
This policy does not cover privacy or data protection issues regarding data handled by our business partners, external service providers, and resellers. These third parties are responsible for complying with applicable data protection regulations and have their own privacy policies. To understand how these actors use your personal data, we refer to their respective policies.
02 · About us and our services
ABC is a laboratory and offers diagnostic laboratory services within clinical laboratory medicine such as drug and alcohol tests. Our services also include the development and provision of a digital platform for secure management of the entire test flow, including logistics around the tests, analysis in the laboratory, and communication of test results.
A data controller is the entity that decides for what purposes personal data shall be processed, and how the processing shall be carried out. The data controller may use a so-called data processor — an entity that may only process personal data in accordance with instructions from the data controller and may not use the personal data for its own purposes.
We are data controllers when we process your personal data in accordance with this privacy policy.
03 · What we collect
Personal data in this context refers to all information attributable to a natural person that can be used directly or indirectly to identify them (e.g., name, contact details, social security number, location information, employer).
We may collect personal data about you in several different ways. We primarily collect information directly from you — for example, when you create an account with us or perform one of our alcohol or drug tests. However, we may also receive information from other parties, such as your employer, a testing center, or another customer.
04 · How we use your data
All processing of personal data is carried out in accordance with the GDPR. We ensure only necessary data is processed for the purposes stated below.
Purpose
Create and manage user accounts
To use our services we register your contact and login details — name, username, email, telephone, job title, employer — plus content you upload, such as staff lists.
Legal ground
Necessary to (i) perform our contractual obligations with users (GDPR Article 6(1)(b)), or (ii) pursue our customers’ legitimate interests (GDPR Article 6(1)(f)). For some features we obtain explicit consent (GDPR Article 6(1)(a) or, where relevant, Article 8).
Purpose
Providing testing and laboratory services
We process personal data — including health data, human samples, and test results — to manage bookings, conduct drug and alcohol tests, and ensure quality assurance and reporting.
Legal ground
Necessary for our legitimate interests (GDPR Article 6(1)(f)) and, where applicable, our legal obligation (Article 6(1)(c), 9.2(h), 9.3) under healthcare legislation. For employer testing outside healthcare, we collect explicit consent (Article 6(1)(a) and 9.2(a)).
Purpose
Invoicing and financial management
Processing personal data to handle payments and comply with accounting requirements.
Legal ground
Fulfillment of contract (Article 6(1)(b)) and legal obligation (Article 6(1)(c)), for example the Swedish Accounting Act (1999:1078).
Purpose
Support and customer service
When you contact us for support, we process your contact details and the information you provide in order to answer your request.
Legal ground
Necessary to (i) perform our contractual obligations (Article 6(1)(b)) or (ii) pursue legitimate interests (Article 6(1)(f)).
Purpose
Communication and reminders
Sending service updates, reminders, and important information about our services.
Legal ground
Necessary to (i) perform our contractual obligations (Article 6(1)(b)) or (ii) pursue legitimate interests (Article 6(1)(f)).
Purpose
Marketing and newsletters
If you have given consent, we may use your contact details to send you information about our services.
Legal ground
Consent (GDPR Article 6(1)(a)).
Purpose
Development and improvement of services
We analyze user behavior and collected data in the platform — excluding test results and sensitive data at the person level — to quality-assure and improve our services.
Legal ground
Necessary to fulfill contractual obligations (Article 6(1)(b)) and pursue legitimate interests in improving, upgrading, and securing services (Article 6(1)(f)).
Purpose
Anonymized data for research and product development
We may anonymize personal data for use in research and product development — for example, to improve our tests and platform. Anonymized data is no longer personal data and falls outside the GDPR.
Legal ground
Necessary to fulfill contractual obligations (Article 6(1)(b)) and pursue legitimate interests in improving services (Article 6(1)(f)).
Purpose
Recruitment
We collect personal data from you in connection with your application and interviews. Where relevant, we also collect information from recruitment agencies, previous employers, our employees, publicly available information, social media (e.g., LinkedIn), and references.
Legal ground
Necessary in view of our legitimate interest in administering the recruitment process and evaluating applicants (Article 6(1)(f)).
Our services are aimed at adults only and we do not intend to use personal data linked to children. For children under 16 years of age, consent from guardians is required before we use their personal data.
05 · Automated processing
When you use our services or interact with our web and hosting platforms, we may receive or collect information about your use of them, such as:
Such information is generally collected through digital identifiers like browser cookies, plugins, or your IP address. These identifiers distinguish information provided through the hardware, browser, or account you use. We may associate the information collected with one of your accounts, for example if you are logged into our services when the information is collected.
06 · Who has access
Only employees and consultants within ABC Labs who need access to your personal data to perform their duties are authorized to process them.
We do not share your personal data with third parties unless necessary to provide our services in a quality-assured manner:
A current list of our personal data processors can be provided upon request.
In some cases, personal data may be transferred to countries outside the EU/EEA. When this happens, we ensure appropriate safeguards are in place — for example, through agreements that comply with the EU Commission’s standard contractual clauses.
07 · Storage and deletion
We only save your personal data for as long as necessary to fulfill the purpose — for our users and customers to utilise our services, including the performance of quality-assured alcohol and drug tests and laboratory services.
Data that is no longer necessary is continuously deleted. We conduct an annual review to identify and delete information that is no longer needed.
We use technical and organizational security measures:
08 · Your rights
Regarding personal data for which ABC is the data controller, users have the following rights:
If you have any comments or questions regarding our compliance with this policy, please contact us using the details below.
09 · Contact
If you have any questions about this policy or wish to exercise your rights, please contact our Data Protection Officer, Ann Cheng.
Emailprivacy@abclabs.se
AddressHagaplan 4, 113 68 Stockholm
Websitewww.abclabs.se
10 · Changes to this policy
We will update this policy as necessary and will post any changes via our website.