Privacy policy
In the operations of Justum (SIF Lögmenn slf.), strong emphasis is placed on data and information protection. Justum seeks to ensure the reliability, confidentiality and security of the personal data processed in its operations. Below you will find information on what personal data is collected in Justum's operations, how it is obtained and for what reasons, how it is used, and who has access to it. It also explains how the retention and processing of personal data by Justum complies with the Icelandic Act on Data Protection and the Processing of Personal Data No. 90/2018 (the Data Protection Act) and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the General Data Protection Regulation).
1. What is personal data?
Personal data means any information relating to an identified or identifiable natural person. This includes information that can be traced directly or indirectly to a particular individual. Data that cannot be linked to an individual is not considered personal data.
2. Responsibility and processing of personal data
Justum (SIF Lögmenn slf.) is the controller when a decision is taken on Justum's behalf as to how particular personal data provided to Justum on the basis of its operations is to be processed. Where Justum is entrusted with the processing of personal data on behalf of others, Justum may be regarded as a processor of that personal data on the basis of a data processing agreement with the controller. If information is shared with service providers (third parties) in Justum's operations, such sharing and processing takes place on the basis of a data processing agreement, and Justum then remains the controller itself.
3. What personal data is collected and where does it come from?
Justum collects necessary personal data about its clients and their contacts, including names, national ID numbers, address or place of residence, telephone number, email address, information from communications, billing information and, where necessary for its operations, sensitive personal data. In connection with payments in its debt collection activities, Justum may also process information on creditworthiness. As a general rule, information is obtained directly from the client or their contact, but it may also come from public authorities, courts, service providers, counterparties, online databases and websites.
4. What is the purpose of collecting and processing the information?
The collection and processing of personal data by Justum takes place primarily in order to be able to perform service agreements with Justum's clients in a satisfactory manner and to fulfil other obligations arising from them. Processing may also take place on the basis of a legal obligation, for example under anti-money laundering rules or accounting obligations.
5. How and for how long is information retained?
Justum retains personal data securely and in accordance with applicable laws and rules. Appropriate technical and organisational measures are taken to protect it against loss, unauthorised access, copying, use or disclosure. Information is retained for as long as is necessary. Information falling under the Icelandic Bookkeeping Act is retained for 7 years from the end of the relevant financial year. Information relating to actual legal services may be retained for longer where this is necessary to establish, exercise or defend legal claims.
6. Is information shared with third parties?
Justum does not share personal data with third parties without the unambiguous consent of the data subject or in order to fulfil obligations under a contract or law. Information may also be shared with service providers who are bound by confidentiality. Justum does not transfer personal data to parties outside the European Economic Area unless such transfer is permitted under the relevant data protection legislation.
7. What rights do I have?
A data subject is, as applicable, entitled to confirmation of processing, access and in certain cases a copy, information about the arrangements for processing, transfer to a third party in certain circumstances, rectification, erasure or restriction of processing, to object to processing and to withdraw consent. These rights are not absolute. If a data subject wishes to exercise their rights or obtain further information, they are advised to contact Justum's data protection officer. If a data subject considers that Justum has not respected their rights, they may submit a complaint to the Icelandic Data Protection Authority (Persónuvernd).
8. Data protection officer
Justum has appointed a person responsible for monitoring compliance with this privacy policy:
Dagný Sif Sigurbjörnsdóttir, attorney, dagny@justum.is.
If you are unsure how this policy applies to you, please contact the data protection officer for further information.
9. Review and amendments
Justum reserves the right to amend this privacy policy in order to ensure that it meets the requirements of the Data Protection Act and the General Data Protection Regulation. All amendments take effect upon publication of an updated version on Justum's website.