PRIVACY POLICY

Last updated: 2025-02-12

Why and who?

We at Ludo Technologies care about privacy and protecting the Personal Data handled by us. This means that we care about your personal integrity and actively work to protect it.

In this Policy we describe how and the purposes for which we use your Personal Data as well as what lawful basis we use and what measures we take to protect Personal Data.

We also provide information on how you exercise the rights you have linked to our Processing of Personal data.

Ludo Technologies AB, registration number 559371-1061, ("Ludo Technologies", "we", "us", "our") is the Controller of all Personal Data listed in this Privacy Policy (the "Policy").

For situations when we are Processors of your Personal Data on behalf of another Controller, please refer to our Data Processing Addendum (“DPA”)

This Policy provides information on how we handle Personal Data when you communicate with us, use the Services or visit our website www.ludoo.app (together the "Functions").

The intended recipient of the information provided in this Policy is:

Definitions

Definitions used here shall have the meanings as specified in the DPA, Policy and the Ludo Terms and Conditions.

"Applicable Law" refers to the legislation applicable to the Processing of Personal Data, including the GDPR, supplementary national legislation, as well as practices, guidelines, and recommendations issued by a national or EU supervisory authority.

"Controller" is the company/organisation that decides for what purposes and in what way personal data is to be processed and is responsible for the Processing of Personal Data in accordance with Applicable Law.

"Data Subject" is the living, natural person whose Personal Data is being processed.

"GDPR" means the retained EU law version of the General Data Protection Regulation ((EU) 2016/679).

"Personal Data" is all information relating, directly or indirectly, to an identifiable natural person.

"Processing" means any operation or set of operations which is performed on Personal data, e.g. storage, modification, reading, handover, and similar.

"Processor" is the company/organisation that processes Personal Data on behalf of the Controller and can therefore only process the Personal Data according to the instructions of the Controller and the Applicable Law.

"The Services" is a platform called Ludoo which contains exercises and games for practical skill training.

The definitions above shall apply in the Policy regardless if they are capitalised or not.

Ludo Technologies's role as a Controller

The information in this Policy covers Personal Data Processing for which Ludo Technologies is the Controller.

As a Controller we are responsible for the Processing for which we decide the purpose of ("the why") and the means for the Processing (what methods), what Personal Data and for how long it is stored.

The Policy does not describe how we Process Personal Data in the role of a Processor - i.e. when we process Personal Data on behalf of our customers. Information regarding how we process Personal Data as a Processor can be found in the DPA.

Ludo Technologies provides a platform (Ludoo) for practical skill training, development and organizational agility. Ludo Technologies use Personal Data to understand app usage internally and to identify users for in-platform statistics and analytics of skill development.

We will use Personal Data you share with us as a Controller in order to create your Account using your credentials. You may assign other users to this account to use it jointly. The Personal Data of these Authorized Persons will be used in accordance with the DPA on your behalf and as per your instruction.

Visitors to our web site may submit Personal Data when booking a meeting or submitting a contact form. This information can be used by Ludo Technologies to contact visitors and for marketing purposes by sending information such as campaigns, newsletters, offers or updates upon agreement by the Visitor.

For information as to how we use Cookies, please refer to our Cookie Policy below.

Ludo Technologies's Processing of Personal Data

We have a responsibility to describe and demonstrate how we fulfil the requirements that are imposed on us when we Process your Personal Data. This section aims to give you an understanding of what type of Personal Data we Process as Controllers and for which reasons.

For how long do we store your Personal Data?

We will keep your Personal Data as long as it is necessary for the purpose for which it was collected. Depending on the lawful basis on which we support the Processing, this may a) be regulated in a contract, b) be dependent on valid consent, c) be stated in legislation or d) followed by an internal assessment based on a legitimate interest assessment (LIA). In the list below, we indicate, where possible, the period during which the Personal Data will be stored and the criteria used to determine the storage period.

We never store your Personal Data longer than necessary and delete Personal Data regularly. Ludo Technologies also takes reasonable actions to keep the Personal Data being Processed updated and to delete outdated and otherwise incorrect or redundant Personal Data.

Processing

Processing that we carry out and for what purposes:

In all instances of Personal Data of a Ludoo customer, user of the Services or visitor of our site being used for marketing purposes or for the sharing of newsletters OPT IN will be required. Such OPT IN may be revoked at any time by contacting Ludo Technologies and unsubscribing to receiving such notices.

In cases where Authorized Persons (as defined in the Terms and Conditions) are given access to an Account, such marketing material and newsletters will be visible to them. The Ludoo customer, user of the Services or visitor who may have created this account is responsible for and can agree on behalf of these Authorized Persons to receive such marketing materials and newsletters in their Account.

Processing of Authorized Persons’ Personal Data will be as per the DPA ( www.ludoo.app/legal/dpa)

The Ludoo customer, user of the services or visitor is responsible for all Personal Data of an Authorized Person and are Controllers of this Personal Data.

There are no Special Categories of data or Sensitive Personal Data being Processed and at no time should any Sensitive Personal Data be shared to the Controller.

Your rights

You are the one in control of your Personal Data and we always strive to ensure that you can exercise your rights as efficiently and smoothly as possible.

Access - You always have the right to receive information about the Processing of data that concerns you. We only provide information if we have been able to verify that it is you that are requesting the information.

Rectification - If you find that the Personal Data we process about you is incorrect, let us know and we will fix it.

Erasure - Do you want us to completely forget about you? You have the right to be forgotten and request deletion of your Personal Data when the Processing is no longer necessary for the purpose for which it was collected. If we are required to retain your information under applicable law or a contract that we have entered with you, we will ensure that it is processed only for the specific purpose set forth in such applicable law or contract. We will thereafter erase the information as soon as possible.

CONTACT: dataprivacy@ludoo.app

Upon the request of deletion of Personal Data, such deletion will be carried out in accordance with applicable Data Privacy Law and within the legal time frames as applicable.

Objections - Do you disagree with our assessment that a legitimate interest for Processing your Personal Data overrides your interest in protecting your privacy? Don't worry - in such case, please inform us and we will review our legitimate interest assessment. Of course, we add your objection to the balance and make a new assessment to see if we can still justify our Processing of your Personal Data. If you object to direct marketing, we will delete your personal information without making an assessment. Please contact us and inform us of your preference or objection or unsubscribe to the marketing.

Restriction - You can also ask us to restrict our Processing of your Personal Data:

Data portability - We may provide you with the data that you have submitted to us or that we have received from you in connection with a contract that we have entered with you. You will receive your information in a commonly used and machine-readable format that you can transfer to another personal data manager.

Withdraw consent - If you have given consent to one or several specific Processing(s) of your Personal Data, you have the right to withdraw your consent at any time and thus ask us to terminate the Processing immediately. Please note that you can only withdraw your consent for future Processing of Personal Data and not for Processing that has already taken place.

How you use your rights

If you have any questions regarding our processing of your personal data, or if you would like to invoke any of your rights, contact us at dataprivacy@ludoo.app and we will help you.

Marketing

We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. You will receive marketing communications if you have signed up for a trial of our Services. We will also send you marketing communications when you have given your consent for us to do so, e.g. when signing up for our newsletter.

You can ask us to stop sending you marketing messages by contacting us at any time by emailing dataprivacy@ludoo.app or by unsubscribing through the instructions in the marketing messages.

Use of AI-Generated Content

As further clarified in the Terms and Conditions and where applicable the DPA

Where the AI-Generated Feature is used, Personal Data may be shared in either one, or both of, two ways. To confirm, neither of these ways are necessary for the use of the feature and We strongly advise against the sharing of Personal Data when using the AI-Generated Feature.

When the Customer shares its Personal Data or its Users or Employees Personal Data with the AI Feature, We will act as processors in accordance with the DPA. We clarify again that no such sharing should be carried out. The Customer is the Controller and will at all times remain responsible for such Personal Data.

When the User shares their own Personal Data with the AI Feature, We will be Controllers and will process the data in accordance with our Privacy Policy.

With regards to any Personal Data shared with the AI Feature, We will carry out such safeguards such as ensuring that the Personal Data is wiped within 30 days, and the Personal Data is kept in the EU or an adequate country as per the GDPR.

WE REQUEST AND STRONGLY ADVISE THAT NO PERSONAL DATA IS SHARED WITH THE AI–GENERATED FEATURE BY CUSTOMERS OR USERS.

In the event a Customer or User share Personal Data they will be fully responsible for such Personal Data as further clarified in the Privacy Policy and DPA (addendum) where applicable.

Transparency and Purpose of AI Systems

We utilize artificial intelligence technology provided by the Microsoft Azure OpenAI Services API (“AI Company”) to enhance certain features of our service.

The AI generates text-based content based on user-provided inputs.

While this technology is designed to assist users in creating useful and relevant content, we cannot guarantee the accuracy, completeness, or appropriateness of the content generated by the AI. Users are encouraged to review and assess the output for relevance and compliance with their intended use.

Prohibited Uses

The AI-generated content feature is intended for lawful and professional purposes only. Users are strictly prohibited from using this feature to:

Users found violating these terms may have their access to the feature suspended or terminated.

Limitation of Data Processing

No Personal Data is required for the AI feature is to function and to offer the Services. In the event Personal Data is shared, contrary to our advice and warnings, such Personal Data will be processed/received by the AI Company in accordance with Our data processing agreement with them and as further clarified in this Privacy Policy.

We have implemented such safeguards such as:

No Personal Data is required for the AI to generate content, however, we understand that the AI feature may allow for sharing and input of Personal Data.

We ask that you do not add any Personal Data as it is unnecessary and will have no benefit to the intended AI generated output.

In any case, rest assured that if for any reason you do, upon Ludoo being made aware of such sharing by you of Personal Data we will wipe it within 30 days.

We will also be Controllers or Processors of such Personal Data as further clarified in our DPA as well as this Privacy Policy.

We will therefore safeguard your data in accordance with applicable law, minimize its processing and delete it in due course as mentioned above.

Audits

To the extent and scope required by applicable law, audits, risk assessments and DPIA (Data Processing Impact Assessments) are conducted to evaluate the AI system's impact on users to ensure compliance with applicable data protection laws and to mitigate potential risks.

Monitoring and Updates to AI Classification

Ludo Technologies confirms that the AI systems used in its Services are not classified as high-risk under the EU Artificial Intelligence Act. Should the nature, functionality, or scope of these AI systems change in a way that may alter their classification:

We commit to maintaining transparency with the Customer regarding the classification and compliance status of its AI systems.

Incident Management for General-Purpose AI Systems

In the event of an issue related to the functionality or operation of the AI-powered systems, We shall:

As the AI systems are not classified as high-risk, such incidents do not require reporting under the AI Act.

Mitigation of Bias and Discrimination in AI Systems

Ludo Technologies is committed to ensuring that all AI systems used in the Services comply with the principles of fairness and non-discrimination as outlined in the EU Artificial Intelligence Act. To achieve this:

The Customer may request documentation on bias mitigation practices and provide feedback to ensure the AI system’s alignment with fairness standards.

Users are encouraged to report any concerns or anomalies observed in AI-generated content that may indicate bias. Such concerns will be addressed promptly and corrective measures will be taken where necessary.

Transfer of personal data

In order to run our business, we may need help from others who will process Personal Data on our behalf, so-called Processors. In cases where our Processors transfer Personal Data outside the EU/EEA, we have ensured that the level of protection is adequate, and in compliance with Applicable Law, by controlling that either of the following requirements are fulfilled:

We have entered into processing agreements with all our Processors. These agreements set out, among other things, how the Processor may process the Personal Data and what security measures are required for the Processing.

We may also need to disclose your Personal Data to certain designated authorities in order to fulfill obligations under applicable law or legally binding judgements.

Our processors

Ludo Technologies does not sell your Personal Data to third parties and of course we do not share your Personal Data with just anyone. However, in some cases we may need to share your Personal Data with selected third parties. If so, we make sure that the transfer happens in a secure way that protects your privacy. To follow are categories of recipients with whom we may share your data and a complete list of our Processors can be found in the appendix below.

security measures

Ludo Technologies has taken technical and organizational measures to ensure that your Personal Data is processed securely and protected from loss, abuse and unauthorized access.

Our security measures

Organisational security measures are measures that are implemented in work methods and routines within the organisation.

Technical security measures are measures implemented through technical solutions.

Cookies

Ludo Technologies uses cookies and similar tracking techniques to analyze the use of the Functions so that we can give you the best user experience.

COOKIE POLICY

If we don't keep our promise

If you think that we are not Processing your Personal Data correctly, even after you have notified us of this, you are always entitled to submit your complaint to the Swedish Authority for Privacy Protection.

More information about our obligations and your rights can be found at https://www.imy.se/.

You can contact the authority via e-mail at: imy@imy.se.

Changes to this policy

We reserve the rights to make changes to this Policy. In the event that the change affects our obligations or your rights, we will inform you about the changes (if you have shared your contact information with us) in advance so that you are given the opportunity to take a position on the updated policy.

Contact

Please contact us if you have questions about your rights, data inquiries, or if you have any other questions about how we process your personal information: dataprivacy@ludoo.app

Appendix - Existing and approved processors

Ludo Technologies AB uses the following processors: