Skip links

Our commitments

& policies

Our commitments

& policies

We place high priority on responsible business practices and comply with international standards for human rights, labor rights, environmental protection, and anti-corruption. This also includes our internal policies regarding personnel, cookies, and privacy protection.

Purpose

Access Solutions ApS works dedicatedly to create and maintain a workplace where health and safety are always in focus. The purpose of this policy is to establish clear guidelines and procedures ensuring that all employees thrive in a safe and healthy working environment.

Principles

Prevention of accidents and injuries
We prioritize prevention by continuously identifying, evaluating, and managing potential risks in the working environment.

Compliance with legislation
Access Solutions ApS complies with all applicable laws and regulations regarding the working environment and safety.

Employee training
All employees receive relevant education and training in safety procedures, correct equipment usage, and risk prevention.

Reporting risks and incidents
We encourage all employees to actively report potential risks or incidents. Early reporting ensures swift action and prevents recurrences.

Procedures and Actions

Workplace inspections
Regular inspections are conducted to identify hazards and carry out necessary improvements.

Emergency procedures
Clear emergency procedures and evacuation plans are communicated to all employees. Drills are conducted regularly to ensure familiarity with the procedures.

Personal Protective Equipment (PPE)
Employees are provided with necessary PPE, and it is expected to be used correctly in accordance with job duties.

Communication and Follow-up

Open dialogue
We foster a culture of open communication where employees can comfortably share concerns or suggestions for improvement.

Follow-up and evaluation
The effectiveness of our safety procedures is continuously evaluated, and necessary adjustments are made based on experience and feedback.

Management Commitment

Active management support
Management at Access Solutions ApS supports all safety initiatives and actively participates in developing and maintaining a safe work environment.

Continuous improvement
We work systematically to improve working environment and safety practices through evaluation, learning, and adaptation.

By adhering to this policy, we create a work environment that supports both employee well-being and corporate responsibility. All employees are encouraged to actively contribute to the implementation and ongoing development of a safe and healthy working environment.

Cookie Policy

At Access Solutions ApS, we want to provide you with a good and personalized user experience when visiting our website. We use cookies to store relevant information about your behavior on the site so the experience can be continuously optimized upon your future visits.

Owner Information

The website is operated and owned by:
Access Solutions ApS
CVR No.: 27 57 00 97
Rødager Allé 127
2610 Rødovre
Phone: 20 40 08 54

 


 

Do you have questions?
When visiting the website, we process personal data. You can read more in our privacy policy.

If you have any questions regarding our use of cookies, feel free to contact us at:
info@access-solutions.dk

Data Breach Policy

When Access Solutions ApS (“we”, “our”, or “us”) works with personal data, there is a risk that a data breach may occur at some point. Data breaches can vary greatly in both scale and consequences, where even small data breaches can have extensive impacts, while large data breaches may have minimal impact. To handle a data breach effectively, we must first be able to recognize one and know how to respond. This is especially important because we have a series of obligations we must fulfill when a data breach occurs.

In this plan, you will find an overview of what a data breach is and what you should do if one occurs.

What is a data breach?

A data breach is a breach of our security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed.

Data breaches typically happen as a result of our own unintended handling of personal data. For example, accidentally sending an email or letter containing personal data to the wrong recipient, or accidentally altering or deleting personal data from our systems.

External factors can also lead to a data breach, such as our IT systems being hacked or a bag containing a USB drive with personal data being stolen from a bicycle.

Finally, external circumstances can cause a data breach—for instance, if fire or flooding prevents access to personal data for a period, or if the fire or flood ultimately destroys it.

When assessing whether an incident constitutes a data breach, we must evaluate the consequences of the event. If there is a risk that the event could cause harm to the individual whose personal data is affected—such as loss of control over personal data, limitation of rights, identity theft, or financial/social damage—it is considered a data breach.

Documentation

If a data breach occurs, we must always document as many details about it as possible, regardless of how large or small the breach is, or how significant its consequences may be.

When documenting a data breach, we must always investigate and record the following:

  • Date and time of the data breach
  • What happened when the breach occurred?
  • What was the cause of the breach?
  • What types of personal data are involved in the breach?
  • What are the consequences of the breach for the affected individuals?
  • What measures have we taken to mitigate the breach since discovering it?
  • Have we reported the breach to the Data Protection Agency?
  • Have we notified the affected individuals?

Contact us if you need access to the form we use to document data breaches.

Lars Valentin is responsible for completing the form and simultaneously evaluating whether the breach is of such a nature that we must report it to the Data Protection Agency and notify the affected individuals.

We are subject to strict time constraints regarding data breaches. You can read more about this under “Reporting to the Data Protection Agency”. To meet these requirements, Lars Valentin must complete the documentation form as quickly as possible, and no later than 24 hours after discovering the breach.

Once filled out, the form must be saved at [insert description and destination].

We must retain the form to demonstrate to the Data Protection Agency that we have handled the breach correctly and met our obligation of accountability.

Reporting to the Data Protection Agency

A data breach often poses a risk to the individuals affected by it. When a data breach involves a risk, it means the individuals whose personal data is affected may be exposed to discrimination, identity theft, fraud, damage to reputation, or other significant financial or social disadvantages.

We may have an obligation to report a data breach to the Data Protection Agency whenever it presents a risk to the rights of the affected individuals.

Which types of data breaches must be reported to the Data Protection Agency?

As a general rule, all data breaches must be reported to the Data Protection Agency. It is only in situations where it is unlikely that the data breach poses a risk to the affected individuals’ rights that we may refrain from reporting it. This could be the case if we act quickly to intervene, or if data was deleted by mistake but successfully restored from our backups.

Safety measures may also minimize or eliminate the risk. For example, if a colleague’s bag containing a USB drive with personnel data is stolen, but we ensured the USB drive was protected with strong encryption, it is not readily possible for others to decrypt it, making it unlikely that the thief gains access to the data. The theft—and thus the breach—would therefore have no impact on any individuals.

When evaluating the risk of a breach, we must use the information documented in the form (Annex 2). Additionally, we must always consider the following:

Type of security breach
Here we must consider whether there has been loss of data, a breach of confidentiality, or an integrity violation. This means investigating whether personal data was deleted or altered and thus no longer available, whether personal data was exposed publicly, or whether someone stole the data. The conclusion drawn from these considerations determines the type(s) of security breach.

Type of personal data and scope
The category of personal data involved in the breach is often decisive in risk assessment. The more sensitive the data, the greater the potential consequences for affected individuals. We must always consider the specific data within the specific context. For instance, publishing an employee’s address is ordinary personal data and typically does not carry severe consequences. However, if the individual has a protected address, the consequences could be severe.

Possibility of identifying affected individuals
The likelihood that affected individuals can be identified—either directly or by combining data with other information—also plays a role in the assessment. If a breach occurred because a USB drive with customer data was lost on a train, whether the drive is encrypted or otherwise secured to prevent unauthorized access and identification will impact the risk level.

Consequences of the data breach
If the breach impacts data belonging to particularly vulnerable individuals, the damage could be greater than usual. The same applies if we know the data ended up in the hands of bad actors with malicious intent, or if the breach is prolonged or permanent and cannot be halted by measures like blocking payment cards.

Particularly vulnerable individuals include children, persons with disabilities, or members of vulnerable demographics. The evaluation should also take into account whether public figures or persons under witness protection are affected, as a breach that would otherwise carry low risk could have severe consequences for them.

Number of affected individuals
The risk of a data breach generally increases with the number of individuals affected. However, we must remember that this is always a case-by-case assessment, and a large number of affected individuals does not automatically equal high risk.

Regardless of whether we determine the breach must be reported to the Data Protection Agency or not, the documentation form in Annex 2 must always be completed, and the risk assessment recorded within it.

When must a data breach be reported to the Data Protection Agency?

As soon as we establish that a data breach presents a risk to the rights of affected individuals, the breach must be reported to the Data Protection Agency. In all cases, the report must be submitted no later than 72 hours after we become aware of the breach. This means we must report the breach as soon as possible, even if that is well before the 72-hour deadline expires.

Specifically regarding emails sent to wrong recipients, it is currently unclear whether the 72-hour deadline runs from the time we receive an email alerting us to the breach, or from the time we discover and read the email. Based on a precautionary principle, it has been decided that data breaches are reported to the Data Protection Agency within 72 hours of receiving an email containing notification of a data breach.

If we fail to meet the deadline, submitting the report after 72 hours is only permitted as an absolute exception. In such cases, we must state the specific reasons that made it impossible to submit the report within the timeframe. However, it is important to remember that even a good justification may not exempt us from criticism or fines.

We have appointed Lars Valentin as responsible for handling data breaches.

When a breach is suspected or confirmed, Lars Valentin is responsible for completing the documentation form and reporting the breach to the Data Protection Agency.

What information must we provide to the Data Protection Agency?

When reporting a data breach to the Data Protection Agency, we must provide as much information as possible, including details on what occurred, what types of data were affected, and what the consequences are or are likely to be.

We must, at a minimum, provide the following information whenever possible:

Nature of the data breach, including

  • what happened and how it happened
  • the approximate number of individuals affected and their categories
  • whether affected individuals are located in other EU countries, and if so, where
  • what categories of personal data are involved
  • the approximate number of data records impacted by the breach

Name and contact details of the data breach manager

The likely consequences of the data breach

Measures we have already taken or propose to take to manage the data breach and mitigate potential damage

The most important requirement is complying with the 72-hour deadline. This means we must always report a breach before the deadline expires, even if we do not yet have all the details. In such cases, supplementary information should be submitted in phases as soon as it becomes available.

After filing the initial report, we must keep the Data Protection Agency updated as more details emerge regarding the breach and its consequences, enabling them to evaluate the breach and our response more easily and quickly.

How to submit a report

Data breaches are reported via the Danish Business Authority’s portal here:
https://indberet.virk.dk/myndigheder/stat/ERST/Indberetning_af_brud_paa_sikkerhed

When submitting a data breach report, digital signature login is required. Follow the on-screen instructions and fill out the form using the information available.

Once the form is completed and submitted, it is forwarded to the Danish Business Authority, which routes it to the Data Protection Agency. The Data Protection Agency will contact us directly if they deem it necessary.

It is crucial that we download a copy of all submitted forms. The Danish Business Authority deletes submitted forms from its systems after 30 days, making the downloaded copy our only proof of submission.

Notification to data subjects

If a data breach occurs that presents a high risk to the rights and freedoms of affected individuals, we must not only document the breach and report it to the Data Protection Agency, but also notify the affected individuals directly.

The purpose is to give affected individuals the opportunity to take necessary precautions to protect their data as effectively as possible.

High risk

We cannot predetermine what constitutes “high risk”. The more severe the potential consequences of a breach, the higher the risk. We must therefore evaluate both direct and indirect consequences.

Examples in this policy illustrate how both direct consequences (e.g., needing to change passwords) and indirect consequences (e.g., risk of compromising other accounts) must be factored into the assessment.

At the same time the documentation form is filled out and the decision on reporting to the Data Protection Agency is made, we also assess whether the breach presents a high risk to the affected individuals. If so, those individuals must be notified.

Situations where notification is not required

Even if we determine a breach poses a high risk, there are situations where we are not obligated to notify the affected individuals. For example, if:

we have implemented appropriate technical and organizational protection measures (e.g., strong encryption) rendering the data unintelligible to unauthorized parties

we have taken subsequent measures following the breach ensuring the high risk is no longer likely to materialize

notification would involve disproportionate effort, and we instead issue a public communication or similarly effective measure

police specifically instruct us to delay notification because it could jeopardize an ongoing investigation

If an exception is used, it must always be documented in the form, and we remain accountable to the Data Protection Agency, which may reach a different conclusion.

When must notification occur?

If we experience a data breach requiring notification and no exceptions apply, notification must occur as soon as possible. Notification is independent of the 72-hour deadline for the Data Protection Agency. In practice, it may be necessary to notify affected individuals very quickly (e.g., in the event of leaked passwords or protected addresses).

Who sends the notification?

Lars Valentin is the data breach manager and is responsible for ensuring affected individuals are notified of the breach.

What information must be communicated?

When notifying individuals of a data breach, we must at a minimum state:

name and contact details of our data breach manager

that a data breach occurred and what it entails

the likely direct and indirect consequences

the measures we have implemented or plan to implement to address the breach and limit harm

Where possible and relevant, we should also offer concrete advice to affected individuals, such as changing passwords.

The notification must be written in clear, plain language, taking into account the recipients’ background (e.g., language and age).

How we notify

In each case, we must evaluate the best method of notification. Notification should be direct—e.g., via email, letter, or SMS—and not embedded within a newsletter or other general communication.

The notification must always be sent as a separate message, and we should utilize channels that offer the highest probability of all affected individuals actually receiving the message, even if that means using multiple channels.

Submitting Invoices to Access Solutions ApS

When invoicing, please send the invoice in PDF format to: faktura@access-solutions.dk

It is important that the order number is clearly stated at the top of the invoice.
The order number will be provided by the responsible project manager.

We do not accept invoices via link or download—such links are automatically rejected, so the above procedure must always be followed.

All invoices, including progress invoices, must be submitted to the responsible project manager no later than the 25th of the month for approval.

Additional Works / Extra Work

All requests for additional financial compensation must be submitted in writing to Access Solutions ApS and approved in writing by a project manager.
Once the additional work is approved, you will receive a new case number.

This ensures a transparent process and smooth cooperation for all parties involved.

Contracted works and any additional works must be calculated and invoiced separately.

Payment Terms

Our payment terms are current month plus 30 days, unless otherwise agreed.

We look forward to a continued great collaboration and a professional business relationship.

Privacy Policy for Job Applicants

This privacy policy explains how Access Solutions ApS (“we” or “us”) processes your personal data when you apply for a position with us. The policy covers both unsolicited applications and applications received in response to a job posting.

You are encouraged to read this policy before submitting your application.

When applying for a job with us, please submit only the information necessary for us to evaluate your application.

Data Controller

The legal entity responsible for processing your personal data is:

Access Solutions ApS
CVR No.: 27 57 00 97
Rødager Allé 127
2610 Rødovre
Phone: 20 40 08 54

Purpose of Personal Data Processing

The purpose of processing your personal data is to review your job application and evaluate whether you are the right candidate for a position with us.

Scope of Processing

When you apply for a position with us, we process the information provided in your application and attached documents, such as your CV, diplomas, and references.

Your application is accessible only to trusted employees involved in the recruitment process, typically an HR manager and the hiring manager looking to fill the position.

Categories of Personal Data

We process the following categories of personal data during the recruitment process.

General personal data, such as

  • contact details, including name, address, phone number, and email
  • age
  • date and place of birth
  • educational background
  • photo, if attached by you
  • references
  • current or previous place of employment
  • other details provided in the application and CV

Sensitive personal data

  • none, unless you choose to provide such details yourself

Confidential information

  • personal identification numbers (CPR) for foreign employees where necessary

Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Your consent, pursuant to GDPR Art. 6(1)(a)
  • Our legitimate interest in selecting the right candidate for a position and evaluating unsolicited applications, pursuant to GDPR Art. 6(1)(f)
  • Compliance with employment law obligations, including collecting foreign job applicants’ personal identification numbers, pursuant to Section 7(2) of the Danish Data Protection Act

Sources

We primarily collect your personal data directly from you through the application process and during any job interviews.

Recipients

We share your personal data with our IT service providers to the extent necessary to operate our IT systems and recruitment process.

Transfers to Countries Outside the EU/EEA

Some of our IT service providers may be located outside the EU/EEA. In such cases, your personal data may be transferred to third countries.

Such transfers are based on the EU Commission’s Standard Contractual Clauses. You can obtain a copy of the relevant contractual clauses by contacting Lars Valentin via email: lvp@accesssolutions.dk
.

Storage and Deletion

As a rule, we retain your job application for up to six months after receipt, whether or not you are offered a position. This is done to document the recruitment process and potentially evaluate you for other relevant roles during this period.

If you have consented to us retaining your application longer for future roles, the retention period will be specified in that specific consent.

Your Rights

You have the following rights regarding our processing of your personal data:

You have the right to

  • access the personal data we process about you
  • have incorrect or incomplete data corrected
  • have your personal data erased in certain circumstances
  • restrict the processing of your personal data
  • object to our processing
  • receive the personal data you provided to us in a structured, commonly used, and machine-readable format (data portability) where applicable

You also have the right to withdraw consent. If you withdraw consent for processing your application, we will delete it, and you will generally no longer be considered in the recruitment process.

You can exercise your rights by contacting:

Lars Valentin
Email: lvp@access-solutions.dk

Please note that exceptions may apply to certain rights depending on the specific situation and our legal obligations.

Right to Complain

If you disagree with how we process your personal data, we encourage you to contact us first so we can try to find a solution.

You also have the right to lodge a complaint with the Data Protection Agency:

Danish Data Protection Agency (Datatilsynet)
Carl Jacobsens Vej 35
2500 Valby
Phone: +45 33 19 32 00
Email: dt@datatilsynet.dk

Privacy Policy

Here you can read how we handle your personal data at Access Solutions ApS. Any information that directly or indirectly can be attributed to you constitutes personal data.

The information we process may have been obtained:

  • directly from you
  • from third parties in connection with the execution of contracts and service tasks
  • when visiting our website
  • or because you have applied for a job with us

Data Controller

Access Solutions ApS is the data controller for the information collected about job applicants, customers, business partners, and visitors to our website. We ensure that the processing of personal data is carried out in accordance with applicable data protection legislation at all times.

Contact Details:

Access Solutions ApS
CVR No.: 27 57 00 97
Rødager Allé 127
2610 Rødovre
Phone: 20 40 08 54

Types of Data Processing

Execution of Contracts and Other Service Tasks

If you or your employer is a customer of ours, we will often process your personal data in order to fulfill a contract (contracting or other service agreement) or to deliver the requested services.

Typically, we process general personal data such as:

  • name
  • email
  • workplace
  • job title
  • phone number

We process personal data as part of fulfilling a contract, pursuant to GDPR Art. 6(1)(b).

Conduct of Legal Proceedings

If you are an opposing party or otherwise involved in a legal matter, we may process information about you, including:

  • name
  • contact details
  • other information appearing in pleadings and case materials

We process this information to establish, exercise, or defend a legal claim, pursuant to GDPR Art. 9(2)(f).

Jobs

If you apply for a job with us, we collect personal data:

  • directly from you via your application, CV, and any attachments
  • from third parties whom you have given consent for us to contact (e.g., references)

The purpose is to evaluate your application and your professional and personal competencies in relation to a specific or future position, pursuant to GDPR Art. 6(1)(f).

We retain job applications for up to six months to ensure we find the right candidate for the position and can document the recruitment process.

Website

When you visit our website www.accesssolutions.dk, we collect data about your use of the site to:

  • prepare statistics
  • optimize the website
  • use preference/remember functions
  • target marketing

Among other things, we may process the following information:</

General Personal Data Policy at Access Solutions ApS

At Access Solutions ApS (“we”, “us”, or “our”), we process information regarding both legal and natural persons as part of our daily work. When processing personal data, we must comply with a wide range of rules governing how data is handled and protected.

In this Personal Data Policy (“the Policy”), we describe how you as an employee must handle personal data, as well as the rules we have established for data processing in general.

Processing all personal data safely and securely is vital to us. Violations of data protection rules can carry severe financial and commercial consequences for us. Therefore, we ask that you read the Policy carefully and do your best to follow it daily. We also monitor compliance with the Policy.

Basic Rules of Thumb

As an employee, you must always:

  • shred paper copies containing personal data
  • consider whether it is necessary to print, save to USB drives, send, or share documents and emails containing personal data
  • promptly forward inquiries regarding access, erasure, or rectification to your contact person (see below)
  • follow the procedure in the data breach policy if you experience a data breach
  • refrain from saving documents containing personal data in Outlook, on your local drive, or other unauthorized locations—always follow your department’s storage guidelines

What is Personal Data?

Personal data is any information that can be used to identify a specific person, directly or indirectly.

There are three main categories of personal data:

General Personal Data
This includes all personal data not covered by the concept of sensitive personal data. Examples:

  • name, address, date of birth
  • job title, payroll number
  • photos
  • email address, IP address, phone number

Confidential Personal Data
Information of a personal nature that is not sensitive, but requires a special degree of protection. Examples include:

  • personal identification number (CPR)
  • criminal record details
  • negatively loaded educational details
  • salary, banking, and financial information
  • internal family circumstances, e.g., debt details or suicide attempts
  • Sensitive Personal Data

Sensitive personal data is explicitly listed in GDPR Art. 9. This includes:

  • racial or ethnic origin
  • political opinions
  • religious or philosophical beliefs
  • trade union membership
  • genetic and biometric data
  • health data
  • data concerning sex life or sexual orientation

This list is exhaustive. Confidential information does not automatically become sensitive information. For example, salary and bank details are confidential or general, not sensitive.

Sensitive personal data enjoys special protection. When handling sensitive data, you must be extra vigilant and strictly follow the Policy.

When Does the Policy Apply?

The Policy applies whenever you process personal data—whether general, confidential, or sensitive.

“Processing” means any operation performed on personal data, e.g.:

  • receipt and collection
  • registration and structuring
  • storage and updating
  • use and alignment/combining
  • disclosure and erasure

Processing can be physical (paper) or electronic. Data processing is only completed once personal data is fully anonymized or permanently erased—both physically and digitally.

Collection of Personal Data

As part of your daily work, you will process personal data when we have a lawful basis to do so. A legal basis may be, for example:

  • a legal obligation
  • performance of a contract or agreement with customers or employees
  • consent

If you are in doubt about whether the necessary legal basis exists, or if you wish to handle personal data in a new way, always contact the responsible manager in your department.

Storage and Use of Personal Data

To ensure compliance with data protection laws, you must familiarize yourself with and abide by our IT policy and IT security policy. You can find them here: [insert link].

Additionally, you must:

  • save all documents and emails containing personal data correctly in our IT systems
  • scan physical documents and store them electronically
  • shred physical documents once scanned and no longer needed
  • We recommend processing personal data electronically whenever possible.
  • If you nevertheless print documents containing personal data:
  • they must be stored securely
  • they must not be left freely accessible on desks or in common areas
  • they must be placed in a locked cabinet when leaving the office
  • they must be shredded when no longer needed

Tearing paper by hand is insufficient. Documents containing personal data must always be placed in a locked shredding bin.

You must never:

  • save personal data on your local drive or “Desktop”
  • maintain your own archive within your email inbox containing documents with personal data

Once documents and emails are transferred to the correct systems, they must be deleted from your inbox, sent items, and deleted items.

This rule applies only to documents containing personal data—not, for example, accounting records, general newsletters, general instructions, etc.

How Do I Protect Personal Data at Work?

You must protect personal data from unauthorized third parties as well as colleagues who do not work on the same tasks as you.

This means, among other things:

  • colleagues not involved must not be able to read your screen
  • you must lock your screen whenever leaving your workspace
  • when working from home, on trains, in cafes, or similar places, ensure unauthorized persons cannot view your screen
  • your family and friends must not be able to view your work on screen
  • printed documents must not be left visible at home—they must be brought back to the office and shredded when no longer needed

Use of Mobile Phones

You may use your private mobile phone for work at Access Solutions ApS when agreed upon and supported by an allowance. In this connection, pay special attention to:

  • only storing work-related data on the phone that is strictly necessary
  • deleting emails and documents from the phone once processed and storing them in our IT systems instead
  • protecting the phone with a passcode to prevent unauthorized access

You must not send work-related text messages (SMS) containing sensitive or confidential personal data, such as CPR numbers or health data, as SMS is not sufficiently secure.

Registration of Illness

If you need to report sick, you must do so in Mobilplan.

In the comments field, state only that you are sick—do not detail the nature of the illness.
The fact that you are sick is general personal data. Diagnostic or health details are sensitive personal data, processing of which we seek to minimize as much as possible.

Special Rules for HR Personnel

If you work in HR, special requirements apply:

When receiving a job application via email or SMS, review it, log relevant details in our IT system, and then delete the email or SMS.

Information regarding unhired job applicants must be erased no later than six months after rejection is issued.

Data regarding former employees in Mobilplan must be erased after five years at the latest (unless other legislation mandates longer retention).

Inquiries from Data Subjects

When we process personal data, data subjects hold several rights. They may, among other things:

  • request access to the data we hold about them
  • request rectification (correction)
  • request erasure
  • request restriction of processing
  • object to processing
  • request data portability (obtaining their own data in a machine-readable format)

Access

An access request may arrive via email, phone, or orally.

If you receive an access request, always contact:

Lars Valentin, who is responsible for handling data access requests.
He will answer the inquiry directly or assist you in doing so. Do not answer access requests independently, as strict formal requirements apply.

Rectification (Correction)

If an individual requests correction of their information, the following applies:

  • we must correct inaccurate information
  • we do not alter subjective evaluations or objectively correct details
  • the individual may instead be permitted to add supplementary statements

Erasure

As a rule, we must erase personal data if requested by the data subject.

However, we must not erase data we are legally obligated to retain, e.g., under book-keeping legislation.

If in doubt, contact Lars Valentin.

Restriction

In certain situations, processing must be restricted, e.g.:

  • if an individual disputes the accuracy of data, until we can verify it

Restriction means the data may only be stored, not otherwise processed during that period.

Data Portability

Data portability means that:

  • the individual can receive their personal data in a structured, commonly used, and machine-readable format
  • the individual can transmit that data to another data controller where technically feasible

Objection

A data subject may object to otherwise lawful processing if specific reasons relate to their particular situation.

We must then reassess whether processing remains necessary or terminate it.

Data Breaches and Leaks

In the event of a data breach, we may be obligated to notify both the Data Protection Agency and affected individuals. We rely on your assistance to identify and report potential data breaches quickly.

A data breach includes, for example:

  • accidental alteration or loss of personal data
  • unauthorized disclosure of personal data to an incorrect recipient
  • theft of a computer, USB drive, or physical file containing personal data
  • unauthorized access to data via malware or hacking

If a breach occurs, contact immediately:

Lars Valentin, who evaluates whether the breach is severe enough to require notification to affected individuals and the Data Protection Agency.

You can read more in our data contingency plan found here: [insert link].

Questions

If you have questions regarding this policy, feel free to contact:

Lars Valentin
Email: lvp@accesssolutions.dk

IT Security Policy at Access Solutions ApS

Purpose

The purpose of this IT Security Policy is to describe the level of IT security at Access Solutions ApS (“we” or “us”), as well as the safety rules and requirements that you as an employee must adhere to at all times when using IT assets.

Maintenance

This IT Security Policy is updated continuously and reviewed at least once a year.
All employees must regularly familiarize themselves with the IT Security Policy and are obligated to comply with the rules outlined herein.

Organization and Responsibility

Management holds overall responsibility for establishing and maintaining the IT Security Policy, ensuring it fits our operational needs and complies with statutory requirements.
Management must ensure that the IT Security Policy is implemented effectively, that the security level reflects policy standards, that ongoing controls are maintained, that technical and administrative controls are in place, that employees understand IT system operations and comply with policy, and that access rights are managed correctly.

Employees and IT Security

Prior to Employment

Employees and system users are set up on our IT resources prior to start date. We apply Microsoft Best Practices for access control. Management determines the precise privileges assigned to each user.

During Employment

Violations of IT security rules can cause instability, anomalies, and errors in IT systems. Violations are addressed by immediate management, and serious or repeated infractions may involve executive leadership. Violations can carry employment consequences.
As an employee, you must keep passcodes confidential, lock your computer when unattended, ensure no unauthorized parties view personal data on your screen, avoid leaving printouts visible, shut down your computer at the end of the workday, and react proactively to potential IT security concerns.

Termination

Upon departure, immediate management must notify executive leadership so all IT access can be revoked and all company IT equipment returned.

Asset Management

General

Management maintains control of all IT assets from acquisition to disposal, managing maintenance and replacements. Equipment purchased without management authorization must not be connected to our network and will not receive IT support.

Classification of IT Assets

Classification determines requirements for data handling. New systems and hardware are evaluated based on the risk level of the data processed.
Security requirements include authorization and annual access reviews, access controls via user ID and password, encryption when transmitting confidential or sensitive data, login attempt logging, logging of personal data processing for up to six months (up to five years for specialized needs), secure physical storage, backup routines, and shredding of physical documentation.

Violations

This IT Security Policy forms an integral part of employment terms. Violations may result in formal warnings, reprimands, termination, or summary dismissal.

Questions

Questions regarding the IT Security Policy should be directed to Lars Valentin via email: lvp@accesssolutions.dk

Annex 1: Description of Our IT Security Level

We have incorporated appropriate technical and organizational measures to protect data against accidental loss, unlawful processing, and unauthorized access. This description is updated continuously.

Identification and Assessment of Risks

We process and store data on our own servers and utilize platforms including Mobilplan, OneDrive, our financial system, and Bluegarden.
We use Microsoft 365 for emails, which may involve transferring personal data to third countries. This takes place on the basis of the European Commission’s Standard Contractual Clauses.

Risks include accidental loss, unlawful processing, unauthorized access, and misuse of personal data.

Measures

To mitigate these risks, we ensure:

  • that only authorized personnel have access to data
  • that all IT usage occurs via traceable accounts
  • that personal data is secured with firewalls and updated antivirus software
  • continuous patching of servers and systems
  • regular backups and testing of backups
  • network segmentation
  • logging of login attempts and usage
  • two-factor authentication where possible
  • monitoring of behavioral patterns to detect abnormal activity
  • ongoing training of employees in proper IT handling

To protect personal data during email transmission, we ensure:

  • anonymization or pseudonymization where possible
  • encryption of data containing confidential and sensitive information
  • that data processors encrypt all transmission at the transport layer and evaluate the need for additional end-to-end encryption

IT Security Policy at Access Solutions ApS

Purpose

The purpose of this IT Security Policy is to describe the level of IT security at Access Solutions ApS (“we” or “us”), as well as the safety rules and requirements that you as an employee must adhere to at all times when using IT assets.

Maintenance

This IT Security Policy is updated continuously and reviewed at least once a year.
All employees must regularly familiarize themselves with the IT Security Policy and are obligated to comply with the rules outlined herein.

Organization and Responsibility

Management holds overall responsibility for establishing and maintaining the IT Security Policy, ensuring it fits our operational needs and complies with statutory requirements.
Management must ensure that the IT Security Policy is implemented effectively, that the security level reflects policy standards, that ongoing controls are maintained, that technical and administrative controls are in place, that employees understand IT system operations and comply with policy, and that access rights are managed correctly.

Employees and IT Security

Prior to Employment

Employees and system users are set up on our IT resources prior to start date. We apply Microsoft Best Practices for access control. Management determines the precise privileges assigned to each user.

During Employment

Violations of IT security rules can cause instability, anomalies, and errors in IT systems. Violations are addressed by immediate management, and serious or repeated infractions may involve executive leadership. Violations can carry employment consequences.
As an employee, you must keep passcodes confidential, lock your computer when unattended, ensure no unauthorized parties view personal data on your screen, avoid leaving printouts visible, shut down your computer at the end of the workday, and react proactively to potential IT security concerns.

Termination

Upon departure, immediate management must notify executive leadership so all IT access can be revoked and all company IT equipment returned.

Asset Management

General

Management maintains control of all IT assets from acquisition to disposal, managing maintenance and replacements. Equipment purchased without management authorization must not be connected to our network and will not receive IT support.

Classification of IT Assets

Classification determines requirements for data handling. New systems and hardware are evaluated based on the risk level of the data processed.
Security requirements include authorization and annual access reviews, access controls via user ID and password, encryption when transmitting confidential or sensitive data, login attempt logging, logging of personal data processing for up to six months (up to five years for specialized needs), secure physical storage, backup routines, and shredding of physical documentation.

Violations

This IT Security Policy forms an integral part of employment terms. Violations may result in formal warnings, reprimands, termination, or summary dismissal.

Questions

Questions regarding the IT Security Policy should be directed to Lars Valentin via email: lvp@accesssolutions.dk

Annex 1: Description of Our IT Security Level

We have incorporated appropriate technical and organizational measures to protect data against accidental loss, unlawful processing, and unauthorized access. This description is updated continuously.

Identification and Assessment of Risks

We process and store data on our own servers and utilize platforms including Mobilplan, OneDrive, our financial system, and Bluegarden.
We use Microsoft 365 for emails, which may involve transferring personal data to third countries. This takes place on the basis of the European Commission’s Standard Contractual Clauses.

Risks include accidental loss, unlawful processing, unauthorized access, and misuse of personal data.

Measures

To mitigate these risks, we ensure:

  • that only authorized personnel have access to data
  • that all IT usage occurs via traceable accounts
  • that personal data is secured with firewalls and updated antivirus software
  • continuous patching of servers and systems
  • regular backups and testing of backups
  • network segmentation
  • logging of login attempts and usage
  • two-factor authentication where possible
  • monitoring of behavioral patterns to detect abnormal activity
  • ongoing training of employees in proper IT handling

To protect personal data during email transmission, we ensure:

  • anonymization or pseudonymization where possible
  • encryption of data containing confidential and sensitive information
  • that data processors encrypt all transmission at the transport layer and evaluate the need for additional end-to-end encryption

Sustainable Supplier Policy – Access Solutions ApS

Purpose

At Access Solutions ApS, we believe that sustainability is key to a responsible and future-proof supply chain. This Sustainable Supplier Policy establishes a framework where our suppliers actively contribute to our ambition of offering sustainable solutions as a top priority, while maintaining the highest standards of environmental, social, and economic responsibility.

Core Principles

Sustainability as First Priority

We commit to always prioritizing and offering sustainable solutions across our entire supply chain and business practices.

Environmental Responsibility

Suppliers are encouraged to employ eco-friendly methods and technologies that minimize overall environmental impact.

Social Rights and Labor Conditions

Suppliers must promote proper working conditions, respect human rights, and contribute to social initiatives.

Supplier Selection and Evaluation

Sustainability Criteria

We select suppliers based on their ability and commitment to deliver sustainable products and services.

Supplier Dialogue and Collaboration

We prioritize continuous, open dialogue with suppliers and seek collaboration on developing and implementing new, sustainable solutions.

Specific Sustainability Measures

Climate and Environmental Initiatives

Suppliers must actively participate in initiatives that reduce climate impact and contribute to sustainable production methods.

Social Responsibility

Suppliers are expected to support local communities, avoid discrimination, and actively work toward diversity.

Ethical Business Behavior

Suppliers must adhere to ethical guidelines and combat corruption, bribery, and unfair business practices.

Reporting and Transparency

Sustainability Reporting

Suppliers are encouraged to regularly document and share their sustainability progress to enhance transparency and accountability throughout the value chain.

Auditing and Monitoring

We regularly monitor and evaluate supplier sustainability efforts and actively collaborate on driving improvements.

Incentives and Recognition

Incentives for Sustainability

We recognize and reward suppliers who demonstrate exceptional efforts and verifiable results in sustainability.

Continuous Improvement

We encourage all suppliers to work purposefully toward ongoing improvement of their sustainability performance to contribute to a more responsible and future-proof value chain.