Policy for the processing and protection of personal data

The data protection policy applies to Bonorum Partners M&A M&A A/S (the company).
The policy should help ensure and document that the company protects its personal data in accordance with the rules for the processing of personal data. The policy also contributes to the company providing information about the processing and use of the registered personal data.
The policy is reviewed every year.
List of personal data processing
The company processes personal data about:
- Employees
- Clients
- Suppliers
- Applicants
The company has prepared a list of the processing of personal data. The list provides an overview of the processing for which the company is responsible.
The personal data is a prerequisite for the Company to enter into employment, customer and supplier contracts.
Purpose and lawfulness of the processing
Personal data is processed and archived in connection with:
- Personnel administration, including recruitment, hiring, termination and payment of salaries
- Master data for customers as well as orders and sales
- Master data for suppliers as well as requisitions and purchases
- Contracts
The processing is legal pursuant to the authorization as stated in the attached list.
The company does not use personal data for purposes other than those listed. The company does not collect more personal data than is necessary to fulfill the purpose.
Storage and deletion
The company has implemented the following general guidelines for the storage and deletion of personal data:
- Personal data is stored in physical folders.
- Personal data is stored in IT systems and on server drives.
- Personal data is not stored longer than is necessary for the purpose of the processing.
- Personal data for employees is deleted five years after employment ends, and personal data about applicants is deleted after six months.
Data security
Based on the attached risk assessment, the company has implemented the following security measures to protect personal data:
- Only employees who have a work-related need to access the registered personal data have access to it either physically or through IT systems with rights management.
- All computers have passwords, and employees must not give their passwords to others.
- Computers must have a firewall and antivirus program installed that is regularly updated.
- Personal data is deleted in a responsible manner when phasing out and repairing IT equipment.
- USB keys, external hard drives, etc. with personal information must be stored in a locked drawer or cabinet.
- Physical folders are located in a locked office or in locked cabinets.
- Personal information in physical folders is deleted by shredding.
- All employees must receive instructions on what they are allowed to do with personal data and how personal data must be protected.
Disclosure
Personal information about employees may be disclosed to public authorities, such as SKAT and pension companies.
Data processors
The company only uses data processors if the data processors provide the necessary guarantees that they will implement the appropriate technical and organizational security measures to meet the requirements of personal data protection law. All data processors sign a data processing agreement before processing is initiated.
Rights
The company safeguards the rights of the data subject, including the right to access, withdrawal of consent, rectification and deletion, and informs the data subject about the company’s processing of personal data. Data subjects also have the right to complain to the Danish Data Protection Authority.
Personal data security breach
In the event of a breach of personal data security, the company shall report the breach to the Danish Data Protection Authority as soon as possible and within 72 hours. The director is responsible for ensuring that this occurs. The notification shall describe the breach, which groups of persons it concerns and what consequences the breach may have for these persons, as well as how the company has or will remedy the breach. In cases where the breach involves a high risk for the persons about whom the company processes personal data, the company will also notify them. The company documents all breaches of personal data security on an access-controlled drive.

Recent transactions
We are proud of the trust placed in us.
Here is a selection of our most recent transactions.
Selling or buying a company is not just another transaction that simply needs to be done. Partner with an experienced and professional business broker – and reach your goal safely and securely.














