Ellions
HomeFeatures
Gym and PTMassage and spaClubs and associationsAquatic facilitiesCamping and accommodation
Calculate priceAbout us
Book a demo
HomeFeatures
Calculate priceAbout us
Book a demo

Data breach policy

1. Purpose

The purpose of this policy is to establish procedures and responsibilities in the event of a suspected or confirmed personal data incident (“data breach”) within the service provided by Ellions AB (the “Service”). The policy clarifies the allocation of responsibility between Ellions AB (processor) and the Customer (controller) in accordance with the General Data Protection Regulation (GDPR).

2. Roles and responsibilities

  • The Customer acts as controller and bears full responsibility for ensuring that personal data is processed in accordance with applicable law.
  • Ellions AB acts as processor and processes personal data solely according to the instructions given by the Customer and according to the data processing agreement (DPA).

The Customer is responsible for:

  • User management, permissions and internal security routines.
  • The security of all access to the Service, including handling of user accounts, passwords, API keys and other authentication.
  • Any incidents that arise through inadequate handling of login credentials or other improper use of the Service.

Ellions AB is responsible for:

  • Maintaining a secure and stable operating environment in accordance with agreed technical and organisational security measures.
  • Informing the Customer without undue delay in the event of suspicion or discovery of a personal data incident related to our infrastructure.

3. Definition of a personal data incident

A personal data incident is defined under GDPR as a security incident that leads to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

Examples:

  • Unauthorised access via a user account due to weak passwords or inadequate internal routines at the Customer.
  • Incorrect sharing of data through an API or manual exports.
  • Security weaknesses in the Customer’s own systems, networks or devices used to access the Service.

4. Procedures for a suspected or confirmed incident

4.1 Identification and notification

  • If Ellions AB discovers a potential incident linked to the Service, we will notify the Customer without undue delay, including available information about the nature, scope and potential impact of the incident.
  • The Customer shall immediately notify Ellions AB in the event of a suspected incident relating to the Service, especially if access credentials may have been compromised.

4.2 Initial assessment

  • Ellions AB carries out a technical analysis to determine whether the incident is related to our infrastructure or originates from the Customer’s own handling, for example through user behaviour or incorrect configurations.
  • In the majority of cases where incidents arise, they can be traced to the handling of authentication credentials or shortcomings in the Customer’s internal routines.

4.3 Actions

For an incident related to Ellions AB’s infrastructure:

  • Immediate action is taken to contain and remedy the incident.
  • A complete report is provided to the Customer.

For an incident caused by the Customer’s handling:

  • Ellions AB assists with technical information and logs to facilitate the Customer’s investigation.
  • It is the Customer’s responsibility to take necessary action, including notification to the supervisory authority and affected data subjects if required under GDPR.

5. Communication and reporting

  • Ellions AB provides an initial incident report within 48 hours of becoming aware of an incident.
  • A final report is delivered after the investigation is completed.
  • The Customer is responsible for all external communication, including contact with the Swedish Authority for Privacy Protection (IMY) and affected individuals.

6. Preventive security measures

To minimise the risk of personal data incidents, Ellions AB recommends that the Customer:

  • Implements strong password policies and two-factor authentication (2FA).
  • Regularly reviews user permissions.
  • Trains staff in data security and GDPR compliance.
  • Ensures that API keys and other integration points are handled securely.
  • Uses encryption when transferring and storing sensitive data outside the Service.

7. Limitation of liability

Ellions AB is not responsible for personal data incidents that arise as a result of:

  • Inadequate handling of access credentials by the Customer or its users.
  • Incorrect settings or use of the Service.
  • Security weaknesses in systems, networks or equipment controlled by the Customer.
  • Third-party integrations initiated and controlled by the Customer.

8. Contact

In the event of a suspected incident, contact immediately:

feedback@ellions.se

Ellions

The platform for gyms, clubs and aquatic facilities.

info@ellions.se010-444 14 80support@ellions.seekonomi@ellions.seHelp centre

Pages

FeaturesCalculate priceAbout usBRP alternativeBook a demoHelp centre

Stay up to date on the product and the industry.

© 2026 Ellions AB
  • Svenska
  • English
Terms and conditionsPrivacy policyData breach policy