Fast EU delivery
Invoice payment for businesses
26 years of expertise
Ex-VAT B2B pricing
Philips certified partner

Privacy policy

Effective date: 15 July 2026.

This privacy policy explains how SpeechCom Systemutveckling AB, trading as ProfessionalDictation, collects and uses personal data when you visit www.professionaldictation.com, contact us, or buy from us. It also explains your rights under the General Data Protection Regulation (EU) 2016/679 (GDPR) and how to exercise them.

1. Who we are

SpeechCom Systemutveckling AB, trading as ProfessionalDictation, is the controller of the personal data described in this policy. This means we decide why and how your personal data is processed.

  • SpeechCom Systemutveckling AB, trading as ProfessionalDictation
  • Company registration number: 556587-9581
  • VAT number: SE556587958101
  • Hemvägen 11, S-442 77 Romelanda, Sweden
  • Telephone: +46 303 24 41 42
  • Email: info@professionaldictation.com

As we are established in Sweden, our lead supervisory authority is the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY). See section 13 below.

2. Data protection officer

We have not appointed a data protection officer. We are not required to appoint one, because none of the criteria in Article 37(1) GDPR apply to us: we are not a public authority or body; our core activities do not consist of processing operations that require regular and systematic monitoring of data subjects on a large scale; and our core activities do not consist of processing special categories of data, or data relating to criminal convictions and offences, on a large scale. We are a reseller of dictation hardware and related products to business customers.

You can raise any question about data protection, or exercise any of the rights described in section 11, by contacting us at info@professionaldictation.com. That address reaches the people responsible for privacy matters at SpeechCom Systemutveckling AB.

3. Who this policy applies to

ProfessionalDictation sells to businesses only. Our customers are organisations with a valid EU VAT number, and we do not sell to consumers through this store. The personal data we process is therefore, in substance, business contact data: information about you in your professional capacity as an employee, representative or contact person of a customer organisation.

We do not collect national identity numbers. We do not ask for and do not process Swedish personnummer or equivalent national identity numbers from any other country. If you have read an older version of this policy that mentioned personal identity numbers, that statement no longer applies and was never applicable to this store.

4. What personal data we process

We process the following categories of personal data:

  • Identity and contact data: your name, your work email address and your work telephone number.
  • Employer and business data: the name of the organisation you represent, its VAT number, its company registration number, and its invoice and delivery addresses. Note that where a customer is a sole trader, business identifiers such as a VAT number may themselves be personal data.
  • Order and transaction data: the products and services ordered, order and invoice numbers, order value, delivery details, payment status and payment method, and your order history with us.
  • Correspondence: messages you send us and our replies, including customer service, support, warranty, repair and returns matters.
  • Account data: your login details and the settings held in your account. This store does not offer guest checkout, so you need to create an account in order to place an order, and we will always hold account data for you as a customer. Passwords are stored in hashed form and are not readable by us.
  • Technical and usage data: your IP address, information about your browser and device, and information about how you use our website, collected through cookies and similar technologies. See section 10.

We do not intentionally collect any special categories of personal data (Article 9 GDPR), such as health data, and we ask you not to send us such data.

5. Where your data comes from

  • Directly from you: when you create an account, place an order, subscribe to our newsletter, or contact us.
  • From the organisation you work for: for example when a colleague places an order and gives us your details as the delivery contact or the invoice contact.
  • Automatically from your device: when you use our website, through cookies and similar technologies.
  • From the European Commission VIES service: we validate the VAT number of your organisation against the EU VAT Information Exchange System (VIES), operated by the European Commission. We do this because a valid, verified VAT number is a condition of supplying goods to you at the zero rate applicable to intra-EU business-to-business supplies. The check returns whether the VAT number is valid and the registration details held for it. See section 6 for the legal basis.

6. Why we process your data, our legal basis, and how long we keep it

We may only process your personal data where we have a legal basis under Article 6 GDPR. The table below sets out each purpose, the legal basis we rely on, and how long we keep the data for that purpose.

PurposeLegal basisRetention
To accept, process, deliver and invoice your order, to provide support, warranty and returns handling, and otherwise to perform the purchase agreement.Performance of a contract - Article 6(1)(b) GDPR.For the duration of the customer relationship. Order documentation that forms part of our accounting records is then kept as described in the row below.
To create and maintain your customer account, which is required in order to place an order in this store.Performance of a contract - Article 6(1)(b) GDPR.For as long as you keep your account. You may ask us to close it at any time, subject to the accounting retention described in the row below.
To validate your organisation's VAT number against the European Commission VIES service, so that we can correctly apply the zero rate to intra-EU business-to-business supplies and account for VAT properly.Legal obligation - Article 6(1)(c) GDPR. Verifying the customer's VAT number is a condition of zero-rating an intra-EU supply, and we must be able to evidence that we did so.The result of the check is retained with the order documentation, and therefore for the accounting period described in the row below.
To fulfil our statutory obligation to keep accounting records, including invoices, order documentation and payment records.Legal obligation - Article 6(1)(c) GDPR. The obligation follows from the Swedish Bookkeeping Act (bokföringslagen (1999:1078)), which applies to us as a Swedish company.Seven years. The Bookkeeping Act requires accounting information to be retained until the end of the seventh year after the end of the calendar year in which the financial year ended. We cannot erase this data earlier, even if you ask us to, because we are required by law to keep it.
To assess whether we can offer payment against invoice, which we offer as a payment method in this store. We do not use any automated credit-checking system: no automated credit decision is made about you, and we do not obtain credit reports through an automated process. Any credit assessment is carried out manually by a member of our staff, and only where it is necessary in the individual case.Legitimate interests - Article 6(1)(f) GDPR. Our legitimate interest is to avoid credit losses and to offer suitable payment methods to business customers. You have the right to object to this processing under Article 21 GDPR.Until the assessment has been completed and any resulting claim has been settled. The outcome is retained with the order documentation where it forms part of our accounting records.
To send you our newsletter and other marketing where you have signed up for it, and you are not an existing customer.Consent - Article 6(1)(a) GDPR. You may withdraw your consent at any time under Article 7(3) GDPR, and withdrawal is as easy as giving consent.Until you withdraw your consent or unsubscribe.
To market our own similar products and services to you by email where you are already a customer, and to inform you about updates to products you have bought.Legitimate interests - Article 6(1)(f) GDPR. Our legitimate interest is to market our own similar products to existing business customers. This is not consent, so it is not something you withdraw: you have an unconditional right to object under Article 21(2) GDPR, and if you object we will stop immediately.Until you object or unsubscribe.
To measure and analyse how our website is used, so that we can improve it.Consent - Article 6(1)(a) GDPR is the basis on which analytics cookies may lawfully be used, together with the consent required for the storing of and access to information on your device. We do not currently operate a consent mechanism, and section 10 describes plainly what our website does today and how you can stop it.For the lifetime of the relevant cookies, as set out in our cookie policy, and thereafter in aggregated reports that do not identify you.
To keep our website, systems and customer data secure, to prevent, detect and investigate fraud and misuse, and to maintain logs and backups.Legitimate interests - Article 6(1)(f) GDPR. Our legitimate interest is to protect our business, our customers and our systems. You have the right to object under Article 21 GDPR.Server logs, security logs and backups are kept only for as long as they are needed for security, troubleshooting and continuity purposes, and are then overwritten or deleted in the ordinary course.

7. How long we keep your data

We keep your personal data only for as long as necessary for the purpose it was collected for, as set out in the table in section 6. In summary:

  • Order and accounting data: seven years, as required by the Swedish Bookkeeping Act. This is a statutory obligation and it takes precedence over a request for erasure.
  • Account data: for as long as you keep your account with us.
  • Marketing data: until you withdraw your consent, object, or unsubscribe.
  • Analytics data: for the cookie lifetimes stated in our cookie policy.

Where different retention periods apply to the same data, we keep the data for the longest applicable period, and then delete it or anonymise it.

8. Who we share your data with

We share personal data only where it is necessary for the purposes described above. Article 13(1)(e) GDPR allows us to describe the recipients by category, and we do so here. We share personal data with the following categories of recipient:

  • Our hosting and IT provider, which hosts this website and the e-commerce platform on which your account, your orders and your correspondence are held. Our hosting provider stores this data within the EU.
  • Payment providers, in order to take and reconcile payment for your order.
  • Shipping and logistics carriers, in order to deliver your order to the address you give us.
  • Google, as our web analytics provider, in connection with the measurement of website use. See sections 9 and 10.
  • The European Commission VIES service, when we validate your organisation's VAT number for tax compliance purposes. See sections 5 and 6.
  • Our accountants and auditors.
  • Public authorities, where we are required by law to disclose data, for example to the Swedish Tax Agency or the police.

Where a supplier processes personal data on our behalf, it acts only on our documented instructions and may not use your data for its own purposes.

If you would like to know which specific suppliers we use within any of the categories above, please ask us using the contact details in section 1 and we will tell you.

We do not sell your personal data.

9. Transfers outside the EU and EEA

We aim to keep personal data within the EU and EEA, and the data held in our shop is stored with our hosting provider within the EU. There is one transfer you should be aware of:

Google Analytics. Our website uses Google Analytics. Personal data collected through it, including your IP address and online identifiers, may be transferred to and processed by Google LLC in the United States. Google LLC has self-certified under the EU-US Data Privacy Framework, which is the subject of an adequacy decision by the European Commission, and this is the principal basis for the transfer. Google also offers the European Commission's standard contractual clauses as an alternative safeguard for transfers that are not covered by that framework.

You have the right to ask us for a copy of, or information about, the safeguards that apply to this transfer. Please use the contact details in section 1.

10. Cookies and analytics

Our website uses cookies and similar technologies. Strictly necessary cookies, which are needed to make the shop work, for example to remember the contents of your basket and to keep you signed in, are used without consent, as the law permits.

We want to be straightforward with you about analytics cookies. Our website currently sets Google Analytics cookies, and an associated Google advertising cookie, as soon as you visit a page. It does this without asking you first, because we do not yet operate a consent banner or any other consent mechanism. We are not going to tell you that we have your consent for this, because we have not asked for it.

We are implementing a consent mechanism so that these cookies are set only if you choose to allow them. Until that is in place, you can prevent these cookies yourself in either of the following ways:

  • Through your browser settings. All common browsers let you block or delete cookies, either for all sites or for individual sites. Blocking cookies for this site will stop the analytics cookies being stored, and may also affect parts of the shop that rely on strictly necessary cookies.
  • Through the Google Analytics opt-out browser add-on, which prevents your data being used by Google Analytics on any website: tools.google.com/dlpage/gaoptout

For details of the individual cookies we set, their purpose and their lifetime, please see our cookie policy.

Cookie policy

11. Your rights

You have the following rights in relation to your personal data. Some of them apply only where we rely on a particular legal basis, so we have said which is which.

  • Right of access (Article 15): you can ask whether we process personal data about you, and receive a copy of it together with information about how we use it. This right always applies.
  • Right to rectification (Article 16): you can ask us to correct inaccurate data about you, and to complete incomplete data. This right always applies.
  • Right to erasure (Article 17): you can ask us to delete your data, for example where it is no longer necessary for the purpose it was collected for, or where you withdraw your consent and there is no other basis. This right is not absolute: where we are required by law to keep the data, in particular accounting records under the Swedish Bookkeeping Act, we cannot delete it until that period has expired.
  • Right to restriction of processing (Article 18): you can ask us to limit our use of your data, for example while we check whether it is accurate, or while we consider an objection you have made.
  • Right to data portability (Article 20): you can ask to receive the data you have provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller. This right applies only to data you provided, and only where we process it by automated means on the basis of your consent or on the basis of a contract. It does not apply to data we process on the basis of a legal obligation or our legitimate interests.
  • Right to object (Article 21): you can object to processing that we carry out on the basis of our legitimate interests under Article 6(1)(f). We must then stop, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims. Where you object to direct marketing, the right is unconditional: we will stop, with no assessment and no exceptions.
  • Right to withdraw consent (Article 7(3)): where we process data on the basis of your consent under Article 6(1)(a), which is the case for our newsletter to non-customers, you can withdraw that consent at any time. Withdrawal is as easy as giving consent, and it does not affect the lawfulness of the processing carried out before you withdrew it. For analytics cookies, see section 10, which explains what our website does today and how you can stop it.

Please note the difference between withdrawing consent and objecting. Consent under Article 6(1)(a) is something you give, and you can withdraw it at any time. Legitimate interests under Article 6(1)(f) is not consent, and there is nothing to withdraw: instead you have the right to object under Article 21. An earlier version of this policy confused these two, by relying on legitimate interests and then saying that data was kept until consent was withdrawn. That was wrong, and this version corrects it.

12. How to exercise your rights

To exercise any of the rights above, contact us by email at info@professionaldictation.com, or by post at the address in section 1.

  • Exercising your rights is free of charge. We may charge a reasonable fee, or refuse to act, only where a request is manifestly unfounded or excessive, in particular because it is repetitive (Article 12(5) GDPR).
  • We will respond within one month of receiving your request. Where a request is complex, or where you have made a number of requests, we may extend that period by up to two further months, and we will tell you within one month if we do, and why (Article 12(3) GDPR).
  • We may ask you for further information in order to confirm your identity, so that we do not disclose your data to someone else.
  • To stop receiving our newsletter, the quickest route is the unsubscribe link at the foot of every newsletter. You do not need to give a reason.

13. Your right to lodge a complaint

If you are not happy with how we process your personal data, we would like you to tell us first, so that we can put it right. You always have the right, however, to lodge a complaint with a supervisory authority under Article 77 GDPR.

Our supervisory authority is the Swedish Authority for Privacy Protection:

  • Integritetsskyddsmyndigheten (IMY)
  • Box 8114, 104 20 Stockholm, Sweden
  • Email: imy@imy.se
  • Website: www.imy.se

You may also lodge a complaint with the supervisory authority in the EU member state where you live, where you work, or where the alleged infringement took place.

You also have the right to an effective judicial remedy against a supervisory authority or against us (Articles 78 and 79 GDPR).

14. Automated decision-making and profiling

We do not carry out automated decision-making, including profiling. No decision that produces legal effects concerning you, or that similarly significantly affects you, is taken about you by automated means within the meaning of Article 22 GDPR. In particular, we have no automated credit-checking system: where a credit assessment is made before we offer payment against invoice, it is made by a person, not by an algorithm. See section 6.

15. How we protect your data

We use technical and organisational measures to protect personal data against loss, unauthorised access, alteration and unauthorised disclosure. We describe here only the measures we can stand behind:

  • Encryption in transit. This website is served over HTTPS, so the data you send us through it, including your login details and your order, is encrypted in transit using TLS.
  • Restricted access. Access to personal data is limited to those members of staff who need it in order to do their work.
  • Storage within the EU. The personal data held in our shop is stored with our hosting provider within the EU.
  • Hashed passwords. Account passwords are stored in hashed form and are not readable by us.

No service can be guaranteed to be completely secure. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, we will inform you in accordance with Article 34 GDPR.

16. Changes to this policy

We may update this privacy policy, for example if we change how we process personal data or if the law changes. The current version is always published on this page, and the effective date at the top is updated whenever we change it. Where a change is significant, we will take reasonable steps to inform you.

If you have any question about this policy or about how we handle your personal data, please contact us at info@professionaldictation.com.