Privacy Policy
1. Introduction
Privacy and data protection laws protect the integrity and confidentiality of a person’s private information. Momgstad Refinery is committed to protecting the privacy rights of our employees and everyone with whom we do business or cooperate with. We will only use personal data for appropriate purposes, and personal data will be processed in accordance with applicable data protection regulation and Mongstad’s Binding Corporate Rules.
2. Mongstad Refinery’s processing of personal data
2.1. General
Mongstad Refinery’s processes personal data about employees and external consultants working from Mongstad premises or in Mongstad systems. Mongstad also processes personal data about data subjects who are not employed or engaged by Mongstad, to whom this privacy policy is primarily aimed. The main categories of personal data processed is described in section 3 below.
Mongstad Refinery will always process personal data fairly and lawfully, and only for a specified, explicit and legitimate purpose or as required by law. Mongstad Refinery will therefore only process personal data when such processing is necessary for us to manage our operations, provide services or other legitimate business interests, comply with legal or contractual obligations or after receiving consent (the latter which can be withdrawn at any time). Withdrawing consent will not affect the lawfulness of the processing based on the consent prior to withdrawing it. Further information on specific legal basis is provided below.
Mongstad Refinery will ensure appropriate information security related to confidentiality, integrity and availability. Personal data will be retained only for the period that is required to serve the legitimate purpose or as required by law. If you want more detailed information on specific retention time, please contact Mongstad Refinery.
Third party service providers may process personal data on behalf of Mongstad Refinery within various areas. Mongstad Refinery has implemented adequate safeguards in accordance with applicable law to protect your personal data processed by third party service providers.
Mongstad Refinery processes personal data about data subjects that are not employed or engaged by Mongstad Refinery for these various purposes:
2.2 Procurement and other business relation purposes
Mongstad Refinery processes personal data necessary to procure goods and services from suppliers and contractors, including purchase and sale of products, for contract management and for human rights verifications. The data processed for such purposes include contact information and human resources information. The legal basis is based on the execution of the agreement with such third -parties and Mongstad Refinery’s legitimate interest in ensuring good management of and support of our suppliers, partners and customers.
Mongstad Refinery may also disclose personal data to a third party for a specific business purpose. In such situations, Mongstad Refinery will in general sign a contract describing the purpose and requiring the recipient to both keep the personal data confidential and not use it for any other purpose. Mongstad Refinery may share personal data with the third parties such as service providers, public authorities and partners.
As an example, Mongstad Refinery may share personal data in connection with a possible operations of corporate reorganization, mergers, acquisitions, incorporations, and similar corporate transactions, as well as to comply with any court order and/or legal obligations to which Mongstad Refinery is subject.
2.3. Integrity Due Diligence
Mongstad Refinery has established an extensive Integrity Due Diligence (IDD) process. The IDD process includes collecting information to help us understand who our counterparties are, their values and how their business is conducted. In some instances, the IDD may also include the processing of personal data. The personal data processed for this purpose may include contact information and IDD specific necessary information, such as position, possible political position and roles, possible sanction listings, personal relations, contracts, relevant memberships, references, legal claims and reputational issues. The legal basis is to comply with legal obligations, pursue our legitimate interests and to establish, exercise or defend legal claims.
2.4. Ethics Helpline
Mongstad Refinery has set up an Ethics Helpline where employees and external third parties interacting with us can raise concerns or report any suspected or potential breaches of law or the Mongstad Refinery Code of Conduct. Due to the nature of the Ethics Helpline, the processing may include all categories of personal data, also special categories. The legal basis is legitimate interest or processing necessary for the purposes of performing the obligations and exercising the rights of Mongstad Refinery in the field of employment, social security and social protection law, or for the establishment, exercise or defense of legal claims.
2.5. Local grievance mechanisms
In some countries, Mongstad Refinery has established local grievance mechanisms in order to receive, investigate and respond to grievances from individuals, communities, or their representatives about Mongstad Refinery or its contractors’ activities adverse impact on communities or individuals. The personal data processed includes contact information and other data necessary for performing the grievance-processes. The legal basis is performance of a task carried out in the public interest, legitimate interest, or our obligations under the Norwegian Transparency Act.
2.6. The Norwegian Transparency Act
To ensure compliance with Mongstad Refinery’s duty of disclosure pursuant to the Transparency Act, Mongstad Refinery will process personal data relating to those requesting information. The personal data processed will primarily be contact information, as well as other information necessary to carry out Mongstad Refinery’s processing of the information disclosure. The legal basis is our obligation under the Transparency Act, as well as to safeguard our legitimate interests and establish, enforce or defend legal claims.
2.7. Screening
To ensure regulatory compliance with Norwegian and international regulations on sanctions, as well as ensuring compliance with anti-money-laundering regulation, Mongstad Refinery may perform a screening of external third parties with whom Mongstad Refinery has or will establish relations. The personal data processed is contact information, position and results from the screening activity. The legal basis is legitimate interest, legal obligation or performing the obligations and exercising the rights of Mongstad Refinery in the field of employment, social security and social protection law.
2.8. Communication
Mongstad Refinery communicates externally and internally with the general public, specific target groups and individual persons. Examples of communication activities performed by Mongstad Refinery or third parties are distribution of newsletters, press releases, company reports, optimising websites, organising events, handling user-initiated dialogue, providing information to public authorities, conducting surveys, and communicating in social media networks. The personal data processed includes contact information and communication-related information. The legal basis is legitimate interest in providing information and ensuring good management of and support for our customers, suppliers and partners, or your consent.
2.9. Recruitment and onboarding
Mongstad Refinery processes personal data for recruitment purposes to ensure that Mongstad Refinery recruits qualified candidates. The personal data processed include contact information, recruitment and human resources information. The legal basis Mongstad Refinery rely on for processing your personal data relates to processing necessary to perform a contract or to take steps at your request, before entering a contract, or your consent to being included in the CV-database.
Mongstad Refinery also processes personal data to cater for onboarding of external personnel into the Mongstad Refinery organization based on mergers and/or acquisitions and/or transfer of an undertaking. The personal data processed include contact information, recruitment and human resources information. The legal basis Mongstad Refinery relies on in these circumstances is legal obligation or legitimate interest.
You will receive more detailed information about the two types of processing and the legal basis when entering the recruitment process or you are being part of the onboarding process.
2.10 Security and emergency response
Mongstad Refinery has implemented various security measures that requires processing of personal data. This is to safeguard against illegal or unauthorized access to areas, buildings, rooms, systems, processes or equipment. For example, Mongstad Refinery premises can have activity logs, camera surveillance (CCTV), controls of delivery vehicles, the drivers, visitor and employee access control. The categories of personal data we collect and use, depend on the security measures in question. It includes a variety of images and videos, contact information and place of employment, date and time of access to premises and information about vehicles.
Mongstad Refinery’s operations entail a certain level of risk, both for Norwegian and international operations. The purpose of the processing is to secure personnel support during an emergency response situation (ensure personnel emergency preparedness). The personal data processed may include all relevant data about the personnel in an emergency incident; contact information, date of birth, next-of-kin, contact person for employer and contractor. The purpose is to comply with legal obligations within different jurisdictions concerning emergency preparedness. The legal basis for such processing of personal data is our legitimate interests in safeguarding of our business and any applicable legal requirements relating to this.
2.11 Recordings of certain trading activities
For certain trading activities, Mongstad Refinery processes contact information and the full content of commercial conversations on telephone and IM to document negotiations, trading and agreements as well as to ensure compliance to regulatory requirements for documentation. The legal basis is to comply with legal obligations and our legitimate interest.
2.12 Mongstad Refinery Pension
Mongstad Refinery processes personal data for handling pension. For further information related to your Mongstad-pension rights, contact pension@mongstadrefinery.com for former Mongstad Refinery employees. For former employees in subsidiaries, contact your local pension scheme provider or your local PO for more information.
2.13 Asset Management in Mongstad Refinery
Mongstad Refinery Asset Management processes personal data related to the company’s management of securities such as contact information, national identity, and social security number etc to ensure compliance with applicable rules regarding asset management, market securities funds and fulfil disclosure obligations.
3. Categories and collection of personal data
For easier understanding of this privacy policy we have set up the following categories. This does not mean or entail that the processing will always entail all the examples of personal information included in the categories.
The categories of personal data Mongstad Refinery may collect and hold about data subjects include:
- Contact information, such as names and addresses, telephone numbers and email addresses, titles etc.
- Recruitment information, such as application, CV, references, background checks, interviews and assessments, immigration and relocation information, exit surveys
- Human resources information such as details about an individual’s work experience and qualifications, date of birth, identification documentation, driver’s license details; national identity, social security number, employee number, position, organization, bank account, next of kin, union membership, location, salary and leader
- Communication-related information, such as public political relations, positions, preferences related to marketing and events (including allergies/diets restrictions when provided by participants), and information related to user behavior in own communication-channels (including IP-addresses).
Personal data may be collected in several ways, including:
- directly by Mongstad Refinery staff when establishing a business relationship or through operational dealings;
- from a third-party service provider or agent, from a source of publicly available information (e.g. websites) or from an employer (e.g. where a supplier or contractor provides personal data about their employees);
- through use of Mongstad Refinery’s website; or
- data provided directly by you.
4. Transfer of personal data
Mongstad Refinery has established Binding Corporate rules (BCR) to provide Mongstad Refinery with a legal basis for transfer of personal data within the Mongstad Refinery to Equinor headquaters which is the sole owner of Mongstad Refinery and Equinor’s companies outside of EU/EEA. The BCRs will apply to all personal data, within the Equinor group, which are protected by applicable EU data protection law.
Mongstad Refinery uses best efforts to ensure that the European rules on trans-border data flows are complied with when personal data are transferred to external processors (outside of the Equinor group) located outside of EU/EEA or located in a country that is not recognised by the EU Commission as ensuring an adequate level of protection. Examples of such safeguards are Binding Corporate Rules, EU Standard Contractual Clauses or other applicable legal mechanisms.
5. Changes to this privacy policy
We may update this privacy policy from time to time. If such updates are not material, we may make such alterations without posting a specific notice on our website. If the changes are material and affects your rights or the way we process personal data, we will provide a specific notice on our website. Please review this privacy policy from time to time.