- AirPlus Eesti
- About AirPlus
- Legal and security
- Privacy policy
SEB Kort Bank AB
Privacy Notice for Corporate Products
Last updated 3rd of August 2026
This Privacy Notice explains how personal data is collected, used, shared, and otherwise processed by the data controller SEB Kort Bank AB and its branches (together referred to as “SEB Kort”, “we”, “us”, or “our”) in connection with our corporate products. Corporate products include products such as cards, portal, online accounts, travel and expense management and related financial services. A data controller is the entity responsible of determining purposes and means of the processing of personal data.
For corporate products where your employer has entered into an agreement with us, the employer is the contractual partner. The contractual partner is often called product subscriber or corporate customer.
The contract, to which the corporate product is connected, can be either with a legal entity or a private individual. This information can be found in the product agreement or card user agreement.
This privacy notice applies to individuals whose personal data we process when providing our corporate products, for example;
- Cardholders (card user or product subscriber/corporate customer)
- Portal users (portal administrator, invited manager or cardholder)
- Account users (users of online accounts and product accounts such as administrators and cardholders)
- Authorised signatories
- Beneficial owners
- Company representatives (Individuals acting as company representatives on behalf of or connected to a corporate customer)
You can download a printable version of our privacy notice here
1. Your Rights in accordance with the GDPR
You have certain rights related to the information that we hold about you. These rights and how to use them are explained below. When you exercise your rights, we may need to ask for additional information to confirm your identity. We do this to protect the information and ensure that no unauthorised person can access or change data that is not theirs.
1.1 Right to access personal data (access request)
You can request access to the information we hold about you, with some limited exceptions for example confidential information or trade secrets, internal drafts and memos. We will also inform you about:
- why we are processing the information.
- who we are sharing the information with and if any information is transferred to a country not deemed to have adequate safeguards in place to protect personal data.
- how long we will be keeping the information.
- the source of the information, if it was not collected directly from you; and
- if we are using the data for automated decision making or profiling.
If you make a request for a copy of the personal information that we are processing, please be as specific as possible as this will help us to identify the information more quickly.
1.2 Right to have personal data rectified
If you feel that the information we hold about you is inaccurate, you can ask us to correct and update it. If we have shared the personal data with a third party, we will inform such third parties about the corrections.
1.3 Right to have personal data erased (right to erasure)
You can also request that we erase information. Erasing might not always be possible. If doing so means we cannot perform our contract with the corporate customer, or we have a legal obligation or legitimate interest to keep the information. We will explain the consequences of erasing your information.
1.4 The right to request restriction of processing
If you feel that we are processing the information unlawfully or with inaccurate information, you can request us to restrict the processing. Where personal data is subjected to restriction in this way, we will only process it with your consent or for the establishment, exercise or defence of legal claims unless we have your consent. If the processing is restricted, we will continue to store the information.
1.5 Right to object to processing
If you disagree with any legitimate interest, we have relied upon to process the information, you can object to the processing. We will then stop processing the information unless we can demonstrate a compelling legitimate basis that overrides your rights, or the processing is required to establish, exercise or defend a legal claim.
You have a right to object to direct marketing.
1.6 Right to withdraw consent
If we process your personal data based on your consent, you may withdraw your consent using the same channels as were used when consent was given.
1.7 Right to access and move personal data to another recipient (data portability)
You have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format and to transmit that data to another controller where technically feasible. The right to data portability does not apply if the information:
- is only available in paper form or as a scanned document in SEB Kort's electronic archive
- would infringe the rights of someone else
- does not come directly from individual; or
- is created for internal use through analysis or evaluation.
1.8 Right to complain
You have the right to complain to us as data controller regarding the processing of your personal information. Please reach out to us via the provided contact details in the last section of this notice.
You can always reach out to your local data protection authority. To find contact information please visit edpb.europa.eu.
2. Why we process your personal data
We may process your personal data for any of the following purposes, depending on the role you have in the company and what service we provide for you and/or your company.
2.1 Administration of customer profiles and contracts
Reasons for processing your personal data
To identify you; register and update customer profiles with your personal details and contact information; manage contracts.
Legal basis
The processing is based on our legitimate interest to ensure the proper fulfilment of our contractual obligations with the corporate customer.
Categories of personal data collected from you
Identification data, contact details, name, national ID/passport, employee number (where applicable), relationship to corporate customer/product subscriber.
Categories of personal data collected from other sources
We regularly update information about name & address via population registers.
Applicable to (categories of data subjects)
Cardholders, Portal users, Account users, authorised signatories, Beneficial Owners, Company representatives
2.2 Providing our services
Reasons for processing your personal data
To process payments; set up and manage accounts; set up and manage portals; issue cards; handle travel bookings; generate reports; facilitate expense management; authorise payment transactions; provide accounting and invoicing information.
To provide push notifications within our mobile applications, we process identifiers that enable messages to be delivered to the correct device. Specifically, the App Installation ID and the Push Token generated by the device. You always have the option to disable app notifications.
Legal basis
The processing is based on our legitimate interest to ensure the proper fulfilment of our contractual obligations with the corporate customer, to deliver safe product functionality and expedite and facilitate travel expense management/procurement.
Categories of personal data collected from you
Transaction data; account data; billing data; travel information, contact information, log in data, identification of authorised signatories; card information.
Transaction data include payment method/network, Date & time of payment, Merchant & Location, Purchased Amount, Descriptive Billing, Card Details: card number, name, expiry date, CVC, means of identification and your credit limit to verify transactions.
Travel information may include Descriptive Billing Information, Ticket Numbers, Destinations, Traveler Data, Time & Date of Travel, Expenses related to Travel
Applicable to (categories of data subjects)
Cardholders, Portal users, Account users, Authorised signatories.
2.3 Credit assessment
Reasons for processing your personal data
To assess credit worthiness; make credit checks; conduct risk analysis including business partner due diligence; monitor credit risk behaviour to prevent credit losses; assess credits applications.
Legal basis
The processing is based on our legitimate interest to assess credit risks, assess if you're likely to meet your payment obligations (Credit Worthiness Check) and prevent credit losses and to ensure the proper fulfilment of our contractual obligations with the corporate customer.
Categories of personal data collected from you
Financial information, user and product information, identification data, relationship to corporate customer.
Categories of personal data collected from other sources
We regularly update information about name & address via population registers. We request information from credit bureaus Tax Registers as well as company registers.
Applicable to (categories of data subjects)
Authorised Signatories, Company representatives, Cardholder if private liability.
2.4 Perform know your customer evaluation
Reasons for processing your personal data
To conduct risk analysis including “know your customer” evaluation and business partner due diligence required to comply with financial crime prevention regulation; identify beneficial owners; comply with sanction lists
We perform know your customer (“KYC”), by obtaining information required to comply with to detection and prevention of money laundering and terrorist financing under the AML Act.
Legal basis
The processing is based on the legal obligation to comply with anti-money-laundering and terror prevention regulation and payment industry guidelines and laws.
Categories of personal data collected from you
Financial information, identification data, relationship to corporate customer, Information regarding affiliations, status as a Politically Exposed Person and close family members.
Categories of personal data collected from other sources
We regularly update information about name & address via population registers. Information from Press, Tax Registers as well as company registers, EU & UN sanctions list, Criminal Offense Data to conduct KYC checks.
Applicable to (categories of data subjects)
Authorised signatories, Beneficial Owners.
2.5 Crime prevention and investigation
Reasons for processing your personal data
Transaction monitoring; fraud detection; investigations; to detect potential suspicious transactions according to Anti Money Laundering and Anti-Terrorist Financing Laws & Regulations (TF).
Our experts who are supported by a software, use previous experience regarding fraudulent transactions as well as an analysis of your previous behaviour. SEB Kort Fraud Prevention uses a proven mathematical statistical model to check for fraudulent transactions.
We may also use automated systems to identify and assess risk levels related to fraud, money laundering and other financial crime. This includes continuous monitoring of transactions that may result in a payment being stopped or blocked where it is likely to be fraudulent or otherwise unlawful.
Legal basis
The processing is based on our legitimate interest to ensure the proper fulfilment of our contractual obligations with the corporate customer, to deliver safe product functionality and to prevent money laundering and terrorist financing.
The processing is based on the legal obligation to comply with anti-money-laundering and terror prevention regulation and payment industry guidelines and laws.
Categories of personal data collected from you
Transaction data; behavioural data; logs; Information on credit card usage expectation, Employer, example includes e.g. Average Amount used, Mathematical Input for Card Security Systems.
Applicable to (categories of data subjects)
Cardholders, Portal users, Account users, Authorised signatories, Beneficial owners.
2.6 Compliance with legal obligations
Reasons for processing your personal data
To transfer data to public authorities to comply with legal obligations. Regulatory reporting; sanctions screening; business partner due diligence.
Legal basis
The processing is based on our legal obligation to carry out pre-contractual measures as well as to transfer personal data to public authorities, such as financial regulators, police, prosecutors, courts when required to do so by law.
Categories of personal data collected from you
Identity data; Politically exposed person (PEP) data; data from sanction list; financial data.
Categories of personal data collected from other sources
Information from Press, Tax Registers as well as company registers, EU & UN sanctions list, Criminal Offense Data.
Applicable to (categories of data subjects)
Beneficial Owners, Cardholders, Portal users & Account users.
2.7 Customer service & support
Reasons for processing your personal data
To manage all customer support matters and manage customer complaints online, in our mobile applications or by phone, to support and correct reported errors, handle customer inquiries & communications; provide customer support; to record customer support phone calls for service improvements, quality and monitoring purposes.
We may, in some cases, ask you to consent to call recordings for service improvements and service agent training purposes. We may also ask for your consent to send notifications in our app.
Legal basis
The processing regarding call recordings is based on consent or legitimate interest depending on country.
The processing of providing general customer support is based on our legitimate interest to provide support to our customers.
Categories of personal data collected from you
Communications; case history; Identification data, contact details, relationship to corporate customer/product subscriber.
Audio & Information you share with us over the phone support.
Applicable to (categories of data subjects)
Cardholders, Portal users, Account users, Authorised signatories, Beneficial Owners, Company representatives.
2.8 Marketing and customer relationship management (CRM)
Reasons for processing your personal data
To market products and services to corporate customers and prospects. Send marketing communications and information; segment audiences; manage events; preference handling.
Legal basis
The processing is based on our legitimate interest to manage marketing and customer relationship, to send ads, promotions and offers about products and services that are relevant to our customers.
You always have the right to decline to direct marketing.
Depending on market, we base our processing of your personal data to advertise by e-mail or text message (SMS) on consent.
Categories of personal data collected from you
Contact details; marketing data; preferences.
Categories of personal data collected from other sources
The corporate product you use. Website Usage Behaviour via Web Analytics or Cookie Consent.
Applicable to (categories of data subjects)
Prospects; card holders, account users; event participants, newsletter subscribers.
2.9 Analytics, business & product development
Reasons for processing your personal data
Analyse usage of our services and products; compile statistics; data analysis for service and product improvement; testing and development of products and services; perform satisfaction and market surveys.
We do not use this data to draw conclusions about you as a person.
Legal basis
The processing is based on our legitimate interest to develop competitive products and services.
Categories of personal data collected from you
Information on the use of mobile app and other online services. E.g. IP Address, MAC ID, geographical location, internet provider, transactions, product usage, contact details.
Categories of personal data collected from other sources
Aggregated usage data and technical data collected from us and our vendors.
Applicable to (categories of data subjects)
Cardholders, Account users.
2.10 Operation & security of IT systems, digital channels & premises
Reasons for processing your personal data
To provide secure access to online account management & digital services; authentication; access and authorization management; logging; system operation; maintenance; troubleshooting.
To conduct CCTV surveillance on SEB Kort premises to keep our visitors and employees safe.
Legal basis
The processing is based on our legitimate interest to ensure the proper fulfilment of our contractual obligations with the corporate customer by keeping systems and services safe and updated and deliver safe product functionality and protect our customers from misuse.
The processing is based on our legitimate interest to keep our premises and employees safe.
Categories of personal data collected from you
Identification data, relationship to corporate customer/product subscriber, log in information, authentication data; role and access data, IP addresses; device data; logs.
CCTV recordings (for more information, see specific policy for each location).
Applicable to (categories of data subjects)
Cardholders, Portal users, Account users, authorised signatories, Beneficial Owners, Company representatives.
Visitors of Premises.
2.11 Handle legal claims
Reasons for processing your personal data
To handle legal claims; dispute management; evidence collection; legal case handling.
Legal basis
Legitimate interest to establish, exercise or defend legal claims.
Categories of personal data collected from you
Contract data; communications; evidentiary material.
Applicable to (categories of data subjects)
Cardholders, Portal users, Account users, Authorised signatories, Beneficial owners.
3. Profiling and Automated Decision-Making
SEB Kort does not use automated decision making concerning individual card users for our corporate products.
4. Data Sharing and Transfers
SEB Kort will share your data with others only if we have a legal basis for doing so, for example if required to fulfil the respective business purposes, if mandated by law, or to service providers which have been contracted by SEB Kort and are obligated to comply with applicable data protection regulations.
4.1 Service Providers
SEB Kort provides access to or shares your personal data with carefully selected service providers. These service providers only handle your product data on behalf of SEB Kort as so-called data processors, acting only on instructions given by SEB Kort. Our service providers are contractually obligated to follow those instructions. SEB Kort shares your personal data under strict confidentiality obligations with the following categories of service providers:
- IT service provider (hosting and infrastructure services),
- Transaction-related service providers (receipt processing services), located in Europe
- Customer relationship service providers (call centre services), located in Europe
4.2 Sharing with other parties
To facilitate payments, transaction data is exchanged among various parties involved: the merchant, the merchant's acquirer (often a bank), credit card networks (like VISA, UATP or Mastercard), and the card issuer (like SEB Kort).
We may share your data to facilitate Corporate Discount Agreements with brokers between travel traders and airlines. We may transmit account data to the contracting partners on request of the Corporate Customer/Product Subscriber (central settlement accounts only).
We may share your data with auditors, insurance companies, lawyers, and public authorities as required by law, such as audits, insurance claims, legal proceedings or regulatory compliance.
4.3 Sharing within SEB Group
We will share personal data about you with other legal entities and affiliates within the SEB Group in order to meet our legal and regulatory obligations such as:
- For internal approval processes
- For risk measurement, control, and reporting
- For regulatory and financial transaction reporting
- Financial crime and external fraud prevention, for instance to be able to comply with our obligations pursuant to AML/TF regulation
- To be able to provide as good service to you as possible and act as one bank
4.4 Third Country Data Transfers
Personal Data will be transferred to countries outside of the European Union or the European Economic Area (“third countries”) only to the extent required for the respective purpose (e.g. enabling transactions or reports to corporate customer/subscribers) or mandated by law (e.g. reporting duties stipulated by tax laws). Prior to any transfer of personal data to processors or third parties in third countries, SEB Kort ensures that a transfer mechanism is in place (e.g. the Standard Contractual Clauses provided by the European Commission).
5. Data Retention
SEB Kort processes and saves personal data only to the extent required to fulfil the purpose for which it was collected. Exceptions apply if SEB Kort has a legal obligation to retain that data (e.g. for trade or tax law requirements).
SEB Kort will erase your personal data as soon as it is no longer needed for the purposes mentioned above. Personal data may also be saved for the period of time in which claims can be asserted against us.
For example, data processed for anti-money laundering (AML) purposes is typically retained for 5 years after the end of the customer relationship, while data required for bookkeeping, tax compliance, and to meet statutory limitation periods may be retained for up to 10 years. Call recordings and similar communication data are retained for shorter periods in accordance with applicable regulations and internal policies. Following account closure, relevant data is retained in line with these obligations, and access within our CRM systems (customer relationship management) is restricted during the retention period. Once the applicable retention period expires, the data is securely and automatically deleted.
6. Contact us
The Data Controller is
SEB Kort Bank AB
Stjärntorget 4
106 40 Stockholm
SEB Kort is committed to safeguarding your information and upholding your rights as a data subject. If you feel we have not done that or if you wish to exercise your rights, please contact our customer service. Depending on your location and corporate association you may have a contact with a branch or subsidiary of SEB Kort Bank AB. You can find all contact information on any of our websites.
To contact our Data Protection Officer (DPO) please use dataskyddsombud@seb.se.