Ascente Law
This policy applies as of 2 October 2026.
Last updated on 2 October 2026.
Ascente Law AB, company registration no. 556624-3787, (”Ascente”) processes personal data in the course of its daily operations. Ascente is the data controller for the processing of personal data described in this policy.
Personal data means information that can be directly or indirectly attributed to a living natural person, such as a name, telephone number or email address.
You are not required to provide us with personal data (except where required by law, for example pursuant to a disclosure order). However, if you choose not to do so, this may mean that we cannot accept engagements for you, process your job application, send you newsletters or seminar invitations, etc.
We value the protection of your personal data and are committed to ensuring that our processing is correct and carried out in accordance with the law. This policy describes which categories of personal data we process, for what purposes and on what legal basis, how the data is collected, with whom it may be shared and how long it is retained. It also contains information about your rights and how to contact us with questions about this policy or our processing of personal data.
The information is structured as follows:
Personal data relating to engagements (section 1)
Personal data of contact persons at clients, suppliers or business partners (section 2)
Personal data relating to seminars, events, newsletters or other mailings (section 3)
Personal data about website visitors (section 4)
Personal data about job applicants (section 5)
Personal data about other individuals (section 6)
Please note that the processing of personal data relating to our employees is not covered by this policy.
1. Personal data relating to engagements
When you or someone else appoints Ascente for an engagement, we will collect, store and otherwise process personal data about you in accordance with this section 1.
What personal data is processed?
a. Natural person as client: Name, personal identification number (or other identification details), contact information (address, email and telephone), a copy of a passport or other identity document, a description of the engagement, information about the purpose and substance of the engagement, information about the origin of the assets used in the engagement, information as to whether the client or a relative or known employee of the client is a politically exposed person, and the name and position of such person, as well as billing information, payment history and any payment reminders.
b. Legal entity as client: Name, personal identification number (or other identification details), title, employer, contact information (address, email and telephone), and a copy of a passport or other identity document for the client’s contact person and beneficial owner, information from a registration certificate or equivalent, and information as to whether such beneficial owner, or a relative or known employee of that person, is a politically exposed person, and the name and position of such person.
c. Natural person as counterparty: Name, personal identification number (or other identification details), contact information (address, email and telephone), and a description of the engagement.
d. Legal entity as counterparty: Name, title, employer and contact information (address, email and telephone) for the counterparty’s contact person.
e. Other individuals involved in the engagement (e.g. counsel for a counterparty, arbitrators, external consultants and witnesses): Name, title, employer and contact information (address, email and telephone).
f. Isolated information that a client, contact person or beneficial owner of the client – or a person represented by any of them in the engagement – has been convicted of an offence, been subject to a prohibition on carrying on business, gone through several bankruptcies, received negative publicity concerning business dealings or may otherwise be assumed to be unreliable, or isolated information that the engagement constitutes or is suspected of constituting part of money laundering or other criminal activity.
g. Isolated information about criminal offences or special categories of personal data (i.e. data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or concerning health or sex life) where the nature of the engagement means that such data is required (e.g. in engagements relating to dismissal or termination for personal reasons or alleged discrimination).
h. Other personal data beyond (a)–(g) above that is relevant in view of the nature of the engagement.
In addition to the above, we do not process any special categories of personal data.
How is the data collected?
The data is provided to us by, or on behalf of, you, the client, the counterparty, the counterparty’s counsel or another person involved in the engagement, or is obtained by us from such persons or from private and public registers and sources. We do not actively collect the data referred to in (f) above, and we collect data under (f) and (g) only to the limited extent required for the purpose.
For what purposes and on what legal bases is the data processed?
The data is processed to enable and carry out conflict of interest checks, assess and decide whether we can accept an engagement or need to withdraw from an engagement, and to fulfil our other legal, regulatory and risk management obligations. The processing is based on our legitimate interest in effective and accurate checks and assessment and is necessary to fulfil our obligations under the Act on Measures against Money Laundering and Terrorist Financing, the EU Market Abuse Regulation, other applicable legislation and AGRD Partners’ Code of Professional Conduct (”The Code”, available at AGRD Partners’ website).
The data is also processed for invoicing, accounting for engagements and fees, collection of client receivables and otherwise safeguarding our rights relating to the engagement. The processing is based on our (and the client’s) legitimate interest in efficient and accurate invoicing, accounting for engagements and fees and collection of client receivables, and is necessary to establish, exercise or defend our legal claims.
The data is processed to perform the engagement and act as legal counsel for the client. The processing is based on our and the client’s legitimate interest in efficient and accurate communication and contact with persons involved in the engagement, effective documentation, administration, handling and evaluation of the engagement, and is necessary to establish, exercise or defend the client’s legal claims.
The data is also processed for internal statistics and analysis and to develop our business. The processing is based on our legitimate interest in monitoring and further developing our business.
Data under (f) above is processed only to assess and decide whether we can accept or need to withdraw from an engagement and to fulfil our legal obligations. The processing is carried out to the limited extent necessary under the Act on Measures against Money Laundering and Terrorist Financing.
Data under (g) above is processed only to perform the engagement and act as legal counsel for the client. The processing is carried out to the limited extent necessary to establish, exercise or defend the client’s legal claims.
With whom may the data be shared?
The data is subject to a duty of confidentiality in accordance with The Code and is not disclosed to third parties except in the following cases:
Data may be disclosed to the client’s insurer (legal expenses insurance), the counterparty, the counterparty’s counsel, an arbitral tribunal, a court, a public authority, a bank, other consultants connected with the engagement or similar recipients to the extent required to safeguard the client’s interests and not contrary to the client’s instructions.
Data may be disclosed to the client’s auditor or another party in accordance with the client’s instructions.
Data is disclosed to the Financial Police when and to the extent we are required to do so under the Act on Measures against Money Laundering and Terrorist Financing.
Data may be disclosed to our bank when we hold client funds and the bank requests information about the client and the beneficial owner, as well as our documentation under the Money Laundering Act, provided that the client has consented to this as a condition for using our client funds account.
Data is disclosed to a public authority or another party when and to the extent we are required to do so by law.
Data may be disclosed to our professional indemnity insurer, auditor, insurance broker, counsel engaged by us or our insurer, the Swedish Enforcement Authority, a debt collection agency, a court, an arbitral tribunal, or our counterparty and its counsel to the extent required to safeguard our legal interests.
Data may in exceptional cases be disclosed to AGRD Partners’ General Counsel or other person responsible for compliance matters in accordance with The Code.
As a general rule, no personal data is transferred outside the EU/EEA. If such a transfer is nevertheless required in an individual case (e.g. to instruct counsel in the United States or another third country), we ensure that appropriate safeguards are implemented in accordance with the EU General Data Protection Regulation. Such safeguards may consist of the recipient country having an adequate level of protection or EU-approved standard contractual clauses being used. If you would like more information about such transfers, please send us a written request using the contact details in section 10.
How long is the data retained?
The data is retained for as long as we are required to retain the file for the engagement, usually ten years after the engagement has ended (or longer if required by the nature of the engagement), after which it is deleted. In addition, we retain the name, personal identification number (or equivalent) and description of the engagement of a natural person who is a client or counterparty to enable necessary conflict of interest checks in accordance with The Code. See also sections 2 and 6 concerning certain data relating to contact persons and others.
2. Personal data of contact persons at clients, suppliers or business partners
If you are, or are a contact person for, a client, supplier or business partner – or a prospective client, supplier or business partner – we will collect, store and otherwise process personal data about you in accordance with this section 2.
What personal data is processed?
Name, title, employer, contact information (address, country, email and telephone), information about your contacts at our firm, stated areas of interest for newsletters and mailings, information about participation in our seminars and events, and notes and summaries from meetings we have had with you (outside an engagement). We do not process any special categories of personal data (i.e. data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or concerning health or sex life). In the context of an engagement, additional data may be processed in accordance with section 1.
How is the data collected?
The data is provided to us or collected by us in the context of an engagement in accordance with section 1, or is otherwise provided by you, the client, the supplier, the business partner, a person who facilitates the contact between us, or collected from private and public registers and other sources.
For what purposes and on what legal bases is the data processed?
The data is processed to administer the relationship with the client, supplier or business partner. The processing is based on our legitimate interest in managing our relationships with clients, suppliers and business partners.
The data is processed, through you as a contact person, to maintain and develop the relationship with the client, supplier or business partner and, unless you have objected, to market our services (e.g. through invitations to seminars and events and newsletters). The processing is based on our legitimate interest in maintaining and further developing our relationships and in marketing our services.
Unless you have objected, your personal data may also be processed by an engaged service provider to conduct industry or market surveys (e.g. Chambers and Partners and Legal 500) as a basis for competitor analysis and analysis and development of our business. The processing is based on our legitimate interest in comparing ourselves with competitors and developing our business.
If you have given your consent, your data may be processed so that we may use you as a reference for another client, supplier or business partner (e.g. in a public procurement procedure). The processing is based on that consent.
With whom may the data be shared?
The data is subject to a duty of confidentiality under The Code and is not disclosed to third parties except in the following cases:
Data may be disclosed as set out in section 1.
Data may be disclosed to a (potential) client, supplier or business partner requesting a reference about us.
Data may be disclosed to an engaged service provider for industry or market surveys.
Data may in exceptional cases be disclosed to AGRD Partners’ General Counsel or other person responsible for compliance matters in accordance with The Code.
As a general rule, no personal data is transferred outside the EU/EEA. If such a transfer is nevertheless required in an individual case, we ensure that appropriate safeguards are implemented in accordance with the EU General Data Protection Regulation. Such safeguards may consist of the recipient country having an adequate level of protection or EU-approved standard contractual clauses being used. If you would like more information about such transfers, please send us a written request using the contact details in section 10.
How long is the data retained?
To the extent the data forms part of an engagement, it is retained in accordance with section 1. In addition, the data is retained for as long as the relationship with the client, supplier or business partner continues and is deleted within three months after the relationship ends or after we have been informed that your role as a contact person has ended. However, name, title, employer, contact information and stated areas of interest for newsletters are retained thereafter for marketing purposes until you object, at which point they are deleted. Your data is nevertheless always retained to the extent and for the period required by law, e.g. the Swedish Bookkeeping Act.
3. Personal data relating to seminars, events, newsletters or other mailings
When you express an interest in our seminars, events, newsletters or other mailings through our website, social media, digital mailing system or otherwise, or register for one of our events, we will collect, store and otherwise process personal data about you in accordance with this section 3.
What personal data is processed?
The data we process includes name, title, employer, contact information (address, country, telephone and email), information about stated areas of interest for newsletters and mailings, requested participation in a seminar or event and, if the event includes food, any dietary preferences.
How is the data collected?
You provide the data to us through our website, social media, digital mailing system or otherwise.
For what purposes and on what legal bases is the data processed?
The data is processed to administer the sending of invitations to seminars and events, as well as newsletters and other information, to you. The processing is based on our legitimate interest in administering mailings in accordance with your stated preferences. If you actively consent to receive the information described in this section, your data is processed on the basis of your consent.
The data is also processed to administer seminars or events in which you participate, including arranging suitable food. The processing is based on our legitimate interest in administering the event in accordance with your stated preferences.
With whom may the data be shared?
As a general rule, the data is not shared with third parties, except through a name badge that you may be offered to wear during the seminar or event, with event partners, or through a list of participants distributed to other participants. Our suppliers of communications systems may also have access to your data, for instance in connection with support or storage of the data. The data may also be shared with our auditor during an internal audit. No personal data is transferred outside the EU/EEA.
How long is the data retained?
The data is retained until you unsubscribe from our seminars, events, newsletters and mailings, at which point it is deleted.
4. Personal data about website visitors
When you use our website, we will (in addition to the data you provide through our digital recruitment tool, see section 5, or by expressing interest in seminars, events, newsletters or mailings, see section 3) collect, store and otherwise process personal data about you in accordance with this section 4.
What personal data is processed?
The data we process includes the website you visited us from, the parts of our site you visit, the date and duration of your visit, your IP address which we anonymise on receipt for use in website analytics, information from the device (device type, operating system, screen resolution, language, nearest city and country you are located in, and web browser type) you used during your visit.
How is the data collected?
The data is collected through cookies when you use our website. More information about which cookies are used and what data is collected can be found in our cookie tool and in our cookie policy. You may access the cookie tool via the icon displayed in the corner of our website. When you visit our website, a pop-up window (the cookie tool) will give you the opportunity to accept or reject certain types of cookies; if you accept cookies at that time, you consent to our use of cookies in accordance with the cookie policy and the information provided in the tool.
For what purposes and on what legal bases is the data processed?
The data is processed to analyse the use of our website and to further develop it, as well as to manage and document user consents for cookies and tracking scripts. The processing is based on your consent and our legitimate interest in analysing and developing the website.
With whom may the data be shared?
The data is not shared with third parties unless provided for in our cookie policy/cookie tool. We use suppliers that help us analyse the data collected via our cookies. These suppliers work mainly with anonymised data.
How long is the data retained?
The retention period depends on which cookie collected the data, ranging from retention only for the duration of the visit (a so-called session cookie) to a maximum of 24 months, as stated for each cookie in our cookie tool.
5. Personal data about job applicants
When you apply for a job or otherwise express an interest in employment with us, we will collect, store and otherwise process personal data about you in accordance with this section 5.
What personal data is processed?
The data we process includes name and contact information (address, telephone and email), personal identification number (or other identification details), gender, the position applied for and positions of interest, information in a cover letter, CV and other documents, information provided by referees, any test results from the recruitment process, notes and summaries from interviews and conversations, and compilations and analyses from a recruitment consultant or other service provider. We do not process any special categories of personal data (i.e. data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or concerning health or sex life).
How is the data collected?
You provide the data to us through our digital recruitment tool or otherwise; it may also be provided by a recruitment consultant or other service provider, or collected from the referees you have identified, through tests conducted during the recruitment process, and from private and public registers and sources.
For what purposes and on what legal bases is the data processed?
The data is processed to carry out the recruitment process. The processing is based on our legitimate interest in effective and accurate recruitment. If you have consented to us processing the data for future recruitment, it is processed for that purpose on the basis of that consent.
With whom may the data be shared?
The data may be disclosed to any recruitment consultant or other service provider engaged in connection with the recruitment. No personal data is transferred outside the EU/EEA.
How long is the data retained?
The data is retained during the recruitment process and deleted in accordance with applicable law. If you have consented to us processing the data for future recruitment, it may instead be retained for two years after the consent is given (or until the consent is withdrawn), after which it is deleted. However, we retain the data for as long as an unsuccessful applicant may take legal action in connection with the recruitment process.
6. Personal data about other individuals
If you are, or are a contact person for, a prospective client, supplier or business partner, we will collect, store and otherwise process personal data about you in accordance with this section 6.
What personal data is processed?
Name, title, employer, contact information (address, email and telephone), information about your contacts at our firm, stated areas of interest for newsletters and mailings, information about participation in our seminars and events, and notes and summaries from meetings we have had with you (outside an engagement). We do not process any special categories of personal data (i.e. data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or concerning health or sex life). In the context of an engagement, additional data may be processed in accordance with section 1.
How is the data collected?
The data is provided to us or collected by us in the context of an engagement in accordance with section 1, or is otherwise provided by you, a client, supplier, business partner, prospective client, prospective supplier or prospective business partner, or by a person who facilitates the contact between us, or collected from private and public registers and other sources.
For what purposes and on what legal bases is the data processed?
The data is processed to establish, maintain and develop the relationship with you as a prospective client, supplier or business partner or with the party for which you are a contact person, and, unless you have objected, to market our services (e.g. through invitations to seminars and events and newsletters and other mailings). The processing is based on our legitimate interest in establishing, maintaining and developing relationships with prospective clients, suppliers and business partners and in marketing our services.
With whom may the data be shared?
The data is not shared outside the EU/EEA. It may be shared with our auditor during an internal audit.
How long is the data retained?
To the extent the data forms part of an engagement, it is retained in accordance with section 1. In addition, the data is retained until you object, at which point it is deleted.
7. What are your rights?
You have rights in relation to us and our processing of your personal data. These rights and how to exercise them are described below.
Please note that your rights apply to the extent provided by applicable data protection legislation and that exceptions may apply. We may need additional information from you, including to confirm your identity, before handling your request.
To exercise your rights or request further information, please contact us by email at: info@ascente.com.
Right of access. You have the right to obtain confirmation as to whether we process personal data about you. If so, you also have the right to access such data by means of a so-called register extract (subject access request), as well as additional information about the processing, such as the purposes, categories of personal data and recipients to whom the data has been disclosed.
Right to rectification. You have the right to have inaccurate data about you rectified without undue delay. You may also have the right to have incomplete data completed.
Right to erasure. You may request that we erase your personal data without undue delay if:
the data is no longer necessary for the purposes for which it was collected or otherwise processed,
the processing is based on your consent and you withdraw that consent,
you object to processing based on a balancing of interests and your objection outweighs our or another party’s legitimate interest,
the data has been processed in breach of the law, or
the data must be erased to comply with a legal obligation.
Right to restriction of processing. You have the right to request that we restrict the processing of your personal data if:
you contest the accuracy of the data, for a period enabling us to verify whether it is accurate,
the processing is unlawful and you oppose erasure and instead request restricted use,
we no longer need the data for the original purposes, but you need it to establish, exercise or defend legal claims, or
you have objected to processing based on a balancing of interests and await verification of whether your objection outweighs our or another party’s legitimate interest.
Right to object. You have the right to object to the processing of your personal data that is based on our or another party’s legitimate interest. If you object, we must, in order to continue the processing, be able to demonstrate compelling legitimate grounds that override your interests, rights and freedoms.
Right to data portability. If we process your personal data on the basis of a contract or consent, you have the right to receive the personal data that you have provided to us in an electronic format. You also have the right to have the data transmitted directly to another data controller, where technically feasible. Please note that this right does not cover data processed manually.
Right to withdraw consent. If our processing is based on your consent, you always have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
8. Complaints to the Supervisory Authority
In Sweden, the Swedish Authority for Privacy Protection (IMY) is the authority responsible for supervising the application of data protection legislation. If you believe that we process your personal data incorrectly, we encourage you to contact us first so that we can consider your comments. You may, however, always lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
9. Language versions
This policy is available in both Swedish and English. For data subjects domiciled in Sweden, the Swedish version applies. For other data subjects, the English version applies.
10. Additions and amendments
We may update this policy from time to time. If we do so, we will publish the updated version on our website and refer to it in our emails and digital mailings. We encourage you to read the updated policy carefully.
11. How can you contact us?
Contact us at info@ascente.com or in writing at Ascente Law AB, PO Box 4501, SE-203 20 Malmö, if you have questions about this policy, our processing of personal data or wish to exercise your rights.