NIMM is committed to protecting your privacy. Whether you are a prospective, current, or former student, patient, or employee of the university, you should feel secure when entrusting us with your personal data. We have established this policy to ensure that.
NIMM processes your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Patient Data Act (2008:355, "PDL") for patient records at the student clinic. The PDL is lex specialis for medical record keeping, but the GDPR applies concurrently (principles, security, rights, and responsibilities).
To provide our educational and clinical services, we need to process your personal data. We also require your personal data to provide you with high-quality service, such as marketing, follow-ups, and information. We may also need your personal data to comply with legal requirements and to conduct customer and market analyses. It is important to us that you understand and feel secure in how we handle your personal data. This privacy policy aims to inform you about what personal data we process, why and how we process it, what rights you have, and our responsibilities regarding your personal data. You are always welcome to contact us if you have any questions.
Any information that can be directly or indirectly linked to you as an individual is considered personal data. When you apply for a program or book a treatment on our website, contact us, use our student portal, or sign up for a course, event, newsletter, or other communications, you provide us with your personal data. This data includes, for example, your name, personal identity number, email address, phone number, and application documents such as transcripts, CVs, certificates, and billing or residential addresses. Furthermore, we process information regarding how you use the NIMM website and student portal, your IP address, and geographic information.
Nordiska Institutet för Manuell Medicin AB (“NIMM”), organization number 556056-9880, is the data controller. The company is based and has its office at Kräftriket 23 A, 114 19 Stockholm. Our website is nimm.se. NIMM can be reached by phone at 08-16 01 20 or by email at info@nimm.se. The student clinic can be reached at klinik@nimm.se.
Data Protection Officer/Data Protection Contact: NIMM has determined that its operations do not require a formal Data Protection Officer under Article 37 of the GDPR. NIMM has appointed an internal data protection contact to coordinate data protection matters. Contact can be made via info@nimm.se (clinic-specific questions via klinik@nimm.se). If this assessment changes, NIMM will appoint a Data Protection Officer and update this policy.
Depending on the integration, we may in some cases be joint controllers together with the provider (Art. 26 GDPR).
Justification – decision not to appoint a Data Protection Officer (DPO)
NIMM has determined that the requirements for a mandatory Data Protection Officer under GDPR Article 37(1)(a)–(c) are not met for our operations. We are therefore not appointing a DPO at this time, but we have a designated data protection contact and review this decision on an ongoing basis (at least annually or upon significant changes).
Basis for the assessment (core arguments)
Review clause
The decision not to appoint a DPO is reviewed annually and upon changes that may imply "large-scale" processing, such as additional clinics, a significant increase in the patient base, expanded data collection (e.g., large-scale registry research), or new forms of systematic monitoring. Should such changes occur, NIMM will appoint a DPO without delay and notify the Swedish Authority for Privacy Protection (IMY) in accordance with Art. 37.7.
NIMM maintains a register of all processing activities in accordance with Article 30 of the GDPR. The register includes, among other things, categories of data and data subjects, purposes, legal basis, recipients/processors, retention periods, and security measures. Requests regarding the register should be directed to info@nimm.se.
Central systems/processors (examples, full list in the Article 30 register):
AD (Active Directory), BR (Brevo), CO (Cookiebot), CB (Clinicbuddy), EQ (Equitrac), FN (Fortnox), FR (Physical paper records), ME (Meta – Facebook/Instagram), GO (Google Workspace for Education), GA (Google Ads/Display; potential analytics from Google if enabled), HD (Physical storage/hard drive), SC (Schoolity), SE (Securitas Direct), VI (Visma), VA (Vaka).
What is our purpose?
Naprapathögskolan is a registered healthcare provider and complies with the Patient Data Act (PDL) (2008:355). According to the PDL, you as a patient must identify yourself so that we can treat you, and we are required to keep records of your treatments. You will also need to show identification during your first visit.
What personal data is processed?
Naprapathögskolan applies integrated medical record-keeping, which means that all students, supervisors, clinical instructors, and administrative staff working at any of the college's clinics may access your medical record if necessary. According to the Patient Data Act, you have the right to access your medical record. A review of the record is always conducted by a supervisor, clinical instructor, or clinic manager before it is released. Common examples include if you are seeking another therapist or medical care. You have the right to add information to your record if you believe something is incorrect. However, you do not have the right to alter a record that has already been written. Please notify us if you need to update your contact information.
The Naprapathögskolan clinic uses Clinicbuddy as our medical record system provider and for collecting health data. All forms are directly linked to your medical record. You submit the information via an encrypted connection (HTTPS), and it goes directly to Clinicbuddy and their databases. The provider is subject to applicable laws regarding GDPR, the Personal Data Act, the Patient Records Act, and the Patient Data Act. These laws provide a safety net for the handling of your health data, and we are confident in their management of it. If you would like more technical details regarding the exact protocols implemented, we will need to forward your inquiry to one of Clinicbuddy's technicians.
How do we collect the data?
Information is provided by you when booking and is supplemented with data from the population register, as well as the information you provide yourself during your appointment with your therapist.
How do we use the data?
You can find more information about how a visit to the Naprapathögskolan clinic works on our website under "Before your visit."
Legal basis
We have a legal obligation to comply with the Patient Data Act (2008:355). The General Data Protection Regulation (GDPR) does not apply to the processing of personal data for medical record-keeping.
Retention periods
Under the Patient Data Act, we are not permitted to delete your medical records until ten years have passed since they were last accessed.
What are our purposes?
We need your personal data to manage your application/enrollment, make an admission decision, and communicate with you regarding the program you have applied for. Sensitive data (e.g., certificates for special educational support) may be processed if necessary for the administration of your case.
What personal data is processed?
How do we collect your information?
All information is provided by you in connection with your application/enrollment and is supplemented with data regarding eligibility, merit points, selection value, and admission status from the admissions process.
How do we use your information?
Legal basis
Measures prior to contract/contract (Art. 6.1 b) and legal obligation (Bookkeeping Act). It is in the applicant's interest that the data is processed, and the processing that takes place is necessary for us to make an admission decision and enter into an agreement to grant the applicant access to the relevant program. Processing is also necessary for NIMM to fulfill the legal obligation imposed by the requirement to keep accounting records, as specified in the Bookkeeping Act. Any processing of sensitive data (e.g., medical certificates for educational support) is carried out with consent (Art. 9.2 a).
Retention periods
Regardless of whether you are admitted to a program or not, we will retain your application data. We do this because we are required to maintain documentation regarding the admissions process and must be able to demonstrate how cases are handled, for example, in the event of inquiries from supervisory authorities or if an applicant requests a deferral. It is also in the applicant's interest that the data is preserved, as it may provide merit points for future applications.
What are our purposes?
To be able to administer your studies and grades, and to issue degree certificates, certificates of education, diplomas, or licenses upon completion of an education or course.
What personal data is processed?
How do we collect the data?
All data is provided by you in connection with your application/registration or in your correspondence with the college's staff. The data is supplemented with information from the college's staff, teachers, and examiners.
How do we use the data?
Legal basis
We process your personal data to fulfill agreements regarding the provision of education and courses. It is also in your interest that your personal data is processed, and it is necessary for the administration of your education or course, including scheduling, grades, diplomas/certificates of completion, and other documentation. It is also in your interest that information regarding degrees and/or license-qualifying education is provided to relevant industry organizations.
Processing is also necessary for NIMM to fulfill the legal obligations regarding accounting as specified in the Swedish Bookkeeping Act, and to provide information about graduated students to relevant authorities such as the National Board of Health and Welfare (Socialstyrelsen), Statistics Sweden (SCB), the Swedish Board of Student Finance (CSN), the Norwegian State Educational Loan Fund (Lånekassen), and the Social Insurance Institution of Finland (Kela).
Retention periods
We retain your personal data to ensure that you can request certificates, transcripts, or other information regarding your completed studies after your education or course has ended. As no legal entity other than NIMM is responsible for maintaining records of those who have completed studies at the college, we have determined that it is in the students' interest to store information regarding academic results. This information is also stored to provide relevant authorities with the documentation required for purposes such as decisions regarding eligibility for clinical internships and the issuance of professional licenses.
What are our purposes?
To ensure the quality of our training, course, and clinical operations, inform you about the services we offer, and communicate other news to you. The ability to issue invoices for the training or treatment you have completed, as well as for bookkeeping purposes.
What personal data is processed?
How do we collect the data?
All data is obtained from the population register or from the information you provided yourself when booking a treatment or applying/registering for a course or training program.
How do we use the data?
Legal basis
Personal data processed to fulfill our accounting obligations is retained for up to seven years after the end of the financial year. We are legally required to process your personal data during this period. NIMM also bases its data processing on a balancing of interests, as we believe we have a legitimate interest in quality control, statistics, and research data to ensure we can offer high-quality educational and clinical services.
Furthermore, we believe that by being part of our operations, whether as a student or patient, you are interested in receiving information about prices and opening hours, upcoming events, other courses, and news regarding our operations. We therefore believe we have a legitimate interest in providing you with this information. After careful consideration, NIMM has concluded that your interests, fundamental rights, or freedoms do not override this, and therefore NIMM may base this processing on the aforementioned legitimate interests.
Retention periods
We will store your personal data for as long as is necessary to fulfill the purposes outlined in this Privacy Policy. Thereafter, we determine that we no longer have a legitimate interest in processing your data for that specific purpose.
If you do not wish to receive surveys, information, or marketing, you may opt out at any time. For matters regarding education and/or courses, please contact info@nimm.se or follow the link provided in every email. For matters regarding any of our clinics, please contact klinik@nimm.se or follow the link provided in every email. Upon such a request, NIMM will immediately cease processing your data for marketing purposes.
What are our purposes?
The purpose of processing personal data is for research or the completion of a thesis project at NIMM.
What personal data is processed?
Depends on the nature of the study.
How do we collect the data?
Depends on the nature of the study.
How do we use the data?
Depends on the nature of the study
Legal basis
Consent and/or tasks carried out in the public interest; for special categories, Article 9 of the GDPR applies.
Retention periods
Until the degree project or research project is completed and/or finished.
What is our purpose?
To fulfill our obligations by organizing the event you have registered for, conducting surveys, and providing information about upcoming events, courses, training, and other news.
What personal data is processed?
How do we collect the data?
All data is provided by you in connection with your registration.
How do we use the data?
Legal basis
NIMM processes your personal data to fulfill the agreement entered into in connection with your registration. Any additional data processing is based on a balancing of interests. When you register for an event, you have shown an interest in our services; we therefore believe you may also be interested in our future events and/or news regarding our business, and we have determined that we have a legitimate interest in preparing marketing materials and marketing our services to you. Furthermore, we have an interest in developing our methods and business operations.
After careful consideration, NIMM has determined that your interests, fundamental rights, or freedoms do not override the need for data protection in this context, which is why NIMM may base processing on the aforementioned legitimate interests.
Retention periods
We will store your personal data for as long as is necessary to fulfill the purposes outlined in this privacy policy. Thereafter, we determine that we no longer have a legitimate interest in processing your data for that specific purpose.
If you do not wish to receive our marketing communications, you can opt out at any time by emailing info@nimm.se or by following the link included in every email. Upon receiving such a request, NIMM will immediately cease processing your data for marketing purposes.
What is our purpose?
To market services, treatments, events, and other content.
What personal data is processed?
How do we collect the information?
All information is provided by you in connection with your subscription sign-up, when you order information materials, or when you register for an event, course, or apply for a program.
How do we use the information?
Legal basis
Your personal data is processed based on your consent and to fulfill the agreement entered into when you sign up as a subscriber. In order for us to fulfill our obligations (i.e., sending you the newsletter you have requested), we must process your personal data. You may withdraw your consent at any time via the unsubscribe link or by contacting info@nimm.se.
Retention periods
We process your personal data for as long as you are a subscriber to the newsletter. You can unsubscribe at any time by following the link provided in every newsletter or by contacting info@nimm.se. When you unsubscribe, our processing of your personal data will cease.
What is our purpose?
To provide and improve our services on the domains: naprapathogskolan.se, kiropraktorakademin.se, nimm.se and, subject to consent, statistics and marketing.
What personal data is processed?
How do we collect the data?
The data is collected via cookies and similar technologies. See the section NIMM's use of cookies.
How do we use the data?
Legal basis
Legitimate interest for necessary/operational and security cookies. Consent for non-essential cookies (statistics/marketing).
Storage durations
According to the respective cookie and your consent choices; see the cookie declaration in our consent solution.
Advertising, measurement, and use of first-party data
We use Cookiebot to manage consent. You can change your choices at any time via "Cookie Settings" on the website.
With your consent via our cookie banner, we may enrich conversion data in advertising platforms (e.g., Google Enhanced Conversions and Meta Advanced Matching). For this purpose, we minimize data (typically email addresses) and hash them using SHA-256 in your browser before the data is sent to the recipient. The purpose is attribution and ad optimization. Processing is based on consent (GDPR Art. 6.1 a), and no non-essential tags are activated before consent is given. Recipients may include Google, Meta, Microsoft, LinkedIn, and TikTok (depending on active campaigns). International transfers are only made to recipients certified under the EU-U.S. Data Privacy Framework or using Standard Contractual Clauses (SCCs), with supplementary protective measures applied following a TIA where necessary. For certain integrations, we may act as joint controllers with the platform (Art. 26); in such cases, we provide a summary of the division of responsibilities upon request. You can withdraw your consent at any time via the "Cookie Settings" link in the footer.
FUNCTIONAL COOKIES (necessary)
These cookies are necessary to ensure the optimal functioning of the website and cannot be adjusted via the consent tool. They enable features such as language selection, screen resolution, access to accounts/shopping carts/logins, security/fraud protection, and operations. Some functional trackers may be set by NIMM or our service providers to verify user data, payment, and delivery methods.
PERFORMANCE COOKIES (statistics/analytics) – requires consent
Used to measure and analyze visits (number of visits, pages viewed, average time, etc.) to improve the website. Typical storage duration: up to 13–14 months.
MARKETING COOKIES – requires consent
Used to personalize and measure ads in third-party channels (including social media). If you do not accept these, ads will still be displayed, but they will not be tailored to your preferences. Typical storage duration: up to 13 months.
Providers and detailed storage durations are listed in our cookie declaration in Cookiebot (e.g., Google Analytics/Ads and Meta Pixel if enabled). You can withdraw or change your consent at any time via Cookie Settings.
What is our purpose?
Deliver educational content, enable communication between students, participants, and instructors
What personal data is processed?
How do we collect the data?
The data is entered by the student themselves or by the university's program coordinator when you are admitted to a course or program.
How do we use the data?
Legal basis
Contract (necessary to provide education and course administration).
Retention periods
We retain your personal data to ensure that you can request certificates, transcripts, or other information regarding your completed studies after finishing a program or course. As no legal entity other than NIMM is responsible for maintaining records of those who have completed studies at the university, we have determined that it is in the students' interest to store information about educational results indefinitely. This information is also stored to provide relevant authorities with the documentation required for purposes such as decisions regarding admission to internship programs for professional licensure and the issuance of such licenses.
What is our purpose?
To administer and fulfill employment/assignments and labor law obligations, including recruitment and onboarding, permission and account management, scheduling and absence tracking, payroll and benefits, pensions and insurance, work environment and rehabilitation, training/professional development, license and equipment management, physical security/access control, IT and information security (e.g., logging and incident management), and auditing and reporting to authorities.
What personal data is processed?
Identity and contact details (name, personal identity number, address, phone number, email), employment and assignment details (type of employment, job title, department, schedule/absence), salary and benefit information (salary category, account number, tax and benefit documentation), education/qualifications (CV, transcripts/certificates, credentials), permissions and IT accounts (user ID, roles, access rights), security and usage logs (logins, email/cloud service metadata, print logs), access card details (card ID, access events), and photos for ID cards. Sensitive data may be processed to a limited extent, such as medical certificates in connection with absence/rehabilitation or information regarding union membership for leave/deductions—only to the extent required or permitted by law.
How do we collect the data?
From you directly in connection with recruitment, employment, and ongoing administration; from internal systems (e.g., scheduling, access, and IT logs); from public sources and government agencies (e.g., the Swedish Tax Agency, the Swedish Social Insurance Agency); and from our data processors as per our agreements.
How do we use the data?
To administer employment/assignments, provide IT resources and premises access, manage payroll, taxes, pensions, and insurance, fulfill work environment and rehabilitation obligations, plan professional development, ensure operational and information security (including troubleshooting and incident management), fulfill legal requirements, and report to competent authorities and auditors. Personal data is shared as necessary with our IT providers (data processors) as well as with authorities, banks, auditors, and insurance/pension providers. We never sell personal data. Any transfers outside the EU/EEA are conducted in accordance with the "International transfers" section.
Legal basis
Contract (Art. 6.1 b) to fulfill the employment/assignment; legal obligation (Art. 6.1 c) under, for example, labor law, accounting law, and tax and social security regulations; legitimate interest (Art. 6.1 f) for necessary IT/information security, logging, access and equipment management, and physical security/access control – with the right to object where applicable. Processing of special categories of data (e.g., health data in medical certificates or information regarding union membership) occurs only when necessary and permitted under Art. 9.2 b/h of the GDPR and applicable Swedish legislation (e.g., work environment and social security regulations).
Retention periods
During the term of employment/assignment and thereafter for as long as required by law or to establish, exercise, or defend legal claims. Accounting and payroll records are retained for up to seven (7) years after the end of the financial year in accordance with the Swedish Accounting Act. Access, security, and entry logs, as well as backups, are retained according to NIMM’s deletion procedures (typically for shorter periods unless longer retention is required for troubleshooting, security, or ongoing investigations). Any archiving in accordance with agreements and legal requirements is specified in NIMM’s Article 30 register.
NIMM is not permitted to use your personal data for purposes other than those stated above without first informing you.
You can contact NIMM at any time with questions regarding how we process your personal data. You have the right to request a register extract free of charge, i.e., access to your stored personal data. The register extract will be sent to your registered address.
Furthermore, you have the right to make the following requests:
1) if you believe that your personal data held by us is incorrect or incomplete, you have the right to request rectification 2) the right to request the erasure of your data 3) the right to request that we restrict our processing of your personal data 4) the right to request the transfer of your personal data (data portability) to another service provider in a commonly used, machine-readable format.
You also have the right to object to processing based on legitimate interest (including direct marketing) and the right to withdraw your consent at any time when processing is based on consent.
Your request will be reviewed and, if deemed justified, we will carry out the requested action to the extent and within the timeframe that we are able to do so.
Requests must be submitted in writing to:
Data Controller
Nordiska Institutet för Manuell Medicin AB
Kräftriket 23A
114 19 Stockholm
If you are dissatisfied or have complaints regarding any part of NIMM's processing of your personal data, you may file a complaint with NIMM. You also have the right to lodge a complaint with the supervisory authority, the Swedish Authority for Privacy Protection (www.imy.se, imy@imy.se, phone number: +46 8 657 61 00).
When selecting software, cloud services, storage methods, and other IT systems, NIMM has to a large extent taken into account the principles of data protection by design and by default.
The university strives to prevent unauthorized use or disclosure through technical, organizational, and administrative measures, including access control, logging, encryption in transit and, where possible, at rest, backups, policies/training, and audits of data processors.
Personal data may be transferred outside the EU/EEA if necessary (e.g., to providers such as Google or Meta). Such transfers are protected by the European Commission's Standard Contractual Clauses (SCCs) and, where required, supplementary protective measures. Transfers are documented in NIMM's Article 30 register.
We use Google Workspace for Education for email and collaboration. Google processes personal data as our data processor in accordance with the Google Cloud Data Processing Addendum (CDPA), and we have specified that EU data protection laws (GDPR) apply. Any transfers outside the EU/EEA are protected by SCCs and supplementary safeguards. For supported services, we use Data Regions (EU).
This Privacy Policy may be subject to change. Changes to this policy take effect once the revised version is published on our websites. Significant changes will be communicated specifically where required.
As of August 20, 2025, the following policy has been established for Nordiska Institutet för Manuell Medicin AB, hereinafter referred to as “NIMM”.
This policy outlines NIMM's approach to video surveillance in our training facilities.
A decision to implement camera surveillance aims to prevent, investigate, and detect crime, prevent accidents, or serve other comparable purposes. This objective must be achieved while protecting those being monitored from undue intrusion into their personal privacy. NIMM considers the interest in surveillance to be particularly significant within its operations.
Legal basis for camera surveillance
NIMM follows the regulations applicable to camera surveillance under the Camera Surveillance Act. The purpose is to meet the need for camera surveillance for legitimate purposes while protecting individuals against undue intrusion into their personal privacy. Therefore, camera surveillance is conducted only for specific and legitimate purposes that, by law, outweigh the rights of employees, students, and patients to personal privacy. The processing of personal data resulting from camera surveillance is carried out based on legitimate interest (Art. 6.1 f GDPR).
Principles for camera surveillance
Camera surveillance is conducted based on the following three principles:
Interest in and purpose of surveillance
NIMM considers camera surveillance justified because the interest in surveillance outweighs the individual's interest in not being monitored. With regard to individual privacy, camera surveillance is not the university's first choice. We have investigated whether other measures less intrusive than camera surveillance could be used in our operations. We have concluded that, despite this balancing of interests, there is a need for camera surveillance. This is because both the university and its clinics are particularly vulnerable to crime. This has been documented through crime reports and other data. We have sought alternatives to camera surveillance but have not found other means adequate to achieve the desired purpose of the surveillance.
To minimize the impact on the personal privacy of the university's patients, students, and staff, camera surveillance is limited to the corridors and entrances required to access the university's premises. The exceptions are NIMM's gym and the FSTT/simulation laboratory, where the entire room is monitored.
The decision to implement camera surveillance also aims to meet students' requests for good accessibility to the school's premises during both weekdays and weekends. The matter has been raised in the university's student social committee, where an agreement was reached between the university, the student union, and class representatives. The camera surveillance also aims to deter unauthorized persons from being on the university's premises, thereby increasing safety for patients, students, and staff.
Individual right to information
NIMM has an obligation to proactively inform those who are monitored or may be monitored about the surveillance. This is done through clear signage in the areas where camera surveillance is in operation.
NIMM provides information about the purposes of the surveillance to those who are monitored or may be monitored if such information is requested. Employers also have an obligation to document the purposes intended to be achieved through camera surveillance.
Employer confidentiality
NIMM is bound by confidentiality regarding material generated by camera surveillance. We do not disclose surveillance material to any parties other than law enforcement authorities or a municipality or authority responsible for emergency services, provided that the recipient has a legitimate need for the information.
Retention of material
NIMM does not retain material from camera surveillance longer than is necessary for the purpose of the surveillance. In normal cases, this means a maximum period of two months. Thereafter, collected material will be automatically destroyed. Only personnel responsible for alarms have access to the material.
Contact persons
Employees or students with questions regarding this policy should primarily direct them to info@nimm.se. Patients with questions regarding this policy should primarily direct them to klinik@nimm.se. If further assistance is needed, please contact one of the individuals listed below.
Head of Administration
Simon Berg
+46 8-16 01 20
simon.berg@nimm.se
Administrative Manager/Clinic Manager
Patrik Otteberg
+46 8-16 01 20
patrik.otteberg@nimm.se
Responsibility
NIMM is responsible for ensuring that everyone who is monitored, or may be monitored, is informed of this policy. NIMM is also responsible for ensuring that camera surveillance is conducted legally and in accordance with good practice.
By clicking "Accept all cookies", you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts.