Legal
Privacy Policy
Last updated 26 June 2026
This Privacy Policy explains how Highex AB ("Highex", "we", "us") collects and processes personal data when you visit this website or contact us, and the rights you have under the EU General Data Protection Regulation (GDPR) and applicable Swedish data-protection law.
1. Data controller
Highex AB is the controller responsible for your personal data:
- Highex AB, Olof Palmes gata 29, 4 tr, SE-111 22 Stockholm, Sweden
- Email: info@highex.se
2. The personal data we collect
We collect only the data needed to respond to you and to operate the site securely:
- Information you provide — when you use our contact form, the name, work email, organisation, type of institution, and the message you submit.
- Technical data — limited information your browser sends automatically (such as IP address, user agent, and request times) recorded in standard server logs for security and reliability.
We do not knowingly collect special categories of data, and we do not require you to provide more than is necessary.
3. How and why we use your data
We process personal data for the following purposes and legal bases under Article 6 GDPR:
- To respond to enquiries and take steps at your request prior to entering into a contract (Article 6(1)(b)), and on the basis of our legitimate interest in answering business enquiries (Article 6(1)(f)).
- To operate, secure, and maintain the website, on the basis of our legitimate interest in running a safe and functional service (Article 6(1)(f)).
- To comply with legal obligations where applicable (Article 6(1)(c)).
4. Cookies and analytics
This website does not set non-essential or tracking cookies and does not run third-party advertising or analytics by default. If cookies or analytics are introduced in future, this policy will be updated and, where required, your consent will be requested through a cookie banner.
5. Sharing and processors
We do not sell your personal data. We may share it with trusted service providers acting as our processors — for example, hosting and email providers — strictly to deliver the services above and under appropriate contractual safeguards. We may also disclose data where required by law or to protect our rights.
6. International transfers
We aim to keep personal data within the European Economic Area (EEA). Where a provider processes data outside the EEA, we rely on an adequacy decision or appropriate safeguards (such as the European Commission's Standard Contractual Clauses).
7. Retention
We keep personal data only as long as necessary for the purposes above — typically for the duration of our correspondence and any resulting relationship — and then delete or anonymise it, unless a longer period is required by law.
8. Your rights
Subject to the conditions in the GDPR, you have the right to:
- access the personal data we hold about you;
- request rectification of inaccurate data;
- request erasure ("right to be forgotten");
- restrict or object to processing;
- data portability;
- withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, contact us at info@highex.se. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or your local supervisory authority.
9. Security
We maintain appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse, consistent with our ISO/IEC 27001-certified information security management.
10. Children
This website is directed at organisations and professionals and is not intended for children. We do not knowingly collect data relating to children.
11. Changes to this policy
We may update this policy from time to time. The "last updated" date above reflects the latest revision.
12. Contact
Questions about this policy or your data can be sent to info@highex.se.