Privacy Policy
Last updated: 15 May 2026
1. Data Controller
The data controller is HightData, with its principal office at Hermiankatu 1–8, Hervanta, 33720 Tampere. We also operate offices in Stockholm, Lysaker and Copenhagen. As the data controller, we determine the purposes and means of processing your personal data. For all matters relating to data protection you may contact our privacy team at privacy@hightdata.com, and we aim to respond within a reasonable time.
2. Scope of this Policy
This privacy policy describes how we process personal data when you visit our website, submit a contact form, subscribe to our newsletter, book a meeting or otherwise communicate with us. The policy applies to all language versions of our website and to all of our offices. It does not cover third-party websites we may link to; we recommend reviewing their own privacy practices.
3. Legal Framework
We process personal data in accordance with the EU General Data Protection Regulation (Regulation EU 2016/679, GDPR) and applicable national data protection laws in Finland, Sweden, Norway and Denmark. We also observe the rules on privacy in electronic communications insofar as they concern cookies and direct marketing. We are committed to processing data lawfully, fairly and transparently.
4. Legal Bases for Processing
Our processing relies on the following legal bases: contact forms and enquiries on our legitimate interest in responding to you (Art. 6(1)(f)); newsletters on the consent you provide (Art. 6(1)(a)); meeting scheduling and service delivery on the performance of a contract or pre-contractual steps (Art. 6(1)(b)); and accounting and statutory record-keeping on legal obligation (Art. 6(1)(c)). Where we rely on legitimate interest, we have assessed that it does not override your rights and freedoms.
5. Categories of Data Collected
Depending on your interaction with us we may collect: identification data such as your name; contact data such as your email address; free-form content and the subject of enquiries you provide in forms; meeting booking details such as the chosen day and time; and technical data such as IP address, browser type, device information and site usage collected via cookies. We do not knowingly collect sensitive special categories of personal data or the data of minors.
6. Purposes of Processing
We use personal data for the following purposes: responding to enquiries and contact requests; arranging and managing meetings; delivering the services agreed; sending our newsletter on the basis of consent; improving the function, security and usability of our website; and meeting our legal obligations. We will not use your data for purposes incompatible with these original purposes without separate notice.
7. Retention Periods
We retain personal data only for as long as necessary to fulfil the purposes described. Contact data is kept for up to 24 months from your last contact. Newsletter data is kept until you unsubscribe. Contract and accounting data is kept for the period required by law, typically six years from the end of the financial year. Technical analytics data is kept for up to 14 months. Once the retention period ends, data is securely deleted or anonymised.
8. Recipients and Processors
Personal data may be shared with trusted service providers who process data on our behalf, such as website hosting, email services and analytics. These processors act on our instructions and are bound by data processing agreements under Article 28 GDPR. We do not sell personal data to third parties. Data may be disclosed to authorities only where required by law.
9. International Data Transfers
We aim to keep personal data within the European Economic Area (EEA). Where data is nonetheless transferred outside the EEA, we ensure an adequate level of protection by relying on the European Commission’s Standard Contractual Clauses (SCCs) or an adequacy decision of the Commission. You may request further information about the safeguards applied.
10. Your Rights
Under the GDPR you have the right to: access your data; rectify inaccurate data; erase your data (the "right to be forgotten"); restrict processing; object to processing; receive your data in a portable format; and withdraw any consent at any time without affecting the lawfulness of processing before withdrawal. You can exercise your rights by contacting privacy@hightdata.com. We aim to respond within one month and may ask you to verify your identity.
11. Withdrawing Consent
Where processing is based on your consent, you may withdraw it at any time. You can unsubscribe from the newsletter using the link at the end of every message or by contacting us. Withdrawing is as easy as giving consent and causes you no disadvantage. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
12. Security Measures
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction. These include TLS encryption in transit, least-privilege access control, event logging, regular backups and continuous monitoring. We review and update these measures regularly. In the event of a personal data breach, we follow the notification obligations under the GDPR.
13. Cookies
Our website uses cookies and similar technologies. Strictly necessary cookies are required for the basic functioning of the site, whereas analytics and marketing cookies require your consent. You can manage your cookie settings through the cookie banner shown on the site and in your browser settings. For more information, see our separate cookie policy.
14. Automated Decision-Making and Profiling
We do not carry out decision-making based solely on automated processing, within the meaning of Article 22 GDPR, that produces legal or similarly significant effects concerning you. Although we develop AI systems for our clients, on our own website we do not use profiling for such decision-making.
15. Children’s Privacy
Our service is aimed at businesses and professionals and is not intended for persons under 16. We do not knowingly collect the personal data of minors. If we become aware that we have collected such data without appropriate consent, we will delete it without undue delay.
16. Changes to this Policy
We may update this privacy policy in line with changes to our practices or the law. The current version and its date are always published on this page. We will endeavour to give separate notice of significant changes, for example on the website or in the newsletter. We recommend reviewing the policy regularly.
17. Supervisory Authority
You have the right to lodge a complaint with the competent data protection supervisory authority if you consider that we process your personal data unlawfully. In Finland the authority is the Office of the Data Protection Ombudsman, in Sweden Integritetsskyddsmyndigheten, in Norway Datatilsynet and in Denmark Datatilsynet. We do, however, ask that you contact us first so we can try to resolve the matter.
18. Contact
For any question relating to this privacy policy or the processing of your personal data, contact our privacy team at privacy@hightdata.com or by post to our principal office in Tampere. We will handle your enquiry confidentially.