# Privacy Policy

> This policy describes how Hasty, a trademark owned and operated by Norrhavet Group AB, processes personal data when you visit our websites, contact us, take part in meetings, or use our services. Norrhavet Group AB is the data controller for the processing described in this policy.

Human view: https://hasty.se/en/juridik/integritetspolicy
Agent view: https://hasty.se/en/juridik/integritetspolicy.md

Languages: sv=https://hasty.se/juridik/integritetspolicy | en=https://hasty.se/en/juridik/integritetspolicy | no=https://hasty.se/no/juridik/integritetspolicy | da=https://hasty.se/da/juridik/integritetspolicy | fi=https://hasty.se/fi/juridik/integritetspolicy

Uppdaterad: 2026-09-21

## 1. Scope and roles

This policy applies to personal data processed in connection with marketing, sales, customer relations, supplier administration, support, recruitment, events and web analytics.

Norrhavet Group AB is the data controller for these purposes.

When we process personal data contained in a customer's material, we act instead as a data processor under a separate data processing agreement (DPA) with the customer, and the customer's instructions then govern the processing.

This policy should be read together with Norrhavet Group's Code of Conduct on confidentiality, data protection, communication and intellectual property.

## 2. What data we process and why

We only process data that is necessary for clearly defined purposes.

- Website operation, security and analytics: data such as IP address, cookie ID, device data and logs. The purpose is to deliver the service, maintain security and gain aggregated insight into usage. The legal basis is legitimate interest and, where required by law, consent. Data is normally retained for up to 26 months for analytics data and 12 months for security logs.
- B2B sales and marketing: name, job title, company, contact details, areas of interest and meeting notes. The purpose is to offer relevant business services. The legal basis is legitimate interest or consent. Data is retained for 24 months from the last active contact or until consent is withdrawn.
- Newsletters and mailings: name, email address and interaction data. The legal basis is consent. Data is retained until consent is withdrawn.
- Contracts and delivery: contact persons' data, contract details, orders, correspondence and case history. The legal basis is contract and legal obligation for accounting purposes. Data is retained for the contract term and thereafter for seven years under accounting law.
- Support and customer service: name, email, logs and attached material. The legal basis is legitimate interest. Data is retained for 12 to 24 months depending on the type of case.
- Events and workshops: attendee lists and, where relevant, dietary preferences and photo or video if you consent. The legal basis is contract for participation and consent for media. Attendee data is retained for 12 months. Media is retained until consent is withdrawn.
- Recruitment: CVs, applications, references and interviews. The legal basis is legitimate interest or contract in preparation for employment. If we want to retain data after the process has ended, we obtain consent. Data is retained during recruitment and for up to 24 months with consent.
- Supplier management: contact details, payment and contract data. The legal basis is contract and legal obligation. Data is retained for the contract term and thereafter for seven years.

When we process personal data on behalf of a customer, we do so as a data processor under our data processing agreement (DPA), and the agreement with the customer then takes precedence over this policy.

## 3. Where the data comes from

We collect data directly from you through forms, email, meetings and workshops.

We may also receive data from your employer, from public sources such as company registers and LinkedIn, and through our website services via cookies and similar technology.

More information about cookies is available in our separate Cookie Policy.

## 4. Recipients and sharing

Data is only shared when necessary and with appropriate safeguards.

Group companies and affiliates within Norrhavet Group may receive data for shared functions such as finance, security and compliance. Each company is independently responsible as a controller for its own purposes.

Data processors such as IT operations, cloud providers, CRM, email, project tools, analytics and support may only process data according to our instructions and are bound by data processing agreements.

Data may be disclosed to authorities where required by law.

In the event of corporate restructuring, personal data may be transferred provided the level of protection is maintained.

## 5. Transfers outside the EU and EEA

If data is transferred to a country outside the EU and EEA, we use appropriate safeguards such as the European Commission's standard contractual clauses, documented risk assessments, and technical and organisational measures.

Information about current recipients of such transfers is available on request via privacy@norrhavet.com.

## 6. Security

We protect data with access controls, multi-factor authentication, encryption, logging, the principle of least privilege, training and contractually binding confidentiality.

We work according to principles inspired by established information security frameworks, without thereby claiming formal certification.

We have an incident process for rapid handling and notify affected parties and the supervisory authority under the GDPR in the event of personal data breaches.

## 7. Retention and deletion

We retain data for as long as necessary for the purposes above or for as long as required by law.

When retention is no longer necessary, data is securely deleted or anonymised.

For creative deliverables, the customer agreement and licences apply. Original files may be retained for versioning and evidentiary purposes during the contract term and for a reasonable period of limitation thereafter.

## 8. Your rights

You can contact privacy@norrhavet.com to exercise your rights under the GDPR.

- Right of access to and a copy of your personal data.
- Right to rectification of inaccurate or incomplete data.
- Right to erasure when the data is no longer needed or when consent is withdrawn.
- Right to restriction of processing in certain cases.
- Right to data portability where applicable.
- Right to object to processing based on legitimate interest.
- Right to withdraw consent at any time.

We respond to requests to exercise your rights as soon as possible and no later than within one month under the GDPR.

You can also lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

## 9. Communication, confidentiality and archiving

Project communication must take place through approved channels and be documented in accordance with our internal guidelines.

Employees and suppliers are bound by confidentiality and may not share customer or company information without written approval.

## 10. Marketing and profiling

We may segment recipients in our B2B CRM to send relevant information about services and content.

Segmentation is done at organisational and professional level and does not normally constitute automated decision-making with legal effects.

You can always unsubscribe via the link in the mailing or by contacting us.

## 11. Children

Our services are aimed at businesses and professional roles.

We do not knowingly collect data about children.

## 12. Links to other websites

Our websites may link to external sites.

We are not responsible for the content or privacy practices of such sites, and recommend that you read their respective policies.

## 13. Limitation of liability and relationship to agreements

This policy describes our general handling of personal data and does not create any rights or obligations beyond those following from mandatory law or from agreements entered into with us. In the event of a conflict between an agreement and this policy, the agreement prevails.

To the extent permitted by law, we are not liable for damage caused by third-party services, by material or personal data provided by the customer, or by other circumstances beyond our reasonable control.

The customer is responsible for ensuring that the material and personal data it provides to us have been lawfully obtained and may be processed for the stated purposes.

## 14. Changes to this policy

We may update this policy. Material changes will be communicated in good time and apply prospectively from the date stated.

History and previous versions are available on request.

## 15. Contact

Privacy matters and questions about agreements and data processing agreements (DPA): privacy@norrhavet.com.

Postal address: Norrhavet Group AB, Bangatan 5A, 722 28 Västerås, Sweden.

Hasty is a trademark owned and operated by Norrhavet Group AB.

## Appendix A. Summary of security principles

- Access management and multi-factor authentication on all systems containing personal data.
- Encryption in transit and at rest where technically feasible.
- Backups with regularly tested restoration.
- Review of suppliers, data processing agreements and standard contractual clauses for third-country transfers.
- Incident process with immediate action, root-cause analysis and notification under the GDPR.
- Confidentiality and protection of intellectual property for all representatives in accordance with our Code of Conduct.

This privacy policy supplements our general terms and conditions, our Cookie Policy and our standard data processing agreement (DPA). This policy is governed by Swedish law, and in the event of a conflict with mandatory law, the law always prevails.

---

## Kontakt

- Allmänna frågor: hej@hasty.se
- Offert och nya uppdrag: christian@hasty.se
- Telefon: 08-480 04 706 (+46 8 480 04 706)
- Besöksadress: Bjurholmsplan 24, 116 63 Stockholm, Sverige
- Kontaktsida: https://hasty.se/en/kontakta-oss
- Personlig service (formulär): https://hasty.se/en/boka-demo
- Juridisk avtalspart: Norrhavet Group AB, org.nr 559258-3792, Stockholm, Sverige.
- Priser och kalkylator: https://hasty.se/en/priser

## Site maps for agents
- https://hasty.se/llms.txt
- https://hasty.se/llms-full.txt
- https://hasty.se/agents.md
- https://hasty.se/sitemap.xml

Hasty is a brand owned by Norrhavet Group AB (org.nr 559258-3792), Sweden.
