Our commitment to the General Data Protection Regulation (EU) 2016/679 — how we comply, what it means for you and how to exercise your rights.
Diginext Sweden AB is committed to protecting the privacy and security of all personal data we process. We comply fully with the General Data Protection Regulation (GDPR) and the Swedish Data Protection Act (Dataskyddslagen 2018:218). This statement explains our obligations and your rights under this legislation.
The data controller responsible for your personal data is:
We process personal data only where we have a lawful basis to do so. Our processing activities are reviewed regularly to ensure continued compliance.
Under Article 6 GDPR, we process personal data on the following lawful bases:
As a data subject under GDPR, you have the following rights (Articles 15–22):
Request confirmation of whether we process your data and receive a copy within 30 days at no charge.
Request correction of inaccurate personal data or completion of incomplete data we hold about you.
Request deletion of your personal data where there is no compelling reason to continue processing it.
Request restriction of processing your data in certain circumstances — e.g. while accuracy is contested.
Receive your personal data in a structured, commonly used, machine-readable format and transfer it to another controller.
Object to processing based on legitimate interests or for direct marketing purposes. We will cease unless compelling legitimate grounds apply.
How to exercise your rights:
Contact us at info@diginext.se with subject line "GDPR Request — [type of request]". We will respond within 30 days. In complex cases, we may extend this by a further 60 days but will inform you. There is no charge for requests unless they are manifestly unfounded or excessive.
Diginext Sweden AB processes personal data primarily within the European Economic Area (EEA). Where we transfer data outside the EEA, we ensure appropriate safeguards are in place in accordance with Chapter V of GDPR — including Standard Contractual Clauses (SCCs) or adequacy decisions.
Our primary processing and storage infrastructure is located in Sweden and Norway, within the EEA.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Swedish Authority for Privacy Protection (IMY) within 72 hours of becoming aware, in accordance with Article 33 GDPR.
Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay (Article 34 GDPR), unless the data was encrypted or other mitigating factors apply.
You have the right to lodge a complaint with the competent supervisory authority if you believe your personal data has been processed in a manner inconsistent with GDPR. In Sweden, this is:
We encourage you to contact us first at info@diginext.se before raising a complaint with the supervisory authority, as we will endeavour to resolve any concerns promptly and directly.