All systems nominal+46 73 576 75 20
Legal

GDPR Statement

Our commitment to the General Data Protection Regulation (EU) 2016/679 — how we comply, what it means for you and how to exercise your rights.

GDPR (EU) 2016/679 Effective: 25 July 2024
Our GDPR Commitment

Diginext Sweden AB is committed to protecting the privacy and security of all personal data we process. We comply fully with the General Data Protection Regulation (GDPR) and the Swedish Data Protection Act (Dataskyddslagen 2018:218). This statement explains our obligations and your rights under this legislation.

01

Who We Are (Data Controller)

The data controller responsible for your personal data is:

Diginext Sweden AB
Org. nr: 559475-0761
Musseronvägen 20, 186 56 Vallentuna, Sweden
info@diginext.se +46 73 576 75 20

We process personal data only where we have a lawful basis to do so. Our processing activities are reviewed regularly to ensure continued compliance.

02

Lawful Bases for Processing

Under Article 6 GDPR, we process personal data on the following lawful bases:

Art. 6(1)(a) Consent
Where you have given clear consent for us to process your data for a specific purpose — e.g. newsletter sign-up or optional data sharing.
Art. 6(1)(b) Contract
Where processing is necessary for the performance of a contract with you, or to take steps before entering into a contract at your request.
Art. 6(1)(c) Legal Obligation
Where processing is necessary for compliance with a legal obligation — e.g. Swedish accounting law, tax reporting.
Art. 6(1)(f) Legitimate Interests
Where processing is necessary for our legitimate interests (e.g. responding to enquiries, improving our website) and these interests are not overridden by your fundamental rights.
03

Your GDPR Rights in Full

As a data subject under GDPR, you have the following rights (Articles 15–22):

Art. 15
Right of Access

Request confirmation of whether we process your data and receive a copy within 30 days at no charge.

Art. 16
Right to Rectification

Request correction of inaccurate personal data or completion of incomplete data we hold about you.

Art. 17
Right to Erasure

Request deletion of your personal data where there is no compelling reason to continue processing it.

Art. 18
Right to Restriction

Request restriction of processing your data in certain circumstances — e.g. while accuracy is contested.

Art. 20
Right to Portability

Receive your personal data in a structured, commonly used, machine-readable format and transfer it to another controller.

Art. 21
Right to Object

Object to processing based on legitimate interests or for direct marketing purposes. We will cease unless compelling legitimate grounds apply.

How to exercise your rights:

Contact us at info@diginext.se with subject line "GDPR Request — [type of request]". We will respond within 30 days. In complex cases, we may extend this by a further 60 days but will inform you. There is no charge for requests unless they are manifestly unfounded or excessive.

04

International Data Transfers

Diginext Sweden AB processes personal data primarily within the European Economic Area (EEA). Where we transfer data outside the EEA, we ensure appropriate safeguards are in place in accordance with Chapter V of GDPR — including Standard Contractual Clauses (SCCs) or adequacy decisions.

Our primary processing and storage infrastructure is located in Sweden and Norway, within the EEA.

05

Data Breaches

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Swedish Authority for Privacy Protection (IMY) within 72 hours of becoming aware, in accordance with Article 33 GDPR.

Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay (Article 34 GDPR), unless the data was encrypted or other mitigating factors apply.

06

Supervisory Authority

You have the right to lodge a complaint with the competent supervisory authority if you believe your personal data has been processed in a manner inconsistent with GDPR. In Sweden, this is:

Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm, Sweden
www.imy.se +46 8 657 61 00

We encourage you to contact us first at info@diginext.se before raising a complaint with the supervisory authority, as we will endeavour to resolve any concerns promptly and directly.