GDPR

Privacy Policy

Last updated: March 2026

Hiper HQ AB ("we", "us", "our"), operating Lönedirektiv.se, is committed to protecting your privacy. This policy explains how we collect, use, and protect your personal data in accordance with the EU General Data Protection Regulation (GDPR).

1. Data Controller

Hiper HQ AB is the data controller for personal data processed through our platform and website. Contact: kontakt@lonedirektiv.se, Stockholm, Sweden.


2. What Data We Collect

We collect: contact information (name, email, phone number) during registration and contact forms; company information (company name, org. number, employee count); salary data and employee information that you upload to the platform; technical data (IP address, browser type, page visits) via cookies; and payment information for subscriptions.


3. Why We Process Your Data

We process personal data to: provide and improve our service; conduct pay gap analyses and generate reports on your behalf; communicate with you about your account and our services; fulfill legal obligations; and send relevant product update information (with your consent).


4. Legal Basis

We process data based on: performance of a contract (delivering the service you pay for); legal obligation (accounting, tax legislation); legitimate interest (service improvement, security); and consent (marketing, cookies).


5. Cookies

We use necessary cookies for the website to function, analytical cookies (with your consent) to understand how the site is used, and functional cookies to save your preferences. You can manage your cookie settings through your browser.


6. Data Retention

We retain your data as long as necessary to fulfill the purpose of processing. Account data is kept for the duration of the customer relationship and deleted within 12 months after the subscription ends. Salary data you upload is deleted when the account is closed. Accounting data is retained for 7 years as required by law.


7. Your Rights

Under GDPR, you have the right to: request access to your personal data; request correction of inaccurate data; request deletion ("right to be forgotten"); request restriction of processing; request data portability (receive your data in machine-readable format); and object to processing based on legitimate interest. Contact us at kontakt@lonedirektiv.se to exercise your rights.


8. Security

We protect your data with encryption in transit (TLS) and at rest, access controls with role-based permissions, regular security audits and penetration testing, and hosting with certified cloud providers within the EU.


9. Contact & Complaints

For questions about our data processing, contact us at kontakt@lonedirektiv.se. If you believe we are violating GDPR, you have the right to file a complaint with the Swedish Authority for Privacy Protection (IMY), imy.se.