Privacy Notice
Last updated: 19 April 2026
Scope of this notice
This Privacy Notice explains how Hive Brand Protection AB (“Hive”, “we”, “us”) processes personal data collected through our public website at hivebrandprotection.com.
It does not cover personal data processed as part of our brand protection services delivered to clients. That processing is governed by a separate privacy notice and the Data Processing Agreement entered into between Hive and each client.
Data controller
Hive Brand Protection AB
Swedish org. no. 559560-5931
Norrgatan 10, 432 41 Varberg, Sweden
General privacy contact: privacy@hivebrandprotection.com
Data Protection Officer: Klas Karlsson, dpo@hivebrandprotection.com
What data we collect
Collected automatically when you visit
- IP address and approximate location
- Browser, device and operating system information
- Referring URL and pages visited on our site
- Timestamps and interaction events
- Cookies and similar identifiers — see our Cookies page for a full list
Collected when you contact us or sign up
- Name, email, company and any information you include when you submit a contact form, request a meeting or apply for a job
- Email address if you subscribe to our newsletter
Purposes and legal basis
| Purpose | Legal basis |
|---|---|
| Operating the website, keeping it secure, preventing abuse | Legitimate interest (GDPR Art. 6(1)(f)) |
| Website analytics and measuring how the site performs | Consent (GDPR Art. 6(1)(a)) |
| Advertising and remarketing measurement | Consent (GDPR Art. 6(1)(a)) |
| Responding to contact form and meeting requests | Legitimate interest or, where relevant, steps taken at your request prior to entering into a contract (GDPR Art. 6(1)(b) and (f)) |
| Sending newsletter emails you have signed up for | Consent (GDPR Art. 6(1)(a)) |
| Handling job applications | Steps prior to contract and legitimate interest (GDPR Art. 6(1)(b) and (f)) |
You can withdraw consent at any time by opening the cookie settings from the banner or by unsubscribing from newsletter emails. Withdrawing consent does not affect the lawfulness of processing that took place before withdrawal.
Who we share data with
We use the following categories of processors and service providers to operate this website:
- Amazon Web Services (AWS) — hosting (Amazon S3) and content delivery (Amazon CloudFront). Data may be processed in AWS edge locations globally and at rest within AWS’ EU infrastructure.
- Google LLC — Google Analytics 4, Google Tag Manager and, subject to consent, Google Ads conversion measurement.
- CookieScript — consent management platform that records your cookie choices.
- Meta Platforms Ireland Ltd. — Meta Pixel, used only if you consent to marketing cookies.
- LinkedIn Ireland Unlimited Company — LinkedIn Insight Tag, used only if you consent to marketing cookies.
We do not sell personal data to anyone. We may disclose data if required by law, a court order, or to protect our rights or those of third parties.
International transfers
Some of our service providers are based in the United States. When personal data is transferred outside the EU/EEA, we rely on:
- The EU–US Data Privacy Framework (DPF), where the recipient is certified (this covers Google and Meta), and
- Standard Contractual Clauses (SCCs) approved by the European Commission, together with supplementary technical and organisational measures where required.
Retention
- Analytics data (Google Analytics 4): 14 months at event level, then aggregated.
- Consent records (CookieScript): retained for the duration of the cookie consent (up to 6 months) and as required to evidence compliance.
- Server and CDN access logs: up to 90 days, longer only if needed to investigate a security incident.
- Contact form and meeting requests: for as long as needed to handle your request and up to 24 months thereafter, unless a longer period is required (e.g. for accounting or to defend legal claims).
- Newsletter subscriptions: until you unsubscribe.
- Job applications: up to 24 months after the recruitment decision, unless you ask us to delete earlier.
Your rights
Under the GDPR you have the right to:
- Request access to your personal data
- Request rectification of inaccurate data
- Request erasure (“right to be forgotten”)
- Request restriction of processing
- Object to processing based on legitimate interest
- Request data portability
- Withdraw consent at any time
To exercise any of these rights, contact privacy@hivebrandprotection.com. We will respond within one month.
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY): www.imy.se.
Cookies
See our Cookies page for the full list of cookies used on this site and how to change your preferences.
Changes to this notice
We may update this Privacy Notice from time to time. When we do, we will update the “Last updated” date at the top of this page. Material changes will be communicated through the website or by email where appropriate.