Privacy Policy
Last updated: 12 May 2026
This policy explains how Insight Harbor HQ ("we", "us", "our") collects, uses, shares and protects personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the ePrivacy Directive as implemented nationally, and the applicable data protection laws of Sweden, Finland, Norway and Denmark. It applies to this website, our newsletter, our contact and enquiry channels, and to personal data we process when providing consultancy services. Please read it alongside our Cookies Policy and Terms of Service.
1. Data controller
The controller responsible for the personal data described in this policy is Insight Harbor HQ, registered office Scheelevägen 15, 223 70 Lund, Sweden. We determine the purposes and means of the processing set out below. For any privacy matter, to exercise your rights, or to raise a concern, contact us at privacy@insightharborhq.com. We aim to respond to all privacy requests within one month, as required by Article 12(3) GDPR; where a request is complex or numerous we may extend this by up to two further months and will tell you if we do. Insight Harbor HQ is owned and operated by Design Solutions Jarosław Apanasewicz (ul. gen. Antoniego Madalińskiego 101/16, 50-443 Wrocław, Poland; NIP PL8871760988, REGON 022011624), which is the legal entity behind this website and the controller of your personal data.
2. Scope and legal framework
We process personal data under the GDPR together with the national data protection acts of Sweden (the Data Protection Act 2018:218 supplementing the GDPR), Finland (Tietosuojalaki 1050/2018), Norway (Personopplysningsloven, which incorporates the GDPR into Norwegian law via the EEA Agreement) and Denmark (Databeskyttelsesloven). Where any national rule imposes a stricter or more specific requirement than the GDPR, the stricter rule applies to the relevant processing. This policy does not limit any mandatory statutory rights you have under those laws.
3. Personal data we collect
We collect: (a) identity and contact data you provide — your name, email address, company or organisation, job title and any details in your message — when you use a contact or enquiry form, book a discovery call, or correspond with us; (b) newsletter data — your email address and subscription and delivery status — if you subscribe; (c) engagement data — the business contact details, project information and correspondence generated when you become a client; and (d) technical and usage data — such as your IP address (anonymised for analytics), browser and device type, pages visited and referring source, and the cookie and consent identifiers described in our Cookies Policy. We do not deliberately collect special categories of data (Article 9 GDPR) through this website, and ask that you do not send us such data in free-text fields.
4. Sources of the data
Most personal data we hold comes directly from you when you contact us, subscribe, or engage our services. Technical and usage data is generated automatically by your interaction with the website, subject to your cookie choices. In the course of an engagement we may also receive business contact data about your colleagues from you or from publicly available professional sources; where we do, we process it under legitimate interests for the purpose of delivering the engagement.
5. Purposes and legal bases
We process each category of data for a specific purpose and legal basis: (a) responding to enquiries and providing information you request — legitimate interests (Art. 6(1)(f)) in operating and responding to interest in our business; (b) sending our newsletter — your consent (Art. 6(1)(a)), which you may withdraw at any time; (c) delivering consultancy services and managing the client relationship — performance of a contract (Art. 6(1)(b)) or steps taken at your request before entering one; (d) meeting accounting, tax and other legal duties — compliance with a legal obligation (Art. 6(1)(c)); (e) securing the website, preventing abuse and establishing, exercising or defending legal claims — legitimate interests (Art. 6(1)(f)); and (f) optional analytics — your consent (Art. 6(1)(a)). Where we rely on legitimate interests, we have carried out a balancing assessment and will provide further detail on request.
6. Categories of recipients
Personal data is accessed by authorised Insight Harbor HQ personnel on a need-to-know basis. We also share data with processors who act only on our documented instructions under Article 28 data processing agreements: our hosting and infrastructure provider, our transactional and newsletter email provider, our privacy-friendly analytics provider, and, during engagements, the collaboration and storage tools used to deliver the work. We do not sell personal data and do not share it with third parties for their own marketing. We may disclose data where required by law, court order or a competent authority, or to protect our rights, safety or property.
7. International transfers
We aim to keep personal data within the EU/EEA. Where a processor or a specific service necessarily involves a transfer to a country outside the EU/EEA that does not benefit from a European Commission adequacy decision, we protect the transfer using the Commission's Standard Contractual Clauses (SCCs, Decision (EU) 2021/914) together with a transfer impact assessment and supplementary technical and organisational measures such as encryption. You may request a copy of the relevant safeguards by contacting privacy@insightharborhq.com.
8. Retention periods
We keep personal data only as long as necessary for the purpose for which it was collected: enquiry and contact data for up to 24 months after our last contact, unless an engagement results; newsletter data until you unsubscribe or your address becomes undeliverable; client, contract and accounting records for the statutory retention period of the relevant Nordic jurisdiction — commonly seven years for accounting records (for example under the Swedish Bokf\u00f6ringslag and equivalent Finnish, Norwegian and Danish rules); and analytics data in anonymised or aggregated form for up to 14 months. At the end of the applicable period we securely delete or irreversibly anonymise the data.
9. Your rights
Subject to the conditions in the GDPR, you have the right to: request access to your personal data and a copy of it (Art. 15); have inaccurate data corrected (Art. 16); have data erased where the "right to be forgotten" applies (Art. 17); restrict processing in certain circumstances (Art. 18); receive data you provided in a portable, machine-readable format and have it transmitted to another controller (Art. 20); object to processing based on legitimate interests, and object at any time to direct marketing (Art. 21); and not be subject to solely automated decisions with legal or similarly significant effect (Art. 22). Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
10. How to exercise your rights
To exercise any right, contact privacy@insightharborhq.com with enough detail for us to identify you and understand your request. Exercising your rights is free of charge, though we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, as permitted by Article 12(5). We may need to verify your identity before acting. If we cannot fulfil a request, we will explain why and inform you of your right to complain to a supervisory authority.
11. Security measures
We implement appropriate technical and organisational measures under Article 32 GDPR, including TLS 1.3 encryption in transit, encryption at rest for sensitive stores, role-based access controls and least-privilege administration, network and application hardening, logging and monitoring, regular backups, vendor due diligence and periodic review of our processors, and staff confidentiality obligations. No system can be guaranteed perfectly secure, but we work to protect personal data against unauthorised access, loss, alteration and disclosure.
12. Personal data breaches
We maintain procedures to detect, investigate and respond to personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it (Art. 33), and where the risk is high we will also inform affected individuals without undue delay (Art. 34).
13. Automated decision-making and profiling
Insight Harbor HQ does not carry out automated decision-making that produces legal or similarly significant effects on you within the meaning of Article 22 GDPR through this website, and we do not build marketing profiles of website visitors. Any analytics we perform is aggregated and does not single you out.
14. Children
This website and our services are directed at businesses and professionals, not children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact privacy@insightharborhq.com and we will delete it.
15. Your obligation to provide data
Providing personal data to us is voluntary. However, if you do not provide the contact data required by an enquiry or engagement, we may be unable to respond to you or to deliver the requested service.
16. Changes to this policy
We may update this policy to reflect changes in law, our processing or our services. The effective date shown above marks the current version. Where changes are material we will highlight them on this page and, where appropriate, notify you directly.
17. Supervisory authority and complaints
If you consider that our processing infringes data protection law, you have the right to lodge a complaint with a supervisory authority, in particular in the EU/EEA country of your residence, place of work or the alleged infringement. The relevant Nordic authorities are: Integritetsskyddsmyndigheten (IMY), Sweden; the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), Finland; Datatilsynet, Norway; and Datatilsynet, Denmark. We would appreciate the chance to address your concerns directly before you approach an authority.
18. Contact
For any question about this policy, our processing, or to exercise your rights, write to privacy@insightharborhq.com or to our registered office at Scheelevägen 15, 223 70 Lund, Sweden.
