Privacy Policy
Version: 01.06.2026
At Pihr, we are committed to protecting your privacy and ensuring that your personal data is processed securely, fairly, and transparently. This Privacy Policy explains what personal data we collect, how we use it, the legal basis for processing, how long we retain it, and your rights under the General Data Protection Regulation (GDPR) and other applicable data protection laws.
If you have any questions about this Privacy Policy or how we process your personal data, please contact us using the details provided in Section 10.
1. Who is responsible for your personal data?
Pihr AB
Birger Jarlsgatan 60, 114 30 Stockholm, Sweden
Organization Number: 556879-1262
Email: support@pihr.com
Pihr acts as a data controller for personal data collected through our website, events, webinars, marketing activities, and customer administration.
For personal data processed within our customers' pay equity analyses, Pihr may act as either a data processor on behalf of the customer or as an independent data controller, depending on the nature of the service and applicable legal requirements.
2. What personal data do we collect?
Personal data is any information that can directly or indirectly identify an individual.
The personal data we collect depends on your relationship with Pihr.
|
Role |
Description |
Personal Data |
|
Visitor |
Individuals visiting our website, registering for webinars or events, or communicating with us through forms or other channels |
Name, email address, company name, job title, communication history |
|
User |
Individuals using Pihr's products and services |
Name, email address, company name, user account information, usage data |
|
Employee at Customer Company |
Individuals included in a pay equity analysis performed by their employer |
Name, employee identifier (where applicable), company, salary information, employment details, tenure, region, age, position, and other employment-related data provided by the employer |
In addition, we may collect technical information when you visit our website, including:
- IP address
- Browser type
- Device information
- Geographic location (derived from IP address)
- Website usage data
- Cookie and tracking information
For more information, please refer to our Cookie Policy.
3. How do we use personal data?
We process personal data only when we have a lawful basis to do so.
3.1 Visitors
If you visit our website, register for a webinar, attend an event, or otherwise interact with us, we may process your personal data for the following purposes:
|
Purpose |
Legal Basis |
|
Administer registrations and event participation |
Performance of a contract |
|
Communicate regarding events, webinars, and related activities |
Performance of a contract |
|
Send information about future events, products, and services |
Legitimate interest or consent where required |
|
Conduct market research and business development activities |
Legitimate interest |
|
Maintain website security and prevent abuse |
Legitimate interest |
|
Comply with legal obligations |
Legal obligation |
3.2 Users
If you use Pihr's products or services, we may process your personal data to:
- Create and manage user accounts
- Authenticate users and maintain access controls
- Provide support and customer service
- Improve and develop our products and services
- Comply with legal and regulatory obligations
The legal basis for this processing is generally the performance of a contract and Pihr's legitimate interests.
3.3 Employees Included in Pay Equity Analyses
Where your employer uses Pihr's services, personal data may be processed to:
- Perform pay equity analyses and reporting
- Compare compensation and benefits across relevant employee groups
- Conduct benchmarking and statistical analyses
- Support compliance with applicable equal pay and pay transparency laws
- Generate reports and recommendations for customers
Where permitted by applicable law, benchmarking and statistical analyses may include aggregated and anonymized data from multiple organizations. Personal data is never shared between customers in an identifiable form.
Depending on the circumstances, the legal basis for processing may be:
- Compliance with legal obligations
- Legitimate interests
- Performance of a contract between Pihr and the customer
3.4 Product Development
Pihr may use anonymized and aggregated data to improve, develop, test, and validate products and services.
Once data has been anonymized so that individuals can no longer be identified, it is no longer considered personal data under GDPR.
4. How long do we retain personal data?
We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy or to comply with legal obligations.
|
Data Category |
Retention Period |
|
Employment data processed through online services |
Up to 2 hours after processing is completed |
|
Employment data processed through advisory services |
According to contractual obligations with the customer and deleted when no longer required |
|
Anonymized data used for product development |
Indefinite |
|
Webinar and event registration data |
Indefinite |
|
Customer and user account information |
For the duration of the customer relationship and thereafter as required by law |
|
Security and system logs |
As necessary for security, compliance, and operational purposes |
Backup copies may be retained for 1 year in accordance with Pihr's disaster recovery and security procedures.
5. Sharing personal data
Pihr may share personal data with carefully selected third parties where necessary.
5.1 Service Providers
We work with trusted service providers that assist us in operating our business, including providers of:
- Secure hosting and cloud infrastructure
- Customer support systems
- Email delivery services
- Analytics services
- Webinar and event platforms
- Security and monitoring services
These providers may only process personal data on our documented instructions and may not use the information for their own purposes.
5.2 Event and Webinar Partners
Where an event or webinar is jointly organised with a partner, attendee information such as name, email address, company name, and job title may be shared with the partner.
Details about partner data sharing will be provided at the time of registration, and you may opt out where applicable.
5.3 Legal Requirements
We may disclose personal data where required to:
- Comply with legal obligations
- Respond to lawful requests from public authorities
- Protect Pihr's legal rights
- Prevent fraud, abuse, or security incidents
6. International transfers
We primarily process personal data within the EU/EEA.
Some service providers may process personal data outside the EU/EEA, including in the United States.
Where personal data is transferred internationally, Pihr implements appropriate safeguards, including:
- European Commission Standard Contractual Clauses (SCCs)
- Transfer impact assessments where required
- Technical and organisational security measures
Further information regarding international transfers can be obtained by contacting us.
7. Your rights
Under GDPR, you have the right to:
- Access your personal data
- Correct inaccurate personal data
- Request deletion of your personal data
- Restrict processing
- Object to processing based on legitimate interests
- Receive your personal data in a portable format where applicable
- Withdraw consent at any time where processing is based on consent
- Not be subject to solely automated decision-making where applicable
You also have the right to lodge a complaint with your local supervisory authority.
For individuals in Sweden, complaints may be submitted to:
Integritetsskyddsmyndigheten (IMY)
https://www.imy.se
To exercise your rights, please contact us using the details in Section 10.
We aim to respond to all requests within one month, although this period may be extended where permitted by law.
8. Security measures
Pihr maintains appropriate technical and organisational security measures designed to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction.
These measures include:
- Access controls and role-based permissions
- Encryption in transit and at rest where appropriate
- Security monitoring and logging
- Secure software development practices
- Regular security assessments and reviews
- Employee confidentiality and security training
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, Pihr will notify affected individuals and relevant authorities in accordance with applicable law.
9. Changes to this Privacy Policy
Pihr may update this Privacy Policy from time to time.
The latest version will always be available on our website:
https://www.pihr.com/privacy-policy
10. Contact us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact:
Pihr AB
Birger Jarlsgatan 60, 114 30 Stockholm, Sweden
Organization Number: 556879-1262
Email: support@pihr.com