Skip to content
navigate open esc close
House of Entertainment

Privacy Policy

Your privacy matters to us

Sweden Entertainment Group AB ("SEG","we","us") is committed to protecting your privacy. This policy explains what personal data we collect, why we collect it, how we protect it, and your rights – in accordance with the EU General Data Protection Regulation (GDPR, Regulation 2016/679), the Swedish Data Protection Act (2018:218), and the Swedish Electronic Communications Act (LEK, 2022:482).

1. Data Controller

CompanySweden Entertainment Group AB
Org. No.559469-3904
Registered seatStockholm
Emailinfo@seglive.se
Phone+46 733 824 941
Websiteseglive.se

If you have questions about how we process your personal data, please contact us.

2. What Personal Data Do We Collect?

We collect the minimum amount of data necessary to provide our services. We never collect sensitive personal data (Article 9 GDPR).

Information you provide

  • Booking enquiries: Name, email, phone number, company name, event details (type, date, venue, guest count, budget), and how you found us.
  • Contact form: Name, email, and your message.
  • Newsletter: Email address.
  • Artist applications: Name, contact details, and information about your act/entertainment.

Information collected automatically

  • Technical data: IP address (anonymised), browser type, operating system, and page views – handled by Cloudflare as our infrastructure provider, solely for security and performance.

We use no third-party analytics tools (such as Google Analytics, Facebook Pixel, or similar). We set no tracking cookies.

3. Why We Process Your Data

We process personal data only when we have a clear legal basis under GDPR Article 6:

Purpose Legal Basis Data
Handle booking enquiries and send quotes Contract / Pre-contractual steps (Art. 6.1b) Name, email, phone, event details
Fulfil booked assignments Contract (Art. 6.1b) Contact and event information
Invoicing and bookkeeping Legal obligation (Art. 6.1c) – Swedish Bookkeeping Act (BFL 7:2) Name, address, invoice details
Send newsletters Consent (Art. 6.1a) Email address
Respond to enquiries Legitimate interest (Art. 6.1f) Name, email, message
Website security and operations Legitimate interest (Art. 6.1f) Anonymised IP, technical data

4. How Long Do We Keep Your Data?

We apply the principle of storage minimisation and retain data only as long as there is a purpose or legal requirement:

Data Type Retention Period Basis
Enquiries that don't lead to a contract 12 months Legitimate interest
Contract information Duration of contract + 36 months Contract + Legitimate interest
Invoice and bookkeeping records 7 years from end of fiscal year Swedish Bookkeeping Act (BFL 7:2)
Newsletter subscription Until you unsubscribe Consent
Contact enquiries 12 months Legitimate interest

5. Where Is Your Data Stored?

All data we store digitally is handled exclusively within the EU/EEA. Our infrastructure runs on Cloudflare with EU jurisdiction enforcement:

  • Databases (Cloudflare D1): Locked to EU jurisdiction – data cannot be stored or processed outside the EU.
  • File storage (Cloudflare R2): Locked to EU jurisdiction – all uploaded files remain within the EU.
  • Applications (Cloudflare Workers): Configured to execute in the EU (Stockholm/Arlanda region).

No personal data is transferred to third countries (outside the EU/EEA). We have no integrations with US-based cloud or analytics services that would entail such transfers.

6. Who May We Share Your Data With?

We never sell your personal data. We may need to share certain information with:

  • Artists and subcontractors: Limited event information (venue, date, contact person) needed to carry out the assignment.
  • Cloudflare, Inc.: Our infrastructure provider (data processor). Cloudflare processes data within the EU in accordance with Standard Contractual Clauses (SCCs) and EU data protection rules.

We ensure that Data Processing Agreements (DPA) are in place with all parties that process personal data on our behalf.

7. Cookies and Tracking

Our website uses no tracking cookies and no third-party marketing cookies.

The only cookies that may be set are technically necessary cookies from Cloudflare (e.g. for DDoS protection and security). These do not require consent under the EU ePrivacy Directive (Article 5.3) and the Swedish Electronic Communications Act (LEK 2022:482, Chapter 9, Section 28), as they are strictly necessary for providing the service you have requested.

Since we use no tracking cookies, marketing cookies, or third-party scripts, there is no need for a cookie consent banner with accept/reject options. There are no scripts to block – only the necessary cookies that Cloudflare sets automatically for security purposes.

Cookie Purpose Duration Type
__cf_bm Cloudflare bot management 30 minutes Necessary
cf_clearance Cloudflare security verification Max 30 minutes Necessary

8. Your Rights Under GDPR

As a data subject, you have the following rights. We respond to all requests within 30 days:

  • Right of access (Art. 15) – You may request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16) – You may request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17) – You may request deletion of your data, provided there is no legal basis requiring us to retain it (e.g. bookkeeping requirements).
  • Right to restriction (Art. 18) – You may request that processing of your data be restricted.
  • Right to data portability (Art. 20) – You may receive your data in a machine-readable format.
  • Right to object (Art. 21) – You may object to processing based on legitimate interest, including any direct marketing.
  • Right to withdraw consent – If you have given consent (e.g. newsletter), you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise your rights, contact us at info@seglive.se. We may need to verify your identity before processing your request.

9. Security Measures

In accordance with GDPR Article 32 (security of processing) and Article 25 (data protection by design and by default), we implement appropriate technical and organisational measures to protect your personal data:

  • Encryption in transit: All communication uses HTTPS/TLS.
  • Encryption at rest: Databases and file storage are encrypted.
  • EU jurisdiction: All infrastructure is locked to the EU.
  • Access control: Strictly limited access to personal data.
  • DDoS protection: Via Cloudflare's network.
  • No third-party code: We do not use WordPress, plugins, or external code that could pose security risks.
  • Continuous updates: Our software is updated on an ongoing basis.

10. Automated Decision-Making

We do not use automated decision-making or profiling (Article 22 GDPR) that produces legal effects concerning you or similarly significantly affects you. All decisions involving your personal data are made by natural persons.

11. Children

Our services are intended for businesses and individuals aged 18 or older. We do not knowingly collect personal data from children under 16 years of age.

12. Complaints

If you believe we are handling your personal data incorrectly, you have the right to lodge a complaint with the Swedish supervisory authority:

AuthorityIntegritetsskyddsmyndigheten (IMY) – Swedish Authority for Privacy Protection
Websitewww.imy.se
Emailimy@imy.se
Phone+46 8 657 61 00

13. Changes to This Policy

We may update this privacy policy from time to time. The latest version is always available on this page. In case of material changes, we will actively inform affected data subjects.

14. Applicable Legislation

This policy is based on and shall be interpreted in accordance with the following legal frameworks:

  • GDPR – EU General Data Protection Regulation (2016/679)
  • Dataskyddslagen – Swedish supplementary Data Protection Act (2018:218)
  • LEK – Swedish Electronic Communications Act (2022:482) – cookies and electronic marketing
  • Bokföringslagen – Swedish Bookkeeping Act (1999:1078) – retention of accounting records
  • Aktiebolagslagen – Swedish Companies Act (2005:551) – company information on website
  • Distansavtalslagen – Swedish Distance Selling Act (2005:59) – pre-contractual disclosure requirements

Last updated: 4 March 2026
This policy does not constitute legal advice. Consult a qualified attorney for advice specific to your situation.