Privacy policy.

HIGHTS Privacy Policy

Last updated: 5 October 2026

1. Who we are

HIGHTS INTO MORNINGS AB is the controller of your personal data. We run HIGHTS, Stockholm's home for good music on good sound since 2016, together with its record label and talent agency.

Company: HIGHTS INTO MORNINGS AB
Org. no.: 556936-7872
Address: Bergtallsvägen 2A, 125 60 Älvsjö, Sweden
Privacy contact: info@hights.se

This policy covers hights.se, HIGHTS membership, our newsletter, our events and our social media channels. It explains what we collect, why, who we share it with and what rights you have.

2. What we collect and why

We only collect what we need for each purpose below. Each purpose has its own legal basis under the GDPR.

HIGHTS membership. Membership is free. It gives you an account, first access to every date, early-tier tickets and exclusive mixes, music and content. Data: name, email, login details and which benefits you use. Legal basis: contract (the membership terms you accept when you sign up).

Selling and delivering tickets, entry and refunds. Data: name, email, phone, order details and ticket scans. Payment is handled by our ticketing partner WERZ, and we never see full card details. WERZ shares your name, email and order with us so we can deliver your ticket and run entry. Legal basis: contract.

Bookkeeping and tax. Data: order and invoice records. Legal basis: legal obligation (Swedish accounting law).

Newsletter and event announcements. Data: email, first name, signup date and source, opens and clicks. Legal basis: consent, and you can unsubscribe at any time.

Messages you send us. Data: name, contact details and message content. Legal basis: legitimate interest in answering you.

Photos and video at events. Data: images where you may appear in crowd shots. Legal basis: legitimate interest in documenting and promoting our events.

Website analytics and ad measurement. Data: cookie IDs, device and browser data, and pages visited. Legal basis: consent via the cookie banner.

Targeted ads on social media. Data: hashed (scrambled) email addresses from our member and newsletter lists, or cookie IDs, matched by Meta. We use them to show HIGHTS news to people who already know us, to leave existing members out of ads, and to reach people with similar taste. Meta deletes hashed emails it cannot match. Legal basis: consent.

Venue safety and guest lists. Data: name on the guest list and age check at the door. Legal basis: legitimate interest and legal obligation.

Event photography. We post signs at the entrance when photographers are present. If you do not want to appear, ask the photographer or email us. We will remove images where you are clearly identifiable.

3. Artists, agents and business contacts

When we book artists or work with agents, venues, sponsors and suppliers, we process contact and contract details so we can run the booking. This includes names, emails, phone numbers, fees, invoicing details, riders, and travel and accommodation details.

For travel bookings we may need passport details and date of birth. We use these only to book the flight or hotel, and we delete them when the engagement is finished.

Our legal bases are contract, legal obligation for invoicing records, and legitimate interest for keeping in touch about future bookings.

4. Cookies and tracking

We only set non-essential cookies after you say yes in our cookie banner. You can change your choice at any time through the cookie settings link in the footer.

Necessary cookies keep the site working and remember your cookie choice. No consent is needed.

Analytics cookies, including Google Analytics, show us which pages people visit so we can improve the site. If you are signed in to Google and allow ad personalisation, Google may add anonymous insights about interests and devices to these reports. These need your consent.

Marketing cookies, including the Meta Pixel and Google Ads, let these platforms measure our ads and show HIGHTS ads to people likely to be interested. These need your consent.

If you decline, the site still works fully. We do not sell your data to anyone.

5. Who we share data with

We share personal data only with partners who help us run HIGHTS, and only what each one needs. Service providers act on our instructions under a data processing agreement.

Squarespace handles website hosting, member accounts and login, signup forms and the newsletter (USA / Ireland).

WERZ, our ticketing partner, handles ticket sales, payment and entry scanning, and with your consent measures ticket sales for our ads (EU).

Meta Platforms handles ads and ad measurement, only with your consent (Ireland / USA).

Google handles analytics and ads, only with your consent (Ireland / USA).

Venues we partner with receive guest lists and handle entry, per event (Sweden).

Our accountant and bank handle bookkeeping and payments (Sweden).

Authorities receive data only when the law requires it (Sweden).

We do not sell your personal data, and we do not share it for reasons not described here.

6. Transfers outside the EU/EEA

Some partners, such as Squarespace, Meta and Google, may process data in the USA. When that happens, we rely on the EU-US Data Privacy Framework where the recipient is certified. Otherwise we rely on the European Commission's Standard Contractual Clauses. Email us for a copy of the safeguards that apply.

7. How long we keep your data

We keep data only as long as the purpose requires, then delete or anonymise it.

Accounting records (orders, invoices): 7 years, as required by Swedish accounting law.

Membership account: kept while your membership is active. We delete it 12 months after you cancel, or after 24 months without a login.

Ticket and entry data not needed for accounting: 12 months after the event.

Newsletter subscription: until you unsubscribe.

Messages and enquiries: 24 months after the last contact.

Artist and business contacts: for as long as we work together, plus 3 years.

Passport and travel details: deleted once the engagement is finished.

Cookie consent choices: 12 months, then we ask again.

Event photos published on our channels: until you ask us to remove them.

8. Your rights

Email info@hights.se to use any of the rights below. We reply within one month, free of charge.

Access: get a copy of the data we hold about you.

Correction: have wrong or incomplete data fixed.

Deletion: have your data erased, except what the law requires us to keep, such as accounting records.

Restriction: ask us to pause processing while a question is resolved.

Portability: receive the data you gave us in a machine-readable file.

Objection: object to processing based on legitimate interest, and to direct marketing at any time.

Withdraw consent: unsubscribe or change cookie settings at any time, without affecting earlier processing.

We may ask you to confirm your identity before acting on a request.

If you are unhappy with how we handle your data, you can complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se. We would appreciate the chance to fix it first.

9. Security, age limits and changes

Security. We limit access to personal data to the people who need it, and we use two-factor login on our accounts. We only work with partners who protect data to GDPR standards. If a breach puts your rights at risk, we will tell you and IMY as the law requires.

Age limits. The age limit for each event depends on the venue and is shown on the event page and ticket listing. HIGHTS membership and our newsletter are for people aged 18 and over. If we learn we hold data about someone under 18 without a valid reason, we delete it.

Changes. We update this policy when our practices change. The date at the top shows the latest version. If a change is significant, we will tell subscribers by email before it takes effect.

© 2026 HIGHTS. All rights reserved.