Last updated: 8 September 2026
1. Who we are
The Next IT Security events and this website are run by Grand IT Security, Regeringsgatan 93, 111 93 Stockholm, Sweden, company registration number 559522-2802, registered with the Swedish Companies Registration Office (Bolagsverket) on 5 March 2025. Grand IT Security trades as Next IT Security and is the controller of the personal data described here (“we”, “us”).
Our administration — delegate registration, badge production, event logistics, marketing production, website maintenance and invoicing — is carried out from Belgrade by two companies that work for us:
- Capital Summits d.o.o., Durmitorska 20, 11000 Belgrade, Serbia, company registration number 21739596, tax identification number 112788645
- Techbook Digital, Bulevar Vudroa Vilsona 21, 11000 Belgrade, Serbia, company registration number 66057356, tax identification number 112370010
For everything to do with delegates, speakers and this website, those two companies act as our processors: they handle personal data only on our written instructions, under a data processing agreement, and never for purposes of their own. Responsibility towards you stays with Grand IT Security.
Where one of them issues an invoice — a partnership package is invoiced by whichever of the two is named on the invoice — that company is the seller of what is invoiced, and is the controller of its own billing and accounting records for that transaction.
For anything in this policy, write to [email protected] or to the Stockholm address above.
2. What this policy covers
It covers personal data we collect through this website, at our events, and through correspondence with delegates, speakers, partners and sponsors. It does not cover websites we link to, or the platforms our partners run, which have policies of their own.
3. What we collect, why, on what basis, and for how long
| What | Data | Why | Legal basis | Kept for |
| Delegate application and admission | Name, company, job title, business email, phone, LinkedIn profile, promotional code, dietary and access requirements | To assess the application, admit you, produce your badge, and arrange catering and access | Steps taken at your request before entering the agreement, and performance of that agreement (Art. 6(1)(b) GDPR). Dietary and access requirements on the basis of your explicit consent (Art. 9(2)(a)) | The current and the following edition, then deleted |
| Introducing you to the partners of your edition | Name, job title, company, company switchboard number, business email address, LinkedIn profile | Partners fund the event in order to meet the people attending it. Sharing these six fields is what makes that meeting possible, and it is what we tell you on the application form | Our legitimate interest, and the partners’ legitimate interest, in the introductions the event exists to create (Art. 6(1)(f)), subject to your right to object — see section 5 | The current and the following edition, then deleted |
| Badge scanning at events | The code on your badge, the partner who scanned it, the time of the scan | To record which partners you met, so that the right follow-up reaches you | The same legitimate interest as above. If you have objected, a scan of your badge returns no personal data at all | The current and the following edition, then deleted |
| Enquiry and partnership forms | Name, company, job title, business email, phone, LinkedIn profile | To answer the enquiry and discuss participation or partnership | Steps taken at your request before entering a contract (Art. 6(1)(b)); our legitimate interest in responding to business enquiries (Art. 6(1)(f)) | 5 years after last contact |
| Partnership contracts and invoicing | Contact details of the people who sign and administer the contract, billing details, transaction references | To agree the package, deliver it, invoice it and keep the accounts | Performance of a contract (Art. 6(1)(b)) and legal obligations to keep accounting records (Art. 6(1)(c)) | As the accounting law applicable to the invoicing company requires |
| Speakers | Name, job title, company, biography, photograph, session materials, travel details | To publish the programme, host the session and arrange travel | Performance of a contract (Art. 6(1)(b)); our legitimate interest in publishing our own programme (Art. 6(1)(f)) | 5 years after the edition |
| Newsletter and event announcements | Email address, name | To send invitations, agendas and announcements | Your consent (Art. 6(1)(a)), given by ticking the box on the form, which you may withdraw at any time | Until you unsubscribe; the record of the unsubscribe is kept so that we do not write to you again |
| Website usage | Pages viewed, approximate location, device, referring source, advertising identifiers | To understand how the site is used and to measure our advertising | Your consent, given through the cookie banner (Art. 6(1)(a)) | 2 years |
| Photography and filming at events | Images and recordings in which you may appear | To document the event and promote future editions | Our legitimate interest in documenting our own events (Art. 6(1)(f)), subject to your right to object — see section 9 | 5 years |
Attending as a delegate is free of charge and by invitation, so we do not hold payment details for delegates.
We do not knowingly collect data from anyone under 18, and our events are not directed at them.
We do not use your data for automated decision-making that produces legal effects for you. An application that does not meet the admission criteria is declined by a person, not by a system.
4. Who we share it with
We use the service providers below. They process personal data on our instructions, under written agreements, and are not permitted to use it for their own purposes.
| Provider | What for | Where |
| Capital Summits d.o.o. | Registration, badge production, event logistics, marketing production, website maintenance, invoicing | Serbia |
| Techbook Digital | Registration, badge production, event logistics, marketing production, website maintenance, invoicing | Serbia |
| Google (Workspace, Analytics, Tag Manager) | Business email, website measurement | EU / United States |
| Cloudflare | Website delivery and security | EU / United States |
| Mailjet | Sending email | EU |
| Mailchimp | Sending email | United States |
| Advertising and advertising measurement | EU / United States | |
| Wistia | Video hosting on this website | United States |
| unlimited.rs | Website hosting | Serbia |
| Venues and on-site suppliers | Only the details needed to admit you and cater for you | Country of the edition |
We also disclose personal data where the law requires it, and to our professional advisers where necessary. We do not sell personal data.
5. Partners and sponsors
Our events are funded by partners, and what a partner buys is the chance to meet the people in the room. We are direct about what that means for you, and about where it stops.
A partner of the edition you attend receives six fields: your name, job title, company, the company switchboard number, your business email address and your LinkedIn profile. We tell you this on the application form, in these words:
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
A partner never receives your direct telephone number or your private email address. That is not a setting that can be changed. Those fields are held separately and are not part of the record from which partner lists are produced.
You can object, and still attend. Write to [email protected] at any time, before or after the event. We take you off the partner list, your badge stops returning data when it is scanned, and we tell every partner that has already received your details to stop using them and delete them. Objecting has no effect on your place at the event.
From the moment a partner receives the list, that partner is an independent controller of the information and answers for what it does with it under its own privacy policy. Partners receive the list under a written agreement that limits use to following up on the edition you attended, forbids passing it on, and requires deletion within 24 months.
6. Where your data goes
Our events take place across Europe. Our back office, and part of our supply chain, are in Serbia, which is not covered by a European Commission adequacy decision. Those transfers are made under the European Commission’s standard contractual clauses (Implementing Decision (EU) 2021/914), supported by a transfer impact assessment and by technical measures — encryption in transit, access control, and the separation of fields described in section 5.
Transfers to providers in the United States are made either under the EU–US Data Privacy Framework, where the provider is certified under it, or under the same standard contractual clauses.
You may ask us for a copy of the safeguards that apply to any specific transfer.
7. How long we keep it
We keep personal data for the periods in section 3, then delete it or anonymise it. Where the law requires a longer period — accounting records in particular — that period applies instead.
8. Your rights
Under the GDPR you may ask us to:
- give you a copy of the personal data we hold about you (Art. 15)
- correct it if it is wrong (Art. 16)
- delete it (Art. 17)
- restrict how we use it (Art. 18)
- send it to you or to someone else in a portable form (Art. 20)
You may object to processing we carry out on the basis of legitimate interests — including the partner list in section 5 and photography at the events (Art. 21). You may withdraw consent where you gave it, such as for our newsletter, at any time, and that does not affect anything done before you withdrew it (Art. 7(3)).
Write to [email protected]. We answer within one month, and tell you if we need the extension the GDPR allows for complex requests. There is no charge.
If you are not satisfied, you may complain to the data protection authority where you live or work, or to the Swedish authority that supervises us: Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, Sweden, imy.se.
9. Photography and filming
We photograph and film our events. If you would rather not appear, tell us at registration or at the welcome desk; we mark it on your badge and instruct the photographer. If you find yourself in a published image and want it removed, write to us and we remove it.
10. Cookies
The site uses cookies that are necessary for it to work, and — only with your consent — cookies that measure how the site is used and how our advertising performs. You can change your choice at any time through the cookie settings link in the footer. The detail is in our Cookie Policy.
11. Security
We hold personal data on services protected by access control, encryption in transit, and restricted administrative access, and it is available only to the people who need it for the task in front of them. No system is perfect; if a breach affects your data and is likely to present a risk to you, we tell you and the supervisory authority within the periods the law requires — 72 hours to the authority, and without undue delay to you.
12. Changes
We update this policy when what we do changes. The date at the top shows the current version. Where a change materially affects you, we say so directly rather than rely on you noticing.
13. Contact
Grand IT Security
Regeringsgatan 93, 111 93 Stockholm, Sweden
Company registration number 559522-2802
+46 (0) 700 61 45 08
We have not appointed a Data Protection Officer. Article 37 GDPR does not require one for the processing described here, and the contact above reaches the person who answers for it.