Last updated: 8 September 2026
Partners come to Next IT Security to meet the people in the room, and delegates come knowing that. This page sets out exactly how that works under the GDPR — what a partner receives, what it never receives, what a delegate is told and when, and how a delegate can be taken off the list without losing their place.
1. Who is responsible for what
| Role | Who | What it means |
| Controller | Grand IT Security, Regeringsgatan 93, 111 93 Stockholm, Sweden, company registration number 559522-2802 | Decides why and how delegate data is processed, and answers for it |
| Processors | Capital Summits d.o.o., Durmitorska 20, 11000 Belgrade, Serbia (reg. 21739596, TIN 112788645) and Techbook Digital, Bulevar Vudroa Vilsona 21, 11000 Belgrade, Serbia (reg. 66057356, TIN 112370010) | Our back office. Run registration, badges and event logistics on our written instructions only, under a data processing agreement |
| Independent controller | Each partner of an edition, from the moment it receives a delegate list | Decides for itself how it follows up, and answers for that under its own privacy policy |
| Supervisory authority | Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, Sweden | The authority that supervises us, and where a complaint about us can be made |
2. What a partner receives
A partner of the edition receives six fields about each delegate on the list, and no more:
- name
- job title
- company
- the company switchboard number
- business email address
- LinkedIn profile
3. What a partner never receives
A direct telephone number and a private email address are never shared — not on request, not as a favour, and not for a delegate who is on the list for everything else.
This is protected at the point of entry, not by a setting. The record from which badges and partner lists are produced contains only the six fields above. A direct number or a private address, where we hold one at all, sits in a separate record that no partner-facing export reaches. There is no checkbox anywhere whose mis-setting could release it.
4. The legal basis, stated plainly
We rely on legitimate interests (Art. 6(1)(f) GDPR): our interest in running an event that partners fund, the partners’ interest in reaching the executives who came to discuss those subjects, and the delegate’s own interest in being contacted about the agenda they signed up for. All three point the same way, which is what makes the balance work.
The test that goes with that basis has three parts, and we can answer each of them:
| Question | Our answer |
| Is the interest legitimate? | Yes. Introductions between security leaders and vendors are the stated purpose of the event, on every page of this site and in the invitation itself. |
| Is the processing necessary for it? | Yes, and it is kept to the minimum that works: six business-contact fields, only for the partners of the edition the delegate actually attends, and only for follow-up on that edition. |
| Does it override the delegate’s rights? | No. The data is business-contact data, not private data. The delegate is told before applying, in the words quoted in section 5. Direct and private contact details are never included. And the delegate can object at any time and still attend. |
5. What the delegate is told, and when
The application form carries this notice, where it is read before the form is sent, not after:
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
Our invitations and news are a separate matter, and those are sent only to delegates who tick the box asking for them.
6. What we record
For every delegate record we keep the date and time the application was submitted, and the version of the notice above that was on the form at that moment. If a delegate later asks what they were told, the answer exists rather than being reconstructed.
7. Objecting, and what happens next
A delegate objects by writing to [email protected]. There is no form and no charge, and it can be done before or after the event. On an objection we:
- take the delegate off the partner list for that edition and every edition after it;
- make the badge return no personal data when it is scanned;
- tell every partner that has already received the details to stop using them and delete them;
- keep the place at the event exactly as it was.
8. What a partner agrees to
A delegate list is released only under the signed partnership agreement for that edition. In it the partner agrees:
- to use the details only to follow up on the edition the delegate attended;
- to act as an independent controller and to give delegates the information Art. 14 GDPR requires when it first makes contact;
- not to sell the list, and not to pass it to another company;
- to act on an objection notice from us without delay;
- to delete the details when the follow-up is finished, and in any case within 24 months of the edition.
9. How long we keep delegate records
We hold delegate records for the current and the following edition, then delete them. Records tied to an invoice are kept for as long as the accounting law applicable to the invoicing company requires. Where a delegate asks for deletion earlier we delete, except where an accounting obligation stands in the way — in which case the record is restricted rather than kept in use.
10. Where data is processed
Our back office and part of our supply chain are in Serbia, which is not covered by a European Commission adequacy decision. Those transfers are made under the European Commission’s standard contractual clauses (Implementing Decision (EU) 2021/914), supported by a transfer impact assessment. Transfers to providers in the United States are made under the EU–US Data Privacy Framework where the provider is certified, and otherwise under the same clauses. A copy of the safeguards for any specific transfer is available on request.
11. Security and breaches
Personal data is held on services protected by access control, encryption in transit, and restricted administrative access, and is available only to the people who need it for the task in front of them. If a breach is likely to present a risk, we notify IMY within 72 hours of becoming aware of it, and the people affected without undue delay. Where a breach concerns a list a partner already holds, we notify that partner as well.
12. Records of processing
We maintain the record of processing activities required by Art. 30 GDPR, covering each activity in our Privacy Policy, its legal basis, its recipients, its retention period and its transfer mechanism. It is available to the supervisory authority on request.
13. Rights, and how to use them
Every person whose data we hold may ask for a copy of it, ask for it to be corrected or deleted, ask us to restrict how we use it, ask for it in a portable form, object to processing based on our legitimate interests, and withdraw any consent they have given.
Write to [email protected]. We answer within one month and there is no charge. If the answer does not satisfy you, you may complain to the data protection authority where you live or work, or to IMY in Sweden, imy.se.
14. For partners’ legal teams
On request we provide, before the first list is delivered: the data processing agreements covering our Belgrade back office, the standard contractual clauses in use, the wording of the notice in section 5 and its version history, and the partnership data clause described in section 8. Write to [email protected].
15. Contact
Grand IT Security
Regeringsgatan 93, 111 93 Stockholm, Sweden
Company registration number 559522-2802
+46 (0) 700 61 45 08