Privacy Policy – Next IT Security
Last updated: 4 September 2026
1. Who we are
This website is operated by Grand IT Security AB, registered at Regeringsgatan 93, 111 93 Stockholm, Sweden, company registration number 559522-2802 (“we”, “us”).
We are the controller of the personal data described in this policy. For any question about it, write to [email protected].
2. What this policy covers
It covers personal data we collect through this website, through our events, and through correspondence with attendees, speakers, partners and sponsors. It does not cover websites we link to, which have policies of their own.
3. What we collect, why, and on what basis
| What | Data | Why | Basis | Kept for |
| Enquiry and partnership forms | Name, company, job title, email, LinkedIn profile | To answer the enquiry and discuss participation or sponsorship. | Steps taken at your request before entering a contract; legitimate interest in responding to business enquiries. | 5 years after last contact |
| Registration and admission | Name, company, job title, email, phone, dietary and access requirements | To assess the application, admit you to the event, produce your badge, and organise catering and access. | Performance of a contract. Dietary/access requirements on the basis of explicit consent. | 5 years after the event |
| Ticket purchase | Billing details, transaction reference | To process the purchase and issue an invoice. | Performance of a contract, and legal obligation to keep accounting records. | As required by accounting law |
| Newsletter and event announcements | Email address | To send invitations, agendas and announcements. | Consent, which you may withdraw at any time. | Until you unsubscribe |
| Website usage | Pages viewed, approximate location, device, referring source | To understand how the site is used and to measure our advertising. | Consent, given through the cookie banner. | 2 years |
| Photography and filming at events | — | To document the event and to promote future editions. | Legitimate interest in documenting our own events, subject to your right to object — see section 9. | 5 years |
We do not knowingly collect data from anyone under 18, and our events are not directed at them.
4. Who we share it with
We use the following service providers, who process data on our instructions and are bound to protect it:
- Google — business email, and website analytics
- Cloudflare — website delivery and security
- Mailjet and Mailchimp — sending email
- LinkedIn — advertising measurement
- Our web hosting provider — unlimited.rs
- The ticketing platform — effinity.rs, which handles ticket purchases
- Venues and on-site suppliers — only the details needed to admit you and cater for you
We also disclose data where the law requires it, and to our professional advisers where necessary.
5. Sponsors and partners
In the lead-up to an event, we share your job title and organisation with our sponsors and partners, so they are aware of who is attending and can prepare for any discussions that may follow. Sponsors and partners receive only your job title and organisation — not your name, email, phone number, or any other contact detail — and they act as an independent controller in relation to that information.
6. Where your data goes
Our events take place across Europe and some of our providers are based outside the EEA. Where data is transferred outside the European Economic Area, we rely on the European Commission’s standard contractual clauses or an adequacy decision. You may ask us for details of the safeguards that apply.
7. How long we keep it
We keep personal data for the periods set out in section 3, and then delete it or anonymise it. Where the law requires a longer period — accounting records in particular — that period applies instead.
8. Your rights
You may ask us to:
- give you a copy of the data we hold about you
- correct it if it is wrong
- delete it
- restrict how we use it
- send it to you or to someone else in a portable form
You may object to processing we carry out on the basis of legitimate interests, including photography at our events. You may withdraw consent at any time, which does not affect anything done before you withdrew it.
Write to [email protected]. We respond within one month. If you are not satisfied, you may complain to the data protection authority in your country, or to Sweden’s Integritetsskyddsmyndigheten (IMY).
9. Photography and filming
We photograph and film our events. If you would prefer not to appear, tell us at registration or at the welcome desk and we will mark it on your badge and instruct the photographer. If you find yourself in a published image and want it removed, write to us and we will remove it.
10. Cookies
The site uses cookies that are necessary for it to work, and — only with your consent — cookies that measure how the site is used and how our advertising performs. You can change your choice at any time through the cookie settings link in the footer.
11. Security
We hold personal data on services protected by access control, encryption in transit, and restricted administrative access. No system is perfect; if a breach affects your data and is likely to present a risk to you, we will tell you and the relevant authority within the periods the law requires.
12. Changes
We update this policy when what we do changes. The date at the top shows the current version. Where a change materially affects you, we will say so directly rather than rely on you noticing.