Privacy Policy

Last updated: 8 September 2026

1. Who we are

The Next IT Security events and this website are run by Grand IT Security, Regeringsgatan 93, 111 93 Stockholm, Sweden, company registration number 559522-2802, registered with the Swedish Companies Registration Office (Bolagsverket) on 5 March 2025. Grand IT Security trades as Next IT Security and is the controller of the personal data described here (“we”, “us”).

Our administration — delegate registration, badge production, event logistics, marketing production, website maintenance and invoicing — is carried out from Belgrade by two companies that work for us:

  • Capital Summits d.o.o., Durmitorska 20, 11000 Belgrade, Serbia, company registration number 21739596, tax identification number 112788645
  • Techbook Digital, Bulevar Vudroa Vilsona 21, 11000 Belgrade, Serbia, company registration number 66057356, tax identification number 112370010

For everything to do with delegates, speakers and this website, those two companies act as our processors: they handle personal data only on our written instructions, under a data processing agreement, and never for purposes of their own. Responsibility towards you stays with Grand IT Security.

Where one of them issues an invoice — a partnership package is invoiced by whichever of the two is named on the invoice — that company is the seller of what is invoiced, and is the controller of its own billing and accounting records for that transaction.

For anything in this policy, write to [email protected] or to the Stockholm address above.

2. What this policy covers

It covers personal data we collect through this website, at our events, and through correspondence with delegates, speakers, partners and sponsors. It does not cover websites we link to, or the platforms our partners run, which have policies of their own.

3. What we collect, why, on what basis, and for how long

WhatDataWhyLegal basisKept for
Delegate application and admissionName, company, job title, business email, phone, LinkedIn profile, promotional code, dietary and access requirementsTo assess the application, admit you, produce your badge, and arrange catering and accessSteps taken at your request before entering the agreement, and performance of that agreement (Art. 6(1)(b) GDPR). Dietary and access requirements on the basis of your explicit consent (Art. 9(2)(a))The current and the following edition, then deleted
Introducing you to the partners of your editionName, job title, company, company switchboard number, business email address, LinkedIn profilePartners fund the event in order to meet the people attending it. Sharing these six fields is what makes that meeting possible, and it is what we tell you on the application formOur legitimate interest, and the partners’ legitimate interest, in the introductions the event exists to create (Art. 6(1)(f)), subject to your right to object — see section 5The current and the following edition, then deleted
Badge scanning at eventsThe code on your badge, the partner who scanned it, the time of the scanTo record which partners you met, so that the right follow-up reaches youThe same legitimate interest as above. If you have objected, a scan of your badge returns no personal data at allThe current and the following edition, then deleted
Enquiry and partnership formsName, company, job title, business email, phone, LinkedIn profileTo answer the enquiry and discuss participation or partnershipSteps taken at your request before entering a contract (Art. 6(1)(b)); our legitimate interest in responding to business enquiries (Art. 6(1)(f))5 years after last contact
Partnership contracts and invoicingContact details of the people who sign and administer the contract, billing details, transaction referencesTo agree the package, deliver it, invoice it and keep the accountsPerformance of a contract (Art. 6(1)(b)) and legal obligations to keep accounting records (Art. 6(1)(c))As the accounting law applicable to the invoicing company requires
SpeakersName, job title, company, biography, photograph, session materials, travel detailsTo publish the programme, host the session and arrange travelPerformance of a contract (Art. 6(1)(b)); our legitimate interest in publishing our own programme (Art. 6(1)(f))5 years after the edition
Newsletter and event announcementsEmail address, nameTo send invitations, agendas and announcementsYour consent (Art. 6(1)(a)), given by ticking the box on the form, which you may withdraw at any timeUntil you unsubscribe; the record of the unsubscribe is kept so that we do not write to you again
Website usagePages viewed, approximate location, device, referring source, advertising identifiersTo understand how the site is used and to measure our advertisingYour consent, given through the cookie banner (Art. 6(1)(a))2 years
Photography and filming at eventsImages and recordings in which you may appearTo document the event and promote future editionsOur legitimate interest in documenting our own events (Art. 6(1)(f)), subject to your right to object — see section 95 years

Attending as a delegate is free of charge and by invitation, so we do not hold payment details for delegates.

We do not knowingly collect data from anyone under 18, and our events are not directed at them.

We do not use your data for automated decision-making that produces legal effects for you. An application that does not meet the admission criteria is declined by a person, not by a system.

4. Who we share it with

We use the service providers below. They process personal data on our instructions, under written agreements, and are not permitted to use it for their own purposes.

ProviderWhat forWhere
Capital Summits d.o.o.Registration, badge production, event logistics, marketing production, website maintenance, invoicingSerbia
Techbook DigitalRegistration, badge production, event logistics, marketing production, website maintenance, invoicingSerbia
Google (Workspace, Analytics, Tag Manager)Business email, website measurementEU / United States
CloudflareWebsite delivery and securityEU / United States
MailjetSending emailEU
MailchimpSending emailUnited States
LinkedInAdvertising and advertising measurementEU / United States
WistiaVideo hosting on this websiteUnited States
unlimited.rsWebsite hostingSerbia
Venues and on-site suppliersOnly the details needed to admit you and cater for youCountry of the edition

We also disclose personal data where the law requires it, and to our professional advisers where necessary. We do not sell personal data.

5. Partners and sponsors

Our events are funded by partners, and what a partner buys is the chance to meet the people in the room. We are direct about what that means for you, and about where it stops.

A partner of the edition you attend receives six fields: your name, job title, company, the company switchboard number, your business email address and your LinkedIn profile. We tell you this on the application form, in these words:

Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.

A partner never receives your direct telephone number or your private email address. That is not a setting that can be changed. Those fields are held separately and are not part of the record from which partner lists are produced.

You can object, and still attend. Write to [email protected] at any time, before or after the event. We take you off the partner list, your badge stops returning data when it is scanned, and we tell every partner that has already received your details to stop using them and delete them. Objecting has no effect on your place at the event.

From the moment a partner receives the list, that partner is an independent controller of the information and answers for what it does with it under its own privacy policy. Partners receive the list under a written agreement that limits use to following up on the edition you attended, forbids passing it on, and requires deletion within 24 months.

6. Where your data goes

Our events take place across Europe. Our back office, and part of our supply chain, are in Serbia, which is not covered by a European Commission adequacy decision. Those transfers are made under the European Commission’s standard contractual clauses (Implementing Decision (EU) 2021/914), supported by a transfer impact assessment and by technical measures — encryption in transit, access control, and the separation of fields described in section 5.

Transfers to providers in the United States are made either under the EU–US Data Privacy Framework, where the provider is certified under it, or under the same standard contractual clauses.

You may ask us for a copy of the safeguards that apply to any specific transfer.

7. How long we keep it

We keep personal data for the periods in section 3, then delete it or anonymise it. Where the law requires a longer period — accounting records in particular — that period applies instead.

8. Your rights

Under the GDPR you may ask us to:

  • give you a copy of the personal data we hold about you (Art. 15)
  • correct it if it is wrong (Art. 16)
  • delete it (Art. 17)
  • restrict how we use it (Art. 18)
  • send it to you or to someone else in a portable form (Art. 20)

You may object to processing we carry out on the basis of legitimate interests — including the partner list in section 5 and photography at the events (Art. 21). You may withdraw consent where you gave it, such as for our newsletter, at any time, and that does not affect anything done before you withdrew it (Art. 7(3)).

Write to [email protected]. We answer within one month, and tell you if we need the extension the GDPR allows for complex requests. There is no charge.

If you are not satisfied, you may complain to the data protection authority where you live or work, or to the Swedish authority that supervises us: Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, Sweden, imy.se.

9. Photography and filming

We photograph and film our events. If you would rather not appear, tell us at registration or at the welcome desk; we mark it on your badge and instruct the photographer. If you find yourself in a published image and want it removed, write to us and we remove it.

10. Cookies

The site uses cookies that are necessary for it to work, and — only with your consent — cookies that measure how the site is used and how our advertising performs. You can change your choice at any time through the cookie settings link in the footer. The detail is in our Cookie Policy.

11. Security

We hold personal data on services protected by access control, encryption in transit, and restricted administrative access, and it is available only to the people who need it for the task in front of them. No system is perfect; if a breach affects your data and is likely to present a risk to you, we tell you and the supervisory authority within the periods the law requires — 72 hours to the authority, and without undue delay to you.

12. Changes

We update this policy when what we do changes. The date at the top shows the current version. Where a change materially affects you, we say so directly rather than rely on you noticing.

13. Contact

Grand IT Security

Regeringsgatan 93, 111 93 Stockholm, Sweden

Company registration number 559522-2802

[email protected]

+46 (0) 700 61 45 08

We have not appointed a Data Protection Officer. Article 37 GDPR does not require one for the processing described here, and the contact above reaches the person who answers for it.

APPLY FOR ACCESS

Next IT Security

Apply for access to Europe’s leading conference for c-suite cybersecurity executives.

Session reserved
05:00
Your registration session is active. Complete your application within the reserved time.
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Attendance by invitation only
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. October 22, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 12, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · DACH
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 26, Frankfurt.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. March 11, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. April 15, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials