The short version
- We only collect personal data that we need to handle your booking, organise the conference and provide related services.
- We never sell your personal data.
- We never receive or store your full card details. Card payments are handled by Stripe.
- Attendee and booking data is normally deleted or anonymised no later than 12 months after the conference. Information that must be retained under Swedish law, such as accounting records, is kept for the legally required period.
- You can ask to access or correct your personal data and, where applicable, have it deleted. You can also object to certain processing or withdraw consent where processing is based on consent.
- Questions? Contact us at testcoast@testscouts.se.
- Who is responsible
- What personal data we collect
- Why we process personal data
- Dietary requirements
- Photos and filming
- Who we share personal data with
- Transfers outside the EU/EEA
- How long we keep personal data
- Emails and marketing
- Cookies
- Security
- Your rights
- Changes to this Privacy Policy
1. Who is responsible
Test Scouts Sweden AB (organisation number 559010-8246), Åvägen 14-15, 41250 Göteborg, Sweden, is the data controller for the personal data described in this Privacy Policy.
For questions about privacy or how we process your personal data, contact testcoast@testscouts.se.
2. What personal data we collect
| Whose data | What |
|---|---|
| The person making the booking | Name, email address, optional phone number, company or organisation, organisation number and VAT number where applicable, invoice address, and invoice reference or similar billing information. |
| Attendees | For each attendee: name, email address, company or organisation, answers to registration questions (such as role or dietary requirements), selected sessions or workshops, and information about conference check-in. |
| Payments | Amount paid, payment method, payment and refund references, invoice numbers and credit note numbers. Card payments are handled by Stripe. We do not receive or store your full card details. |
| Communication | Communications related to your booking, such as booking confirmations, tickets and other transactional emails, whether an email was successfully delivered, and whether you have opted out of marketing communications. |
| Technical data | IP address, browser information, timestamps, and security and server logs. This is primarily used for security, troubleshooting and preventing misuse. |
| Photos and recordings | Photography and filming may take place during the conference. See section 5. |
Booking on behalf of someone else
If you provide personal data about another attendee, you are responsible for having the right to provide that information to us and for making the attendee aware of this Privacy Policy.
Each attendee receives their ticket by email and can contact us directly regarding their personal data.
3. Why we process personal data
| Purpose | Legal basis (GDPR) |
|---|---|
| Managing bookings: registrations, tickets, payments, invoices, booking changes, ticket transfers, refunds and customer service | Performance of a contract (art. 6(1)(b)) |
| Running the conference: entrance and check-in, badges, session and workshop administration, catering and other practical arrangements | Performance of a contract (art. 6(1)(b)). Special rules apply to dietary information, see section 4 |
| Accounting: retaining invoices, receipts, payment information and other accounting records where required by law | Legal obligation (art. 6(1)(c)), including obligations under the Swedish Bookkeeping Act |
| Conference information: matters directly connected with your booking or participation, such as programme changes, practical information, venue information, important conference updates and post-event feedback | Performance of our contract with you and/or our legitimate interest in administering and improving the conference (art. 6(1)(b) and/or 6(1)(f)), depending on the nature of the communication |
| Security and fraud prevention: protecting our systems, preventing fraud and misuse, and protecting tickets and bookings | Legitimate interest (art. 6(1)(f)) |
| Sharing with sponsors: if you opt in, passing your name, company and email address to the conference's sponsors so they can contact you | Consent (art. 6(1)(a)). Optional, never pre-selected, and can be withdrawn at any time, see section 6 |
| Statistics about ticket sales, attendance, sessions and similar conference information. Where possible, statistics are aggregated or anonymised | Legitimate interest (art. 6(1)(f)) |
4. Dietary requirements
Providing dietary information is optional.
Dietary requirements may reveal information about health, allergies, religious beliefs or other information that may constitute special categories of personal data under the GDPR. If you voluntarily provide dietary information, you explicitly consent to us processing that information for the purpose of arranging suitable catering (art. 9(2)(a)).
We only share dietary information with the venue, caterer or other parties where necessary to provide suitable food. Dietary information is deleted after the conference when it is no longer required.
You can withdraw your consent at any time before the conference by updating your booking, where that functionality is available, or by contacting us at testcoast@testscouts.se. Withdrawal of consent does not affect processing that took place before the consent was withdrawn.
5. Photos and filming
Photography and filming may take place during the conference. We may use photos and recordings to:
- document the conference,
- communicate about the conference,
- publish information about the event on our websites and social media channels, and
- promote future events.
For general conference photography and recordings, our legal basis is our legitimate interest (art. 6(1)(f)) in documenting and communicating our events. We will inform attendees that photography and filming take place.
If you do not wish to appear in identifiable photos or recordings, please tell us at the registration desk or contact us at testcoast@testscouts.se. We will take reasonable steps to respect your request. You may also object to our continued use of an identifiable image or recording of you by contacting us.
Separate arrangements may apply to speakers, interviews, staged photography and other situations where an individual is deliberately the main subject of a recording.
6. Who we share personal data with
We never sell personal data. We only share personal data where necessary to organise and operate the conference or where required by law.
- Stripe processes card payments. Stripe may process payment-related personal data on our behalf and may also process certain information for its own purposes as a data controller, for example for fraud prevention, security and regulatory compliance. Stripe's role depends on the particular processing activity; see Stripe's privacy policy. We do not receive or store your full card details.
- IT service providers for hosting, operation of the ticketing system, email delivery and technical infrastructure. Where these providers process personal data on our behalf, they do so under appropriate data processing agreements.
- Venue and catering providers receive only information necessary to provide their services, such as attendee numbers and relevant dietary requirements.
- Authorities, where required by law, for example the Swedish Tax Agency.
- Conference sponsors, only if you have opted in. See below.
Sponsors
We do not share attendee information with sponsors unless the attendee has actively opted in. If a conference has sponsors, you can choose when booking, or later on your booking page, to let us share your name, company and email address with the sponsors named next to the checkbox. Only the attendee can give this consent; ticking it on behalf of another attendee has no effect.
Each sponsor that receives your details becomes an independent data controller and is responsible for how it uses them under its own privacy policy. You can withdraw your consent at any time on your booking page (“Stop sharing”) or by contacting us. We will then not share your details with sponsors again, but details already shared remain with the sponsor; contact the sponsor directly to have them removed.
Company bookings: if your employer or another organisation books tickets on your behalf, the person administering that booking may have access to information about the tickets included in the booking.
7. Transfers outside the EU/EEA
We aim to process and store personal data within the EU/EEA where reasonably possible. Some service providers, including Stripe, may process or transfer personal data outside the EU/EEA.
Where personal data is transferred outside the EU/EEA, we require an appropriate legal mechanism and safeguards in accordance with the GDPR. Depending on the provider and transfer, these safeguards may include:
- an adequacy decision by the European Commission, including the EU–US Data Privacy Framework where applicable, or
- the European Commission's Standard Contractual Clauses.
8. How long we keep personal data
We do not keep personal data longer than necessary for the purposes for which it was collected.
- Attendee and booking information (names, email addresses, registration answers, session selections, check-in information and similar) is deleted or anonymised no later than 12 months after the conference, unless we have a legal reason to retain particular information for longer.
- Dietary information is deleted after the conference when it is no longer needed.
- Your sponsor-sharing choice (whether and when you opted in) is kept together with your attendee information and deleted at the same time.
- Accounting information (invoices, receipts and payment records) is retained for the period required under the Swedish Bookkeeping Act. This generally means until the end of the seventh year following the calendar year in which the relevant financial year ended.
- Unfinished bookings, where registration or payment was never completed, are deleted within 12 months, unless the information needs to be retained for another legitimate reason.
- Marketing opt-outs: information necessary to record that someone has opted out of marketing communications may be retained for as long as necessary to ensure that the person's preference is respected.
- Server logs are normally retained for no longer than 90 days, unless longer retention is necessary to investigate a security incident or comply with a legal obligation.
9. Emails and marketing
Booking and conference emails
If you register for the conference, we will send communications necessary to manage your booking and participation, such as booking confirmations, tickets, invoices and receipts, payment information, important programme changes, venue information and other important information relating to your attendance. You cannot unsubscribe from communications that are necessary to administer an active booking.
Information about future events
Where permitted by applicable law, we may send previous customers information by email about similar conferences and events. Where we rely on the existing-customer exception under Swedish marketing law, you will be given a clear and easy opportunity to decline such marketing when your email address is collected and in every subsequent marketing email. Where consent is required, we will ask for consent before sending marketing communications.
You can opt out of marketing communications at any time. Opting out does not affect transactional emails relating to an existing booking.
10. Cookies
We only use cookies and similar technologies that are necessary to provide the website, booking system, payment functionality and security. Necessary cookies do not require consent under the Swedish Electronic Communications Act.
| Cookie | Purpose | Typical duration |
|---|---|---|
csrftoken | Protects forms against forgery and other security threats | Up to 1 year |
messages | Displays confirmation or system messages | Until displayed |
sessionid | Maintains authorised staff sessions | Up to 2 weeks |
| Stripe payment cookies | Payment security and fraud prevention | Depends on Stripe |
We do not use analytics, advertising or behavioural tracking cookies unless this Privacy Policy and our cookie information are updated accordingly and any legally required consent mechanism is introduced.
11. Security
We use appropriate technical and organisational measures to protect personal data, including encrypted HTTPS connections, access controls, role-based permissions, logging of sensitive administrative actions, and limiting access to people who need the information for their work.
Your personal booking page may be accessible through a unique private link. You should treat this link as confidential. If you believe someone else has gained access to your booking link, contact us at testcoast@testscouts.se.
12. Your rights
Under the GDPR, you may have the right to:
- access the personal data we hold about you,
- have inaccurate personal data corrected,
- have personal data erased where the conditions for erasure are met,
- request restriction of processing,
- object to processing based on legitimate interest,
- object to direct marketing,
- receive certain information in a portable format where the right to data portability applies, and
- withdraw consent at any time where processing is based on consent.
Some rights are subject to exceptions. For example, we cannot delete information that we are legally required to retain for accounting purposes.
To exercise your rights, contact testcoast@testscouts.se. We will respond without undue delay and normally within one month, as required by the GDPR.
If you believe that we process your personal data incorrectly, you also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten – IMY).
13. Changes to this Privacy Policy
We may update this Privacy Policy, for example if our booking system changes, we introduce new services, we change service providers, or applicable legal requirements change. The latest version will always be published on this website.
If we make a significant change that affects people with active bookings, we will provide appropriate information about the change, for example by email.
Last updated: 27 September 2026
