Data protection & GDPR
Data protection built into event operations
Eventgo processes personal data as part of delivering professional event management, accreditation and access-control services. Our approach is based on clear responsibilities, controlled processing and appropriate technical and organisational safeguards.
Eventgo Sweden AB · Reg. no. 556402-2704
Controller and Processor responsibilities
In many customer deployments the responsibilities are divided as follows:
- The event organiser (our customer) acts as the Data Controller.
- Eventgo Sweden AB acts as the Data Processor when processing personal data on behalf of the customer.
- Eventgo processes personal data according to the customer's documented instructions and the applicable Data Processing Agreement.
- The customer determines the purposes for which participant data is processed and is responsible for having an appropriate legal basis and for providing the required information to data subjects.
The exact roles can depend on the particular service and the agreement in place. In some situations — for example when Eventgo processes contact information relating to its own customer relationships — Eventgo is the Data Controller for that processing.
Processing for event operations
Eventgo may process the information necessary to provide the contracted event services. Depending on the customer's configuration and the enabled modules, this can include information connected to:
- participants
- accreditation
- access permissions
- groups and roles
- credential production
- shifts and workforce
- integrations
- photographs
- event-specific participant information
The information processed depends on the event, the customer's configuration and the services being used. Not every event environment uses every module or collects every type of information.
Security and controlled access
Eventgo applies technical and organisational measures appropriate to the processing and its risks. The underlying principles include:
- confidentiality
- integrity
- availability
- controlled access to personal data
- protection against unauthorised access, disclosure, alteration or loss
- procedures for restoring availability where appropriate
- ongoing review of relevant technical and organisational safeguards
Detailed information about internal security architecture is not published, as such information can itself introduce risk. Customers can request relevant security information in connection with their agreement.
Sub-processors
Eventgo may use approved sub-processors where necessary to provide the service. In those cases:
- relevant data-protection obligations are passed on contractually to the sub-processor;
- Eventgo remains responsible for its sub-processors in accordance with the applicable agreement;
- customers may receive information about applicable sub-processors in accordance with their Data Processing Agreement.
Data subject requests
When Eventgo processes personal data on behalf of an event organiser, requests concerning that personal data should normally be handled by the organisation acting as Data Controller.
Where applicable, Eventgo assists its customers in responding to requests concerning data-subject rights, in accordance with the applicable agreement. Acting as Processor, Eventgo does not independently decide whether participant information is deleted, changed or disclosed.
If you are a participant at an event and are unsure who to contact, please contact the event organiser in the first instance.
Personal data incidents
Eventgo has processes for handling personal-data incidents. When acting as Processor, Eventgo informs the relevant Controller without undue delay after becoming aware of a personal-data breach affecting data covered by the applicable agreement.
Internal incident-response procedures are not published.
Data Processing Agreements
Where Eventgo processes personal data on behalf of a customer, the processing can be governed by a Data Processing Agreement defining responsibilities, instructions, security requirements, sub-processors, assistance obligations and incident handling.
Eventgo can enter into a Data Processing Agreement with customers where this is required.
Questions about data protection?
Contact Eventgo to discuss privacy, security or Data Processing Agreements for your organisation.
Contact Eventgo