Privacy policy
How Jirango processes personal data — both as the provider of the event platform and when you are in contact with us as a company.
Jirango provides a platform for digital, physical and hybrid events. Personal data is processed on it in two different roles, and that difference decides whom you should turn to with a question.
Your organiser is the data controller
When you register for an event, it is the organiser who decides what data is collected and why. Jirango processes it on the organiser's behalf, as a data processor, under a data processing agreement.
Jirango is the data controller
For our own contacts: visitors to jirango.com, newsletter subscribers, people who book a demo or contact support, and contact persons at customers and suppliers.
Data we process
Which data is involved depends on why you are in contact with us.
- Registering for an event — name, contact details and the information the organiser asks for in their form, for example organisation, role, special diet, choice of sessions and accommodation. The data is decided by the organiser, not by us.
- Participation — check-in, session attendance, chat messages, questions, votes in polls and contacts that exhibitors save when scanning.
- Payment — amount, payment method and invoice details. Card details are handled by our payment partner and are not stored by us.
- Communication — email address, mobile number, notification subscriptions, and statistics such as opens and clicks.
- Contact with us — name, company, contact details and the content of your enquiry.
- Technical data — logins, IP address, times and logs needed for operation, security and troubleshooting.
Why we process it
For our own processing we rely on the following legal bases.
- Contract — to deliver the platform to the customer and fulfil what we have agreed.
- Legitimate interest — to develop and secure the service, prevent misuse, keep statistics and contact customers and stakeholders in our business.
- Consent — for newsletters, notifications and non-essential cookies. You can withdraw your consent at any time.
- Legal obligation — accounting records and anything else we are required by law to keep.
How long we keep it
We don't keep data longer than we need to.
- Event data — for as long as the organiser has an agreement with us, and after that as agreed. The organiser can request deletion or export of their event.
- Accounting records — seven years under the Swedish Accounting Act.
- Newsletter — until you unsubscribe.
- Enquiries and support cases — normally 24 months after the most recent contact.
- Logs — normally 12 months.
Who has access
The data is never sold on. It is only shared when this is needed for the service to work:
- The organiser and the people the organiser has given permissions in their event.
- Sub-processors — hosting providers, email and text message providers, payment service and support system. All are bound by agreements and may only process the data according to our instructions. A current list is available on request.
- Public authorities when we are required to by law.
Where the data is kept
Jirango is hosted within the EU/EEA. If a supplier were to involve a transfer to a country outside the EU/EEA, it would only take place on a valid legal basis — primarily the European Commission's standard contractual clauses — and with the additional safeguards required.
Security
We protect the data with encryption in transit, access control and permissions per role, logging of changes, backups and incident management procedures. Permissions in the platform are set by the organiser, who thereby also controls who in their own organisation sees what.
Cookies
We use essential cookies for signing in and basic functionality, and cookies for statistics that show how the website is used. Non-essential cookies are only set once you have given your consent, and you can change your choice at any time.
The statistics are collected with Google Analytics 4, which Google provides and processes on our behalf. The IP address is anonymised and is not stored by the tool, and the statistics are kept for 14 months. The data may be processed in the USA, on the basis of the EU–US Data Privacy Framework and the European Commission's standard contractual clauses. The cookies are named _ga and _ga_NDGZZR87J5 and remain for up to 13 months. If you say no, the tool is not loaded at all, and nothing is sent to Google.
Your rights
Under the General Data Protection Regulation you have the right to:
- know what data we process about you, and get a copy
- have incorrect data corrected
- have data erased when we no longer need it
- request that the processing be restricted, or object to it
- receive the data you yourself have provided in a machine-readable format
- withdraw a consent you have given
If your question concerns data in an event you have registered for, you should turn to the organiser, who is the data controller. If you contact us, we will help you on to the right party.
Complaints
If you are not satisfied with how your personal data is processed, you can turn to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten), imy.se, which is the supervisory authority in Sweden.
Changes to the policy
We update this policy when the service or the legislation changes. Significant changes are communicated to our customers. The date at the top shows when it was last changed.