Privacy policy for SummitHub
This policy describes how MRC Collective AB processes personal data in and around SummitHub.
1. Controller
MRC Collective AB, Swedish company registration no. 559094-1406, Fjallvindsvagen 28, 433 49 Partille, Sweden, is controller for MRC's own processing. When a customer uses SummitHub for a conference, the customer is normally controller for participant data and MRC is processor under the Data Processing Agreement.
2. Data we process
We may process name, email address, organisation, role, language, account settings, invitations, registration data, session choices, food choices, allergies, special diets, invoice data, support cases, technical logs, IP address, user agent, and other information entered into the service.
3. Purposes
We process data to create and administer accounts, provide conference and participant functions, send invitations and system messages, handle support, security, troubleshooting, logging, billing, agreement administration, and legal compliance.
4. Legal basis
Processing is based on contract, legitimate interest, legal obligation, or consent where consent is required. Where MRC processes data on behalf of a customer, processing follows the customer's instructions.
5. Sharing
We share data with suppliers required for operations, hosting, email, support, and security. These suppliers may only process data under agreement and for specified purposes. We do not sell personal data.
6. Retention
Data is stored for as long as needed for the service, agreement, support, security, accounting, legal claims, or statutory obligations. The customer can often export or delete data in the service.
7. Your rights
You may have rights of access, rectification, deletion, restriction, objection, and data portability under GDPR. Contact the organisation that invited you or administers the conference first. For MRC's own processing, contact MRC.
8. Security
MRC uses technical and organisational safeguards to protect data, such as permission management, encrypted communication, logging, backup, and operational monitoring.
9. International transfers
We strive to process data within the EU/EEA. If data is transferred outside the EU/EEA, appropriate safeguards are used, such as Standard Contractual Clauses.
10. Contact
Questions about privacy and data protection can be sent to MRC Collective AB through the contact details stated on mrccollective.se or in the service.