SummitHub
  • Login

Terms

User terms and Data Processing Agreement for SummitHub

Version 1.0 - effective from 2026-07-25

User terms and Data Processing Agreement for SummitHub

Web standard version for SaaS, electronic acceptance, and conference management.

A. User terms

1. Parties and scope

These user terms apply to SummitHub, a SaaS service for conference and event management provided by MRC Collective AB, Swedish company registration no. 559094-1406, Fjallvindsvagen 28, 433 49 Partille, Sweden.

Customer means the legal or natural person that creates an account, orders the service, administers a conference, or otherwise uses the service. A person accepting these terms on behalf of an organisation confirms that they are authorised to represent that organisation.

The terms apply from electronic acceptance, account creation, order, or other activation of the service and remain in force while the Customer has an active account, event, trial, or other right to use the service.

2. The service

SummitHub is a hosted service for creating, publishing, administering, and following up conferences, registrations, participants, sessions, participant choices, invitations, and conference-related messages.

The service may include a web interface, public registration pages, participant pages, admin views, email notifications, invoice data, exports, support, and technical administration.

MRC may update, change, and improve the service continuously, provided that the core function is not materially reduced for active customers without reasonable cause.

3. Account, authority, and acceptance

The Customer is responsible for keeping account information, contact details, organisation affiliation, invitations, and permissions correct, secure, and up to date.

The Customer is responsible for all use through the Customer's accounts, users, and permissions, including use by employees, consultants, participants, and other persons granted access by the Customer.

When terms are accepted electronically, MRC stores evidence of acceptance, including agreement version, date and time, account, email address, IP address, user agent, request id, and other technical log information.

4. Permitted use

The Customer may use the service for lawful conference and event administration connected to the Customer's own activities.

The Customer must ensure that there is a lawful basis for processing participant personal data, that participants receive information required under GDPR and other applicable law, and that invitations and messages are not used in a way that harms MRC, other customers, participants, or third parties.

5. Prohibited use

The Customer may not use the service for spam, phishing, misleading invitations, unlawful content, harassment, intrusion attempts, circumvention of technical limits, or processing of particularly sensitive information without a separate agreement and appropriate safeguards.

MRC may temporarily restrict, stop, or terminate functions, accounts, messages, or access in case of suspected abuse, security risk, unauthorised access, breach of law, non-payment, or material breach of agreement.

6. Customer data

The Customer retains its rights to Customer Data. Customer Data means data, participant lists, registrations, session choices, food choices, allergies, special diets, invoice data, message content, and other material provided or created by the Customer in the service.

MRC may process Customer Data to the extent necessary to provide, secure, troubleshoot, administer, maintain, and improve the service. Where Customer Data contains Personal Data processed on behalf of the Customer, the Data Processing Agreement in part B applies.

MRC does not sell Customer Data and does not use Customer Data for third-party advertising.

7. Fees and payment

Fees, periods, price levels, and any limits are stated in the price list, order, quote, subscription view, invoice data, or separate agreement.

Unless otherwise stated, prices for legal entities are exclusive of VAT. Paid fees are non-refundable on termination, suspension, or non-use unless mandatory law or a separate agreement says otherwise.

8. Availability, operations, and support

MRC strives to provide the service with good availability, security, and stability. Temporary interruptions may occur because of maintenance, updates, operational issues, security measures, or events outside MRC's control.

Support is provided through the contact channels and service levels stated in the service, on the website, or in a separate agreement.

9. Intellectual property and licence

MRC and its licensors retain all intellectual property rights to SummitHub, including software, code, design, trademarks, documentation, operating environment, databases, and other material provided by MRC.

The Customer receives a limited, non-exclusive, non-transferable, and time-limited right to use the service during the agreement term. The Customer may not copy, sell, rent, sublicense, reverse engineer, or recreate the service except where mandatory law or written permission from MRC allows it.

10. Personal data and data protection

For personal data processed by MRC on behalf of the Customer, the Data Processing Agreement in part B applies.

MRC is an independent controller for certain processing of its own, such as customer relationship, account and agreement administration, billing, support, security, abuse prevention, and communication. Such processing is described in MRC's privacy policy for SummitHub.

11. Confidentiality

The parties shall protect confidential information received under the agreement and use it only to perform the agreement. Customer Data, participant information, security information, and non-public technical information shall be treated as confidential.

12. Limitation of liability

MRC is not liable for indirect loss, lost profit, loss of data, production loss, damage to reputation, email delivery failure, or consequential loss unless mandatory law provides otherwise.

MRC's total liability under the main agreement is limited to direct loss and to the amount paid by the Customer for the service during the twelve months preceding the event giving rise to the claim, unless mandatory law or a separate written agreement provides otherwise.

13. Term and termination

The main agreement applies from electronic acceptance, order, or other agreed start date and remains in force while the Customer has an active account, event, trial, or other right to use the service.

MRC may terminate or close the service in case of material breach, non-payment, security risk, abuse, prohibited use, or where continued provision would conflict with law or acceptable risk management.

14. Changes

MRC may update these terms. Material changes shall be notified to the Customer in an appropriate way. Continued use after the change has entered into force means that the Customer accepts the new version.

15. Governing law and disputes

The agreement shall be interpreted under Swedish law, excluding Swedish conflict-of-law rules. Disputes shall be settled by a competent Swedish court.

B. Data Processing Agreement

Agreement under Article 28.3 of Regulation (EU) 2016/679. This Data Processing Agreement is an integrated part of the main agreement for SummitHub and is accepted electronically together with the user terms.

1. Parties and roles

The Customer is controller for personal data entered into the service by the Customer or its users. MRC Collective AB is processor when MRC processes personal data on behalf of the Customer.

2. Subject matter and duration

Processing takes place to provide SummitHub, including conference publishing, registrations, participant management, sessions, choices, invitations, email notifications, support, operations, security, and administration.

Processing continues while MRC provides the service and thereafter for the time necessary for deletion, export, accounting, legal claims, or statutory obligations.

3. Categories of data subjects

Data subjects may include customer users, client admins, participant admins, participants, invited persons, contact persons, invoice recipients, and support contacts.

4. Categories of personal data

Personal data may include name, email address, organisation, role, language, registration data, session choices, food choices, allergies, special diets, invoice data, technical logs, IP address, user agent, and communication metadata.

5. Customer instructions

MRC processes personal data only according to the Customer's documented instructions, this agreement, the main agreement, and applicable law. The service functions, settings, and the Customer's use constitute ongoing instructions.

6. Security

MRC shall apply appropriate technical and organisational security measures considering risk, nature, scope, and purpose. Measures may include access control, encrypted communication, permission management, logging, backup, monitoring, and incident handling.

7. Subprocessors

The Customer authorises MRC to use subprocessors listed in Appendix 2. MRC is responsible for ensuring that subprocessors are bound by data protection terms materially corresponding to this agreement.

MRC shall inform the Customer of material changes to subprocessors. The Customer may object where there are objective data protection reasons.

8. International transfers

MRC strives to process data within the EU/EEA. If personal data is transferred outside the EU/EEA, MRC shall ensure a valid transfer mechanism, such as EU Standard Contractual Clauses and supplementary safeguards where required.

9. Rights and authorities

MRC shall assist the Customer, to the extent reasonable and possible, with data subject rights, supervisory authority contacts, impact assessments, and prior consultation under GDPR.

10. Personal data breaches

MRC shall notify the Customer without undue delay after becoming aware of a personal data breach involving the Customer's personal data and provide information reasonably required for the Customer's incident handling.

11. Confidentiality

MRC shall ensure that persons processing personal data are subject to confidentiality or an appropriate statutory duty of secrecy.

12. Deletion and return

On termination, MRC shall, at the Customer's choice and within a reasonable time, delete or return personal data processed on behalf of the Customer, unless continued storage is required by law or to handle legal claims.

13. Audit

MRC shall provide information reasonably required to demonstrate compliance with this agreement. Audits shall be conducted on reasonable notice and without compromising security, other customers' confidentiality, or MRC's operations.

Appendix 1 Instructions and processing specification

Service: SummitHub.

Purposes: conference and event administration, registrations, participant management, invitations, communication, invoice data, support, operations, and security.

Processing operations: collection, recording, storage, organisation, display, alteration, export, deletion, troubleshooting, and sending of service-related communication.

Appendix 2 Subprocessors

beebyte AB, Sweden: hosting, operations, database, server environment, and related infrastructure within the EU/EEA.

Postmark/ActiveCampaign LLC, United States: transactional email, invitations, account links, security codes, and system messages when email functionality is configured. Transfers outside the EU/EEA are protected by appropriate transfer mechanisms.

MRC Collective

© 2026 MRC Collective AB. All rights reserved.

Terms DPA Subprocessors Privacy policy License terms

Login

Enter the code for your account.

Use your SummitHub account to continue.