Privacy Policy for Vepino
How personal data inside Vepino is handled — for you as a customer, participant or guest.
Introduction
Human Syntax AB
This Privacy Policy describes how Human Syntax AB (“Vepino”, “we”, “us”) processes personal data in connection with the Vepino service — our platform for event management and related communication. The policy covers:
- Our web service for organisers
- Our mobile application for check-in (iOS and Android)
- Public registration pages and event pages
- Email campaigns and SMS delivered via Vepino
Vepino is a service from Human Syntax AB. As data controller, Human Syntax AB is the entity you turn to for data protection matters related to Vepino.
For questions concerning Human Syntax AB’s own company operations outside Vepino (e.g. visitors to humansyn.tax, prospects or supplier contacts), see our separate Privacy Policy.
1Data controller
| Field | Value |
|---|---|
| Company name | Human Syntax AB |
| Registration number | 559316-1853 |
| Address | Rönnowsgatan 8C, 252 25 Helsingborg, Sweden |
| Contact | privacy@humansyn.tax |
Human Syntax is not required to appoint a Data Protection Officer under Article 37 GDPR. Contact for data protection matters is via privacy@humansyn.tax.
2Who is data controller for what
Vepino is used by organisers who process the personal data of their own guests, participants and recipients. Data controller responsibility is therefore distributed as follows.
2.1We (Human Syntax AB) are data controllers for:
- Organisers’ accounts, user data and login credentials
- Invoice and payment data with the organiser
- Operational and security logs for the Service
- Our own marketing to organisers and prospects (see HS Privacy Policy)
2.2The organiser is data controller for:
- Participant data (invited, registered, checked in)
- Distribution lists and contact data for marketing or newsletters
- Custom fields the organiser chooses to collect
- Content of campaigns and event pages
For this category we act as data processor under the organiser’s instruction in accordance with our Data Processing Agreement (DPA, Annex C with appendices) with the organiser.
2.3If you have received a campaign or been invited via Vepino
If you have received an email campaign, an event invitation or an SMS delivered via Vepino: the sender — not Vepino — has decided to contact you and is the data controller for that processing. Vepino provides the technical infrastructure for delivery, registration and communication.
For information about why you received the campaign, how long your data is retained, what legal basis is invoked and how to exercise your rights — turn to the sender. The sender’s contact details and privacy policy can normally be found in the campaign or on the registration page.
For questions about Vepino’s technical processing as processor, you can contact privacy@humansyn.tax. We normally forward such questions to the sender as the data controller.
3Data we process
3.1About you as organiser or user (logged in to Vepino)
- Name and email address
- User ID and authentication data (one-time code via email or federated login via SSO — see §6.3)
- Associated workspaces and organisation affiliation
- Settings (language, Live/Demo environment, etc.)
- Usage data (logins, activity, IP address, browser and operating system, timestamps)
3.2About participants, invitees and campaign recipients
As processor for the organiser we process the data the organiser chooses to collect or import. This typically includes:
- Name
- Email address
- Mobile number (if relevant)
- Company and role/title (in professional context)
- Custom fields created by the organiser (may in some cases contain special categories under Article 9 GDPR — see 3.4)
- Check-in data (time, status, attendance)
- Payment confirmation for paid events (Swish reference, invoice reference)
- Engagement data per campaign (delivery, opens, clicks, bounces, unsubscribes)
A complete and structured list is available in Annex C Appendix 1A — Record of Processing Vepino.
3.3About you as visitor to a Vepino-hosted registration page
When you visit an event or registration page operated on Vepino’s infrastructure, we technically log:
- IP address
- Browser and operating system
- Timestamp, pages visited, referrers
This takes place as processor for the organiser and is used for security, troubleshooting and statistics.
3.4Custom fields and special categories (Article 9 GDPR)
Vepino allows the organiser to create custom fields for participant registration. These may contain special categories of personal data under Article 9 GDPR depending on the organiser’s design — for example:
- Food allergies or dietary preferences (health)
- Disabilities or accessibility needs (health)
- Religion or belief (diet, holidays)
- Other data covered by Article 9
It is the organiser’s responsibility to obtain explicit consent under Article 9(2)(a) or another applicable basis for processing special categories.
4The mobile application for check-in
Vepino Check-In is our mobile app for iOS and Android used for on-site check-in of participants.
4.1Data stored locally on the device
- Authentication tokens in encrypted storage (iOS Keychain and Android Keystore respectively)
- Local cache of event and participant data to enable offline mode
- Device identifiers for paired Bluetooth printers (locally on the device)
- Diagnostic logs (stored locally; not sent automatically from the device, but a user can choose to share them manually with support for troubleshooting purposes)
All local data is deleted on logout or uninstall.
4.2No ad networks, analytics or tracking
The app contains no ad networks, analytics tools or third-party libraries that collect data for marketing or tracking purposes.
4.3Secure communication
All communication between the app and the Vepino backend takes place via HTTPS (TLS 1.2 or later). Authentication tokens are deleted from the device on logout and invalidated server-side so they can no longer be used for access.
5How we collect data
- Directly from you when you register, log in, fill in forms or use the Service
- From the organiser when they import or create lists in Vepino
- Automatically via cookies and similar technologies on our website and registration pages (see Cookie Policy)
- From identity providers at SSO login (see §6.3)
- Automatically through operation of the Service (server logs, engagement data)
6Recipients and subprocessors
6.1Subprocessors for the Vepino service
We use the following data processors to operate Vepino:
- Oderland Webbhotell AB (Sweden) — hosting and operation
- AC PM LLC (operator of Postmark, subsidiary of ActiveCampaign) — outgoing email for campaigns initiated by the organiser
- Amazon Web Services EMEA SARL (Amazon SES) — outgoing email for campaigns initiated by the organiser
- Microsoft Ireland Operations Limited (Microsoft 365) — office tools we use for support cases, customer correspondence and file storage (Exchange/Outlook and OneDrive/SharePoint) where personal data from the Service may occur. Microsoft also appears as an independent data controller for SSO login, see §6.3.
A complete and current subprocessor list is available in Annex C Appendix 2 — Subprocessors.
6.2SMS provider (independent data controller)
SMS delivery is mediated via 46elks AB (Sweden), a Swedish telecommunications operator. 46elks acts as an independent data controller for traffic data under the ePrivacy Directive and the Swedish Electronic Communications Act (LEK), not as a subprocessor to Vepino.
6.3Identity providers for SSO login
When the Customer chooses federated login (Single Sign-On), the following identity providers handle authentication data as independent data controllers, not as subprocessors to Vepino:
- Google Ireland Limited (Sign in with Google)
- Microsoft Ireland Operations Limited (Sign in with Microsoft)
- Apple Distribution International Ltd. (Sign in with Apple — available in beta)
For EU-based end users, each Irish company is the data controller in accordance with the provider’s terms. No third country transfer occurs via the SSO mechanism.
6.4Third country transfers
We use subprocessors both within and outside the EU/EEA. For transfers to third countries (USA), the EU-U.S. Data Privacy Framework applies primarily, and Standard Contractual Clauses under EU Commission Decision 2021/914 as backup. Detailed information about each subprocessor, place of processing and applicable mechanism is available in Annex C Appendix 2. Otherwise our primary processing takes place within the EU/EEA.
6.5Authorities
We may disclose personal data to authorities where required by law.
7Retention periods
| Category | Retention period |
|---|---|
| Organiser’s account and data in the Service during active subscription | For the duration of the agreement |
| Organiser’s account and data in the Service after termination of the agreement | 30-day read and export period, total erasure within 90 days of termination of the agreement |
| Business data and contact information about the organiser (contact persons, correspondence, contract documents) | According to HS Privacy Policy |
| Participant data processed as processor | According to the organiser’s instruction and contract |
| Invoice and accounting material | 7 years under Bokföringslagen (Swedish Accounting Act) |
| Server logs and security logs | 6 months |
| Local data in the mobile app | Deleted on logout or uninstall |
8Security
We take appropriate technical and organisational measures to protect personal data against loss, alteration, unauthorised access or unauthorised disclosure. Measures include, among others:
- Encryption in transit (TLS 1.2 or later)
- Encrypted storage of authentication tokens on mobile devices
- Access control and role-based permissions in the backend
- Secure hosting environment with a Swedish operator
- Regular backups with strict separation between production and development environment
9Your rights
Under GDPR you have the following rights:
- Right of access to the personal data we process about you
- Right to rectification of incorrect data
- Right to erasure in certain circumstances (“the right to be forgotten”)
- Right to restriction of processing
- Right to data portability for data you have provided and that we process based on consent or contract
- Right to object to processing based on legitimate interests, including direct marketing
- Right to withdraw consent when processing is based on consent
To exercise any of these rights, contact us at privacy@humansyn.tax. We respond to your request without undue delay and at the latest within one month.
If your request is particularly complex or extensive, the response time may be extended by up to two months. In that case we will inform you of the extension and the reasons for it within one month from when we received your request.
Note: If you are a participant or recipient of a campaign via Vepino where the organiser is data controller, you should normally turn to the organiser to exercise your rights. See §2.3 above.
10Complaints to the supervisory authority
If you believe that we are processing your personal data in violation of applicable data protection legislation, you have the right to lodge a complaint with the supervisory authority. In Sweden, this is Integritetsskyddsmyndigheten (IMY / Swedish Authority for Privacy Protection): imy.se.
11Children's privacy
Vepino is aimed at organisers and their professional recipients. The Service is not intended for children under 13, and we do not knowingly collect personal data from children.
12Changes to this policy
We may update this Privacy Policy from time to time. The current version is always published on vepino.com with a clearly stated update date. For significant changes we mark this visibly on the website and also communicate with registered organiser users via email.
13Contact
Human Syntax AB
Rönnowsgatan 8C, 252 25 Helsingborg, Sweden
Email: privacy@humansyn.tax
Website: https://vepino.com