Privacy Policy
Last updated: 24 September 2026 · Version 2.1
Organisations and members. In short: This Privacy Policy is a separate document from the idbuddy Terms and Conditions of Service (available at idbuddy.io/terms), which govern organizations’ use of the platform. The policy is published in English, Swedish, Danish and French; in case of discrepancies between language versions, the English version prevails to the extent permitted by applicable law.
Your data, your control
We’re built around memberships, not around selling your attention. Here’s a plain-language summary of what we collect, why, and how you stay in control. The full legal text follows directly after the summary.
In a nutshell
We follow the EU General Data Protection Regulation (GDPR) and the Swedish Data Protection Act. Here’s what that actually means for you as a member or admin.
- We never sell your personal data. Your data is never shared with or sold to ad networks, data brokers or marketing partners. Full stop.
- Your data belongs to you. You can export, correct or delete your data. We respond within 30 days, free of charge.
- We collect only what we need. Name, email, membership status, the interactions the service records and, only if you choose to add it, your date of birth. A phone number or a further email address is there only if you add it, and each organisation gets only the one you choose for it. Postal addresses and similar are not part of a member profile at all.
- Two roles, the same protection. Sometimes we act as controller, sometimes as a processor for your organisation. Protection is identical and we explain the difference clearly.
- Your membership data stays in the EU/EEA. Our database, file storage and scheduled jobs run in an EU region. A short, named list of vendors processes some data elsewhere, and section 11 tells you exactly which and on what legal basis.
- No advertising, no profiling, no ad SDKs. We measure how the site is used only if you agree to it, and we check sign-ins for automated abuse. Section 17 lists every cookie and every third party your browser contacts.
- Encrypted in transit and at rest. TLS for all traffic, encryption at rest, least-privilege access and logging of administrative access.
- Human contact, and the right to complain. Email info (at) idbuddy.io. You always have the right to lodge a complaint with the Swedish DPA (IMY) if we don’t reach a resolution.
Which parts of this are about you
Organisations and members. In short: A member and an organisation are told different things here. This says which is which.
Two kinds of people read this policy, and what it says about them is not the same.
If you hold a membership in the app, you are a member. What we hold about you is your account in section 5.1, your memberships in 5.2, what you did with them in 5.3, and where an event took place in 5.4. Section 6 says where each of those sits, section 10 how long it stays, and section 14 what you can demand. Your own account is ours to answer for; everything inside an organisation's workspace is that organisation's, which section 4 explains and which decides who you ask. The member app has terms of its own at idbuddy.io/member-terms.
If you run an organisation on idbuddy, you and the administrators you appoint are a customer. What we hold about you is the account each administrator signs in with in section 5.1, what you sent us when you registered interest in 5.5, and the record of using the console in 5.6. Your agreement with us is the Terms and Conditions of Service, and the data processing agreement covers what we do with your members' data on your instructions.
Your members are not ours to answer for on your behalf. For them you are the controller and we are the processor, so section 4 and the data processing agreement set out what that puts on you.
1. Introduction and scope
Organisations and members. In short: Who we are, what this policy covers, and which laws we follow.
This policy explains how Byte Buddies AB (corporate ID 559491-4979), hereafter "idbuddy", "we" or "us", collects, uses, shares and protects personal data when you visit idbuddy.io or use the services hosted at app.idbuddy.io (member app) and admin.idbuddy.io (administrator tool). It also covers ops.idbuddy.io, the internal console our own staff use to operate the platform.
The policy also applies when an organisation that uses idbuddy adds you as a member. For the membership relationship the organisation is the primary data controller and we act as their data processor. Section 4 develops the two roles further.
We comply with Regulation (EU) 2016/679 ("GDPR"), the Swedish Data Protection Act (2018:218), the Electronic Communications Act (2022:482), and other applicable data-protection legislation.
For organizations using idbuddy, the processing of their Members’ personal data is further governed by Section 8 of the Terms and Conditions of Service (idbuddy.io/terms) and by the Data Processing Agreement (DPA).
2. Definitions
Organisations and members. In short: The GDPR vocabulary used in this policy, gathered in one place.
The following terms have the meanings set out in Article 4 GDPR:
- Personal data: any information relating to an identified or identifiable natural person.
- Processing: any operation or set of operations performed on personal data (collection, storage, alteration, retrieval, erasure, etc.).
- Controller: the entity that, alone or jointly with others, determines the purposes and means of processing.
- Processor: the entity that processes personal data on behalf of a controller.
- Sub-processor: a party engaged by us to process data on our behalf (e.g. cloud host).
- Third country: a country outside the EU/EEA.
- Data subject ("you"): the natural person whose personal data is processed.
- Special categories: sensitive data under Article 9 GDPR (health, ethnic origin, religion, sexual orientation, etc.).
3. Data controller and Data Protection Officer
Organisations and members. In short: Byte Buddies AB is responsible; our privacy team answers at info (at) idbuddy.io.
Byte Buddies AB is the data controller for the processing described in this policy where we determine the purposes and means ourselves. Our contact details are set out in the "Contact and complaints" section at the bottom of the policy.
We have not currently appointed a formal Data Protection Officer (DPO) under Article 37 GDPR. Privacy matters, including requests to exercise your rights, are handled by our privacy team and can be addressed to info (at) idbuddy.io. We undertake to appoint a DPO and update this policy accordingly if and when required.
4. Our two roles: controller and processor
Organisations and members. In short: For your own account we are the controller; for your membership in an organization we act only on that organization’s instructions.
idbuddy operates in two distinct data-protection roles depending on context:
- Controller: when you register your own account directly with us, browse our websites, contact our support, or receive marketing directly from us.
- Processor: when you are a member of an organisation that uses idbuddy as a tool. The organisation then determines the purposes and means; we process the data on their behalf under a data-processing agreement (Article 28 GDPR).
In the processor role we follow the organisation's documented instructions and inform you about the processing through them. Queries about such memberships are addressed primarily to the organisation. We forward requests without undue delay where required, and we assist the organisation to the extent Article 28(3)(e) demands.
5. What personal data we process
Organisations and members. In short: A member profile is a name, an email address, a picture and, if you choose to add it, your date of birth. Everything else is a record of something you did.
We process only the personal data necessary for the relevant purpose and apply the data-minimisation principle under Article 5(1)(c) GDPR. Depending on your role, the following categories may apply.
5.1 Account data
Your first and last name, your email address and, if you upload one, a profile picture. Your password is held by our authentication provider as a salted hash and is never visible to us. If you sign in with Google instead of a password, we also store the identity details Google returns to us about your account, such as the identifier Google uses for you and whether Google has verified your address.
You can add a date of birth. It is optional: you decide whether to enter it, and it is there so that an organisation you share it with can give you a birthday offer. You choose under What you share in your profile settings which of your organisations see it, unless an organisation requires it as a condition of membership, and you can remove it from your profile at any time. You can also add further email addresses, each confirmed by a link we mail to it before it counts, and phone numbers, and choose per organisation which address and which number it may use. There is no postal address or free-text note on a member profile: those fields do not exist in the platform, and an organisation cannot add them.
5.2 Membership data
Which organisations you are a member of, the display name that organisation knows you by, your role in that organisation and the date you joined. Your digital membership card and the QR code it shows. Where an organisation charges a membership fee, the record it keeps against your membership: the amount, the currency, the period it covers and whether the payment succeeded. For each membership, which of your name, email address and date of birth you have chosen to share with that organisation, which of them it requires, and which of your email addresses and phone numbers, if any, it may use.
5.3 Interaction data
What the service records when you use it. Each time your QR code is scanned we record who scanned it, for which organisation, when, whether the code was valid, what the scan was for and its outcome. So that the admin doing the scan can see who is in front of them, we also store a copy of your name as it stood at that moment. Your stamp cards and each individual stamp. Offers you have claimed. Which events you attended, whether an admin recorded that by scanning you at the door or added you to the list by hand. Newsletters an organisation has queued and sent to you, and, if you unsubscribed from one, that you did and when. Each membership also holds a random identifier that appears only inside that unsubscribe link, so pressing it says which membership you meant without asking you to sign in. Once a month, so that we can invoice the organisation, we also keep a count of how many of these things you did there, and in which month.
5.4 Data about events and places
If you administer an organisation, the events you create carry a venue name, a street address and map coordinates. Where you type an address, we look it up through a third-party geocoding service so the map can show the right place. Section 11 names the service.
5.5 Data you send us when you get in touch
If you apply for your organisation to join through the form at idbuddy.io/get-started, that form collects your name, your position, your email address, your phone number, your organisation's address, its invoicing details including a bank giro or bank account number where you provide one, and the plan you picked. What you send is stored in the platform as an application, which exists before your organisation does. Our staff read it to decide whether we can set you up, and we write back to the address you gave, either to say the organisation is ready or to say what we still need from you. Section 10 gives a period for an application whichever way it goes.
Anything you write to info (at) idbuddy.io or contact (at) idbuddy.io is separate from that: it sits in ordinary business email rather than in the platform, and we keep the correspondence.
We do not operate a chat service, we do not record calls, and we do not have a helpdesk system.
5.6 Technical data
We do not store IP addresses, device identifiers or browser fingerprints in our own database. Our hosting, database and bot-protection providers do process technical data of this kind in order to serve the site, keep it available and block automated abuse; section 11 names them and section 17 explains what runs in your browser.
5.7 Billing data for an organisation
An organisation on a paid plan gives us the details invoicing it takes. Four of them are required: its legal name, its address, and the name and email address of the person the invoice goes to. The rest are asked for and may be left blank: its organisation number and VAT number, that person’s phone number, its address, its bankgiro number, bank account number or IBAN and BIC, and an invoice reference in its own wording, which is a free-text field and is printed on the invoice. We also keep a record of every change to those details and to the chosen plan: who made it and when. For the details themselves we record only which fields moved, never the value before or after. For a change of plan we also record the plan on each side of it, because a figure on an invoice has to be explainable. An organisation that stays on the free tier is never asked for any of this.
6. Where your data is stored, and why
Organisations and members. In short: One EU database holds almost everything. This section names every other place a piece of your data goes, and what it is doing there.
Article 13(1) requires us to tell you who receives your data. We think you should also be able to see where it physically sits, so here is the map.
- Our database, in an EU region at Supabase. This is the system of record: accounts, including a date of birth where you have added one, memberships, membership cards, stamp cards, offers, offer claims, events, invitations, scan history, applications from organisations that want to join, the queue of newsletters to be sent and the billing details of organisations on a paid plan. It is there because the service cannot function without it, and it is in the EU because that is where our members are.
- File storage, in the same EU region at Supabase. Profile pictures, organisation logos and the images organisations upload for their member pages, events and offers. Stored so the apps can display them.
- Our email delivery provider, Resend. Every message the platform sends passes through it: sign-in links, password resets, invitations, replies to an organisation that has applied to join, and organisation newsletters. It receives the recipient's address, the name and reply address of the organisation sending, the subject and the message body, and it keeps delivery logs. Resend is a United States company; see section 12.
- Our application host, Vercel. The four idbuddy websites run there. Vercel processes the technical data that serving a web request involves, and it also provides the usage measurement and the sign-in bot protection described in section 17. Vercel is a United States company; see section 12.
- Google, only if you choose it. Pressing "Continue with Google" sends you to Google to sign in, and Google tells us your email address and basic account details in return. If you use a password instead, Google receives nothing.
- OpenStreetMap, for maps in the administrator tool. When an admin types an event address or views the events map, the address text and the map area are requested from OpenStreetMap servers. Members are not affected; this only happens in the admin tool.
- Our own mailbox. Correspondence with info (at) idbuddy.io and contact (at) idbuddy.io sits in ordinary business email rather than in the database above.
- Encrypted backups of the database, held by Supabase in the same region and overwritten on a rolling cycle.
We do not copy your personal data to any analytics warehouse, customer-data platform, advertising system or data broker, and we do not use it to train machine-learning models.
7. Where we get the data
Organisations and members. In short: Your data comes from you, from your organization, and from the way you use the service.
Article 14(2)(f) GDPR requires us to be transparent about the sources of personal data. We collect data from the following sources:
- Directly from you: when you register an account, update your profile, change settings, or contact us.
- Directly from you before you have an account at all: when you apply for your organisation to join through the form at idbuddy.io/get-started.
- From organisations that use idbuddy: when an organisation invites you to join it. We process this data in the processor role. An invitation records your email address before you have any account with us, and section 10 says how long we keep it.
- From your identity provider: if you sign in with Google, the name, email address and profile picture Google returns to us.
- Automatically through use: your interaction history is generated as you use the service, and our providers generate technical data as described in section 5.6.
8. Purposes and legal basis
Organisations and members. In short: Every purpose has a named legal basis; marketing from us always requires your consent.
We process your data for the following purposes, on the legal bases set out below per Article 6(1) GDPR. Where processing rests on legitimate interest (Article 6(1)(f)) we always perform a documented balancing test demonstrating that our legitimate interest is not overridden by your interests, rights and freedoms, and you can object at any time (see section 16).
- Delivering and maintaining the service (account, sign-in, membership card, check-ins): contract, Art. 6(1)(b).
- Sending system notices related to your account (sign-in links, password resets, change notifications, security alerts): contract, Art. 6(1)(b).
- Sending newsletters and marketing from idbuddy: consent, Art. 6(1)(a). You can withdraw your consent at any time, from your communication settings in the app or through the unsubscribe link in every marketing email, and we act on it immediately.
- Sending newsletters and offers from your organisation: the organisation decides the legal basis for its own mailings, and we act on its instructions as processor. In either case you can stop them, from your communication settings or from the unsubscribe link in the message.
- Handling support and service requests: contract or legitimate interest, Art. 6(1)(b) and (f).
- Deciding on an application to join, and building the organisation from what it says if we approve it: steps taken at your own request before any contract exists, Art. 6(1)(b). Keeping a record of what was decided and when rests on legitimate interest, Art. 6(1)(f).
- Preventing fraud, abuse and security incidents, including automated checks on sign-in and account creation: legitimate interest, Art. 6(1)(f). Our interest is to protect you and the service. Section 18 explains this check and how to have a decision reviewed.
- Measuring how our websites are used so we can improve them: consent, Art. 6(1)(a), on aggregated measurement only. Section 17 explains what is collected, and nothing is measured unless you say yes.
- Improving and developing the service through aggregate statistics and troubleshooting: legitimate interest, Art. 6(1)(f), with pseudonymisation where possible.
- Meeting legal obligations (bookkeeping, tax, responding to authorities): legal obligation, Art. 6(1)(c). Swedish Bookkeeping Act (1999:1078) and others.
- Meeting legal claims and asserting or defending our rights: legitimate interest, Art. 6(1)(f).
- Marketing idbuddy to admins at existing organisations (B2B): legitimate interest, Art. 6(1)(f), with a right to object.
- Working out what an organisation owes us, and being able to show it a breakdown of a past invoice: legitimate interest, Art. 6(1)(f). Our interest is to charge correctly and to answer a query about a charge. We count what happened, per month, and we do not use it for anything else.
- Invoicing an organisation and keeping the record of who changed its billing details: contract with that organisation, Art. 6(1)(b), and legitimate interest, Art. 6(1)(f), in the part that concerns the individual named as its contact. Our interest is to invoice the right party and to be able to show who changed a payment detail.
9. Special categories and children's data
Organisations and members. In short: We never ask for sensitive data, and we do not read what organisations write. If your membership list is sensitive by its nature, section 9.2 is written for you.
9.1 Special categories under Article 9
We do not ask for, and the platform has no field for, any of the special categories listed in Article 9 GDPR: health, racial or ethnic origin, political opinions, religious or philosophical belief, trade-union membership, genetic or biometric data, sex life or sexual orientation. A member profile holds a name, an email address, a picture and, if you add them, a date of birth, further email addresses and phone numbers.
Our Terms prohibit organisations from uploading or processing special-category data unless a valid exception applies (Section 10.1). You should know exactly how far that goes, because the honest answer matters more than a reassuring one:
- We do not inspect the content organisations write into their own fields. There is no scanning, no classifier and no detection, so we cannot promise to find such data on our own.
- We act on reports. If you tell us, or if we otherwise become aware, that an organisation is processing special-category data in breach of our Terms, we investigate, require the organisation to remove it, and notify the organisation.
- We can enforce it. We are able to switch off individual capabilities for a single organisation, including its ability to send messages, and to suspend or terminate access entirely. We do this where an organisation will not correct a breach.
- The organisation remains the controller. Where an organisation puts special-category data into idbuddy, that organisation, not idbuddy, has to have an Article 9 condition for it.
9.2 When membership itself is sensitive
Some memberships reveal a special category simply by existing. Belonging to a faith community, a trade union, a political association or an LGBTQ organisation reveals religion, union membership, political opinion or sexual orientation, and the Court of Justice has confirmed that data which reveals such information indirectly is still caught by Article 9 (Case C-184/20).
If you are an organisation of that kind, treat your whole membership list as Article 9 data, identify your condition under Article 9(2), which for a non-profit association is usually Article 9(2)(d), and keep your list inside the organisation. We support that by not exposing member lists to other organisations and by letting you turn off your public discoverability.
9.3 Children
The Service is not directed at children under 13, and we do not market to children. Workspace administrators must be at least 18 years old (see our Terms).
Where consent is the legal basis, the age at which a child can consent for themselves differs by country: 13 years in Sweden under Chapter 2, Section 4 of the Swedish Data Protection Act (2018:218), and between 13 and 16 years elsewhere in the EU/EEA under Article 8(1) GDPR. Below that age, the consent has to be given or authorised by the holder of parental responsibility.
Where an organisation adds members who are minors, the organisation, as data controller, is responsible for complying with Article 8 GDPR and the age threshold that applies to it, including obtaining parental consent where required. idbuddy does not verify anyone's age. A date of birth on a profile is optional, entered by the member and used for birthday offers, and an organisation sees it only where the member shares it or the organisation requires it; we do not use it to assess age or to decide who may join, so an organisation that enrols minors has to handle the age check outside the platform. If we become aware that we have collected personal data from a child without a valid legal basis, we will delete it as soon as reasonably practicable.
10. How long we keep your data
Organisations and members. In short: A period for every category, not a vague promise. When the period ends we delete or anonymise.
We keep personal data only as long as necessary for the purpose for which it was collected, or as required by law. The periods below apply to our own processing as controller. Where we act as processor, your organisation as controller decides how long its membership data is kept, and it can instruct us to delete sooner.
- Email addresses added to a profile but never confirmed: 7 days.
- Account data, including a date of birth you have added: for as long as your account exists, or until you remove the date of birth yourself. If you have not signed in for 24 months we contact you, and if you do not return we delete or anonymise the account.
- Membership data: for as long as the membership lasts, and 12 months afterwards, unless your organisation instructs us otherwise. If you leave an organisation yourself, your cards, stamps and activated offers there go at once and your name comes off its scan history.
- Membership fee records an organisation keeps against you: for the period that organisation's own accounting law requires. For a Swedish organisation that is seven years under Chapter 7, Section 2 of the Bookkeeping Act (1999:1078).
- Check-in, stamp and offer history: 24 months from the interaction, or 12 months after the membership ends, whichever comes first.
- Newsletter dispatch records: 12 months from sending.
- Evidence that you gave marketing consent: for as long as the consent lasts and 24 months afterwards, so that we can show it existed.
- A record that you objected to marketing or unsubscribed: kept for as long as your account exists, and not lifted by rejoining an organisation or by a later import. This is the only way we can keep honouring it. Erasing your account removes the record together with the address it protected.
- Invitations that have been accepted, revoked or have expired: 30 days, then deleted.
- An application to join that nobody has decided: until it is decided, and at most 60 days, after which it is marked as timed out and kept as long as a declined one.
- An application we declined, or one that timed out: 12 months from that point, then deleted.
- An application we approved: your name, your position, your email address and your phone number are cleared from it as soon as the organisation exists, because from then on you hold an owner membership or an invitation to take one. What is left is the organisation's own details and the record of the decision, and it is deleted when the organisation is.
- Replies we sent you about an application: 90 days from sending.
- Correspondence with our support: 24 months after the matter is closed.
- Our own bookkeeping records: seven years under the Bookkeeping Act (1999:1078).
- Security logs, including sign-in and administrative access: 12 months, or longer while an incident is under investigation.
- Operational and troubleshooting logs: 30 days.
- Encrypted backups: overwritten on a rolling cycle of no more than 35 days.
- The monthly count of what you did at an organisation, held so we can invoice it: 24 months, after which only the organisation's totals remain and they no longer say who was counted.
- An organisation's billing details: for as long as the organisation has a paid plan, and seven years afterwards under the Bookkeeping Act (1999:1078).
- An issued invoice or credit note: seven years under the Bookkeeping Act (1999:1078). It freezes a copy of the billing details as they stood when it was issued, including the name and email address of the contact, and it is never rewritten. Deleting the workspace does not delete it; it only cuts the link between the two.
- The record of who changed an organisation's billing details or plan: 24 months. It holds the name as it stood at the time, so it outlives the account of the person who made the change; deleting that account cuts the link to it but leaves the name until the 24 months are up.
When a period ends we delete the data or anonymise it so that it can no longer be linked to you.
11. Recipients and sub-processors
Organisations and members. In short: Six named vendors, what each one does, and where it sits. Never advertisers or data brokers.
We share data with the vendors needed to operate the service. All are bound by data-processing agreements under Article 28 GDPR and by confidentiality and security obligations. We only engage providers that offer sufficient guarantees of GDPR compliance. The current list is:
- Supabase Inc. (United States), with our project provisioned in an EU region. Database, authentication, file storage and scheduled jobs. This is where your account, membership and interaction data lives.
- Vercel Inc. (United States). Hosting for idbuddy.io, app.idbuddy.io, admin.idbuddy.io and ops.idbuddy.io, plus the aggregated usage measurement and the sign-in bot protection described in section 17.
- Resend, Inc. (United States). Delivery of every email the platform sends. Message content and recipient addresses pass through it and its delivery logs and message metadata are held in the United States.
- Google Ireland Limited, with Google LLC (United States) as its sub-processor. Only where you choose "Continue with Google" to sign in.
- OpenStreetMap Foundation (United Kingdom). Address lookup and map tiles in the administrator tool. Marker images for those maps are served from a public code distribution network operated by Cloudflare, Inc. (United States).
- A hosted business email service for correspondence with info (at) idbuddy.io and contact (at) idbuddy.io.
We do not use advertising networks, data brokers, customer-data platforms or third-party analytics products beyond the aggregated measurement named above.
Before we engage a new sub-processor we perform a risk assessment, ensure a valid legal basis for any third-country transfer, and inform our customers in good time so they can object. Organisational customers can find the authoritative list, and the mechanism for objecting to a change, in the DPA, published at idbuddy.io/dpa; a copy is also available free of charge from info (at) idbuddy.io.
12. Transfers outside the EU/EEA
Organisations and members. In short: Your membership data sits in the EU. Some named vendors are US companies, and each transfer has a legal basis we can show you.
Your account, membership and interaction data is stored in an EU region, and our own staff access it from Sweden. Several of the vendors in section 11 are established outside the EU/EEA, so some processing reaches a third country. Where it does, it happens only on one of the following grounds under Articles 44 to 49 GDPR:
- Adequacy decision (Article 45). The United Kingdom is covered by an adequacy decision, which is the basis for the OpenStreetMap processing in section 11.
- European Commission Standard Contractual Clauses (Article 46), supplemented with technical and organisational safeguards: encryption in transit and at rest, access controls and transparency undertakings. This is the basis for Supabase, Vercel, Resend and Cloudflare.
- The EU-US Data Privacy Framework, where the vendor is certified under it and the processing falls within its scope.
We carry out a Transfer Impact Assessment before initiating a new third-country transfer to ensure the level of protection is essentially equivalent to that of the EU. You can request current information on transfers via info (at) idbuddy.io.
13. Disclosure to public authorities
Organisations and members. In short: Authorities receive data only when the law compels it, and we review every request first.
We disclose personal data to Swedish or foreign public authorities only when required by law, a court order, or a binding order from a competent authority.
Every request is formally and legally reviewed before any disclosure, and we keep a record of the requests we receive and how we handled them. Where the law permits, we notify the data subject. We challenge requests that fail to meet legal requirements, are disproportionate, or lack a legal basis.
14. Your GDPR rights
Organisations and members. In short: Access, correct, delete, export, object. All free of charge, answered within 30 days.
You have the following rights under Articles 15–22 GDPR. We handle every request free of charge and respond within 30 days (extendable by two months in complex cases, in which case we will tell you the reason).
- Right to be informed (Art. 13–14): to know what data we process and why. This policy fulfils the bulk of that.
- Right of access (Art. 15): a copy of the personal data we hold about you, including your interaction history.
- Right to rectification (Art. 16): correct inaccurate or complete incomplete data.
- Right to erasure (Art. 17): ask us to delete your data where no legal basis remains. Some exceptions apply, such as our bookkeeping obligations and the record of a marketing objection described in section 10.
- Right to restriction (Art. 18): pause processing while a complaint is investigated or accuracy is contested.
- Right to data portability (Art. 20): receive your data in a structured, machine-readable format and transfer it to another controller.
- Right to object (Art. 21): to processing based on legitimate interest or direct marketing.
- Right not to be subject to fully automated decisions (Art. 22) producing legal or similarly significant effects. See section 18.
- Right to withdraw consent (Art. 7.3): withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Where we hold the data as processor for an organisation, we forward your request to that organisation and help it respond.
15. How to exercise your rights
Organisations and members. In short: Email us, or use the privacy settings in the app.
Requests to exercise any of the rights in section 14 are made most easily via:
- Email: info (at) idbuddy.io, stating clearly which right you are invoking.
- Logged in to the service: your account settings offer self-service for exporting your data, managing your communication preferences and deleting your account. If you are the owner or the only administrator of an organisation, hand that organisation over first, so that it is not left with nobody able to run it.
To protect you from identity theft we may need to verify your identity (e.g. by an existing sign-in or other reasonable check). If we cannot identify you we may decline to act on the request under Article 11(2).
If you are a member of an organisation and your request concerns that membership, we may need to forward the request to the organisation that is the data controller.
16. Direct marketing and right to object
Organisations and members. In short: One objection stops all direct marketing from us, permanently.
You have an unconditional right under Article 21(2) GDPR to object to the processing of your personal data for direct-marketing purposes. The objection is honoured without delay and without you needing to state a reason.
We keep a record of everyone who has objected to marketing. It is checked before a message is queued and again before it is sent, it applies across our systems, and it is never lifted automatically, not by a later import and not by rejoining an organisation.
- Marketing from idbuddy: use the unsubscribe link in any marketing email, change your communication settings in the app, or email info (at) idbuddy.io.
- Mailings from an organisation you are a member of: use the unsubscribe link in the message, or turn its email address off under What you share in your profile settings. Both record the same objection. You can also contact the organisation directly.
17. Cookies, local storage and similar technologies
Organisations and members. In short: No advertising or cross-site tracking. Here is every cookie, every browser storage entry and every third party your browser is asked to contact.
Chapter 9, Section 28 of the Swedish Electronic Communications Act (2022:482) covers anything stored in or read from your device, not only cookies, so this section lists both.
17.1 Strictly necessary
These are set without consent because the service cannot work without them.
- idbuddy.locale: a first-party cookie, and a matching entry in your browser's local storage, that remembers your language for 12 months. It is scoped to idbuddy.io so your choice carries across our subdomains.
- The Supabase Auth session cookie, named after our project and sometimes split across two entries. It keeps you signed in and is currently set for a long-lived session, up to 400 days; signing out removes it.
- pending_invite_id and pending_invite_link_id: first-party cookies that live for 5 to 10 minutes and carry the invitation you clicked through the sign-in round trip, so you land in the right organisation.
- idbuddy_admin_selected_company: a local-storage entry in the administrator tool that remembers which organisation you last had open. It is written when you first open the tool and stays until you clear your browser storage.
- Cookies beginning KP_, set by our bot-protection provider when a sign-in is checked. See section 18.
- idbuddy_terms_ok: a first-party cookie holding the identity of a signed-in person who has already accepted the current terms and privacy policy, so the check does not run on every request. It lasts one hour and is not readable by scripts.
- idbuddy_consent: a first-party cookie holding your answer to the usage measurement question in 17.2. It lasts 180 days and is only set once you answer.
17.2 Usage measurement
We measure how our websites are used with Vercel Web Analytics. It reports which page was viewed and basic technical details of the request to Vercel, and it does not set a cookie or build a profile of you. We use it in aggregate to see which pages people need and where they get stuck.
This runs only if you accept it. Nothing is loaded before you answer, and declining or ignoring the question leaves it switched off. Your answer is kept in the idbuddy_consent cookie in 17.1, and the panel that asked can be reopened at any time to change it. If your browser sends a Global Privacy Control signal we take that as a refusal and do not ask. Before any event is sent, the page address is stripped of every identifier and token and of the whole query string, so an address inside the member app no longer says which organisation it belonged to. Our cookie policy at idbuddy.io/cookies sets all of this out in full.
17.3 What we do not do
We do not set advertising, profiling or cross-site tracking cookies. We do not embed advertising SDKs, social media pixels, session recorders or heatmap tools. We do not load web fonts from a third party. Every font is served from our own domain.
You can clear cookies and site data at any time via your browser settings; you may need to sign in again afterwards.
18. Automated decisions and profiling
Organisations and members. In short: One automated check runs when you create an account, to keep bots out. If it blocks you, try again or use Google, which does not pass through it. Signing in is never refused on its verdict.
We do not profile you, score you, rank you or segment you as an individual on the basis of your behaviour, and we do not sell or share any such data. There is no advertising or recommendation model in the product.
There is one automated check. When you sign in or create an account, our bot-protection provider assesses the request, looking at the browser and device characteristics and the pattern of the request rather than at who you are, and returns a verdict on whether it came from an automated client. If the verdict is that it did, the account creation is refused. A sign-in is assessed the same way but is never refused on the verdict, so the only request this check can stop is the creation of an account. This is the only automated decision in the service that can affect your access to it.
If you are refused, the screen says so and you can try again straight away, or create the account with Google, which does not pass through the check. We do not review refusals one by one, because that route out of a wrong one is open immediately. What we keep instead is a record of each refusal: the time, which of our sites it happened on, and the domain of the email address used, never the address itself, so that a run of wrong refusals shows up. If it keeps refusing you, write to info (at) idbuddy.io and a person will look at what that record shows and complete the registration for you. That is the human intervention Article 22(3) reserves for you, and we would rather hear about a false positive than lose you to one.
Aggregate statistics and segmentation are used only to:
- Help your organisation understand its own membership, for example how many members it has and how many stamps have been issued.
- Troubleshoot and monitor the performance of the service.
- Improve our product.
19. Anonymisation and aggregate data
Organisations and members. In short: Data that can no longer identify you may be kept for long-term statistics.
We anonymise personal data when it is no longer needed for identifying purposes. Properly anonymised data is outside the scope of the GDPR (Recital 26) and may therefore be used for long-term statistics and product development without being linked back to you.
Where full anonymisation is not possible we reduce what identifies you: for example, when the retention period for your check-in history ends, the record of the interaction can be kept for statistics with your name and your account reference removed, so that neither we nor the organisation can trace it back to you.
20. Security and data breaches
Organisations and members. In short: Encryption, least-privilege access and access logging; if a breach puts you at risk, we notify you and IMY.
We apply appropriate technical and organisational measures under Article 32 GDPR, taking into account the state of the art, costs of implementation, the nature and scope of the processing and the risk to your rights and freedoms. Examples:
- TLS 1.2 or higher for all traffic in transit, and encryption at rest for the database, file storage and backups.
- Row-level security in the database, so that an organisation's data is reachable only by that organisation, enforced by the database itself rather than by application code.
- Every write to the platform goes through a checked server-side function rather than a direct database write from the browser.
- Access by our own staff is governed by the principle of least privilege, protected by two-factor authentication, and logged.
- Regular security reviews, and penetration testing of the platform.
- Encrypted, geographically separated backups.
- Staff are trained in data protection and bound by confidentiality.
In a personal data breach likely to result in a risk to your rights and freedoms, we will notify IMY within 72 hours per Article 33 GDPR. Where the risk is high under Article 34, we will notify you directly by email, describing the scope, likely consequences and the measures we have taken or recommend you take.
21. Changes to this policy
Organisations and members. In short: Material changes are announced at least 30 days in advance.
We may update this policy to reflect changes in law, new services, or improved practice. The date at the top reflects the most recent revision.
For material changes affecting your rights or expanding our processing, we will notify you by email at least 30 days before the change takes effect, and the next time you sign in we ask you to accept the new version before the service opens. For non-material changes (language edits, typo fixes) the updated version applies from the publication date.
Earlier versions of the policy can be requested at info (at) idbuddy.io.
22. Complaints to the supervisory authority
Organisations and members. In short: Not satisfied? You can always complain to IMY or your local supervisory authority.
We appreciate hearing from you directly if something feels wrong. Write to info (at) idbuddy.io and we will resolve it promptly. You always have the right under Article 77 GDPR to lodge a complaint with the supervisory authority, in parallel or without contacting us first.
In Sweden this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY). If you live or work in another EU/EEA country you may also contact the supervisory authority there.
- Postal address: Box 8114, 104 20 Stockholm, Sweden
- Email: imy (at) imy.se
- Website: imy.se
Contact and complaints
Questions about how we handle your personal data, or want to exercise any of your rights? Get in touch. We respond within 30 days. If you believe we have processed your data in breach of the GDPR, you also have the right to lodge a complaint with the supervisory authority.
Data controller
Byte Buddies AB
Corp. ID 559491-4979
Malmö, Sweden
Supervisory authority
Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm, Sweden
imy (at) imy.se · imy.se